← Back to home

Privacy policy

Last updated: 25 September 2026

This policy describes how BAUGEY MATHEO, trading as DEVOLIM (the "publisher", "we"), handles the personal data of users of the Faux Appel mobile app and of the fauxappel.devolim.fr website. These operations are governed by Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR") and by French Act No. 78-17 of 6 January 1978 on data protection. The publisher acts as data controller.

In short. Faux Appel works without an account: we do not know who you are or where you are. The first name you enter, the names you give to people close to you, their photos and the voices you record all stay on your phone and are never sent to us. On iPhone, so that the call can ring on time even when the app is closed, a server located in the European Union receives three things and nothing else: a randomly generated call identifier, the time at which it must ring, and the notification token your iPhone receives from Apple. That server has no idea who is supposed to call you, or why. Those records erase themselves 48 hours after the call. On Android, the call is scheduled on the phone itself: no server is involved. No advertising, no advertising trackers, no data resale. The app measures its own usage and reports its crashes so that it can be fixed: this is on by default and can be turned off in the settings, under « Privacy ».

1. Data controller

BAUGEY MATHEO, trading as DEVOLIM
248 rue de Bègles, 33800 Bordeaux, France
Company number (SIREN): 948 000 757
Email: [email protected]

Given the nature and volume of the processing carried out, appointing a data protection officer is not required under Article 37 GDPR. Any request relating to personal data may be sent to the address above.

2. Design principles

The app was designed to process as little data as possible, in application of Articles 5 and 25 GDPR (data minimisation, data protection by design and by default). In practice:

3. Data processed

3.1 Data kept on your device

The following is stored in the app's private storage area, on your phone. It is sent neither to the publisher nor to any third party:

You can erase all of it at any time from Settings › Delete my data, or by uninstalling the app. If you have enabled your device backup, these files may be included in it: the backup is then a matter between you and Apple or Google, not the publisher.

3.2 Data that is sent

Scheduling a call on Android. The call is handed to a system alarm, on the phone itself. Nothing is sent to our servers.

Scheduling a call on iPhone. So that the phone rings at the appointed time while the app is closed, the call has to be triggered from outside, by a call notification sent through Apple's notification service. Our servers then receive, and only for that purpose:

Neither the character, nor the reason, nor the displayed name, nor your first name, nor any audio content is sent to that server: the notification contains only the identifier, and the device looks up the rest locally. A cancelled call is removed immediately.

Abuse prevention. Counters are attached to that same fingerprint (calls pending, per day and per week), to prevent the service from being misused and to keep triggering costs under control.

Messages sent from the app. If you use the "write to us" page, we receive the rating you give, the message type, its text, the platform, the app's language, its version, two usage counters and the device fingerprint described above. The content of the message is free text: please do not include sensitive data or information about other people.

Usage measurement and crash reports. The app sends usage statistics (screens opened, actions taken, and for each scheduled call the catalogue identifier of the chosen caller and reason, such as « mom » and « dinner », never the name you gave to someone close to you) and crash reports (device model, system version, technical state at the time of the incident) through Firebase Analytics and Firebase Crashlytics. This collection is on by default and relies on our legitimate interest in fixing defects and knowing which features are actually used. It is disclosed to you on first launch, under the button that ends the entry flow, before any data is stored: continuing means accepting this policy. You may object at any time in the app's settings, under « Privacy »: it takes effect immediately and nothing further is sent. If the age band declared in the entry flow is "under 18", usage measurement starts switched off, with nothing to do. This data serves no advertising purpose and is never sold to third parties; Google's advertising signals are disabled in the app.

App authenticity. Before any request is made to our servers, Apple's App Attest mechanism (on iPhone) or Google's Play Integrity API (on Android) issues an attestation confirming that the request comes from a genuine installation of the app. That attestation contains no data relating to your identity.

Remote settings. The app downloads operating parameters (usage limits, enabled options) from Firebase Remote Config. No personal data is sent in that exchange.

4. The people you add

The app lets you add personal characters, with a name, a photograph and voice recordings. Those files are stored in the app's private area on your phone and are never sent to us: we have no access to them and no copy is made on any server.

A person's image and voice are personal data about them, and are also protected by image rights. As soon as you record someone, you act under your own responsibility and it is for you:

What you do with those recordings is on you. The publisher, having no access to them, cannot answer for it.

PurposeLegal basis
Ringing a call you have scheduled, at the time you set Performance of a contract, Article 6(1)(b) GDPR
Providing and restoring subscription features Performance of a contract, Article 6(1)(b)
Preventing abuse and misuse of the service, and capping its costs Legitimate interest, Article 6(1)(f)
Replying to a message you send us Legitimate interest, Article 6(1)(f)
Usage measurement and crash reports Legitimate interest, Article 6(1)(f); you may object at any time in the app's settings
Keeping accounting records relating to subscriptions Legal obligation, Article 6(1)(c)

6. Recipients and processors

The data described in § 3.2 is accessible only to the publisher and to the following technical providers, who act on instructions and under a contract compliant with Article 28 GDPR:

ProviderRoleData concerned
Google Ireland Limited and Google LLC (Firebase, Google Cloud) Server functions, database, scheduling of the trigger, usage measurement, crash reports, remote settings, authenticity check Call identifier, time, notification token, device fingerprint, counters, messages sent, usage statistics and diagnostics unless you have turned usage measurement off
Apple Inc. and Apple Distribution International Ltd App distribution, notification service, payment collection, authenticity attestation Notification token; account and payment data processed by Apple on its own behalf, to which the publisher has no access
Google Ireland Limited (Google Play) App distribution on Android, payment collection, authenticity attestation (Play Integrity) Account and payment data processed by Google on its own behalf, to which the publisher has no access
RevenueCat, Inc. Technical management of subscriptions and purchase restoration Anonymous purchase identifier, store receipt, subscription status
LWS (Ligne Web Services SAS) Hosting of this website Web server technical logs

No data is sold, rented or transferred to third parties for commercial purposes.

7. Transfers outside the European Union

The server functions and the trigger queue are configured in the europe-west1 (Belgium) region: the processing that decides to send the call takes place within the European Union.

The database that holds the items listed in § 3.2, however, is hosted in the United States (Google Cloud's nam5 multi-region). It stores the call identifier, the time, the notification token, the device fingerprint and its counters, and the messages sent from the "write to us" page. Those are the only data concerned: not your first name, not the photos, not the recordings, not the content of the calls, none of which ever leaves your phone.

Other providers are established in the United States, or may carry out maintenance and support operations from there, in particular for usage measurement, crash reports and subscription management. This database transfer, like the others, is governed by the standard contractual clauses adopted by the European Commission on 4 June 2021, supplemented, where the provider has subscribed to it, by its certification under the EU-US Data Privacy Framework, found adequate by the Commission's implementing decision of 10 July 2023.

8. Retention periods

DataPeriod
Scheduled call: identifier, time, notification token Automatically erased 48 hours after the scheduled time of the call, by a scheduled deletion policy
Usage counters attached to the device fingerprint Rolling windows of 24 hours and 7 days; the record, which contains nothing but numbers and a fingerprint, is kept while the device uses the service
Message sent from the app 2 years, then automatically erased
Usage statistics, unless you have turned them off 14 months at most
Crash reports, unless you have turned them off 90 days
Data stored on your device (§ 3.1 and § 4) Until you delete it, or uninstall the app
Accounting records relating to subscriptions 10 years, under Article L.123-22 of the French Commercial Code

9. Subscriptions and purchases

Subscriptions are taken out and charged by Apple, through the App Store, or by Google, through Google Play. The publisher sees neither your identity, nor your address, nor your bank details, and has access to no payment method. Apple and Google process that information on their own behalf, under their own privacy policies.

RevenueCat, Inc. acts as a technical processor to verify the receipt issued by the store, determine your subscription status and allow it to be restored on a new device. It receives an anonymous purchase identifier, unconnected to your identity.

10. Security

Appropriate technical and organisational measures are in place under Article 32 GDPR:

No system is infallible. In the event of a data breach likely to result in a risk to your rights and freedoms, the CNIL would be notified within 72 hours and you would be informed in accordance with Articles 33 and 34 GDPR.

11. Website

This website is static. It sets no cookies, uses no audience measurement tool and embeds no social media button. Fonts are hosted on our own servers: your visit triggers no request to any third-party domain, and in particular none to Google Fonts.

The host keeps technical logs (IP address, date and time of the request, page requested, browser type) for security and proper operation of the server, on the basis of legitimate interest, for no longer than six months.

12. Your rights

Under Articles 15 to 22 GDPR, you have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to give instructions about what happens to your data after your death (Article 85 of the French Data Protection Act). These rights may be exercised by email at [email protected]. We reply within one month, which may be extended by two months for complex requests.

Two points follow from the way the app is built. First, the data described in § 3.1 is under your sole control: erasure is immediate from Settings › Delete my data, with no need to write to us. Second, the data described in § 3.2 is attached to no identity, but to a technical fingerprint: in accordance with Article 11 GDPR, we are not in a position to link it to a person and will not keep additional information for the sole purpose of doing so. If you wish to exercise your rights over that data, please include in your request the details that allow it to be found, in particular the date and time of a scheduled call or the text of a message sent from the app.

13. Complaint to the CNIL

If, after contacting us, you believe your rights have not been respected, you may lodge a complaint with the French data protection authority: Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or online at cnil.fr. If you live in another EU country, you may also contact your national supervisory authority.

14. Minors

The app is not intended for children. In France, the age of digital consent is set at 15 by Article 45 of the Data Protection Act: below that age, using the app requires the authorisation of the holder of parental authority, who may exercise the rights described in § 12 at any time. When the age band "under 18" is declared in the entry flow, usage measurement and crash reports are switched off by default on that device. We do not ask for, and do not knowingly collect, data that would identify a minor; if you find that a child has provided information, write to us and it will be erased.

15. Changes

This policy may change to reflect legal or technical developments. The date of the latest update appears at the top of this page; substantial changes are announced in the app.