Privacy Policy
Last updated: October 10, 2026
Spam Call AI is a personal call-screening application. This policy explains how information is used when the application is connected to Google Contacts and telephony/AI services.
Google Contacts data
The application requests read-only Google Contacts access. It uses that access only to read contacts associated with the configured trusted-caller label so those callers can bypass AI screening.
- Google Contacts are not edited or deleted by Spam Call AI.
- Trusted contact names and phone numbers may be cached locally within the Home Assistant installation so the call screener can recognize safe callers.
- Google Contacts data is not sold, used for advertising, or shared for unrelated purposes.
Call data
Incoming calls are processed through Twilio. Calls that require AI screening may send call audio and transcript content to OpenAI so the assistant can conduct the screening conversation and classify the call.
The application may locally store call metadata such as the caller's phone number, call time, classification, callback number, reason for calling, and whether the caller was blocked or trusted.
Other service providers
The application may rely on Twilio for telephony, OpenAI for AI voice and call analysis, ngrok or another secure tunnel provider for webhook connectivity, Google for Contacts access, and Home Assistant for local application state and automation.
Data retention and control
Local application data is retained in the user's own Home Assistant environment until it is removed by the user or overwritten by normal application operation. OAuth access to Google Contacts can be revoked from the user's Google Account at any time.
Security
Spam Call AI is designed to minimize access to private information. The Google integration uses read-only Contacts access, and the voice assistant is instructed not to reveal private or sensitive information about the phone owner.
Contact
For questions about this application or its Google authorization, use the support contact shown on the application's Google OAuth consent screen.