Author and publisher: Voiperia LLC. Contact: zgloszenia@bitcaller.pl.
The bitCaller app
Version: 2026-10-01. Applies to the bitCaller app.
What data the app processes
- the SIP username and password needed to register with the configured provider;
- local account and app settings;
- a history of up to 100 events: number, direction, time, duration and result;
- microphone audio and received audio only during a call;
- technical SIP and network metadata needed to establish a call.
Recording is an optional feature of otoTelefon accounts. By default, it is available without an expiry date, and automatic recording is off. The provider of a managed account with a hidden password can disable recording or limit it to a date. Existing recordings remain available. Recordings stay local; users can delete them or copy them themselves. Call history does not contain audio content or raw SIP messages.
The system contact picker passes only the number selected by the user to the app and also works without permission to read the contact list. When Contacts is first tapped, the app asks for permission to read contacts so it can display caller names locally on the call screen, in the call notification and in call history. Refusing permission does not block the picker or calls. Contact data is not sent off the device. Names are not saved in call history: they are matched when numbers are displayed. A small name cache exists only in process memory and is cleared when contacts or the setting change. The feature can be turned off using the contact names switch in Settings; the app then does not look up names or ask for permission. Permission can also be revoked in the system’s app settings.
On the first launch with no configured accounts, bitCaller checks the clipboard locally once for a setup link, asks for permission to import the settings and removes that link from the clipboard after the decision, while ignoring unrelated content without saving or sending it.
Where the data goes
Credentials are encrypted with AES-GCM using a key from Android Keystore. The key cannot be exported, and the encrypted envelope and settings remain in the app’s private storage. Call history also remains solely on the device. System backup, transfer of app data to another device and cloud synchronisation are disabled.
During registration and calls, the SIP provider and the intermediate network receive the data required by the protocol, including the account identifier, numbers, call metadata and the RTP audio stream. The app uses SIP over UDP and RTP audio without transport encryption.
What the app does not do
The app contains no ads, analytics, telemetry, automatic crash reporting or tracking mechanisms. It does not automatically send call history to the developer and does not use its own intermediary server, push notifications or account synchronisation. Voluntary problem reporting is described below.
Voluntary problem reports
In Settings → About the app → Report a problem, you can describe a problem and review the full report. The report includes the app version, device model and Android version, theme, number of accounts and their profiles, registration categories, relevant settings and a limited selection of history and log categories from the selected period. It does not contain call content, recordings, raw SIP messages or saved passwords. Numbers, IP and email addresses, and marked credential fields are masked; known usernames, account names and available contact names are used locally only for masking. Reading available names for masking does not change the setting for displaying them during calls. The form does not request new permissions. The filter cannot recognise every piece of private information written in your own words. Do not enter passwords or other people’s data, and check the text before sending.
The draft and preview stay in process memory, without an exported file. Send by email opens the system mail chooser with the content visible. The app does not send the report in the background. The user must confirm sending in the mail app; the selected mail app may save a draft according to its settings. The recipient is shown in the preview. Once sent, the report is also handled by the sender’s and recipient’s email providers.
Storage and deletion
Credentials remain until the account or app data is deleted. Deleting an account removes its encrypted envelope; the shared Keystore key is deleted when the last account is removed. This does not guarantee that all data in the phone’s storage is physically overwritten. Call history can be removed with the clear history button; clearing app data or uninstalling the app also removes it.
Permissions and security
The microphone is used for calls. The network is used for SIP/RTP, while notifications, vibration and background operation allow calls to be received and made. The app is not intended for emergency calls. The displayed number comes from SIP signalling and does not verify the caller’s identity.
The website and partner panel
The website contains no ads, tracking tools or analytics. Your choice of light or dark theme is saved locally in the browser. The panel uses an essential session cookie for login, form protection and automatic logout after inactivity.
The panel stores the date, panel operator and unencrypted settings of generated accounts: SIP username, name, server, port, extension, DDI numbers, recording setting and end date, and format version. Historical entries may contain an unlock signature and a service code from the previous variant. The SIP password entered in the generator is sent to the panel over HTTPS and stored encrypted in the database. This also applies to managed accounts with a hidden password and other SIP providers. The encryption key is stored separately from the database. A logged-in panel user can display passwords from their own history or use them to generate a code again. The panel also stores the exact setup link and customer message, encrypted with the same key. The show code action displays the user’s own code again without creating a new entry. Older entries may not contain a password or saved code. Data remains in the panel’s history; contact the publisher to request its deletion. Passwords are not placed in request URLs or server application logs. This protection is not end-to-end encryption: the server decrypts the password at an authorised user’s request. The password used to log in to the panel itself is used for authentication; its hash is stored in the database.
To limit login attempts, the database stores a counter, time and a hash of the panel username combined with the IP address. Setup codes and QR codes may contain the account password: keep them confidential. The hosting service handles website requests according to its server configuration.