Privacy Policy
Last reviewed: Sep 23, 2026
This is a complete draft undergoing final legal review. The substance reflects the architecture we run today; the legal wording may still change.
This policy describes what Idyno collects, why, where it is stored, and who can reach it. It is written to be understood rather than to protect us, and it contains no sentence that hides an actual practice.
Who we are
Idyno is a caller identification and reverse phone lookup service, available as iOS and Android apps and as a public website. We act as the data controller for everything processed through the service.
What we collect
- Phone numbers and the names attached to them, as received from the address books of users who explicitly agreed to share.
- Basic device data: operating system, device model, app version, and SIM country code — used to determine your region and ensure compatibility.
- Activity records: lookups, spam reports, and deletion requests, with their time and origin.
- Upload attribution for every record: who uploaded it, from which device, when, and from which app version.
- Network address and the country code Cloudflare derives from it — used to route you to your region and to prevent abuse.
- Your account identity if you sign in: your identifier at Apple or Google, or your phone number once proven by a WhatsApp code — together with your email address and display name where the provider sends them.
- On the website only: to understand how the site is used, we measure visits from outside the European Economic Area, the United Kingdom and Switzerland with Google Analytics — pages viewed, language, country, and actions such as store clicks, lookups and deletion requests. Advertising features and Google signals are switched off, and no phone number, name or contact is ever sent. Inside those regions Google Analytics stores nothing on your device. Separately, we keep our own daily counts that carry no identifier.
What we never collect or do
- We show no ads and embed no advertising library — not in the apps and not on the website.
- We do not sell, rent, or share your data for marketing purposes.
- We do not read your clipboard contents; we only detect that a number is present, and reading happens only on an explicit tap from you.
- We never expose your contacts to any third party.
Your account and signing in
The app has one account per person, created in a single step: signing in and signing up are the same action here, not two. You pick a way in — your Apple account, your Google account, or your phone number with a WhatsApp verification code — and if we already know you, you are in; if we do not, we create your profile.
What reaches us from Apple or Google is your identifier with them, your email address and your name, inside a signed token whose signature we verify against their published keys. Nothing travels the other way: we send them no phone number, no name, and not one contact. All they learn through us is that you pressed their button. If you chose to hide your email with Apple, what we hold is an anonymous relay address, not your real one.
Your account name is visible to you and to our admin panel, and nowhere else. It never appears to someone searching your number and it never enters the name database — the names shown in search results come from other people’s contact books alone.
You can delete your account from inside the app at any time. Deleting your account erases your profile and your ways of signing in. It does not remove your number from other people’s search results — that is a separate request, it works with no account at all, and it is described under “Deleting your number” below.
Caller identification while the phone rings, blocking, the privacy centre, and removing your number all keep working with no account, exactly as before.
Upload attribution — who uploaded your number
For every record we store who uploaded it, from which device, and when. This data is necessary for compliance, for abuse prevention, and for responding to lawful requests.
It is never shown to any user — not in the app, not on the website, not in any export. Access is limited to our administration console, and every access is written to an audit log capturing who looked, when, and for what stated reason.
Individual names are never published
Names received from address books never appear on a public page or in search engine results. Number pages on our website show only number facts and aggregate community signals.
Caller names appear inside the app while the phone rings, and to users who meet the sharing requirement when performing a manual lookup. Verified business identity is a declared exception: a business identifies itself and asks for its name to be shown.
The contact sharing requirement
The caller ID database is built from user contributions, so manual lookup inside the app requires sharing your address book. Sharing is optional, but manual lookup does not work without it.
The requirement never touches three things: caller identification during an incoming call, deletion of your number, and the privacy centre. Those are open to everyone with no condition attached.
You may withdraw sharing at any time, and we then delete what was uploaded from your address book.
How your data is stored
Every number is normalised to international format before storage, then stored in two forms: a stable fingerprint used for fast lookup, and an AES-256-GCM encrypted value that can be decrypted.
The encryption keys belong to us and live in a hardware vault per region. We can decrypt when required, our administration console reads the full data, and we respond to lawful requests.
What the encryption clearly protects against: a leaked disk or backup. What it does not claim: that it prevents us from access. We state this plainly, because claiming otherwise would be a lie.
Where your data is stored
We run one region: Riyadh, Saudi Arabia. It has its own database, its own keys, and its own backups, and your data does not leave the Kingdom.
Your region is fixed at registration from your number’s country code. Numbers from the European Union, the EEA, the United Kingdom, and Switzerland are refused at registration: no account is created and no data row is written. We refuse because we do not operate a European region, and letting you register on a promise that your data sits in Europe when it sits in Riyadh would be a false statement.
Countries we do not serve
We do not accept registration from country codes that impose localisation we cannot satisfy or that are subject to sanctions: Russia and Kazakhstan (+7), China (+86), Vietnam (+84), and Iran (+98). We neither process nor store data for users in those countries.
Deleting your number — instant and free
Deletion is a statutory right that we attach to no condition: no account, no subscription, no contact sharing, no fee.
From inside the app: verify ownership with a WhatsApp code, and deletion executes automatically in under a minute with no human in the loop.
From the website, on the "Control your number" page: verify ownership with a WhatsApp code and delete it instantly the same way — no account, no app. Anyone with no WhatsApp on their number fills in the removal request form instead; we confirm the request by email and carry it out manually.
After removal, your number enters a suppression list checked on both write and read, and remains hidden even if others upload it. This suppression is lifted only at your explicit request after you prove ownership. Restoring visibility does not bring back previously removed data or lift suppression of names you deleted.
Your rights
These rights are exercised free of charge and without requiring the app. Access, rectification, deletion of an individual name, and removal of your number from view take effect immediately on the “Control your number” page after ownership verification; anyone without WhatsApp on their number uses the removal request form on the same page. The verified owner may explicitly request restored visibility. If you believe a request was not handled properly, you may lodge a complaint with the supervisory authority in your country.
- Access: on the "Control your number" page, after verifying ownership with a WhatsApp code, see every name registered against your number, spam reports, and search count — directly, with no need to wait for a reply from us.
- Rectification: from the same page, declare your correct name, which deletes the names on file and shows yours instead with a "Confirmed by the owner" badge, or delete a single name on its own.
- Removal: delete an individual name or remove your number from view at any time, from the app or the “Control your number” page. You may request restored visibility after proving ownership, without bringing back previously removed names.
- Restriction: ask us to hide your number from lookup results without full deletion.
- Objection and withdrawal of consent: withdraw contact sharing whenever you wish.
Retention
- Raw contact batches are kept as they reached us, with no automatic time limit — no scheduled job deletes them after a set period.
- The effect of removal on internal records depends on the route used: deleting a number from the app erases its raw and aggregated records from the live database in the same transaction. Removing it through the “Control your number” page hides it from others while retaining its raw and aggregated records in encrypted form for internal use under the retention policy.
- Retaining aggregated records internally after removal through the website does not permit showing them to others. Restoring the number’s visibility does not republish old names or reports that were hidden or removed; new contributions received after restoration remain subject to the usual publication rules.
- Suppression of the number’s visibility has no automatic expiry and is not lifted when someone else uploads it or merely by signing in. It is lifted only at the owner’s explicit request after ownership verification.
- Audit logs are retained for the period the law requires.
Security
- Encrypted transport over TLS 1.3 only, with certificate pinning in both apps.
- Encryption at rest with keys held in a hardware vault per region.
- Administration console access via passkeys, a one-time code, and an IP allow list.
- Every administrative access to personal data requires a stated reason and is written to the audit log.
- Rate limiting on every API per device, per account, and per address.
Children
The service is not directed at anyone under sixteen, and we do not knowingly collect their data.
Changes to this policy
Any material change is announced in the app and on this page well before it takes effect, together with a plain statement of exactly what changed.
Contact
For any question or request about your privacy, use the form on the removal request page or the privacy address published in the app.
Who searched for your number
We record searches attributed to identified accounts, and show the owner of a number who searched for it — after they prove ownership of that number with a WhatsApp verification code.
- **Reciprocal**: you see who searched for you because you accepted being seen by those you search for. One condition for everyone.
- Only the **owner of the number** can see this log. It is never shown to another user, nor included in any export.
- No path in the system asks “who did X search for”. Reads are keyed by the number searched for, never by the searcher.
- The log **ages out and is erased** automatically after the period stated under “Retention”.
- Searches from public pages on the website are **not recorded**: they have no account, and a visitor opening a page is not a person searching.