SpamHole

Development support

Know what to expect.

SpamHole is an open-source development app for iPhone on iOS 26 or later. It has not been submitted to the App Store, and this site is not an app download.

Public release remains blocked. SpamHole is call-only and has no message access. Physical-call acceptance, VoiceOver, signing and distribution review remain pending.

Report a problem or ask a question

Use the repository’s public issues for app bugs, documentation feedback, and privacy questions. Include the app version, iOS version, general device model, the screen involved, expected behavior, and a reproduction using synthetic data.

Issues are public. Do not post personal phone numbers, personal communications, contacts, exported rule backups, raw device logs, credentials, or signing material. Redact screenshots and use synthetic examples.

Open public support issues

Report a security vulnerability privately

GitHub private vulnerability reporting is enabled for this repository. Use that route for suspected security vulnerabilities rather than publishing them in a support issue. Provide synthetic reproduction data and omit credentials and personal communications.

Report a vulnerability privately · Read the security policy

Common questions

Does “offline” mean the app never uses the network?

No. Calls are matched locally, but the containing app downloads datasets directly from subscribed publishers. Publishers can see request metadata, including your IP address and timing. There are no incoming-call lookups or message access. See the privacy policy.

What does a caller label prove?

A label reflects local source evidence, not verified ownership or origination. FTC complaints are unverified, and caller IDs can be spoofed. The association index is a proposed heuristic rather than a calibrated probability. Custom lists identify callers but cannot authorize automatic blocking.

Why do removed call entries still appear?

A rebuilt local snapshot and the entries installed in iOS are separate states. Removing a rule or disabling a source changes the local snapshot, but installed call entries remain until a Call Directory reload succeeds. The Protection screen shows installation state and stale-state information. Background refresh timing is controlled by iOS and is best-effort.

How can I correct a wanted caller?

Use a personal allow rule or the Lookup screen’s correction action for the exact identifier. This affects SpamHole locally, takes priority over its other decisions, and does not verify the number’s owner or send a report to the publisher. Call changes still require a successful reload.

How do I export or remove my data?

Settings provides Export Rules & Settings; the resulting file contains personal call numbers and preferences. Legacy SMS-only data may remain dormant after an upgrade, but it is excluded from current protection and new exports. Remove individual rules in Lookup. Remove a custom source to delete its saved token and subscription; disabling it does not delete its credential. Before uninstalling, remove custom sources to clear their Keychain tokens. Exported files must be deleted separately. See retention and deletion details.

Source attribution and authority

  • FTC Do Not Call reported-call data is the default call-identification source. It is U.S. government public data based on unverified consumer reports. It has no automatic block authority. Current on-device download acceptance remains open.
  • Custom sources retain their publisher’s rights and terms. Subscription settings or feed-supplied grades cannot grant reviewed confirmation authority.

Dataset attribution does not imply publisher endorsement. Source contracts and qualification findings explain the evidence limits. Release requirements track the remaining gates.