VoIPMe

Privacy Policy

Last updated · August 13, 2026

Effective: August 10, 2026 · Last updated: August 13, 2026

Short version: VoIPMe is a softphone for a SIP account you bring — your calls go straight from your phone to your provider and never pass through our servers, so we don't see who you called. We never record your calls or listen to your audio, and we never sell your data.

How calling works here

You connect SIP credentials for a provider or PBX you already have. Call signalling and audio travel directly between your phone and that provider — they never pass through our servers, and we do not see the numbers you dial. VoIPMe does not sell phone service, provision numbers, or carry your calls.

What we collect

Your account. An account is required. When you sign in with Apple or Google we receive your email address, your display name if you share one, and a provider identifier that lets us recognise you when you sign in again.

Call counts and durations. While you're signed in, the app tells us that a call finished and how many seconds it lasted. It does not tell us who you called — no phone number, no contact name, no destination of any kind leaves your device. We use these figures to understand how much the service is used and to spot abuse. Because your calls never touch our servers, the app's own report is the only record of them, and it is not something we can independently verify.

Device push token. When you enable inbound calls, the app sends your device's push token (Apple's APNs on iOS, Google's FCM on Android) to our push relay so we can wake the app when a call arrives. The token is stored alongside your push routing identifier and nothing else.

Inbound call metadata. When an incoming call is signalled to the relay, we receive the caller's number and an opaque call ID so we can deliver the push. On bring-your-own-provider accounts this is held only for the few seconds needed to deliver the notification, and is not persisted.

Contacts you save in VoIPMe. Contacts you create inside the app are stored on your device. On plans that include contact sync they are stored on our servers instead, so they follow you to a new phone — that record holds the name, phone numbers and VoIPMe address you entered. Separately, the app can read your phone's address book if you grant permission, purely so you can pick someone to call; your address book is never uploaded to us.

Advertising, on the free plan. The free plan is supported by ads served by Google AdMob. VoIPMe shows non-personalised ads only — it does not track you across apps or other companies' services, and does not use your device's advertising identifier for tracking. In the EU/EEA and UK you'll still see a consent form before any ad data is processed, and you can decline and still use the app. Paid plans show no ads at all. See Google's advertising privacy notice. We never share your call history or contacts with advertisers.

Payments. Subscriptions bought through the App Store or Google Play are processed by Apple or Google; payments made by PayPal are processed by PayPal. We receive confirmation that a purchase happened, its product and transaction identifier, and when it renews or lapses. We never see your card number.

Crash and diagnostic reports. If the app crashes or hits an unexpected error, an anonymous crash report is sent to Sentry so we can diagnose it. Reports include a stack trace, app version, OS version and device model. They do not include your SIP password, contacts, call history or audio. You can also tap Settings → Reports → Send report to attach your recent registration status and a note to a manual report.

What we never collect

  • Audio from your calls — at any point, ever. We do not record calls.
  • Your SIP password in readable form. It is held in your device's Keychain. If you turn on hosted wake-on-push (a paid option that keeps a registration to your PBX so it can wake the app), that one credential is stored encrypted on our servers; otherwise it never leaves your device.
  • Your phone's address book.
  • The numbers you dial — those calls go straight to your provider and never reach us.
  • Your card or bank details.

Who else is involved

Push notifications are delivered by Apple (APNs) and Google (FCM), which receive your device token. Ads on the free plan are served by Google AdMob. Purchases are handled by Apple, Google or PayPal. Crash reports go to Sentry. None of these parties receive your call audio, and none of them are permitted to sell your data.

Where data lives

Our servers — including the push relay — are hosted in Germany with Hetzner. This marketing website is served as static files by our web host and handles no account or call data. Apple, Google, PayPal and Sentry operate their own infrastructure internationally, so your data may be processed outside your country. Your call signalling and audio go directly between your phone and your SIP provider and are never routed through us.

How long we keep it

  • Per-call rows (counts and durations): deleted after 90 days. A daily total per account is kept for longer so we can see usage trends; it holds no per-call detail and no numbers.
  • Push tokens: until you sign out, delete your account, or your device unregisters them.
  • Inbound call metadata: when your provider signals an incoming call to the relay, the caller number is used to raise the ring and held only for the few seconds needed to deliver the push — not persisted.
  • Crash reports: 90 days, by Sentry.

Your rights

Delete your data. Open the app and tap Settings → Privacy → Delete account. This deletes your account and everything attached to it — usage figures, any synced contacts, subscriptions and push tokens — and wipes the SIP credentials and call history held on your device. You may also email hello@voipme.online for a manual purge.

Access, export, correction. Email hello@voipme.online for any data-rights request and we'll respond within 30 days.

Region-specific rights. If you're in the EU/EEA or UK (GDPR), we process your account details to provide the service you asked for (performance of a contract); usage counts and fraud checks rest on our legitimate interest in keeping the service working and unabused; showing ads relies on your consent to ad-data processing where the law requires it, which you can withdraw at any time. You have the right to access, correct, export, or erase your data, and to object to processing based on legitimate interest. If you're in California (CCPA/CPRA), we do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Children

VoIPMe is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children.

Changes

Material changes will be announced in the app and on this page, and the effective date above will be updated.

Contact

Questions? Email hello@voipme.online.