Dot Dialer
Privacy
Last updated: 4 October 2026
Who is responsible for the app
Dot Dialer is developed by Dot Design / Alexandru Butica and provided by Dot Design Web S.R.L., Romanian company number 26427855, J40/701/2010, 4 Johann Sebastian Bach Street, Sector 2, Bucharest, Romania. Contact: contact@dotdesign.ro.
Contacts and calls
With the permissions granted in Android, the app can read and modify contacts and the call log to display, search and manage contacts and use calling features. Calls are handled by Android/Telecom and the configured phone service, not a network operated by Dot Dialer. If your Android address book is synced through a system account, changes may also be synced by that account's service. We do not upload the address book or call history to Dot Design servers.
Data kept on the device
Notes, preferences, cached photos and the local journal remain on the device. Android contacts and system call history are managed separately by Android and configured accounts. There is no active private-contacts feature or encrypted address-book vault. The journal is bounded to approximately 256 KiB; trimming keeps at most 600 recent lines. Notes and preferences remain until deleted; caches are managed separately. Uninstalling does not delete the system address book or separately saved exports.
SMS, WhatsApp and sharing
When you choose to send a message, use WhatsApp or share information, the app passes the action and necessary data to the selected Android function or app. A quick reply to a call may use Telecom's reject-with-message function. The recipient, external app and carrier may process data under their own terms.
Google Contacts photos
In the Google Play variant, you can optionally enable Google Contacts photos and authorise read-only access to contacts through Google. The app uses Google People API to find photos and downloads them over HTTPS; this is not a Google Photos integration. The authorisation token and lookup index are held in memory; the selected account, enablement preference and sync progress are stored locally. Disconnecting revokes the Google authorisation. The feature is off by default; a later suggestion locally checks time in use, sessions and the existence of Google photos. It does not contact Google before your choice. A photo may be written to the local Google source, and Google synchronization may sync the change to your account.
Backup and transfer
A manual .rphone export is an unencrypted ZIP archive containing preferences and notes. You select the file and destination through Android's file picker; the destination may be local or provided by an external service. Protect the export and do not share it if it contains private data. Android cloud backup and device-to-device transfer may include DataStore preferences under the app's rules and system settings. Clearing app data does not automatically delete separately saved exports. PIN/password verifiers, the Keystore key and authentication configuration are excluded from manual archives. Android backup does not export verifiers or the key.
Authentication
App lock is off by default. Android checks biometrics and device credentials; we do not receive or store fingerprints. Custom PIN/password uses a salted derived verifier encrypted through Android Keystore. Interface locking does not encrypt Android contacts, history or every file and does not guarantee absolute protection on a compromised phone.
Sentry diagnostics
If the distributed version has Sentry configured, crash and unresponsive-app reports, limited technical lifecycle events, app and Android versions, and the device model and manufacturer may be sent. Configuration and filters aim to exclude contact names and phone numbers, notes and call content. Screenshots, view-hierarchy captures, session replay, tracing and interaction tracking are not enabled. The local diagnostic journal is separate from these reports. The provider may see the IP address during transport; these data are not described as fully anonymous. Reporting is Automatic by default. In Advanced → Diagnostics you may select On demand only: automatic reporting no longer starts and the old automatic queue is not reused. A manual event is sent only when you explicitly tap the button; it does not send the whole local journal. Changing the option cannot recall a report already transmitted. The local journal can be copied or cleared in both modes.
Providers, retention and transfers
Google processes the integration you authorize under its own policies. Sentry, provided by Functional Software, Inc., processes reliability diagnostics; the configured endpoint uses the DE region. Reports follow the retention configured in the Sentry project, not the local journal lifetime. Third-party services may involve access or processing outside the EEA under their applicable safeguards and subprocessors. Sentry details: https://sentry.io/privacy/ and https://sentry.io/legal/dpa/. We do not claim IP addresses or all technical data are fully anonymous.
Purchases and payments
Purchases through Google Play or RuStore are handled through the store's services. Any external payments take place outside the app. Dot Dialer's code does not process payment-card details; payment providers and stores apply their own policies to their operations.
GPlay product statistics
In the Google Play variant, Automatic reporting includes app version, Android version/API, manufacturer and model, language, SIM country and operator code when available, the manually chosen number-interpretation region, and daily counts for favorites, swipe actions and dialpad opens. SIM country and the manual region are not the current location. Reports use HTTPS to dialer.dotdesign.ro, separately from licensing, without contacts, phone numbers, notes, call content or durations, GPS or hardware identifiers. The random statistical identity changes daily; these are pseudonymized technical data, not guaranteed anonymous data. On demand stops these automatic requests and clears the local statistical queue; an already dispatched request cannot be recalled. Daily identities become eligible for deletion after no more than 48 hours, aggregates after 90 days; cleanup runs on subsequent service requests. Hosting may process IP addresses in transport and its own logs; the app does not include them in reports and the statistical database does not store them.
Free activation codes
When you choose to activate an early-adopter code, the Dot Design service stores the license, an administrative label, hashes/HMACs of the code and refresh token, random activation identifiers and technical timestamps needed to manage the entitlement. These records are not linked to product statistics. No address book, call history or photos are sent. The code is a recovery secret; the signed grant allows at most 7 days offline. The grant and token are encrypted locally with Android Keystore and excluded from backups. Resetting removes activations; revocation withdraws access at refresh or grant expiry, not immediately offline. License records remain for entitlement administration; correction or deletion can be requested at contact@dotdesign.ro. Licensing audit records are cleaned after 90 days on service requests.
Permissions and control
You can revoke permissions in Android, change the default phone app, disconnect Google Contacts and clear the app's local data. Features that depend on revoked permissions will no longer be available. The reviewed version does not provide call-audio recording or its own video-calling feature.
Legal bases and rights
Local data supports the services you request. Limited diagnostics serves our legitimate interest in keeping the app safe and reliable; you may choose on-demand reporting. Google features require explicit choice and authorization. Where GDPR applies, you may request access, correction, deletion, restriction, portability or object at contact@dotdesign.ro and complain to the Romanian supervisory authority, ANSPDCP. Include the report ID if available and never send secrets or your full address book.
Updates
This policy may be updated when features or data processing change. The publication date of the applicable version will be shown on this page.