Legal
Privacy Policy
Effective date: June 1, 2026
Last updated: September 25, 2026
NumBan ("we," "us," or "our") operates the NumBan mobile application and the numban.com website (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
1.1 Account Information
When you create an account, we collect your US mobile phone number and send a one-time SMS code to authenticate you. That phone number is linked to your NumBan account. We assign a display handle (username) used on the public leaderboard. We do not currently offer email or Sign in with Apple.
1.2 Report Data
When you submit a scam voicemail report, the following is linked to your NumBan account:
- The voicemail audio file you share from your device
- An uncropped screenshot or photo of the voicemail screen that you choose to share, including text and dates visible in the image
- Text recognized from a shared screenshot to help match it to the voicemail report and callback number
- Transcript metadata provided by iOS (the visual voicemail transcript)
- An independent audio transcription generated on our servers (Workers AI Whisper) to extract and verify callback numbers
- The callback phone number you confirm for the report
- The scam type classification
- Timestamps associated with the report
1.3 Device Information
If you enable push notifications, we collect your APNs device token and may use OneSignal to deliver service notifications about report submissions, report status, remaining report quota, number changes, and kill confirmations. These notifications are related to activity or reports in NumBan, not promotional messages. Device tokens are linked to your account. We do not sell device identifiers for advertising.
1.4 Subscription and purchase data
If you subscribe to NumBan Pro, Apple processes the payment. We use RevenueCat to validate entitlements and sync your subscription status to your NumBan account. We store subscription tier and expiry, linked to your account. We do not store full payment card numbers. Payment method details stay with Apple.
1.5 Diagnostics
We use Firebase Crashlytics to collect crash logs and device diagnostics so we can fix bugs. Crash reports may include device type, OS version, and stack traces. They are not used for advertising.
1.6 Automatically Collected Information
Our servers log standard request metadata (IP address, user agent, timestamps) for security, abuse prevention, and rate limiting.
1.7 Product Analytics and Install Attribution
We use the Layers SDK to record app lifecycle and screen-view events, voicemail shares, screenshot shares, report approvals, and successful purchases, and to attribute app installations to campaigns. The SDK may send persistent installation or device identifiers, app and device context, campaign or referral attribution signals, and your NumBan account ID after sign-in; purchase events include the product identifier. We use this information for product analytics and install attribution, not to show ads in NumBan. NumBan does not request App Tracking Transparency permission.
2. How We Use Your Information
We use the information we collect to:
- Authenticate your account — verify your identity via SMS one-time codes
- Process reports — verify callback numbers by cross-referencing transcript metadata and audio transcription; recognize visible text in screenshots to help match them to reports; identify the responsible carrier via number lookup; and prepare abuse complaints
- Route abuse complaints — prepare approved reports for carrier filing; while automated email delivery is disabled, NumBan files complaints manually
- Track number status — periodically probe reported numbers (SIP/voice) to confirm kills, separate from carrier attribution lookups
- Deliver notifications — inform you about report status changes and kill confirmations via push notifications
- Maintain public number pages — publish aggregate, redacted report data for public interest and search engine indexing
- Operate the leaderboard — rank users by confirmed kills using their chosen display handle, and show hit (submission) counts (Pro status does not affect rank)
- Provide Pro features — recording clusters, rotation tracking, dossiers, evidence export, and family seats for paid subscribers
- Diagnose crashes — collect crash logs via Firebase Crashlytics
- Prevent abuse — enforce rate limits, free-tier monthly report caps, detect false reports, and maintain service integrity
3. Information We Share
3.1 Carrier Abuse Reports
Approved reports are prepared as abuse complaints for the carrier or Responsible Organization (RespOrg) that controls the callback number. While automated email delivery is disabled, NumBan files complaints manually. When sent by email, they use a NumBan-managed relay address (e.g., report-xxxx@relay.numban.com). Your personal email address, phone number, and name are not included in carrier communications.
3.2 Public Number Pages
Reported numbers that meet our publication threshold may appear on public pages at numban.com/numbers/[number]. Public pages display only aggregate, redacted data: the callback number, report count, carrier name, scam type classification, evidence confidence level, and current status. No voicemail audio, screenshots, text recognized from screenshots, transcripts, personal recordings, or user identifiers are ever published.
3.3 Leaderboard
Your display handle, confirmed kill count, and hit (submission) count may appear on the public leaderboard. No other account information is displayed. We may remove a handle that violates these Terms.
3.4 Service Providers
We use the following third-party services to operate NumBan:
- Cloudflare — hosting, database (D1), object storage (R2), key-value store (KV), and edge compute (Workers)
- Twilio — SMS delivery for authentication codes and number lookup
- Resend — transactional email delivery; automated carrier-complaint email is currently disabled
- Apple Push Notification service (APNs) — push notification delivery
- RevenueCat — in-app subscription entitlement management
- Firebase Crashlytics — crash reporting and diagnostics
- OneSignal — transactional push delivery for report and number-status notifications
- Layers — product analytics and install attribution, including app lifecycle/screen views, report events, and purchase events. We do not sell this data.
These providers process data only as necessary to provide their services and are bound by their respective privacy policies and data processing agreements.
3.5 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of NumBan, our users, or the public.
4. Data Storage and Security
Account data, report metadata, recognized screenshot text, and number records are stored in Cloudflare D1 (SQLite). Voicemail audio and screenshot evidence are stored in Cloudflare R2 object storage. Shared screenshots are private report data and are not placed on public number pages. Session tokens are stored as SHA-256 hashes; we never store plaintext session tokens. Authentication codes are similarly hashed and expire after 10 minutes.
All data is transmitted over HTTPS/TLS. We use Cloudflare's global edge network for DDoS protection and request filtering.
5. Data Retention
- Account data — retained until you delete your account
- Voicemail audio and screenshot evidence — retained for up to 180 days from upload, or deleted sooner when you delete your account
- Report metadata — personal associations (transcripts, evidence keys) are removed upon account deletion; aggregate report statistics (counts, carrier, scam type) are retained for public interest
- Sessions — expire after 90 days; all sessions are deleted upon account deletion
- Authentication codes — expire after 10 minutes
- Subscription records — tier and expiry retained while the account is active; Apple retains payment records per Apple's policies
- Crash reports — retained by Firebase Crashlytics per Google's retention settings
- Server logs — retained for up to 30 days for security and debugging
6. Your Rights and Choices
6.1 Account Deletion
You can initiate account deletion from the app settings. If an Apple-billed NumBan Pro subscription is set to renew, you must cancel it before deletion can continue; billing remains managed by Apple, and access may continue through the paid period. Account deletion removes your personal data, voicemail audio and screenshot evidence, recognized report text, sessions, and device tokens. Your display handle is replaced with "deleted-user." Aggregate, anonymized report statistics (contribution to report counts on numbers) are retained.
6.2 Notifications
You can disable push notifications at any time through your device's notification settings.
6.3 Display Handle
A display handle is assigned when you create an account and may appear on the public leaderboard. Contact support@numban.com if you need it changed. We may replace a handle that violates our Terms.
6.4 Subscriptions
You can manage, cancel, or request a refund for NumBan Pro through your Apple ID (Settings → Apple ID → Subscriptions, or Manage subscription in the app). Canceling stops future renewals; it does not delete your NumBan account.
7. Children's Privacy
NumBan is not directed to children under 13. We do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.
8. International Users
NumBan currently supports US phone numbers only. Data is processed on Cloudflare's global edge network. By using the Service, you consent to the transfer and processing of your data in the United States and other jurisdictions where Cloudflare operates.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new "Last updated" date. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at privacy@numban.com.