Phone privacy policy
Last updated: 29 September 2026
This policy covers Phone (Zia Phone), including the Android app with package com.ziahamza.phone, its other clients and connected service. It is provided by Zia Studio, operated by Zia Capital, LLC (“we” or “us”).
Calls, messages, and an assistant
Phone is a connected calling and messaging service. It stores account information and communication history so you can use the service across devices. Carriers process calls and messages, and the assistant uses cloud processing when you use assistant features. Phone supports call recordings, transcripts and summaries; call capture is enabled by default in the current app, with controls available for supported call flows.
You can request deletion of your account and associated data without reinstalling the app.
Information Phone handles
Account and sign-in
We handle your account ID, name, email address and sign-in phone number when supplied, plus authentication records and sessions. Signing in through Google or Apple provides the identity information you authorize that provider to share, such as your email address and name. Phone does not receive your Google or Apple password.
Calls and messages
We handle the phone numbers and contacts involved in calls and messages; call direction, timing, duration, status and history; SMS/MMS message content and attachments; and recorded call or voicemail audio, transcripts and summaries where captured. Assistant interactions can also create notes, outcomes and follow-up records. The content and necessary call context are processed to provide calling, messaging, transcription and assistant features.
Contacts, preferences, and phone lines
Phone handles your contact names and numbers, account and calling settings, assistant preferences, assigned phone numbers and line-purchase records. Device contacts require your device's contacts permission. Imported contact names and other details remain on your device unless you add them to the connected service. When caller screening is enabled, Phone sends eligible contact phone numbers and the device identifier to the service to recognize callers; the screening list is stored there. Using a number to call or message also sends that number to the service and carrier.
Devices and notifications
We handle installation and device identifiers, push-notification tokens, platform information and calling-device registration records to direct incoming calls and notifications to your devices. Android push uses Firebase Cloud Messaging; Apple devices use Apple's push infrastructure. Permissions such as microphone, contacts and notifications are requested through the device's permission controls.
App use and diagnostics
PostHog receives app interactions, screen and onboarding events, operation outcomes, JavaScript errors and sanitized diagnostics. After sign-in, these events can be linked to your opaque Phone account ID. Session replay is configured to mask text, inputs and images; it records interface behavior rather than call audio. Diagnostic filtering is configured to exclude message and transcript content, phone numbers, contact details, authentication headers and recording URLs. Service infrastructure also processes request and network information needed to deliver and troubleshoot the service.
If you contact support, we receive your email address and the information you include in your request.
Why we use this information
We use these records to authenticate you, route and deliver calls and messages, maintain communication history and settings across devices, provide assistant and transcription features, deliver notifications, manage phone lines, respond to support requests and diagnose reliability or security issues. Phone has no advertising integration, and we do not sell personal information.
Services that process information
Phone uses service providers for the functions described above:
- Telnyx and telecommunications carriers: phone numbers, calls, messages and their necessary content and routing records.
- OpenAI: audio, text and context needed for cloud assistant, transcription and summarization features.
- Cloudflare and Turso: application hosting, request processing and account-associated storage.
- Google/Firebase and Apple: sign-in when selected and device push-notification delivery.
- PostHog: app analytics, masked interface replay and sanitized diagnostics.
When you send a message or place a call, the recipient and their service providers receive that communication. They may keep their own copies. We may also retain or disclose limited records when necessary to comply with legal obligations or investigate security and fraud.
Security and your controls
Phone's application requests use HTTPS for encryption in transit. SMS and ordinary telephone calls are not end-to-end encrypted; the service and carriers process their content. Recordings and cloud assistant content must be accessible to the services that provide those features.
You can manage device permissions in your operating system, use available call-capture controls, manage contacts and settings in Phone, and sign out of the app. Signing out, releasing a line or uninstalling the app does not itself delete your server-side account and history.
Retention and deletion
Account records and communication history can remain in the connected service while your account is in use. Some features apply content-expiry controls, but we do not currently provide a single automatic account-deletion or backup-expiry schedule. Expiry from the app's view does not establish erasure of provider records or backups.
To request deletion of your account and associated data, or specific data while keeping your account, use the Phone account and data deletion page or email support@ziahamza.com. Our support team verifies ownership and handles deletion manually, including coordinating with our providers where applicable. We reply with the result.
Limited billing, carrier, security, fraud-prevention or legal records may need to remain for legitimate obligations. We will identify any retained records, explain why, and state the applicable retention period in our reply. Provider records and backups may have separate requirements; we do not promise immediate erasure of all such copies. Device-local data, your exports and recipients' copies are outside the deletion page's control.
Contact
For privacy questions, access or correction requests, email support@ziahamza.com. We update this page as Phone's data flows and controls change.