Privacy Policy
This Privacy Policy explains what personal information Fortress Freedom Phone Ltd ("Fortress", "we", "us") processes when you visit our website, buy a device, or use the Freedom Fone calling and messaging app. We deliberately collect as little as practical. The deletion setting controls copies held in Fortress systems; telephone carriers, DIDWW, Apple, Google and payment providers may keep separate records under their own legal and operational requirements.
1. Who we are
Fortress Freedom Phone Ltd is a private limited company registered in England & Wales (Companies House No. 17168647). For data-protection purposes we are the data controller of any personal information we collect from you. You can reach us at admin@fortressfreedomphone.co.uk.
The Freedom Fone mobile app is distributed through Apple App Store and Google Play by Socialiser App Ltd (registered in England & Wales, Companies House No. 17243028). Socialiser App Ltd is the app-store publisher and receives store settlement information in that role. Fortress Freedom Phone Ltd operates the communications service and remains the controller for the account, calling, messaging and support information described in this policy.
2. Information we collect
We process the following information where needed to provide the feature you choose:
- Account details — your email address, optional display name, password hash, account identifier, privacy setting and account status. We never store your password in readable form. One-time verification and reset codes are stored only as keyed hashes and expire after 15 minutes.
- Telephone identifiers — numbers rented by you, destination and source numbers, provider order identifiers and encrypted calling credentials.
- Number-inventory searches — the country and optional locality you submit when searching for an available number. We pass these filters to our telecommunications provider to return live inventory; Fortress does not keep a searchable history of the terms.
- Message content — SMS content is encrypted in our database and retained according to your selected setting: until a received message is read or an outgoing send attempt completes, for 24 hours, for one week, or until manually deleted. SMS is not end-to-end encrypted across the public telephone network.
- Call metadata — calling number, called number, direction, time, state and provider call identifier. Fortress schedules this metadata for deletion after 24 hours. We do not record call audio.
- Device and notification data — platform, installation identifiers, push tokens and a one-way token fingerprint used for app delivery and calling services. Push tokens stored in our database are encrypted. On Android, Firebase installation and push registration can occur even if you decline permission to display notification alerts.
- Optional contact backup — if you explicitly enable cloud recovery, contact names, telephone numbers and labels selected from your device address book. This feature is off by default. The backup is encrypted in our database and is not used to create advertising, marketing or social graphs.
- Purchase and service records — credit ledger, number rentals, Keep Number reservation and renewal dates, subscription status, store transaction identifiers and product identifiers. Apple, Google and their payment processors handle full payment-card details; we do not receive or store full card numbers.
- No advertising tracking in the updated iOS app — iOS build 42 and later contain no Meta advertising SDK, collect no advertising identifier and send no advertising-measurement events. The optional ad-measurement control and Apple tracking-permission request have been removed. Essential account, notification, billing and diagnostic processing described in this policy remains.
- Order details — the products and services you have ordered, the address or collection arrangement for delivery, and any preferences you have specified (e.g. duress PIN configuration).
- Support communications — information you send when asking for help.
- Website preference and session storage — a local colour-theme preference and, only while you use the authenticated web top-up page, a short-lived access token in your browser's session storage. The session token is removed when you sign out and is designed to disappear when the browser session ends. We do not use this storage for advertising or cross-site tracking.
Normal Freedom Fone signup does not ask for a government identity document, selfie or proof of address. Where a country, number type or carrier would require those documents from each customer, we may withhold that inventory instead of adding blanket identity checks. A simple country-presence confirmation may be requested only where necessary for an offered number.
We do not sell personal data or use communications content or contact records for advertising. The updated iOS app does not track users across other companies’ apps or websites. Contact permission first lets the app show names and telephone numbers locally. Cloud contact recovery is separate, optional and off by default; the app displays a confirmation before uploading the limited contact fields described above. Broadcast-list membership remains on the device. Telephone numbers you actively call or message are necessarily sent to Freedom Fone and our telecommunications provider to provide that communication. The public website uses no marketing cookies or third-party analytics. It uses only the local preference and session storage described above. Hosting and network providers may process short-lived connection and security data when a device connects.
Earlier app builds: Android builds through version code 27 and iOS test builds through build 39 included optional Meta advertising measurement. If enabled, those builds could send app-open, completed-registration and purchase-value/currency events with installation/device identifiers and basic app/device information to Meta. iOS builds 38–39 additionally required Apple tracking authorization. Earlier Android builds disabled Android advertising-ID collection. In those builds, turn off Account → Privacy & deletion → Optional ad measurement to stop new events. Previously dispatched data cannot be recalled by Fortress and remains subject to Meta’s retention and international processing. The updated iOS build removes this integration entirely.
3. Why we collect it & legal basis
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 we rely on the following lawful bases:
- Performance of a contract — to create and secure your account, rent and renew numbers, route calls and messages, apply your deletion setting, provide optional contact recovery requested by you, provide support and process purchases.
- Legitimate interests — to provide the contact-recovery feature you deliberately enable while minimising uploaded fields, to communicate with you about your account, to investigate suspected breaches of our Acceptable Use Policy, to maintain and improve the service, and to prevent fraud.
- Legal obligation — to comply with valid legal process and records required by tax, consumer, company and communications law.
- Consent — only where we ask you for it explicitly, such as a non-essential mailing list. You can withdraw consent at any time.
4. How long we keep it
We hold personal information only for as long as we need it for the purpose we collected it for, plus any minimum period required by law. As a guide:
- Message content in Fortress systems — until a received message is read or an outgoing send attempt completes, for 24 hours, for one week, or until manual deletion, according to your setting. Changing the setting is applied immediately to content already held; eligible content is erased at once or by the purge worker. For the immediate policy, Fortress keeps only a content-free retry tombstone for up to 24 hours to prevent duplicate texts and charges.
- Call metadata and hashed provider-webhook replay receipts in Fortress systems — scheduled for deletion after 24 hours.
- Account and active-number records — while the account or number remains active. Releasing a number removes it from service; limited transaction records may remain where legally required.
- Optional contact backup — until you turn cloud recovery off, replace the backup, or delete your account. Turning it off deletes the cloud copy and the restored in-app copy; it does not delete contacts from your device address book.
- Order, ledger and payment records — normally six years where required for tax, accounting, chargeback or legal-claims purposes.
- Provider and app-store records — retained independently by DIDWW, telephone carriers, Apple, Google and RevenueCat under their policies and legal duties; your Fortress deletion setting cannot erase those third-party records.
- Pre-sale enquiries that do not result in an order — up to twelve months, then deleted.
- Support correspondence — for as long as needed to resolve the issue and normally no more than twelve months afterward, unless needed for a dispute or legal duty.
Where the law allows, we delete or fully anonymise records earlier than the periods above.
5. Who we share it with
We share personal information only with parties who need it to deliver the service to you, and only the minimum required. These include:
- Shipping carriers — to deliver your device. They receive your delivery address and a parcel reference, nothing more.
- Payment providers — for card payments, to process the transaction. They receive payment details directly; we do not pass them anything beyond what is necessary to settle the payment.
- DIDWW and downstream telephone carriers — telephone numbers, routing identifiers, message content and call/message metadata needed to deliver communications, prevent abuse and bill usage.
- Apple and Google — app distribution, in-app purchases, subscription management and push notifications.
- RevenueCat — store product, transaction, entitlement and account identifiers needed to reconcile in-app purchases. RevenueCat does not receive message content from us.
- Our crypto checkout provider, where that feature is available — an opaque Fortress order reference and the payment, wallet and blockchain information needed to create and verify a crypto top-up. We do not send message content, contacts or call history. Blockchain transaction data is public and cannot be deleted by Fortress.
- Our infrastructure providers — limited account and operational data necessary to host, secure and back up the service.
- Our transactional email provider — your email address and generic verification or password-reset email content. It does not receive your telephone numbers, contacts, message content or call history.
- Lawful authorities — when we are served a valid legal order. We respond only to what the order requires, and only with information we hold.
We do not sell or rent personal information. The updated iOS app does not share personal information for advertising or marketing purposes. We do not share your communications content with third parties for advertising purposes. Necessary sharing with telecommunications providers to deliver and bill your calls and messages is described above.
6. Where information is stored
Our hosting arrangements do not mean your information is processed only in one country. DIDWW operates internationally, and communications may traverse carriers and sub-processors in other countries to reach their destination. Our existing private handset voice infrastructure is hosted in Iceland. Apple, Google, RevenueCat, DIDWW and our infrastructure providers may process data internationally. We require an applicable adequacy basis or contractual safeguard for restricted transfers where UK data-protection law requires one.
7. Your rights
Under UK data-protection law you have the right to:
- Be informed about how your data is used (this policy).
- Access a copy of the personal data we hold about you.
- Rectify inaccurate or incomplete data we hold about you.
- Erase ("right to be forgotten") your data, where we are not required to keep it for a legal reason.
- Restrict our processing of your data in certain circumstances.
- Object to processing based on legitimate interests, where applicable.
- Data portability — to receive a copy of your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing was based on consent.
These core privacy controls are available to every Freedom Fone user, wherever they live. Additional rights and response periods may apply under the law of your country or state. To exercise a right, use our Privacy Choices page or email admin@fortressfreedomphone.co.uk. We respond to valid UK requests within one calendar month and follow any shorter mandatory period that applies. Freedom Fone users can also follow our account deletion instructions to delete an account in the app or submit a request without the app.
8. Security
Message bodies, optional contact backups, push tokens and calling credentials are encrypted in the Freedom Fone database; passwords are one-way hashed; refresh tokens are rotated and stored only as hashes; and production HTTP access logging is disabled. Access is restricted to people who need it to operate the service. No internet service can promise absolute security. Where legally required, we will notify the Information Commissioner's Office within the applicable deadline and notify affected people without undue delay where the risk threshold is met.
9. Children
Our products and services are intended for adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has supplied us with personal information, please contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The current version is identified at the top of this page. Material changes will be brought to the attention of active customers by email at the address held on file.
11. Complaints
If you are unhappy with how we have handled your personal information, please contact us first and give us the opportunity to put it right. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Online: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF