Skip to content
BanCaller
How it works Security About us Account

Legal information

Privacy Policy

What stays on your phone, what information reaches BanCaller and what happens to it after account deletion.

Version: 25 September 2026

In this document

  1. Controller and contact
  2. Data and its sources
  3. Data on your phone
  4. Purposes and legal bases
  5. Recipients and location
  6. Data retention
  7. Account deletion
  8. Your rights
  9. Information about your number
  10. Cookies and web services
  11. Minors
  12. Changes to this document
support@bancaller.com

1. Controller and contact

The controller of personal data processed through BanCaller is WISE Group Sp. z o.o., ul. Poznańska 64, 05-850 Jawczyce, Poland, KRS 0000957362, NIP 1182237693. This policy covers bancaller.com and the BanCaller apps for iOS and Android.

For personal data matters, write to odo@wise.pl. For questions about the app or your account, write to support@bancaller.com. You may also write to the company’s postal address. Full operator details are available in the Legal notice.

2. What data we process and where it comes from

  • Account, if you create one: nickname, email address, secured password hash, selected language, account state and service dates, associated devices, report history and point history. Your nickname is public and need not be your real name. An account is optional, but using the service without one does not mean that no technical device data is processed.
  • Device and security: installation and device identifiers used by BanCaller, platform, device name, public key, access and verification information, attestation results, timestamps and IP address. App and device authenticity checks use Apple or Google services. On Android, anti-abuse mechanisms may use a hash of the Android ID; on iOS, identifier signals may include IDFV. The device private key is never sent to BanCaller.
  • Checking or reporting a number: phone number, selected category, operation identifier and time, and its technical link to the device and, once the device is assigned, to the account. A manual online number check sends the checked number to the server. It does not automatically submit a report.
  • Number database: numbers, categories, statuses, report and moderation history, and names or labels entered by the operator. Sources include user reports and entries added manually by WISE Group. The data may concern someone who does not use BanCaller.
  • Protection and notifications: selected numbering zones, synchronisation settings, database update information, access identifiers, and a PUSH token and notification history when notifications are used.
  • Website and contact: session data, preferred language, IP address and technical request information, security events, email address and the content of correspondence you send. Do not send passwords, tokens or other people’s data that is not needed to resolve the matter.

We do not use advertising, additional analytics tools or third-party error monitoring. Security features and technical logs are not used to build advertising profiles.

3. What happens on your phone

Call identification relies on a downloaded database on the phone. An incoming call alone does not send a report to BanCaller. The app does not upload your address book or full system call history. It does not record calls or send SMS content.

On iOS, the system reporting extension receives the call or message data selected by the user. BanCaller uses the sender’s number and the selected category, not the message content. A deliberately prepared report may be delivered through Apple’s system to the server as a proposal and confirmed using the app’s mechanism.

On Android, the call-screening role allows the system to pass handled-call data to the app. Matching against the database and the handling decision occur locally. The app may retain local call context so the user can later report a selected number. Submitting the report requires user action.

System settings let you disable identification, blocking and notifications. Revoking a permission may limit the related feature but does not erase data previously sent to the server. Uninstalling the app does not delete the account.

4. Purposes and legal bases

  • Providing requested features: operating accounts and devices, search, database updates and reports — necessary to perform a contract or take steps before entering into one, Article 6(1)(b) GDPR.
  • Limiting abuse and maintaining security: device verification, limits, prevention of false reports and incident handling — the legitimate interests of the controller and users, Article 6(1)(f) GDPR.
  • Creating and sharing number information: helping identify unwanted calls and updating and moderating the database — the legitimate interests of the controller and users, Article 6(1)(f) GDPR, with due regard for the rights of people whose numbers are involved.
  • Contact, complaints and claims: performance of a contract or the legitimate interest in responding and protecting rights — Article 6(1)(b) or (f) GDPR. Compliance with a legal obligation is based on Article 6(1)(c) GDPR.

Providing data is voluntary, but we cannot provide a feature without the data it requires. System consent for notifications or access to phone features is not consent to arbitrary data processing and does not replace a legal basis.

A number’s status is calculated automatically from reports and moderation rules and may be changed by the operator. Depending on the recipient’s settings, this may result in a call being labelled, silenced or rejected. It is not a finding that the number owner committed a crime. You can challenge the result and request human review.

5. Recipients and data location

WISE Group operates hosting, the database, mail and backups itself on infrastructure in Poland. Administrative access is limited by role and by the responsibilities of people operating the service.

Other users’ apps receive the data needed to identify numbers: a number, its label, category and status. We do not distribute your email address, password or the identity of a particular report’s author with the database.

  • Apple: iOS app distribution, app and device verification, system reporting and APNs notifications. These services may process identifiers, authenticity evidence and technical data needed to perform an operation.
  • Google: Android app distribution, Play Integrity and Device Recall, and Firebase Cloud Messaging notifications. These features use verification data, installation identifiers, tokens and other technical data required by the service.
  • Google Fonts: the website downloads fonts from Google servers. In doing so, the browser connects to Google and transfers an IP address and technical request data, among other information.
  • Authorised authorities: data may be disclosed where and to the extent required by law.

The Polish location of WISE servers does not mean that all Apple and Google operations take place in Poland or the European Economic Area. These providers operate globally. They describe data transfers and safeguards in the Apple Privacy Policy, Google Privacy Policy and Firebase privacy information. Information about safeguards applicable to a particular transfer by BanCaller and how to obtain a copy is available from odo@wise.pl.

6. How long we retain data

The following describes how the service currently operates. Account deletion and backup retention are separate matters.

  • Account data: until account deletion, with parts of the history retained as described below.
  • Report, number, moderation and point history: currently retained without a set automatic deletion date. After account deletion it remains in pseudonymised form and should not be treated as fully anonymous.
  • Application and server logs and support correspondence: the operator does not currently apply a general deletion schedule. Cleanup of certain data associated with a deleted account is described in the next section.
  • Backups: cover up to five years. A backup created before account deletion may contain earlier data until that backup expires. Account deletion does not retroactively modify every historical backup.
  • Short-lived data: activation tokens, authentication challenges and synchronisation files have their own expiry periods or cleanup mechanisms. This does not delete source reports or the entire history.

The absence of an automatic deletion period does not remove your GDPR rights or mean that every type of data may be retained without limit. You may ask us to assess whether continued processing is necessary, erase the data or restrict its processing.

7. How to delete your account and data

You can delete your BanCaller account on the website without having the app installed: go to your account, sign in, choose account deletion and confirm it with your current password. Deletion is also available in the app. If you cannot sign in, write to odo@wise.pl. We may need suitable identity verification before completing a request — do not send us your password.

Account deletion is permanent. In the active database, the email address and preferred language are removed, the nickname is replaced with a neutral label, and the existing password, sessions, tokens and assigned-device access are revoked. Some associated cleanup runs in the background and includes, among other things, IP addresses in linked application logs, names from registration attempts and selected notification content.

We do not automatically delete the entire history. Reports, points, status history and identifiers needed to preserve technical relationships remain. This is pseudonymisation, not a guarantee of irreversible anonymisation. Numbers that were reported do not disappear merely because the reporter’s account was deleted.

Signing out or uninstalling the app does not start account deletion. Deleting the account does not automatically remove correspondence from a separate mailbox, every infrastructure log or data independently processed by Apple and Google. You can submit a request concerning additional data to the data protection contact address.

8. Your rights

Subject to the GDPR, you have rights of access and to a copy of your data, rectification, erasure, restriction of processing and data portability when the relevant conditions are met. You may object to processing based on legitimate interests by explaining your particular situation. If processing is based on consent, you may withdraw it without affecting the lawfulness of earlier processing.

Send your request to odo@wise.pl. You do not need a BanCaller account to make a request about your data. We should respond without undue delay, generally within one month; any extension requires a legal basis and notice to you under the GDPR.

You may lodge a complaint with the President of the Polish Personal Data Protection Office — information is available at uodo.gov.pl — or another competent supervisory authority. You do not have to exhaust the operator’s complaint procedure first.

9. If your number is in the database

Information may come from other users or be added by WISE Group. A number and its label are shared through search and the protection database. This does not mean that we have confirmed the identity of the person who actually made every call — a number may be spoofed or reassigned.

If you believe an entry is wrong or infringes your rights, write to odo@wise.pl with the number and a description of the matter. You may request information about the data source, rectification, erasure or restriction, or object to the processing. Verifying your entitlement to a number should not require unnecessary data.

Resetting a spam label in the app is a technical feature. It does not replace a GDPR request and does not erase historical reports.

10. Cookies and website services

The website uses cookies needed to maintain a session, protect forms and, when selected, remember sign-in. The bancaller-session cookie currently lasts for 120 minutes and is renewed during activity. It is sent over HTTPS and is not available to website scripts. We do not use advertising or analytics cookies. Signing out or invalidating a session removes its access even if the cookie remains in the browser.

When you select a language, we store an encrypted bancaller_locale cookie for 12 months. It is unavailable to website scripts and is used only to select the Polish or English version of the service. For an active account, the preferred language may also be stored in the account data.

You may delete or block cookies in your browser, but this may prevent sign-in and form handling or return the website to its default language. It does not delete account data. The website also uses Google Fonts as described above. Facebook, Instagram and YouTube links lead to external services governed by their own rules once opened.

11. Minors

BanCaller does not set one universal minimum age. This does not remove restrictions under the law applicable to a user or app-store rules. Where use of the service or data processing requires the consent or action of a parent or guardian, that requirement must be met.

The current forms do not collect dates of birth or provide a separate mechanism for verifying parental consent. We do not present the absence of our own age limit as confirmation that children’s-data requirements are met in every country. A parent or guardian may contact us about a child’s data at odo@wise.pl.

12. Changes to this document

The document version is shown at the top of the page. Changing the privacy description does not itself constitute consent to a new processing purpose. If a new feature requires separate information or consent, it must be provided in accordance with the law.

Other documents

Terms / EULA Legal notice
BanCaller

Less spam. More peace of mind.

Product

How it works Security About us

Help

Help centre Contact

Legal

Privacy Policy Terms / EULA Legal notice

Follow us

© 2026 BanCaller. All rights reserved.