Privacy Directive
Vendetta Labs ("we", "us") operates the SecureCall mobile application. This Privacy Policy describes how we collect, use, and protect your information.
Our Commitment
SecureCall is built on the principle that privacy is a fundamental right. We collect the minimum operational data necessary to provide the service and avoid collecting call content, contact lists, or persistent call history server-side.
Data We Collect
- Call content: End-to-end encrypted — we cannot access it
- Call metadata: No persistent call history or recordings stored on servers. Signaling metadata (session IDs, connection IDs) is processed transiently for connection setup.
- Contacts: Raw contact names and numbers stay on device. SHA-256 hashes of normalized phone numbers are sent for optional SecureCall-user discovery. Because phone numbers have a limited search space, hashing alone does not guarantee anonymity or prevent re-identification.
- Phone number: Optional. If supplied, it is processed for registration, caller identification and number lookup; the SecureID-only path can be used without it.
- IP address: Visible during signaling and STUN/TURN connectivity; not persistently logged by our servers. TURN relay providers may see IPs required for WebRTC.
- Push tokens: FCM tokens may be stored for push delivery and cleared on deregistration.
Advertising (FREE Version Only)
The free version displays ads via Google AdMob. AdMob may collect device identifiers for ad personalization. You can opt out in your device settings. See Google's Privacy Policy. Pro and Premium versions contain no ads.
IFR Token
IFR holder verification is browser-only and launch-gated. When enabled, the checkout service processes the public wallet address, a one-time signed challenge and the public on-chain token balance; no wallet credential or private key is requested.
Third-Party Services
FREE: Firebase Crashlytics (anonymous crash reports, opt-out), Google AdMob (ads).
PRO & PREMIUM: No ads. Firebase Cloud Messaging (FCM) is used for push notifications across all tiers. STUN/TURN relay services are used for WebRTC connectivity.
Your Rights (GDPR)
You have the right to access, rectify, erase, and port your data. Because SecureCall avoids call content, contact uploads, and persistent server-side call history, most rights can be fulfilled locally or by deleting operational records tied to your SecureCall ID.
Account & Data Deletion
To delete your account and all associated data:
- Open SecureCall → Settings → Reset App
- Or use STEALTH-DELETE (5 rapid taps on "Reset App" in Settings)
- Or contact: kaspartisan@proton.me
All data is deleted immediately:
- SecureID registration data
- Contact list
- Call history
- All app data on device
No call content or call recordings are stored on our servers. FCM push tokens are cleared on deregistration. Uninstalling the app removes all remaining local data.
Source Transparency
The SecureCall client source code is publicly available for transparency and independent security auditing. Official SecureCall/StealthX branding, backend services, store releases, and paid Pro/Premium licensing remain operated by Vendetta Labs.
Source code: github.com/NeaBouli/stealth
StealthX Platform — Cross-Product Privacy
This privacy policy covers all products of the StealthX Platform:
- SecureCall — Voice calls. E2E encrypted, no call content stored server-side.
- SecureChat — Messaging. E2E encrypted via XChaCha20-Poly1305 + Double Ratchet. The Android APK is published on GitHub Releases; relay and identity layers are documented in the SecureChat security design. SecureChat Security Design
- Chameleon — Privacy overlay for Android. Protects text and app context with local-first encryption features. All sensitive data stays on device.
All three products share the same cryptographic direction and data-minimization principle. Product-specific network services such as FCM, STUN/TURN, and optional ads or crash reporting are documented above.
Contact
X: @secureslot · GitHub Issues
Vendetta Labs · Greece · GDPR compliant