Legal
Privacy Policy
This Privacy Policy explains how Callio collects, uses, shares, stores, and protects information when you access or use our website, random voice-calling service, text-chat features, guest-profile features, reporting tools, and any other Callio service that links to this Policy.
In this Policy, these features are collectively called the "Service."
Your privacy matters to us. We aim to collect only the information reasonably needed to operate Callio, keep the Service secure, enforce our rules, and improve the user experience.
Please read this Privacy Policy carefully.
Our Terms of Service explain the rules governing your use of Callio. Our Community Guidelines explain the conduct permitted on the Service.
If you do not agree with this Privacy Policy, you should not use the Service.
1. Who Is Responsible for Your Information
Callio is responsible for deciding how and why personal information is processed through the Service.
For privacy questions, privacy requests, or general support, contact Callio through our support email.
Support email: [SUPPORT EMAIL]
In data-protection terminology, Callio is generally referred to as the "controller" of your personal information.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal information processed when you:
- visit the Callio website;
- access or use the random voice-calling service;
- create or use a guest identity;
- choose a display name, profile image, biography, or other profile information;
- enter or leave the matching queue;
- participate in a voice call;
- exchange text messages or other communications through Callio;
- use call-history, callback, incoming-call, or related communication features where available;
- submit a report;
- contact support, safety, privacy, or legal teams;
- interact with Callio's official communications; or
- otherwise use a feature that links to this Policy.
This Policy does not govern third-party websites, applications, or services that have their own privacy policies.
3. Information You Provide to Callio
Depending on how you use the Service, you may provide the following information.
3.1 Guest-profile information
Callio may allow you to create or use a guest identity without registering a traditional account.
Guest-profile information may include:
- a display name;
- a profile image or avatar;
- a biography;
- profile preferences;
- language or region preferences;
- profile identifiers generated by Callio; and
- other information you choose to add to your profile.
Do not include highly sensitive personal information in your display name, biography, profile image, or other public-facing profile information.
Other users may be able to see some of the profile information you choose to provide.
At launch, Callio profile fields currently include a generated or edited display name, a selected profile image, a biography, locally stored profile preferences, and identifiers created to operate the Service.
3.2 Communications
When you use communication features, you may provide:
- voice communications during calls;
- text messages sent during a call;
- emojis or reactions;
- callback or incoming-call requests;
- information voluntarily disclosed during conversations; and
- other content submitted through communication features.
You control what you choose to say or share with another user.
Avoid disclosing passwords, authentication codes, payment details, government identification numbers, precise home addresses, or other highly sensitive information to strangers.
3.3 Reports and safety information
When you report another user or safety concern, we may collect:
- the report category;
- the reason for the report;
- information you include with the report;
- identifiers associated with the reporting and reported users;
- relevant session or call identifiers;
- timestamps;
- relevant moderation history;
- technical information connected to the reported interaction; and
- communications or supporting material submitted through the reporting process.
Callio does not automatically capture or permanently store ordinary call audio, screenshots, or message transcripts as report evidence. Reports typically contain the information a user submits together with related technical, session, and moderation metadata reasonably needed to review the report.
You must not submit unlawful content or unnecessary sensitive information when filing a report.
3.4 Support and other correspondence
If you contact us, we may collect:
- your name or display name;
- your email address;
- the content of your message;
- attachments you choose to provide;
- information needed to investigate your request; and
- our correspondence with you.
3.5 Privacy requests and appeals
If you submit a privacy request, moderation appeal, or legal request, we may collect information necessary to:
- understand the request;
- verify that you are authorised to make it;
- locate relevant records;
- communicate with you;
- prevent fraud or misuse; and
- comply with legal obligations.
We do not seek more identity information than is reasonably necessary for the relevant request.
4. Information Collected Automatically
When you access or use Callio, certain information may be collected automatically.
4.1 Device and browser information
This may include:
- device type;
- operating system;
- browser type and version;
- browser language;
- screen or viewport information;
- device and browser capabilities;
- microphone permission status;
- notification permission status;
- user-agent information;
- application version;
- referring page;
- pages or features accessed; and
- diagnostic information.
4.2 Network and connection information
This may include:
- Internet Protocol address;
- network and connection information;
- approximate geographic area derived from an IP address;
- country or region indicator;
- connection timestamps;
- connection quality;
- latency;
- call-connection status;
- WebSocket or Socket.IO connection information;
- WebRTC connection information;
- error and disconnect information; and
- security-related network signals.
An IP-derived location is generally approximate and should not be treated as precise GPS location.
Callio may use IP-derived location information to display an approximate country or region indicator to other users and to support safety, abuse prevention, and moderation.
4.3 Service-usage information
This may include:
- when you access the Service;
- pages and features used;
- queue activity;
- matching attempts;
- call start and end times;
- call duration;
- call outcome;
- skipped, ended, missed, incoming, or callback interactions;
- reports submitted or received;
- moderation or restriction events;
- settings and preferences;
- button and feature interactions;
- error logs;
- crash information; and
- performance information.
4.4 Identifiers
Callio may generate or store identifiers used to operate the Service, such as:
- guest identifiers;
- session identifiers;
- socket identifiers;
- call identifiers;
- report identifiers;
- device-related identifiers;
- browser-storage identifiers;
- moderation identifiers; and
- security or abuse-prevention identifiers.
Some identifiers may remain associated with a browser, device, network, guest profile, or session for a limited period.
4.5 Cookies and similar technologies
Callio may use cookies, local storage, session storage, or similar browser technologies to:
- maintain a guest identity;
- remember preferences;
- keep the Service functioning;
- support security;
- prevent abuse;
- remember age or policy acknowledgements;
- support call-history or related functionality;
- understand whether features work correctly; and
- measure or improve the Service where permitted.
More information appears in the "Cookies, Local Storage, and Similar Technologies" section below.
5. Voice Calls and Audio Information
Callio is primarily a live voice-communication service.
Voice calls may require audio data to be transmitted between users using technologies such as WebRTC and supporting connection infrastructure.
Callio needs to process technical information necessary to establish, maintain, and end a call.
This may include:
- call and session identifiers;
- connection timestamps;
- connection state;
- call duration;
- network information;
- connection-quality information;
- signalling information;
- error information; and
- other metadata needed to operate or secure the call.
Callio uses live audio-connection technology and managed real-time media infrastructure to connect users and route voice audio during calls. Supporting signaling and connection infrastructure is also used to establish, maintain, or end the call.
Callio does not intentionally record or permanently store the audio content of ordinary voice calls.
Other users may independently attempt to record conversations. Our Terms of Service and Community Guidelines restrict recording without any consent required by applicable law, but Callio cannot guarantee that another user will follow those rules.
Think carefully before disclosing personal information during a call.
6. Text Messages and Other In-Call Content
Callio may allow users to exchange text messages, emojis, reactions, or other communications during a call.
Ordinary in-call text messages are intended to be delivered only during the active conversation.
Callio does not intentionally store ordinary text-chat content as part of permanent call history after a call ends, except to the extent a user separately includes message content in a report, support request, or similar submission.
Where message content is processed, Callio may process it as reasonably necessary to:
- deliver the communication;
- operate the feature;
- maintain safety and security;
- investigate reports;
- enforce our rules;
- prevent fraud or abuse; and
- comply with legal obligations.
Do not use Callio to send highly sensitive information to strangers.
7. Call History, Callback, and Incoming-Call Features
Callio may provide call-history, callback, incoming-call, or related features.
Depending on the feature you use, these features may process:
- another user's display name or profile information;
- guest identifiers;
- call identifiers;
- whether a call was completed, missed, ended, or skipped;
- call timestamps;
- call duration;
- callback status;
- incoming-call status; and
- local browser or server-side records needed to provide the feature.
At launch, call-history information is stored locally in the user's browser rather than as a server-side account history.
Locally stored call-history information generally remains available until you delete it through the Service, clear the relevant browser storage, or reset your browser data.
Deleting the relevant browser storage may remove locally stored call-history information, guest-profile information, and related preferences from that browser.
8. Information from Other Users
Other users may provide information about you.
For example:
- another user may report your conduct;
- another user may mention you in a support request;
- another user may provide your guest or session information;
- another user may submit communications or evidence involving you; or
- another user may identify a safety or legal concern connected to you.
We may process this information to investigate reports, enforce our rules, protect users, respond to requests, and comply with legal obligations.
A report does not automatically establish that a violation occurred.
9. Information from Service Providers and Other Sources
We may receive information from companies that help us operate Callio.
Depending on the services used, this may include information from:
- hosting providers;
- cloud infrastructure providers;
- content-delivery networks;
- database providers;
- analytics providers;
- error-monitoring providers;
- email or support providers;
- security and abuse-prevention providers;
- WebRTC, STUN, or TURN infrastructure providers;
- notification providers; and
- legal, compliance, or professional advisers.
We may also receive information from:
- public sources;
- competent authorities;
- users reporting safety issues;
- fraud or security researchers; and
- other sources where permitted by law.
Where specific provider disclosures are legally required, Callio will publish them through this Policy or another appropriate notice.
10. How We Use Information
Callio may use personal information for the following purposes.
10.1 Providing and operating the Service
We may use information to:
- provide access to Callio;
- maintain guest identities;
- display profile information;
- place users in the matching queue;
- match users for calls;
- establish and maintain voice connections;
- deliver text messages and other communications;
- provide call-history, callback, or incoming-call features;
- remember settings;
- provide support; and
- otherwise deliver requested functionality.
10.2 Safety, security, and abuse prevention
We may use information to:
- detect suspicious activity;
- prevent spam, fraud, scams, harassment, and technical abuse;
- investigate reports;
- enforce our Terms of Service and Community Guidelines;
- detect or prevent ban evasion;
- protect users;
- protect Callio's systems;
- diagnose security incidents;
- maintain service integrity; and
- respond to serious safety risks.
10.3 Maintaining and improving Callio
We may use information to:
- diagnose errors;
- monitor performance;
- understand how features are used;
- improve call quality;
- improve reliability;
- test new functionality;
- measure the effectiveness of changes;
- conduct internal research and analysis; and
- develop or improve features.
Where reasonably possible, we may use aggregated or de-identified information for these purposes.
10.4 Communicating with you
We may use information to:
- respond to support requests;
- respond to privacy requests;
- communicate about reports or appeals;
- send important service messages;
- notify you about safety or security matters;
- inform you about material policy changes; and
- send communications you have requested.
10.5 Legal and compliance purposes
We may use information to:
- comply with applicable law;
- respond to lawful requests;
- establish, exercise, or defend legal claims;
- protect our legal rights;
- maintain required records;
- respond to regulators or competent authorities; and
- enforce agreements.
10.6 Business operations
We may process information for limited internal business purposes, such as:
- auditing;
- accounting;
- fraud prevention;
- service planning;
- corporate transactions;
- risk management; and
- professional advice.
11. Legal Bases for Processing
Where the General Data Protection Regulation, United Kingdom GDPR, or similar law applies, Callio must have a valid legal basis for processing personal information.
Depending on the specific processing activity, Callio may rely on the following legal bases.
11.1 Performance of a contract
We may process information when it is necessary to provide the Service you requested under our Terms of Service.
Examples may include:
- maintaining your guest session;
- placing you in a matching queue;
- connecting a call;
- delivering a text message;
- remembering essential settings; and
- responding to a service request.
11.2 Legitimate interests
We may process information where it is necessary for a legitimate interest and that interest is not overridden by your rights and freedoms.
Legitimate interests may include:
- securing Callio;
- detecting fraud and abuse;
- investigating reports;
- enforcing our rules;
- preventing ban evasion;
- improving reliability;
- understanding service performance;
- protecting users;
- defending legal claims; and
- operating an effective communication service.
Where required, we will assess the relevant interests and privacy impact.
11.3 Legal obligations
We may process information where necessary to comply with a legal obligation.
Examples may include:
- responding to valid legal requests;
- maintaining legally required records;
- addressing data-protection requests;
- cooperating with competent authorities where required; and
- complying with applicable safety or reporting obligations.
11.4 Consent
We may rely on consent where required.
Examples may include:
- optional analytics cookies if Callio introduces them in the future;
- optional notifications;
- certain communications;
- optional device permissions; or
- other processing for which the law requires consent.
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawing consent does not make earlier processing unlawful.
11.5 Vital interests
In rare circumstances, we may process information where necessary to protect someone's life or physical safety.
11.6 Legal claims and substantial public interests
Where permitted by law, we may process information to establish, exercise, or defend legal claims or for another substantial public-interest reason recognised by applicable law.
The specific legal basis for any processing activity depends on the feature used, the information involved, and the law that applies in your jurisdiction.
12. Sensitive Personal Information
Callio does not require users to provide sensitive personal information in order to participate in ordinary conversations.
However, users may voluntarily reveal sensitive information during calls, messages, reports, or support requests.
Sensitive information may include information concerning:
- health;
- disability;
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- sexual orientation;
- sex life;
- biometric identity;
- genetic information; or
- criminal allegations.
Do not share sensitive information unless you understand the risks.
Where Callio knowingly processes legally protected sensitive information, we will do so only where an appropriate legal basis and additional legal condition apply.
We may process sensitive details contained in a safety report where necessary to investigate serious misconduct, protect users, establish or defend legal claims, or comply with law.
15. Analytics and Performance Monitoring
Callio does not currently use separate third-party analytics or performance-monitoring tools in the live Service.
Depending on the tools selected, information may include:
- page views;
- feature interactions;
- approximate location;
- browser and device information;
- performance measurements;
- error messages;
- crash information;
- session identifiers; and
- limited network information.
If Callio later introduces analytics or monitoring tools, we will update this Policy before they are used and obtain any consent required by law.
16. Advertising and Marketing
Callio does not currently display third-party advertising, conduct marketing tracking, sell personal information, or use personal information for cross-site behavioural advertising.
If Callio introduces advertising, sponsored content, promotional tracking, or marketing profiling, this Policy must be updated before that activity begins.
Callio may send essential service communications without treating them as marketing.
Optional marketing communications should be sent only where permitted by law, and users must be able to unsubscribe.
17. Data Retention
Callio retains personal information only for as long as reasonably necessary for the purposes described in this Policy, including to:
- provide the Service;
- maintain security;
- prevent abuse;
- investigate reports;
- enforce our rules;
- resolve disputes;
- comply with law; and
- establish or defend legal claims.
Retention periods may depend on:
- the type of information;
- why it was collected;
- whether the user continues to use the Service;
- whether a report or investigation is active;
- whether the information is needed to prevent ban evasion;
- technical limitations;
- legal limitation periods; and
- legal retention obligations.
At launch, key retention practices work as follows:
- guest-profile information, selected avatars, preferences, and local call history may remain in your browser until you delete them through the Service or clear browser storage;
- active-call signaling data and temporary session state are retained only as long as reasonably needed to operate the live session and related connection handling;
- ordinary voice-call audio and ordinary in-call text messages are not intentionally retained as permanent call content after the live interaction ends;
- report information, moderation records, IP and security logs, support correspondence, privacy-request records, and related compliance records may be retained for as long as reasonably necessary to investigate safety issues, enforce rules, comply with law, and establish or defend legal claims; and
- backups may retain information for a limited additional period until they are overwritten or expire in the normal backup cycle.
Information may be retained longer where:
- required by law;
- necessary for an active investigation;
- necessary to protect users;
- necessary to prevent fraud or repeated abuse;
- required for legal claims; or
- requested by a competent authority under valid legal process.
When information is no longer reasonably needed, we aim to delete it, anonymise it, or place it beyond normal operational use until deletion from backups.
18. International Data Transfers
Callio may use service providers or infrastructure located outside your country.
This may result in personal information being transferred to or accessed from countries with different data-protection laws.
Where legally required, Callio will use an approved transfer mechanism or safeguard.
Depending on the circumstances, safeguards may include:
- an adequacy decision;
- standard contractual clauses;
- the United Kingdom International Data Transfer Agreement or addendum;
- another legally recognised transfer mechanism; or
- a lawful exception available for a specific transfer.
We may also apply additional technical, contractual, or organisational safeguards where appropriate.
Callio and the service providers that support it may process information in the country where you use the Service and in other countries where Callio or its service providers operate.
Where applicable law requires safeguards for international transfers, Callio will rely on the transfer mechanism required or permitted under that law.
Users may contact us for more information about relevant safeguards where the law gives them that right.
19. Data Security
Callio uses reasonable technical and organisational measures intended to protect information against:
- unauthorised access;
- unlawful use;
- accidental loss;
- alteration;
- disclosure;
- destruction; and
- other security risks.
Measures may include, where appropriate:
- access controls;
- authentication;
- encryption in transit;
- encryption at rest where appropriate;
- secure development practices;
- logging and monitoring;
- vulnerability management;
- backups;
- incident-response procedures;
- vendor controls;
- staff access restrictions; and
- data minimisation.
No online service can guarantee absolute security.
You are responsible for maintaining the security of your device, browser, email account, and any information you choose to share with other users.
If you believe you have discovered a security issue, contact:
Support email: [SUPPORT EMAIL]
Do not exploit a security issue or use it to access another person's information.
20. Personal Data Breaches
If Callio becomes aware of a personal-data breach, we will assess the incident and take steps appropriate to the circumstances.
Where required by applicable law, we will:
- notify the relevant supervisory authority;
- notify affected individuals;
- provide information about the nature of the incident;
- explain likely consequences;
- describe measures taken or proposed; and
- provide appropriate contact information.
Not every security incident creates a legal obligation to notify every user.
21. Your Privacy Rights
Depending on your location and applicable law, you may have some or all of the following rights.
21.1 Right to information
You may have the right to receive clear information about how your personal information is processed.
21.2 Right of access
You may have the right to ask whether Callio processes personal information about you and to request a copy of that information.
21.3 Right to correction
You may have the right to correct inaccurate personal information and complete information that is incomplete.
21.4 Right to deletion
You may have the right to request deletion of personal information in certain circumstances.
This right is not absolute. Callio may retain information where processing remains legally permitted or required, such as for security, fraud prevention, legal obligations, or legal claims.
21.5 Right to restrict processing
You may have the right to ask Callio to limit certain processing in specific circumstances.
21.6 Right to object
You may have the right to object to processing based on legitimate interests or to object to direct marketing.
21.7 Right to data portability
For certain information processed by automated means on the basis of consent or a contract, you may have the right to receive information in a structured, commonly used, machine-readable format or ask for it to be transferred where technically feasible.
21.8 Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.
21.9 Rights concerning automated decisions
You may have rights relating to decisions made solely through automated processing that produce legal or similarly significant effects.
More information appears in the "Automated Processing and Moderation" section.
21.10 Right to complain
You may have the right to complain to a data-protection or privacy authority.
If you are in the EEA, the UK, or another jurisdiction with a data-protection authority, you may also complain to the authority in the place where you live, work, or believe an infringement occurred.
You may also have the right to contact the authority where you live or work or where an alleged infringement occurred.
21.11 Additional regional rights
Residents of certain jurisdictions may have additional rights, such as rights to:
- know categories of information collected;
- know categories of recipients;
- opt out of certain selling or sharing;
- opt out of targeted advertising;
- limit certain uses of sensitive information;
- correct information;
- delete information;
- obtain a portable copy; and
- appeal a denied privacy request.
Additional privacy rights and disclosures may depend on where you live and on the specific processing activity involved.
22. How to Exercise Your Privacy Rights
To submit a privacy request, contact:
Support email: [SUPPORT EMAIL]
Callio does not currently provide a separate public privacy-request form.
Include enough information for us to understand your request.
Because Callio may use guest identities rather than traditional registered accounts, it may be difficult to connect a person to particular records.
We may ask for information reasonably necessary to:
- verify that you are connected to the relevant guest identity or information;
- prevent unauthorised access;
- understand the scope of the request; and
- locate responsive records.
We will not ask for excessive information solely to discourage a valid request.
Deleting cookies, local storage, a guest identifier, or browser data before submitting a request may make it harder or impossible for us to connect you to certain records.
We will respond within the period required by applicable law.
Where legally permitted, we may refuse or charge a reasonable fee for requests that are manifestly unfounded, excessive, repetitive, fraudulent, or impossible to verify.
If we deny a request, we will provide an explanation and information about available complaint or appeal rights where required.
You may be allowed to use an authorised representative where applicable law permits it.
23. Automated Processing and Moderation
Callio may use automated systems and technical signals to support:
- spam detection;
- fraud prevention;
- abuse prevention;
- ban-evasion detection;
- security;
- queue and matching integrity;
- report prioritisation;
- service reliability; and
- moderation workflows.
Automated systems may assist human reviewers or trigger temporary protective measures.
Callio may use automated systems to identify technical, abuse, or safety signals and to support moderation workflows.
Callio does not currently rely on solely automated decisions that by themselves produce legal or similarly significant effects on users.
Where applicable law gives you rights concerning a solely automated significant decision, Callio will provide the legally required information and review process.
24. De-Identified and Aggregated Information
Callio may create aggregated, statistical, or de-identified information that does not reasonably identify an individual.
We may use this information to:
- understand service usage;
- monitor performance;
- improve matching and call quality;
- research safety trends;
- plan features;
- prepare internal reports; and
- describe general platform activity.
Where information has been properly anonymised so that individuals are no longer identifiable, it may no longer be treated as personal information under applicable law.
Callio does not describe information as anonymous where it can reasonably be linked back to a person.
25. Age Requirements and Children's Privacy
Callio is intended only for people aged 18 or older.
Children and minors are not permitted to use the Service.
We do not knowingly offer Callio to children.
If we reasonably believe that a user is under 18, we may:
- restrict or terminate access;
- investigate the account or guest identity;
- remove associated profile information;
- preserve information where required for safety or legal reasons; and
- take other appropriate protective action.
If you believe a minor is using Callio, report the concern through Callio's reporting tools or contact:
Support email: [SUPPORT EMAIL]
If a parent or guardian believes Callio has processed a child's personal information, they may contact us.
We may request limited information needed to understand and verify the request.
Where required, we will delete a child's information unless retention is legally permitted or required for safety, investigation, or legal compliance.
Nothing in this section should be interpreted as allowing minors to use Callio with parental permission unless Callio formally changes its age policy.
26. Do Not Track and Browser Privacy Signals
Some browsers send "Do Not Track" signals.
There is not one universally accepted technical standard for responding to every Do Not Track signal.
Callio does not currently respond to generic "Do Not Track" browser signals.
Where applicable law requires Callio to recognise a legally valid opt-out preference signal, such as a Global Privacy Control signal, Callio will configure its systems to respond as required.
Because Callio does not currently sell personal information or use cross-site behavioural advertising, it does not currently operate a separate opt-out flow based on Global Privacy Control or similar signals. If that changes and applicable law requires such controls, Callio will update this Policy accordingly.
27. Third-Party Links and Services
Callio may link to or integrate with third-party services, such as:
- Discord;
- social platforms;
- support tools;
- hosting or infrastructure providers;
- external websites; and
- other services.
When you use a third-party service, that service may process information under its own terms and privacy policy.
Callio does not control the privacy practices of independent third parties.
Review the relevant third party's privacy information before providing personal information.
A link to another service does not mean Callio is responsible for that service's data practices.
28. Changes to This Privacy Policy
We may update this Privacy Policy as Callio develops.
We may make changes because of:
- new features;
- changes in technology;
- changes in our service providers;
- new safety or moderation practices;
- legal or regulatory developments;
- changes to the information we process; or
- efforts to make the Policy clearer.
When we update this Policy, we will change the "Last updated" date.
Where required by law, we will provide additional notice or request consent before a material change takes effect.
We will not use an updated Policy to retroactively justify materially different processing where applicable law does not allow it.
You should review this Policy periodically.
29. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or Callio's handling of personal information, contact us through our support email.
Callio
Support email: [SUPPORT EMAIL]
If your request concerns access to, correction of, or deletion of personal information, clearly state that your request is a privacy request so that it can be handled appropriately.