Privacy
Last updated 7 September 2026
Doorman holds calls, texts and app notifications you did not invite, and tells you afterwards what it held. This page says exactly what that involves, including the part we cannot make a comfortable claim about.
The short version. The record of who contacts you is written on your phone, read on your phone, and deleted on your phone. We have no analytics, no advertising code and no crash reporting. We do not sell, share, or otherwise pass on anything about you, and there is no version of Doorman that pays for itself with your data.
What Doorman never touches
- Your messages. Doorman sees who a notification came from and which app sent it. It does not read the body of a message. It holds no permission that would let it.
- Your contacts. Android puts a saved contact's name on a notification before Doorman sees it, so a name means someone you know and a bare number means a stranger. That is the entire test, and it needs no access to your address book.
- Your call log. Written by your phone's dialler, not by us.
- Your microphone. Doorman holds no microphone permission and records nothing on your phone. The Line, which is not released yet, is the one exception and it is not on your phone: when a caller leaves a message on a Doorman number, that message is recorded on our side so it can be written down for you. What happens to it is set out under The Line below.
What stays on your phone, and only your phone
Screening calls on your own number, and the door that holds texts and app notifications, both run entirely on the device. The code that stores those records has no network access of any kind.
What a record contains
- A one-way fingerprint of the phone number, not the number. Numbers are hashed with SHA-256 and shown to you in a masked form such as
+1•••••0142. - For an app, its package name. That is not a secret and it is what you act on.
- The decision, the rule that produced it, and a plain-English reason.
- The time it arrived.
- For a call, the region an area code belongs to, worked out from a fixed table on the device. This is geography, not caller identity, and it involves no lookup and no network.
How long
You choose: 7, 30 or 90 days. The default is 30. Deletion is real code that runs when the app starts, not a sentence in a policy, and you can also clear the history immediately from Settings.
The Doorman line, and the claim we will not make
The Line is an optional paid feature: a phone number we operate, which your carrier can send your unanswered calls to, so that they are answered rather than left in your voicemail.
A service that answers a call has to process that call. So we cannot tell you we see nothing, and we are not going to pretend otherwise. What we can tell you is narrower and true: we keep the least we need to show you the decision, we keep it for a bounded time you control, we send it nowhere else, and we will not build a second business on it.
When the Line handles a call, our server processes:
- The caller's number, the time, and the reason the caller selected from a fixed menu of options.
- An identifier for your device. Your own phone number is never returned by our API, never written to our logs, and never appears in a notification summary.
- The message itself. A caller who leaves one is recorded, and that recording is transcribed so you can read who called and why without listening to anything. The caller is told the message is recorded, in plain words, before recording starts.
The recording is deleted as soon as it has been transcribed, at the company that captured it, not merely dropped from our own database. If a transcript never arrives it is deleted anyway, within ten minutes. What we keep is the text.
You can ask us to keep the audio as well, and it is off unless you do. When it is off, an empty audio field on a message means the recording is gone, not that we simply did not fetch it.
Two companies see a message on its way to you: the telephone provider that answers the call and records it, and the service that turns speech into text. Neither is given anything about you beyond the call itself, and neither is permitted to keep it.
These records are deleted after 30 days by a sweeper that runs on a timer. Our logging filter strips anything shaped like a phone number or a credential before a line is written, and request bodies are never logged.
Payments
Purchases are handled by Google Play. Doorman never sees or stores your card, your billing address or any payment detail. We ask Google Play what you own; it answers yes or no, and we keep only that answer.
Permissions, and why each one exists
- Notification policy access. Do Not Disturb is the only mechanism Android evaluates before a notification makes a sound, so it is the only way to hold a text without one. Doorman registers its own rule and never edits the Do Not Disturb settings you chose for yourself.
- Notification access. Lets Doorman tell you what the door held. The door works without it; you simply lose the record. Nothing read here leaves the phone.
- Post notifications. The twice-daily summary, which is the only notification Doorman ever sends you.
- Internet, and network state. Reaching Google Play, and the Line. Two of the entries in our manifest are added by Google's billing library rather than written by us.
Requesting a permission is not the same as being granted one. Every item above is granted by you and can be taken back by you at any time, in Android's own settings.
Children
Doorman is not directed at children and we do not knowingly collect anything from them.
Changes
If this page changes in a way that affects what we handle, we will say so in the app rather than quietly updating the date at the top.
Contact
Questions, or a request about your data: privacy@mydoorman.app. To delete everything, see deleting your data.