Privacy Policy for Citizen Phone

Effective 16 September 2026 · Citizen Phone, published by MasumApps ("we", "us", "the app")

The short version. Citizen Phone keeps two kinds of information strictly apart.

Your personal content never leaves your phone. Your contacts, your call history, the photos you pick for favourites, and your home-screen layout are stored only on this device. We never upload them, never see them, and never share them with anyone.

Some technical data is sent to Google so the app can report crashes, measure basic usage, show ads, ask for your ad choices, and process purchases. That data is about the app and the device — not about who you call or who is in your contacts. Citizen Phone has no servers of its own.

Every feature is free. The app is paid for by ads. Citizen Premium, bought through Google Play, removes the ads and nothing else.

Who this policy covers

This policy applies to the Citizen Phone Android application (package com.citizen.app), which acts as your home screen (launcher) and, if you choose, your phone app (dialer). It does not cover other apps you open from Citizen Phone — those follow their own policies.

Information that stays on your device

The following is saved in the app's own private storage, readable only by the app. It is never transmitted to us or to any third party, and it is never included in analytics, crash reports, or advertising:

Uninstalling Citizen Phone deletes all of it.

Information collected and sent to Google

The app includes the Google services listed below, each with what it collects and why. We use Google's standard integrations and do not add personal data of our own.

Google Analytics for Firebase

Collects a randomly generated app instance identifier, your device model, operating system version, language and country (derived from your IP address, which is not retained by us), the app version, and in-app events such as app opens, session length, and which screens are viewed. It also records the steps of buying Premium: the offer being shown (and where), a plan being chosen, a purchase finishing, failing, or being cancelled, and the home-screen offer being closed. This tells us which features are used and where people get stuck. In regions where consent is required, Analytics does not store an identifier for your device or record your usage until you agree to it; if you decline, only limited signals without such an identifier may be sent. It does not record what you type, who you call, your contacts, or any payment details.

Firebase Crashlytics

When the app crashes, it sends a crash report containing the technical stack trace, a Crashlytics installation identifier, and the state of the device at the time (model, operating system, available memory and storage, whether the device is rooted). This exists only so we can find and fix the fault.

Firebase Remote Config

The app downloads a small number of settings from Google, such as how far apart ads appear in a list, how long the home-screen "Remove ads" card is shown after installation, and a switch to turn all ads off. To do this, Google receives a Firebase installation identifier, the app version, and basic device information such as language and country. No personal content is sent.

Google AdMob

The app displays ads supplied by Google AdMob: a banner at the bottom of the app list, and ads placed between entries in the call history and the contact list. Ads are never shown on the home screen, on the dial pad, on the incoming-call or in-call screens, or in search results.

To select, deliver, cap the frequency of, and measure ads, and to prevent ad fraud, AdMob may collect your device's advertising ID, IP address, approximate location derived from that IP address, device and browser information, and your interactions with ads. Your contacts, call history, and photos are never used for advertising. In regions where consent is required, no ad is requested until you have made your choice (see Consent below). Once Premium is active, the app stops requesting ads.

Google User Messaging Platform

Google's consent tool shows the ad consent message where the law requires one, and stores your choice on the device so ads can respect it. To decide whether a message is needed and to record the choice, it uses your IP address (to determine your region), device information, and a consent string saved on the phone.

Google Play Billing

Citizen Premium removes all ads. It is offered as a monthly subscription, a yearly subscription, or a one-time Lifetime purchase. It is optional: every feature of the app works without it.

Purchases are processed entirely by Google Play. Your payment card details are never given to Citizen Phone. Google Play tells the app only which Premium products your Google account owns, with a purchase token and product identifier. The app confirms (acknowledges) new purchases with Google Play and keeps the result on your device. Nothing about your purchase is sent to us, and we have no server that stores it.

Premium belongs to the Google account signed in on the phone where it was bought. If someone else pays on your behalf, for example a family member using their own card at checkout, the purchase still belongs to the Google account on that phone. Subscriptions renew automatically until cancelled. You can cancel, change plan or payment method, or request a refund in the Google Play Store under Payments & subscriptions, or through Google Play Help.

Third-party privacy policies

These services process data under their own policies:

Your advertising choices

You can limit advertising at any time, from the phone itself:

If you are in the European Economic Area, the United Kingdom, Switzerland, or a US state with its own privacy law, the app shows a Google-certified consent message covering advertising and analytics. Until you answer, no ad is requested and Analytics does not store an identifier for your device. You can accept, decline, or choose which purposes to allow; analytics is enabled only if you allow storing information on your device and measuring content performance. If you decline personalised advertising, you may still see non-personalised ads, which rely on limited data such as your approximate region.

The message is shown on browsing screens (such as the app list, call history, or Settings), never on the home screen and never while you are making a call. You can change or withdraw your choice at any time in the app under Settings → Privacy choices, which appears wherever a consent message applies. Withdrawing consent does not affect processing that already took place.

Where the law requires a legal basis for processing, ours are: consent for usage analytics, personalised advertising, and storing or reading advertising information on your device; legitimate interests for crash reporting, remote app settings, non-personalised ads, fraud prevention, and keeping the app secure and working; and performance of a contract for processing and honouring a purchase you have made.

Data sharing and sale

We do not sell your personal information for money. Under California law (CCPA/CPRA), showing personalised ads may count as "sharing" personal information for cross-context behavioural advertising. If you are a resident of California or another US state with a similar law and wish to opt out of that sharing, use Settings → Privacy choices in the app, turn off ad personalisation using the advertising choices above, or email us at the address below. We do not knowingly sell or share the personal information of anyone under 16.

Beyond the Google services named above, we disclose information only where legally required — for example to comply with a court order or lawful request, or to investigate fraud or protect the rights and safety of users.

International data transfers

The Google services above operate globally and may process data on servers outside your country, including in the United States. Where data protection law requires safeguards for such transfers, Google relies on mechanisms including the European Commission's Standard Contractual Clauses and adequacy decisions. Data kept on your own device is never transferred anywhere.

How long data is kept

DataRetention
On-device dataUntil you delete it or uninstall the app. We never hold a copy.
AnalyticsUser-level records are retained for the period configured in Firebase (a maximum of 14 months), after which they are deleted. Aggregated, non-identifying reports may be kept longer.
Crash reportsRetained by Crashlytics for up to 90 days.
Remote settingsFetched settings are cached on the device and replaced at the next fetch. Google keeps fetch logs under its own policies.
Consent choiceStored on your device until you change it, clear the app's data, or uninstall the app.
AdvertisingRetained by Google under its own policies. Deleting your advertising ID breaks the link to your device.
PurchasesPurchase records are held by Google Play for as long as required to honour your entitlement and to meet legal and tax obligations. The Premium status kept on your device is removed when you uninstall the app, and restored from Google Play if you reinstall while signed in to the same account.

Your rights

Depending on where you live, you may have the right to access the personal information held about you, to have it corrected or deleted, to obtain a copy of it, to object to or restrict its processing, to withdraw consent, to opt out of the sale or sharing of personal information, and not to be treated differently for exercising any of these rights.

To exercise any of them, email masum14092@gmail.com. Please tell us which right you wish to use. Because we hold no account or name for you, we may need your advertising ID or the approximate date and device you used in order to locate the relevant records; if we cannot identify data as yours, we will say so rather than act on someone else's. You can also delete everything held on your device at any time by uninstalling the app, and you may lodge a complaint with your local data protection authority.

Children

Citizen Phone is designed for general audiences and is not directed at children. We do not knowingly collect personal information from children under 16, and the app is not intended for use by them without the consent of a parent or guardian where local law requires it. If you believe a child has provided personal information through the app, contact us at masum14092@gmail.com and we will delete it.

Permissions and why the app asks for them

PermissionWhat it is used for
READ_CONTACTSTo show your contact list and favourites so you can call someone by tapping their name or picture. Read for display only, never copied off the phone. Adding or editing a contact is handed to your phone's contacts app; the app never writes to your contacts.
READ_CALL_LOGTo show your recent and missed calls. Read for display only.
CALL_PHONETo dial the number you tapped. If you decline, the number is handed to your phone's built-in dialer instead and the app still works.
READ_PHONE_STATERequired by Android so the app can receive the system's missed-call notice while it is your default phone app. It is not used to read your phone number, SIM details, or subscriber identifiers.
POST_NOTIFICATIONS
USE_FULL_SCREEN_INTENT
To show the incoming-call screen and missed-call notifications, including over the lock screen.
FOREGROUND_SERVICE
FOREGROUND_SERVICE_PHONE_CALL
To keep a call running reliably. The service runs only for the length of a call.
WAKE_LOCKTo blank the screen while the phone is at your ear during a call, so your cheek does not press buttons.
ACCESS_NETWORK_STATE
ACCESS_WIFI_STATE
To draw the signal and Wi-Fi strength icons on the home screen. Signal strength only; nothing about your network is recorded or sent.
INTERNETUsed by the Google services above to send crash reports and analytics, fetch remote settings, check ad consent, load ads, and confirm purchases. No personal content from your phone is sent over it.
AD_ID
ACCESS_ADSERVICES_*
To read the advertising ID for ad selection and measurement. You can reset or delete this ID in your phone's settings.
BILLINGTo let Google Play process a Premium purchase or subscription, and to check which purchases your account owns.
App list accessThe launcher reads which apps are installed so it can show their names and icons on the home screen and in the app list. That list stays on the device and is not sent anywhere.

The app does not request camera, microphone, precise location, storage, SMS, or body-sensor permissions. Tapping the camera tile opens your own camera app; the flashlight tile only toggles the torch.

Photos

You can give a favourite contact a picture. The app uses Android's system photo picker, so it never gains access to your whole photo library — you choose one photo, and only that photo is handed to the app. The cropped copy is saved in the app's private storage on this device. Photos are never uploaded, and are never used for advertising or analytics.

Security

Data saved by the app is kept in Android's private per-app storage, which other apps cannot read. Data sent to Google's services travels over encrypted connections. No method of transmission or storage is completely secure, but we limit what is sent in the first place: your contacts, calls, and photos are simply not part of it. If a breach affecting personal data occurs, we will notify affected users and the relevant authorities as required by law.

Changes to this policy

If this policy changes, the updated version will be published here with a new effective date, and the revised text will also appear inside the app under Settings → Privacy Policy. Where a change materially affects how your information is used, we will seek your consent before it takes effect if the law requires it. Earlier versions are available on request.

Contact

Questions about privacy, requests about your rights, or anything else in this policy: masum14092@gmail.com.