Effective Date: January 1, 2026 · Last Updated: September 11, 2026
Niobium LLC ("we," "our," or "us") operates CloakID, a privacy-first phone identity management platform. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services.
Information We Collect
Information You Provide
- Account Information: Your mobile number for sign-in, and the name, email address, or other profile information you provide. Your account phone number is stored using encryption and a separate lookup hash.
- Profile Information: Professional details and preferences you add to your personas, including persona names and AI context descriptions.
- Contacts: Phone numbers and names of contacts you add within the app for caller management purposes.
- Communications: Messages and feedback you send to our support team.
Information We Automatically Collect
- Usage Data: Features used, personas created, call outcomes (allowed, blocked, sent to voicemail), and interaction patterns within the app.
- Device Information: Device type, operating system, and a device-level identifier (push notification token) used to deliver push notifications to your device.
- User ID: An internal identifier linked to your account, used to authenticate and personalize your experience.
- Purchase History: Your subscription plan, billing status, and billing-provider identifiers. Subscriptions are processed by Apple (iPhone in-app purchase) or Stripe (web and Android). Historical store purchase records may also be retained. We do not store your full payment card details.
- Log Data: IP address, access times, and API request logs for security and troubleshooting purposes.
Call and Voicemail Data
When you receive calls through CloakID:
- Caller phone numbers are collected, logged, and associated with your account to provide call history and screening decisions.
- Caller audio during screening is processed for transcription through Deepgram or Telnyx, depending on the call flow. Live streams are processed in real time. Where recorded screening segments are used, they are scheduled for deletion after processing, with cleanup for leftover provider recordings.
- Call transcripts generated during screening and relevant persona context are processed by OpenAI to help decide whether to allow, block, challenge, or send a call to voicemail. Screening transcripts can be stored with call history after the call ends. They are not automatically deleted at the end of every customer call.
- Voicemail recordings left by callers are downloaded from our telephony provider, encrypted, and stored securely on Amazon Web Services (AWS) S3. Voicemail transcriptions are encrypted and stored in the database so you can read them in the app. You can delete voicemails at any time.
- Call metadata — including timestamps, duration, and screening decisions — is stored and linked to your account.
Device Contacts
With your explicit permission, CloakID can write your virtual phone numbers into your device's native Contacts app. This allows your persona numbers to appear in iOS Focus filters and other device features. CloakID reads your device contacts only to check whether a persona number has already been saved, to avoid duplicates. Your device contacts are never uploaded to our servers.
Biometric Data
When you enable biometric unlock, your device’s operating system verifies your face or fingerprint. CloakID does not receive or store your biometric template. App credentials use platform secure storage; biometric templates are managed by the operating system.
Diagnostics and Crash Reporting
We use Sentry to collect crash reports and performance data when the app encounters errors. This data may include your user ID, device information, and details about what the app was doing when the error occurred. This information is used solely to identify and fix bugs and improve app stability.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the CloakID platform
- Screen incoming calls and make routing decisions (allow, block, voicemail)
- Store and transcribe voicemails for your review
- Deliver push notifications about calls, voicemails, and account activity
- Process transactions and manage your subscription
- Send service updates and important account notifications
- Provide customer support and respond to inquiries
- Detect and prevent fraud and spam
- Identify and fix bugs and improve app performance
- Comply with legal obligations
Abuse Prevention and Enforcement
To keep CloakID and the phone network safe, we use account and usage information — such as call and message volume, account provisioning and number-change activity, spam and fraud signals from our telephony provider and screening tools, and reports submitted by call or message recipients — to detect and act on prohibited use. We do not proactively monitor the content of your communications for this purpose. When we investigate a specific abuse report, we may review relevant account records, including call logs, message history, and account details, to confirm what occurred and take appropriate action consistent with our Terms of Service. We never sell your information, and we do not use the content of your communications for advertising.
Third-Party Service Providers
The following providers process data to operate the CloakID service. Their services have their own terms and retention practices. Website measurement providers are described separately under Website Analytics and Cookies.
- Telnyx: Our telephony provider. Phone numbers, call routing, SMS delivery, and voicemail recording are handled by Telnyx. Phone numbers, communication content, and routing metadata are processed by Telnyx as needed to deliver the service.
- Deepgram, Inc.: Caller audio is processed for speech-to-text transcription. Provider retention is governed by the applicable service configuration and terms; we do not promise zero provider retention.
- OpenAI: Screening transcripts and relevant persona and caller context are processed to generate a screening decision. This content may contain personal information supplied by you or the caller.
- Amazon Web Services (AWS): Hosts service infrastructure and media, including encrypted voicemail audio in S3. App records and transcription text are also stored with our database hosting provider.
- Firebase (Google): We use Firebase Cloud Messaging (FCM) to deliver push notifications to your device. Your device's push notification token is shared with Google/Firebase for this purpose.
- Sentry: Crash reports and performance data are sent to Sentry for error monitoring and app stability. This data may include your user ID and device context.
- Stripe / Apple: Apple handles purchases made in the iPhone app; Stripe handles purchases made on the web and Android. Historical Apple or Google purchase records may be used for support and verification. We receive billing status and purchase identifiers, not your full payment card details.
- IPQualityScore / Twilio: Used at account registration to validate your phone number. Caller phone numbers may also be looked up via Telnyx's Number Lookup service during call screening to detect spam or VOIP numbers.
Service Communications and SMS Consent
By using CloakID, you consent to receive text messages from Niobium LLC regarding:
- Account setup and configuration notifications
- Service updates and feature announcements
- Billing reminders and payment confirmations
- Technical support and customer service messages
- Security alerts and important account information
You can opt-out of SMS communications by:
- Replying STOP to any text message
- Updating preferences in your account dashboard
- Contacting support at support@cloakid.app
Message frequency varies based on your account activity and preferences. Standard message and data rates may apply. For help, reply HELP to any message or contact support@cloakid.app.
Information Sharing and Disclosure
We do not sell account or communications data or share it with data brokers. Website interaction data is processed for measurement as described below. We may also share information in these circumstances:
- Service Providers: As described above, with providers who help us operate CloakID (telephony, transcription, AI screening, cloud storage, push notifications, error monitoring, and billing).
- Legal Requirements: When required by law, court order, or to protect the rights, property, or safety of Niobium LLC, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, or sale of assets. You will be notified of any such change.
- With Your Consent: When you explicitly agree to sharing in any other circumstance.
Data Security
We implement industry-standard security measures to protect your information, including:
- Application-level encryption for account phone numbers and voicemail audio and transcription text (Fernet encryption)
- HTTPS for app and website connections to the public API; carrier calls and SMS/MMS are not end-to-end encrypted
- Voicemail recordings stored encrypted in AWS S3
- Security checks during development and maintenance; no independent certification is claimed here
- Access controls and multi-factor authentication for internal systems
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Your Rights and Choices
You have the right to:
- Access: Request a copy of your personal information
- Update: Correct inaccurate or incomplete information in your profile
- Delete: Request deletion of your account and associated data. You can delete your account directly in the app under Profile settings.
- Port: Receive your data in a portable format
- Opt-out: Unsubscribe from marketing communications at any time
To exercise these rights, contact us at privacy@cloakid.app.
Data Retention
Account records, messages, call history, and screening transcripts may remain while your account is active. Voicemail audio and transcription text are stored so you can access them in the app; individual voicemails can be deleted.
Deleting your account removes your profile and associated app records and requests release of your phone numbers. Media cleanup is separate: message media is scheduled for cleanup, and stored audio, backups, or provider copies may remain beyond deletion of app records. Contact privacy@cloakid.app about removal of remaining stored media.
Billing, security, and abuse-prevention records may be retained for accounting, dispute resolution, fraud prevention, or legal obligations. For trial accounts that never subscribed, a one-way phone-number hash may be retained for up to 180 days after deletion to prevent repeat trials. Service providers may retain records under their own requirements. We do not promise immediate deletion of every copy or one retention deadline for all categories.
Public demo call records are scheduled for removal of caller numbers and words after 24 hours. Rate-limit counters may remain for up to 26 hours. Provider records are separate. See Security and Account deletion for more detail.
Children's Privacy
CloakID is not intended for users under 18 years of age. We do not knowingly collect information from children under 18. If you believe we have inadvertently collected information from a minor, please contact us at privacy@cloakid.app.
International Data Transfers
Your information is processed and stored in the United States (AWS us-east-2). By using CloakID, you consent to the transfer of your information to the United States. We ensure appropriate safeguards are in place for any international transfers.
California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. For more information or to exercise your rights, contact us at privacy@cloakid.app.
Website Analytics and Cookies
The marketing website uses Vercel Web Analytics and Google Ads measurement to understand page visits, navigation, store-link clicks, and checkout-link clicks. Google’s tag may use cookies or similar technologies and process device or network information. These website interactions are separate from the content of your calls and messages. A checkout-link click does not mean a purchase was completed.
You can restrict cookies through your browser settings. The native mobile app does not use browser cookies. See Google’s Privacy Policy and Vercel’s analytics privacy information for provider details.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the app. Continued use of CloakID after changes take effect constitutes acceptance of the updated policy.
Contact Information
For questions about this Privacy Policy or our privacy practices, contact us at: