Overview
MyRule ("we", "us", "our") is a call-screening app for Android that blocks unwanted callers using rules you define. This Privacy Policy explains what data we access, why we need it, and how we protect it. We do not sell your data to anyone.
Data We Access & Why
Call Logs Sensitive permission
We read your call history to display how many calls were blocked (today / this week / all-time) in the Home screen stats. Call log data is stored only on your device in an encrypted local database. It is never uploaded to our servers.
Phone State & Call Screening
MyRule registers as the system Call Screening app to silently reject calls that match your block rules, before your phone even rings. No audio is captured during this process — it is purely a call-routing decision.
SMS / Send SMS Sensitive permission
The Send SMS permission supports the optional "Caller Gate" feature, which sends an automated SMS to unknown callers asking them to identify themselves via a web link. Messages are sent using your device SIM; standard carrier rates may apply. SMS content is not logged or uploaded.
Contacts
We read your contacts to build the "known caller" allowlist so that people you trust are never blocked. Contact data stays on device and is never uploaded.
Notification Access
Used to show you real-time alerts when a call is blocked and to display the status of the call screener.
Battery Optimisation Exemption
We request exemption from battery optimisation so the call screening service keeps running reliably in the background. We do not perform any background data collection beyond what is listed in this policy.
Firebase Services (Google)
We use the following Firebase services, all provided by Google LLC:
- Firebase Authentication (Anonymous) — assigns each install a random anonymous ID so we can safely read remote configuration without requiring you to create an account. No name, email, or phone number is ever collected.
- Cloud Firestore — stores remote admin configuration (e.g., emergency admin passwords) and gift-code redemption records. No personal call or SMS data is ever written to Firestore.
- Firebase Crashlytics — collects anonymised crash reports and device/OS details to help us fix bugs. Crashlytics data is governed by Google's privacy policy at firebase.google.com/support/privacy.
- Firebase Analytics — records anonymised usage events (e.g., total calls blocked, feature toggles) to help us understand how the app is used. Analytics data does not include the content of calls, contacts, or messages.
Firebase data is processed in accordance with Google's Privacy Policy and Data Processing Terms.
Data Storage & Retention
- On-device only: call log stats, your block rules, contacts cache, subscription/trial status, and all user settings are stored locally in an encrypted Room database and EncryptedSharedPreferences. Uninstalling the app deletes this data.
- Firebase (cloud): anonymous UID, crash reports, and gift-code redemption records. You may request deletion by contacting us (see below).
- We retain crash and analytics data for up to 90 days, after which it is automatically purged by Firebase.
Data Sharing
We do not sell, rent, or trade your personal data. Data is shared only with:
- Google / Firebase — as described above, solely to operate the app.
- Law enforcement — only if legally compelled to do so by a valid court order or government request.
Children's Privacy
MyRule is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Your Rights & Choices
- Revoke permissions — you can revoke any Android permission at any time via Settings → Apps → MyRule → Permissions. Revoking the Call Screening role will stop call blocking.
- Delete your data — uninstalling the app deletes all on-device data. To request deletion of your Firebase anonymous UID and associated records, email us at the address below.
- Opt out of Analytics — Firebase Analytics respects the Android Advertising ID opt-out. You can also disable personalised ads in Google Settings.
Security
All on-device data is encrypted using AndroidX Security / EncryptedSharedPreferences (AES-256-GCM). Admin credentials are stored as SHA-256 hashes — never in plaintext. Firebase connections use TLS 1.2+.
Changes to This Policy
We may update this policy from time to time. Material changes will be announced via an in-app notification. The "Effective date" at the top of this page always reflects the latest version.
Contact Us
If you have questions, concerns, or data deletion requests, contact us at:
Last updated: July 22, 2026