ALOFI
Privacy Policy
How Alofi processes personal data when you visit the website or use the app.
Last updated: September 15, 2026
Controller and contact
Flarely e.U., owned by Severin Hilbert, Herbert Rauch-Gasse 16, 2361 Laxenburg, Austria, is responsible for the personal data described here. For privacy requests, email [email protected].
What this policy covers
This policy covers visits to alofi.world and use of the Alofi app and its related calling, rented-number, messaging, voicemail, recording, purchase, support, and verification functions. Alofi accounts and paid services are intended for people aged 18 or older. We do not knowingly offer these services to minors. Apple and other independent providers may also process data under their own privacy notices when you use their services.
Website visits
When you open the website, Cloudflare Pages receives technical request data such as your IP address, request time, requested page, browser information and error information. This processing is needed to deliver the page, maintain security, and diagnose failures. The legal basis is our legitimate interest in operating a secure website, under Article 6(1)(f) GDPR. We do not use website analytics, advertising trackers, a newsletter, contact forms, social-media embeds or remote fonts. If you contact us by email, we use your address and message to respond and keep the correspondence for the period needed to handle the matter and meet legal obligations.
Account and authentication
The app and backend process your account identifier, device and app identifiers needed for security, verified phone number, verification attempts, and session data to create and protect your account. Apple-signed app identity and transaction information help us establish purchase ownership. The legal basis is performance of the service contract under Article 6(1)(b) GDPR and, for abuse prevention and security, our legitimate interests under Article 6(1)(f).
Calls, rented numbers and text messages
To provide calling and rented numbers, we process numbers you call or receive calls from, your selected caller ID, rented number, call status and timing, usage and charge records, and information needed to route calls. To deliver incoming text messages, we process the sender and receiving numbers, message content, delivery time, length, and charges. We use this information to perform your service contract under Article 6(1)(b) GDPR. Some records are also needed to meet accounting and telecommunications obligations under Article 6(1)(c), and to prevent fraud and resolve disputes under Article 6(1)(f).
If you submit an identity, address, or business check for a regulated number, we process the details and documents required by the applicable number provider and local rules. We send the necessary information to the number provider and retain only the data needed for verification, service, and applicable legal duties. The legal bases are Article 6(1)(b) and, where a specific rule applies, Article 6(1)(c) GDPR.
Voicemail and call recordings
If you enable voicemail, we process the greeting, recorded message, call information, and any resulting transcript and summary so you can receive and review messages. If you record a call, we process the audio and an optional automated summary. A recording may begin on your device and be uploaded for storage and summary processing. Audio and transcripts may include personal data of the other person on the call; you must meet any notice or consent duties that apply to recording. The legal basis for providing these features is Article 6(1)(b) GDPR. Where required for the act of recording under local law, you are responsible for obtaining the other person's consent.
Purchases and credits
Apple handles payment in the App Store. We receive and verify transaction, product, refund, subscription, and storefront details needed to grant credits and prevent duplicate or fraudulent grants. We keep credit balances, reservations, usage charges, and purchase records. We do not receive your full payment-card number from Apple. The legal bases are Article 6(1)(b) GDPR for purchase and service delivery, Article 6(1)(c) for accounting duties, and Article 6(1)(f) for fraud prevention and payment dispute resolution.
Notifications and device permissions
If you allow notifications, the app uses device push identifiers and notification delivery records to alert you to calls, incoming messages, verification results, and number renewals or release. Operating-system permission controls whether notifications can appear. If you grant Contacts permission, the app reads names and phone numbers on your device to help you choose a contact and identify a caller. Your address-book names do not leave your device. The legal basis for service notifications is Article 6(1)(b) GDPR and for optional presentation features is our legitimate interest in providing the requested feature under Article 6(1)(f). You can change device permissions in system settings.
Who receives data
We use service providers to operate Alofi: Cloudflare for website delivery, Convex for the application backend and storage, Twilio for calling, rented numbers, text messages and required number verification, Apple for app distribution, purchase and device push services, RevenueCat for subscription and credit-purchase administration, OneSignal for some service notifications, and OpenRouter for automated voicemail transcription and call-recording summaries. The app sends audio and resulting text through OpenRouter to transcription and summary models identified as Microsoft and OpenAI models; OpenRouter may route the requests to the providers that serve those models. Each recipient processes information needed for its task. Other telecommunications carriers may receive routing data needed to complete calls and deliver messages.
We may disclose data to authorities when legally required, or to professional advisers where necessary to defend or establish legal claims. We do not publish your message content or audio as website content.
Processing outside the European Economic Area
Some providers and telecommunications routes may process data outside the European Economic Area, including in the United States. Where GDPR requires a transfer mechanism, we rely on an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses, and assess supplementary measures where necessary. Contact [email protected] for information about safeguards relevant to your data.
How long data is kept
We retain account information while the service relationship continues. When it ends, account data required only for that relationship is deleted as required by telecommunications law; separate purchase, charge, and claim records are retained only for their own lawful purposes. Accounting books, transaction records, and related evidence are ordinarily kept for seven years from the end of the relevant calendar year under Austrian tax law, and longer when a relevant proceeding is pending. This does not mean that message content, audio, or detailed call traffic is kept for seven years merely because a charge appears in the ledger. Website security logs and support correspondence are kept for the period needed for security, handling the request, and any applicable legal duty or claim; provider log periods may differ.
Call traffic data needed for billing is deleted or anonymised once payment is complete and no written charge objection is made within three months, subject to the specific statutory exceptions for disputes, unpaid charges, proceedings, and lawful orders. We retain only the traffic detail needed for those purposes. Incoming message content, voicemail, and saved recording content remain available while needed to provide their features, unless you delete them or a legal requirement calls for a different outcome. Clearing a conversation in the app hides older messages from the app view but does not itself erase the underlying message records. Deleting a voicemail or saved recording removes its stored audio and associated text from your Alofi view and starts deletion of any provider copy that Alofi controls.
Local document uploads for number verification are scheduled to expire after seven days if abandoned; submitted files are held while review is pending and local copies are removed after transfer to the number provider. The provider may retain documents for its regulatory duties. We may retain minimal verification references and outcomes to avoid repeating required checks.
Your privacy rights
Subject to the conditions in GDPR, you may ask for access to your data, correction, deletion, restriction, portability, or objection to processing based on legitimate interests. Where processing depends on consent, you may withdraw it at any time without affecting processing already carried out. You may complain to the Austrian Data Protection Authority or your local supervisory authority in the European Economic Area. Email [email protected] to exercise a right. We may need to verify your identity before responding.
Changes to this policy
We update this policy when our data practices or legal duties change. A material change will be communicated where required by law.