Privacy Policy
Last updated: 23 June 2026
1. Introduction
This Privacy Policy explains how Xfaang sp. z o.o. ("we", "us", "our") collects, uses, shares and protects personal data in connection with your use of the CallNinja mobile app and this website (together, the "Service").
CallNinja is a service that protects a loved one (the "ward", typically a senior) from unwanted and suspicious phone calls. The Service is used by a guardian who manages the protection. The ward does not install any app on their phone.
2. Data Controller
The controller of your personal data is:
Xfaang sp. z o.o.
REGON: 385801871
NIP: 7010975511
KRS: 0000833989
For any data protection matter, contact us at gdpr@xfaang.com or visit www.xfaang.com.
3. Cookies and Tracking
This website does not use cookies. We do not use analytics, tracking technologies or third-party services that would place cookies or similar mechanisms on your device.
4. What Data We Collect
As part of the Service we process the following categories of data:
Guardian account
- Email address
- Password (stored only as an encrypted hash, never in plain text)
- Display name
- Guardian phone number (used to receive notifications and forwarded calls)
Ward data
- Ward's name or label
- Ward's phone number
- Verification status and active-protection status
Phone lists and call history
- Phone numbers added to the whitelist, blacklist, AI Reception or redirect lists, together with their labels
- Information about incoming calls to the ward (caller number, date and time, number of attempts)
- AI Reception screening results (who called, the reason, and a risk assessment)
5. How We Use the Data
- To provide and maintain the CallNinja Service and manage the guardian account
- To verify the ward's phone number with an SMS code
- To filter incoming calls and route them according to the guardian's settings
- To let the AI Receptionist answer calls from unknown numbers and prepare a report
- To send the guardian notifications about rejected calls and risk assessments
- To ensure security and to improve our products and services
6. Legal Basis for Processing
We process data on the basis of:
- Art. 6(1)(b) GDPR — performance of the contract for the Service;
- Art. 6(1)(a) GDPR — your consent (e.g. SMS verification);
- Art. 6(1)(f) GDPR — our legitimate interest in protecting users from phone fraud and in the security of the Service.
7. Ward Data Provided by the Guardian
The guardian adds the ward's data to the app (name, phone number) as well as numbers from the ward's contacts. By adding this data, the guardian confirms that they are authorised to do so and that, to the appropriate extent, they have informed the ward about the use of the Service. We process this data solely to provide the protection and for no other purpose.
8. Data Sharing — Service Providers
We do not sell your data. We use trusted providers (processors) to whom we entrust data only to the extent necessary for the Service to function:
- Airtable — hosting of the database that stores accounts, phone lists and protection configuration.
- SerwerSMS.pl — sending the SMS verification code to the ward's number. Learn more: serwersms.pl/en/privacy-policy.
- Twilio — routing and handling of phone calls (forwarding, filtering).
- ElevenLabs — the voice AI Receptionist that answers calls from unknown numbers and processes their content to prepare a report for the guardian.
Some of these providers may process data outside the European Economic Area. In such cases the transfer is carried out under the appropriate safeguards required by the GDPR (e.g. standard contractual clauses).
9. Data Retention
We retain data for as long as necessary to provide the Service and maintain the guardian account. When an account or a ward is deleted, we remove the associated data, unless longer retention is required or permitted by law.
10. Your Rights
In relation to the processing of your data, you have the following rights:
- the right to access your personal data,
- the right to rectification of inaccurate data,
- the right to erasure ("right to be forgotten"),
- the right to restrict or object to processing,
- the right to data portability,
- the right to withdraw consent at any time,
- the right to lodge a complaint with the Polish Data Protection Authority (UODO) or your local supervisory authority.
To exercise these rights, contact us at gdpr@xfaang.com.
11. Security
We apply appropriate technical and organisational measures to protect data against unauthorised access, alteration, disclosure or destruction. Passwords are stored only as an encrypted hash.
12. GDPR Compliance
- We collect only the minimum data needed to provide the Service.
- We process data lawfully, fairly and transparently.
- We implement appropriate data security measures.
- We respect all rights of data subjects.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new version on this page along with an updated date.
14. Contact
Xfaang sp. z o.o.
Email: gdpr@xfaang.com
Website: www.xfaang.com