Privacy

ProZvonki Privacy Policy

ProZvonki is an Android dialer. The app works with sensitive data: calls, contacts, call log and work notes. This policy explains what is processed on your device, what is sent and to whom, on what legal basis, and how you stay in control.

Last updated: August 25, 2026.

1. Who processes the data

The ProZvonki app (package ru.prozvonki.phone, the “app”) is distributed via Google Play and RuStore. The data controller and contact point for privacy matters is the app's developer — UnGooD (developer name on Google Play), reachable at pro.zvonok@yandex.ru.

2. Core principle: data stays on your device

Unlike many caller-ID apps, ProZvonki does not upload your address book to the cloud and does not build a shared database from users' contacts. The main information is stored only on your device and is not sent to us or third parties:

  • call log, contacts and favorites;
  • call comments, tags, importance and statuses;
  • block and allow lists of numbers;
  • CRM client cards, tasks and reminders;
  • call recordings (when created by the system) and app settings.

This data is used locally to show the call log, contacts, statistics and cards. You can save a backup to a .prozbak file and protect it with a password — the file stays under your control.

3. What data leaves your device

A limited set of data is sent from the device for analytics, stability and spam protection:

  • Analytics (AppMetrica, by Yandex). Anonymized app-interaction events (screens opened, taps, bucketed counters — no phone numbers, names or comment text), plus technical device identifiers, app and OS version, crash and diagnostic information.
  • Cloud services (Firebase, by Google). Used to verify app authenticity (App Check / Play Integrity) and to power the number-reputation database (see section 4).

We do not sell your data and do not share it with third parties for their own advertising purposes. Analytics and cloud providers process data on our behalf.

4. Unwanted-number reputation database

To warn you about spam, scammers and unwanted calls, the app uses a shared number-reputation database. When you report a number, or the app checks an incoming number, the following is sent to the cloud (Firebase):

  • an irreversible hash of the number (SHA-256 with a secret salt) — the full number is never sent or stored;
  • the last 4 digits of the number and the country code;
  • the report category (e.g. spam, scammer, robot) and the source type;
  • a random installation identifier (to prevent duplicates) and the app version.

This data is anonymized and not linked to your identity or any account. It is used only for fraud and unwanted-call protection.

5. Optional features you enable yourself

Some features are off by default and work only if you configure them. In that case data is sent to systems that you specify:

  • Cloud PBX integration. If you enter your PBX address and token, the app exchanges call data, including phone numbers, with your server. Data goes to a server you control.
  • Call reports by email. If you set up your own mail account (SMTP), call reports — including phone numbers, contact names, call times and durations — are sent to the address you specify through your mail service.
  • Forwarding incoming SMS to email (RuStore version only, beta). Available exclusively in the RuStore build, enabled manually, and sends SMS to an email address you specify. This feature does not exist in the Google Play version.

In these cases the recipient of the data is the service you choose, not the app developer.

5.1. Protect Loved Ones

This feature is off by default and is configured by the phone owner with their consent. To provide it, the app processes the following locally:

  • the names and numbers of one to three selected trusted contacts;
  • warning intervals, feature state and the state of unknown-call blocking;
  • the settings PIN as a cryptographic derivative with an individual salt — the plaintext PIN is not stored;
  • the TOTP secret used by an authenticator and backup codes. Security secrets are kept in protected app storage using Android Keystore.

Contacts. Access is used on the device to distinguish saved contacts from unknown numbers and to exempt trusted people and emergency numbers from blocking. The address book and selected trusted numbers are not uploaded to the developer or an external database.

New incoming SMS. When protection is enabled, the app may inspect only a newly received message to identify signs of a one-time password (OTP), or a message from a trusted number during a protected call. The app does not request READ_SMS, does not read SMS history, does not store or upload the inspected message content and does not write it to diagnostic logs.

Outgoing safety SMS. The app may automatically send selected trusted people an alert, call duration, the unknown party's number and instructions. No unlock code is sent in the SMS. The message is delivered through the mobile carrier and may be charged under the SIM plan; its recipient is the trusted person selected by the phone owner.

Authenticator and unlocking. The six-digit code is generated locally by an authenticator on the trusted person's phone and requires no internet connection. A previously saved one-use backup code can be used instead. The settings PIN cannot unlock calls.

When emergency blocking is triggered, the app locally retains the required protection settings and cryptographic number identifiers so it can allow previously saved contacts while blocking unknown numbers. This information stays in private app storage and is removed when app data is cleared or the app is uninstalled. See the setup guide for details.

6. App permissions

The app requests permissions only for its dialer features:

  • Phone, call log, phone state — to make and receive calls, show the call log and act as the default dialer;
  • Contacts — to show names, favorites and speed dial, and optionally to save contacts;
  • Receiving new SMS — to detect an OTP or a message from a trusted person when Protect Loved Ones is enabled, without reading message history;
  • Sending SMS — for safety alerts to trusted people and other SMS features enabled by the user;
  • Microphone — for talking during a call;
  • Notifications, full-screen notifications, background work — to show incoming and active calls and reminders;
  • Bluetooth — for calls via a headset.

Access to this data is used on the device and does not mean it is sent to us, except as explicitly described in this policy.

7. Legal bases for processing

We process data on the following bases (Art. 6 GDPR, and Russian Federal Law No. 152-FZ “On Personal Data”):

  • Performance of the app's functions — processing calls, contacts and the call log on the device, without which the dialer cannot work;
  • Your consent — for optional features you enable yourself (PBX integration, email reports, SMS forwarding). You can withdraw consent at any time by turning the feature off;
  • Legitimate interest — protecting against spam and fraud, keeping the app stable and secure, and anonymized analytics to improve it.

8. Data retention and deletion

We keep data no longer than necessary:

  • Local data is kept while the app is installed. You can delete it inside the app or by uninstalling the app;
  • Analytics data is kept in anonymized form according to the provider's retention periods (AppMetrica);
  • Records in the number-reputation database are kept anonymized for as long as needed to maintain spam protection and are not linked to your identity.

To request deletion of data associated with you, email pro.zvonok@yandex.ru — we will handle the request within a reasonable time. Please note: some data is anonymized, so linking it to a specific person and deleting it individually may be technically impossible. Step-by-step instructions are on the Data deletion page.

9. International data transfers

The services we use may process data on servers in different countries: AppMetrica on Yandex infrastructure, and Firebase on Google infrastructure, which may be located outside your country. These providers apply safeguards for cross-border transfers (including standard contractual clauses). See their policies for details (section 12).

10. Your rights

Regarding your personal data, you have the right to:

  • access your data and information about its processing;
  • request correction of inaccurate data;
  • request erasure of data or restriction of its processing;
  • object to processing and withdraw any consent previously given;
  • lodge a complaint with a supervisory authority — Roskomnadzor (in Russia) or your local data protection authority (in the EEA).

To exercise your rights, email pro.zvonok@yandex.ru.

11. Data security

Data that leaves the device is encrypted in transit over a secure connection (HTTPS/TLS). Local data is kept in private app storage; the PIN, TOTP secret and backup codes receive additional Android Keystore protection. A backup can additionally be protected with a password.

12. Third-party services

The app uses services that have their own privacy policies:

13. Website analytics and cookies

The pro-zvonki.ru website is owned and maintained by the developer UnGooD. For website data questions, contact pro.zvonok@yandex.ru.

When a page opens, Yandex.Metrica may receive the IP address, page URL and title, referrer, browser, operating system and device details, approximate location, screen size, visit time, viewed pages, clicks and other interactions. Session Replay, click maps and outbound-link tracking are enabled.

Metrica uses cookies and localStorage, including anonymous browser identifiers, to distinguish visits, compile statistics, identify interface problems and measure interest in pages and download buttons. Analytics starts when a page loads and is not linked to data inside the ProZvonki app.

Analytics is provided and received by Yandex LLC. Retention is governed by the counter settings and Yandex rules. See the Metrica cookie documentation and Yandex privacy policy.

The website also stores the selected theme, acknowledgement of the notice and, when present, campaign attribution parameters. By continuing after the notice appears, you acknowledge this section. You can restrict or remove cookies in your browser or use the Yandex opt-out add-on. Main pages remain available.

14. Children

The app is not intended for persons under 16 and does not knowingly collect data from children. If you believe a child's data has been provided to us, contact us and we will delete it.

15. Changes to this policy

We may update this policy. The current version is always available on this page, with the last-updated date shown at the top.

16. Contact

For any privacy or data-processing questions: pro.zvonok@yandex.ru.