Privacy Policy
Last updated 9 September 2026
The short version
Ringfence is built so the numbers you call and are called by stay on your iPhone. The blocking list is downloaded to the device and applied there. We do not receive a log of your calls.
What leaves your iPhone
- An APNs device token — an opaque routing handle so the app can be told a new protection list exists. It carries no phone number and no identity.
- An install identifier — a random UUID generated on your device, used to return your own screening log to you and nobody else's.
- Numbers you choose to report — only when you tap report. Reporting is optional and the app works fully without it.
- Calls you forward to the screening line — only if you set up call forwarding yourself. Those calls reach our screening service by design; that is what forwarding means.
What never leaves your iPhone
- Your Allowed list and your personal blocks.
- Your contacts. Ringfence does not request contacts access.
- The numbers that call you, unless you forward or report them.
- The content of your text messages. The Message Filter extension runs on-device and, in this version, has no network permission at all.
Live Caller ID Lookup
When Live Protection is on, iOS — not Ringfence — performs an encrypted lookup for an unknown caller using Apple's Private Information Retrieval. The service that answers cannot see which number was asked about. That is a property of the protocol, not a promise we are making on our own behalf.
Purchases
Subscriptions are processed by Apple. We never see your payment details. The app stores only whether an entitlement is currently valid, and its expiry, on your device.
Analytics
There is no third-party analytics SDK, no advertising identifier, and no cross-app tracking in Ringfence.
Retention and deletion
Screened-call records are kept for 30 days and then deleted. Deleting the app ends all reporting; to have server-side records removed sooner, contact support.