01The short version
PhoneShield answers the calls you forward to it, decides what each one is, and shows you the result. To do that we keep your account details, the numbers and names on your lists, and a written transcript of what callers say to the front desk and to Nora, the assistant. We do not keep audio recordings of your calls, we do not sell or rent anything about you, and we do not run advertising trackers.
One thing is shared on purpose: when a caller is confirmed as a scam, that phone number and the reason go on a list that protects every PhoneShield customer. Your name, your number and your transcript never travel with it.
02Who we are
PhoneShield.ai is operated by Who Can It Be, LLC, a Florida limited liability company. This policy covers the website at phoneshield.ai, the customer dashboard, the PhoneShield iPhone app, the phone numbers we answer on your behalf, and the emails and notifications we send. It applies to you as a customer and, in the parts marked as such, to people who call a PhoneShield number.
03What we collect
From you, the customer
- Your name, email address and password (the password is stored only as a salted hash).
- The phone number you forward to PhoneShield, the number where vetted calls should ring you, and the PhoneShield number we assign to you.
- Your lists: favorites, contacts and blocked numbers, with the names you give them. If you import contacts from your phone, only the names and numbers you chose to import are stored, and only on your own account.
- Your settings: the screening mode, greeting, assistant name and voice, and any temporary passes you grant.
- Sign-in records: when and from which network address you signed in, and, for the app, a device token and the push notification token for that device.
- Billing status from Stripe. Card numbers never reach our servers; Stripe holds them under its own policy.
From each call
- The caller's number, the time, how long the call lasted, and what happened to it.
- A written transcript of what the caller said to the front desk or to Nora, the classification we made, and any message the caller left.
- Signals that arrive with the call from the phone network, such as caller-ID attestation, and whether the number appears in the FTC's public Do Not Call complaint data.
From your browser
Server logs with network addresses and the pages requested, kept briefly for security and debugging. We set the cookies described in the cookie policy and nothing else.
04If you called a PhoneShield number
When you call someone who uses PhoneShield, a front desk answers, says so, and asks who is calling and what it is about. Your words are transcribed in real time so the customer can decide whether to take the call. The transcript belongs to the customer you called, the same way a note taken by a receptionist would.
We do not store audio of the call. If the customer marks the call as a scam, or the front desk confirms a known scam script, your number and a short reason are added to the shared list described below. To dispute an entry, contact us with the number and the date of the call.
05How we use it
- To answer, screen, route and summarise the calls you forward to us. That is the service.
- To ring you on the number you verified, and to whisper who is calling before we connect you.
- To show your call history, messages and lists in the dashboard and the app.
- To send the emails and push notifications you asked for: a message was taken, a number is ready, a receipt.
- To bill you through Stripe and to count Nora minutes against your plan.
- To keep the shared scam list accurate and to stop abuse of the service.
- To improve how the front desk and Nora handle calls, using transcripts in aggregate.
We do not use your data for advertising, and we do not build profiles of callers beyond whether a number has been confirmed as a scam.
07Who helps us run the service
A few companies process data on our behalf, only to provide their part of the service and under contracts that forbid any other use.
| Provider | What they do | What they see |
|---|---|---|
| Telnyx | Carries the calls and transcribes the front desk conversation | Call audio in transit, phone numbers, transcripts |
| OpenAI | Classifies what a caller said and powers Nora, the assistant | Transcript text; live audio while Nora is on the line |
| Stripe | Payments and receipts | Your name, email, card details, billing history |
| Vercel and our own servers | Host the website, dashboard and the call engine | Everything above, in the United States |
| Email and push delivery services | Deliver notifications you enabled | Your email address or device push token, the notification text |
| Integrations you connect (such as Telegram) | Receive the notifications you route to them | The notification text you chose to send there |
Beyond these, we share personal data only when the law requires it, to protect someone's safety, or with your direction, for example when you ask us to connect a caller to you.
08How long we keep things
- Call history, transcripts and messages: as long as your account is open, or until you delete them.
- Technical call events used to run a live call: deleted automatically within days.
- Sign-in history: 90 days.
- Billing records: seven years, as tax law requires.
- Shared scam list entries: kept while reports keep arriving; a quiet number ages out.
When you close your account we delete it, and the calls, lists and transcripts on it, within 30 days, apart from the billing records above and copies in backups that are overwritten on their own schedule.
09Your choices and rights
- See, correct or export your data from the dashboard, or ask us and we will send it to you.
- Delete a call, a contact or your whole account from the dashboard, or ask us to.
- Turn notifications off per channel, and revoke an app device from the dashboard.
- Stop the service at any time by removing call forwarding on your phone.
- Object to, or ask us to restrict, a particular use, and complain to your local data protection authority.
If you live in California, the CCPA gives you the rights above by law, and we do not sell or share personal information as those words are defined there. If you live in the European Economic Area or the United Kingdom, our legal bases are the contract with you, our legitimate interest in running a safe service, and your consent where we ask for it.
10Security
Traffic to and from PhoneShield is encrypted, passwords are hashed, app device tokens are stored only as hashes, secrets are kept out of the code, and access to production is limited to the people who run it. No system is perfect. If we learn of a breach affecting you we will tell you promptly and say what we know.
11Children
Accounts are for adults. Many customers set PhoneShield up for a parent; the parent does not need an account, and we hold about them only the phone numbers involved and the calls we answered. We do not knowingly collect data from anyone under 16.
12Changes to this policy
When we change this policy in a way that matters we will email account holders and show the new date at the top. The plan is currently $29.99 a month with 150 assistant minutes included; pricing lives on the pricing page, not here.
13Questions
Write to privacy@phoneshield.ai or use the contact form. A person reads every message; there is no ticket robot in front of them.
Who Can It Be, LLC, a Florida limited liability company, operates PhoneShield.ai.