Reviewed October 4, 2026
Privacy policy
Reputation and call matching happen on your iPhone. Dataset refreshes connect directly to the publishers you subscribe to.
This policy describes the development version. SpamHole has not been submitted to the App Store. Public release remains pending physical-call acceptance, VoiceOver, signing and distribution review. This policy must be rechecked against the final distributed binary.
Information kept on your device
SpamHole stores personal allow/block rules (including telephone numbers, timestamps, and any saved correction notes), preferences, source subscriptions and their status, downloaded evidence, and generated protection snapshots locally. The app and its Call Directory extension share protection files on the device.
If you enable Contacts protection and grant permission, SpamHole reads the phone numbers it can access to protect them from its automatic decisions. Limited access protects only accessible contacts. Contact names are not requested or cached. Contact numbers are not uploaded; protection snapshots may contain local allow entries derived from those numbers. Explicit personal rules take priority.
The shared data directory is excluded from automatic device backups. Its file protection permits access after the first device unlock, so the extension can use protection data while the phone is subsequently locked.
Incoming calls
iOS matches incoming caller numbers against the installed Call Directory entries. SpamHole does not receive or collect a call history and does not make an incoming-call server lookup.
SpamHole is call-only and has no access to messages. It does not contain a Message Filter extension or request message access.
Publisher downloads and credentials
The containing app requests complete, non-personalized datasets over HTTPS from enabled sources. Requests are not queries about the number that just called. Manual refresh and scheduled refresh can use the network; background updates are best-effort.
Publishers and their hosting providers receive ordinary request metadata, such as your IP address, requested URL, timing, and request headers. Public background downloads identify the app as SpamHole. Each publisher controls its own handling and retention of this metadata; SpamHole does not control those practices.
If you configure an optional bearer token for a custom source, it is stored in the iOS Keychain and sent to that source using a foreground HTTPS transfer with redirects restricted to the same host and port. Tokens are excluded from rule exports and use device-only Keychain storage. Do not put credentials or personal telephone numbers in a feed URL. A custom publisher receives the URL and token you configure.
To stop future scheduled refreshes, choose the manual-only refresh cadence in Settings. Disable a source to stop future refresh requests for that source; a download already handed to iOS may finish. Removing a custom source removes its saved credential and local subscription. Disabling a source is not credential deletion.
No account or tracking service
SpamHole has no account service, advertising, usage analytics, crash-upload SDK, or in-app public report submission. Personal corrections create local allow rules; they do not send a complaint or correction to a publisher.
Export, removal, and retention
In Settings, Export Rules & Settings creates a JSON file containing personal telephone numbers, rule details, and preferences. It excludes contacts, source subscriptions, credentials, and downloaded evidence. You choose where to save or share it; that destination may be a cloud service. Protect the file as personal data. A successful import replaces personal rules and settings, and leaves Contacts protection off until you enable it again. New exports contain call rules only. Older mixed backups restore valid call rules and the call portion of combined rules, omit message-only rules, and show converted and omitted counts. Short codes are never promoted to call numbers. A nonempty message-only backup leaves your current rules intact; an explicitly empty backup can clear them. Invalid backups are rejected before replacement.
Upgrading from the former call/SMS development build does not automatically erase all old local data. Legacy SMS-only records may remain dormant locally for compatibility; they are excluded from active call protection and new rule exports. The current app has no message access.
Remove a personal rule from the Lookup screen. Disable a subscription in Sources, or remove a custom subscription to remove its saved token and local evidence. Snapshot rebuilding removes inactive contributions, but installed call entries change only after a successful Call Directory reload. Local protection generations and temporary download files may persist until the app’s cleanup runs.
Delete the app, rather than offloading it, to remove its app-managed local storage according to iOS behavior. Remove custom sources before deleting the app to delete their Keychain tokens; do not assume uninstalling removes Keychain items. Files you exported or shared remain wherever you saved them and must be removed separately. SpamHole cannot delete publisher request logs or GitHub support posts.
Source retention depends on the source contract. FTC complaint evidence is retained within a 90-day window and pruned during rebuilds; full-snapshot custom sources replace previous evidence when a valid update succeeds. There is no universal on-device retention period for personal rules and settings.
This website and support
These static pages use no JavaScript, analytics, forms, cookies set by page code, or external fonts or assets. The hosting provider still receives requests to load the site. Following an external link or posting a GitHub issue is subject to that service’s practices.
Public support issues are visible to others. Do not share real telephone numbers, personal communications, contact lists, rule backups, raw device logs, or credentials. Use the support page for public questions and private vulnerability reporting.
Policy changes
The date above identifies the version reviewed. Changes to app behavior, sources, or distribution require a new review. The repository privacy document and source code provide the technical basis for this policy.