통화필름 CALLFILM
CALLFILM · PRIVACY

Privacy Policy

Recordings, captions and videos are processed on your device. Google services support ads, usage analytics and crash diagnostics. Optional model downloads connect to Hugging Face.

Version 1.3.0 · 2026-09-07

Optional caption model downloads

Only when you select the model download action in Settings, CallFilm connects over HTTPS to Hugging Face and its file delivery network to retrieve model data. The hosting service may receive connection metadata, including your IP address and the requested public model URL, under the Hugging Face Privacy Policy. Recordings, contacts, captions, source file names and rendered videos are not sent. Downloaded models remain in app-private storage until app data is cleared or the app is removed. Internet permission also supports this optional download.

Information processed

The app processes media explicitly chosen through the Android system picker; file name, MIME type, size, modified time, and SHA-256 integrity digest; a title, counterparty name, phone number, recording time, and duration entered or selected by the user; one contact name and number explicitly selected through the Android contact picker; SRT or WebVTT files selected by the user and their name, format, and SHA-256 digest; caption text, speaker, and timing information; and generated cover images and MP4 files. Video inputs contribute only their audio track. This content is used on the device to provide app features. The active caption document is stored in that recording's app-private directory.

Collection, transmission, and sharing of recordings and captions

CallFilm has no user account or developer-operated content server. It does not send selected media, contact details, call records, captions, or rendered videos to the developer, Google Analytics, Crashlytics, or an advertising provider.

When the user chooses Share, the app creates a unique temporary copy at cache/callfilm_shares/<share-id>/recording.mp4 and grants temporary read access only to the destination selected in the Android share sheet. Saving to the gallery and exporting SRT or WebVTT also occur only after an explicit action and system destination choice. The receiving app or storage provider applies its own policy to an exported copy.

Advertising and information processed by Google

The User Messaging Platform checks advertising privacy status when the app starts. If an existing choice permits ad requests, Google Mobile Ads may request an app-open ad, banners on the four main tabs, and a completion ad after every third single-video export. Ads that are not ready are skipped. The batch rewarded ad and any required consent form open only after the user selects the button to watch an ad and begin.

Google Mobile Ads may process IP address and approximate location, product interactions, diagnostics, Android advertising ID, app set ID, and related device or account identifiers to deliver and measure ads and prevent abuse. Data is encrypted in transit. Ads may be personalized, non-personalized, or limited according to region, device settings, and the user's Google privacy choices. CallFilm does not pass recordings, contacts, captions, covers, or rendered video to the ads SDK. Google's processing is governed by the Google Privacy Policy and the Google Mobile Ads data disclosure. Where required, Google presents a consent form. A privacy-options entry is available in Settings when Google reports that it is required.

Google Analytics and Firebase Crashlytics

Google Analytics for Firebase is always enabled in the Android app. Its default implementation processes user and session counts, session duration, operating system, device model, approximate geography, first launch, app opens and updates, and an app-instance identifier. CallFilm adds only these values:

  • app ready (app_ready);
  • current screen (screen_view, limited to library, studio, batch, or settings); and
  • video export completed (video_export_completed).

  • caption timestamp taps (caption_timestamp_tapped), separately from verified playback movement;

  • workflow start, success, failure, cancellation, skip, and caption reuse (workflow_step), using fixed codes for import, caption generation, search, seek, video creation, save, and ad consent;
  • execution type (traffic_type: production or test) and app build (app_build), as user properties and default event parameters, plus the measurement schema version.

Linked AdMob impressions and revenue use Google's automatic collection. Additional measurement never includes recordings, captions, search terms, file information, raw error messages, playback timestamps, or query lengths.

CallFilm does not set an Analytics user ID. Analytics Advertising ID collection and ad-personalization signals are disabled in the Android manifest. This Analytics setting does not disable the separate Google Mobile Ads processing described above.

Firebase Crashlytics processes crashes, application-not-responding events, and unhandled errors. It may process stack traces, relevant app state, app version, device and operating-system metadata, a Crashlytics installation UUID, Firebase installation ID, and session metadata. CallFilm adds only a predefined reason code, error type, and bounded technical state: app version, build, release channel, target platform, screen route, lifecycle state, configuration revision, operation code, renderer backend, generation and quality tier, and audio focus. Raw error messages are removed before reporting, and stack traces are restricted to app or Dart package locations and line numbers.

CallFilm does not attach recording or video bytes, caption text, file names, paths or hashes, titles, counterparty names, phone numbers, contacts, search terms, email addresses, user IDs, or Advertising IDs to Analytics or Crashlytics. Under Google's current policy, Crashlytics keeps crash stack traces and associated identifiers for 90 days before beginning deletion. The connected Google Analytics property retains event data for 2 months and user data for 14 months, with the user-data period reset on new activity. See Firebase Privacy and Security and the Google Privacy Policy.

Permissions

The app does not request call-log, full contacts, microphone, or broad storage permission. Media, subtitle files, and a contact are read only when explicitly selected in an Android system picker. MediaStore or the system document picker is used for exports. Internet access is used for advertising privacy status, ads, usage analytics, crash diagnostics, and user-requested model downloads. Android Advertising ID and Privacy Sandbox advertising API permissions are used for advertising and abuse prevention; Analytics Advertising ID collection is separately disabled.

Secure processing

Selected files and call records are stored in app-private Android storage. The installed speech models process audio on the device in chunks of at most five minutes. The app does not use a remote caption API, upload audio, embed a caption API key. Base is bundled with the app, and Small and Medium are installed with the app through Google Play install-time asset packs. Only the additional Turbo model is downloaded from Hugging Face when requested in Settings. Android cloud backup and device transfer are disabled, cleartext traffic is disabled, and third-party audio playback capture is blocked. Exports occur only through an explicit user action.

Retention and deletion

A call record remains in app-private storage until the user deletes it in the app or removes the app. Deleting a record removes the app's source copy, metadata, cover, AI captions, rendered video, and imported final caption document. The originally selected file and external subtitle source remain at their original locations. Unreadable records are not deleted automatically; the user can confirm deletion from the Library recovery warning.

Android may reclaim a share copy earlier; any remaining copy older than 24 hours is cleaned up on a later app start or sharing action. Exported copies must be deleted from their destination separately.

Advertising information is not stored on a developer server and cannot be looked up by CallFilm as a user-specific record. Analytics and Crashlytics data is processed in the connected Firebase and Analytics projects. The app has no account and does not connect an app-instance identifier to a person's identity or support email, so it does not provide a way for the developer to locate and delete one person's remote records. Clearing app data or uninstalling removes local CallFilm data and identifiers; records already sent are deleted according to the applicable provider settings and retention rules.

User responsibility

Recording and sharing laws and consent requirements differ by country and region. Use only recordings you lawfully possess and for which you have obtained any required consent.

Contact

Use email for a privacy request. The issue tracker is public; do not attach or enter a recording, phone number, or other personal information there.

Previous policy 1.2.0