Privacy
GemFlare is a small, independent calling and messaging service, built and run by Techies365 LLC. The honest summary: we store what is needed to run your account, your conversations and your call history; we never see or record the calls themselves; and nothing about you is sold, shared, or used for advertising.
What we store
- Your phone number — it is your account identity, verified when you send us a WhatsApp message. The only message we ever send you is a sign-in code, and only when WhatsApp hides your number from us so the usual method cannot work.
- A display name and @username, and a profile photo if you set one.
- Google or Facebook profile basics — only if you choose to link one of those accounts: your name, email address and profile picture, used to fill in your own GemFlare profile. We never post anything to those accounts, and we never pass the data on.
- Your messages — chat messages are stored on our servers so they reach you on every device and are still there when you come back. Deleting a message for everyone erases its text from our servers straight away; deleting it only for yourself hides it from your side and leaves the other person's copy alone. Everything left goes when an account is deleted — yours or theirs. Any reactions on a message are stored with it.
- Call records — who called whom, when, how long it lasted, and at what quality. This powers your Recent list and, when paid plans launch, your usage allowance. We store the record of the call, never its contents.
- Your contacts and blocked list — which GemFlare accounts you have added, any nickname you gave them, and any conversations you have muted.
- Reports — if you report someone, or someone reports you, we keep that report and its reason so we can act on it.
- A push token per device, so we can ring your phone when the app is closed. It identifies a device, not a person.
- Your settings — whether you appear online, who may call you, and your preferred video quality.
- A session cookie so you stay signed in. No analytics cookies, no trackers, no fingerprinting.
How long we keep it
- Your account and conversations — for as long as your account exists. Deleting a message for everyone erases its text immediately; the rest goes when an account is deleted.
- Call records — up to 12 months, then deleted.
- Sign-in codes — minutes. They expire quickly by design and are removed with your account.
- When you delete your account — your profile, messages, reactions, contacts, blocked list, muted conversations, reports, linked sign-ins, devices and sessions are all erased. The bare record that a call happened stays in the other person's history — it carries no name, number or photo once your account is gone — and is deleted with everything else inside the 12-month window. See Delete your account for the exact list.
What we never see
- Your calls. Audio and video are encrypted in transit with standard WebRTC encryption (DTLS-SRTP) and forwarded in real time by Cloudflare's network. They are never recorded and never stored — by us or by anyone else in the path.
- Your address book. The Android app can check which of your contacts already use GemFlare, but only if you turn it on and grant permission. It sends a SHA-256 hash of each phone number and nothing else — no names, no numbers — and we store none of it. Numbers that are not registered are never reported back to us, so we never learn who else is in your phone. To be straight about what hashing does and does not buy: phone numbers are a small enough set to work through, and we already hold the numbers of everyone registered here, so this is not anonymity from us. What it is, is a guarantee that we never hold anybody's address book. On the web there is no such feature at all: you dial numbers yourself.
- Your WhatsApp. Verification uses one message that you send to our number. Through Meta's WhatsApp Business API we receive only that message's text and your sender number, and we use them for nothing except signing you in. We never send marketing. If WhatsApp hides your number from us during sign-in, we send one six-digit code to the number you typed so you can prove it is yours — that is the only message we originate.
Where it runs
GemFlare is hosted on Cloudflare's global infrastructure, and your account, messages and call records are stored there. Call media passes through it encrypted and is gone the moment the call ends. Payments, when paid plans launch, are handled by Stripe — we never see or store card details.
Your choices
- Sign out at any time — the session is deleted server-side.
- Choose who can call you, and silence calls from people who are not in your contacts.
- Delete any message, for yourself or for everyone in the conversation.
- Turn contact matching off, or never turn it on. Everything else in the app works without it.
- Delete your account yourself, from the app or from a browser, with no request and no waiting period — see Delete your account.
Questions, or want a copy of your data or its removal? Write to support@gemflare.com — see Support. We answer within 30 days.