Screendoor
Privacy PolicyTerms of ServiceEULA

Legal

Privacy Policy

Last updated August 4, 2026

Helix Networks LLC (“Helix Networks,” “Company,” “we,” “us,” or “our”) operates ScreenDoor, an iPhone application and related services that answer a subscriber’s incoming calls with an AI receptionist before the subscriber’s phone rings (the “Service”). Helix Networks is located at 1 Washington St., #1046, Boston, MA 02201.

This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the rights available to (a) people who download and subscribe to ScreenDoor (“Subscribers” or “you,” when addressing a Subscriber) and (b) people who call a Subscriber’s number and are answered by ScreenDoor (“Callers” or “you,” when addressing a Caller). Callers do not need an account and do not agree to our Terms of Service, but this Policy still applies to them, and Section 14 addresses Caller rights specifically.

If you do not agree with this Policy, do not use the Service (Subscribers) and, if you are a Caller who does not wish to be screened, you may decline as described in Section 13.

Contents

  1. Information We Collect From Subscribers
  2. Information We Collect From Callers
  3. Information We Receive From Our Service Providers
  4. How We Use Information
  5. Is Call Audio Recorded?
  6. Automated AI Decision-Making
  7. No Voice Biometrics
  8. Contacts Are Processed Locally
  9. Data Retention
  10. Data Security
  11. Your On-Device Archive
  12. Push Notifications — Known Limitation
  13. Caller Disclosure and Consent to Screening
  14. Callers’ Privacy Rights
  15. How Long the AI-Screening Vendor Retains Data
  16. Where Your Data Is Stored
  17. Account Deletion
  18. Children’s Privacy
  19. Your Privacy Rights
  20. Changes to This Policy
  21. Contact Us

1. Information We Collect From Subscribers

  • Identity and login. Apple Sign-In (an Apple ID token) or an email address and password, processed through our authentication provider (Supabase Auth).
  • Personal phone number. The mobile number you enable call forwarding from. It is verified by SMS one-time code (via Twilio Verify) and stored encrypted at rest. It is decrypted only when needed to show you the correct carrier code to disable forwarding, including at account deletion.
  • Display name (optional).
  • Onboarding and preference data. Onboarding quiz answers, your chosen AI voice and greeting style, an optional custom greeting suffix you write, screening mode, quiet hours, blocked area codes, and your allowed-business list.
  • Device tokens. Apple push notification tokens (standard APNs and VoIP/PushKit) used to ring and notify your device.
  • Subscription status, once in-app billing is live, received from our subscription management vendor (RevenueCat) and Apple.
  • Email address, used today solely to send you a warning if your subscription is about to lapse.
  • Your iOS contacts, on-device only. See Section 8 — your contact list in plaintext (names, numbers, photos) never leaves your device.

2. Information We Collect From Callers

Callers are not Subscribers and do not create accounts, but calling a Subscriber’s number causes ScreenDoor to process:

  • Caller ID (the calling phone number), stored in plaintext so the Subscriber can see who called, and separately as a one-way (SHA-256) hash used only for spam/block/trust matching.
  • Carrier-resolved caller name, where available from the telephone network.
  • Voice audio during AI screening or voicemail — processed live and never stored as an audio recording (Section 5).
  • What is said, retained as a text transcript and a short AI-generated summary of the reason for the call (for voicemail, the summary field holds the message itself).
  • A single keypress (DTMF tone) if a call is handled through our automated “captcha” spam-deterrent mode.

3. Information We Receive From Our Service Providers

We work with vendors who each receive a limited slice of information necessary to operate the Service:

VendorRoleWhat it receives
TwilioTelephony carrierThe Caller’s number, our dedicated ScreenDoor number, and the call’s audio on both the phone-network leg and the leg bridged to the AI screener and, when connected, to the Subscriber’s app; the Subscriber’s number for SMS verification
OpenAIAI voice screening and transcriptionLive caller audio (for AI-screened calls only — blocked, trusted, and captcha calls never reach OpenAI), the screening prompt and Subscriber-configured context (e.g., allowed-business list), Subscriber-authored greeting text (for a moderation check), and the fixed disclosure script (for text-to-speech, containing no personal information)
SupabaseDatabase, authenticationEncrypted account, call, and content records described throughout this Policy
RailwayBackend hostingOur backend does not persistently store user content in a primary database (its application filesystem is ephemeral and holds only pre-rendered disclosure audio); like most hosted applications, it may generate short-lived operational logs and diagnostics as part of standard hosting practices
ResendTransactional emailSubscriber email address, solely to send subscription-lapse warnings
Apple (APNs)Push notificationsDevice push tokens and notification payloads
RevenueCat / Apple In-App PurchaseSubscription management (once billing is live)Subscription and purchase status

We do not use any third-party analytics, advertising, or crash-reporting SDKs. We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months.

4. How We Use Information

We use the information above to: forward and screen your calls; distinguish spam, trusted, and unknown callers; generate the AI conversation, verdict, and one-line summary; deliver call logs, transcripts, and voicemail text to you; operate blocking, trust lists, and quiet hours; verify your phone number and identity; bill and manage your subscription (once live); send service and security notices, and subscription-lapse warnings; maintain the security and integrity of the Service; and comply with legal obligations.

5. Is Call Audio Recorded?

Caller and AI voice audio is transmitted in real time between Twilio and OpenAI for the sole purpose of generating a live AI response and a text transcript. ScreenDoor does not intentionally create, store, or retain a playable audio recording of any call, and no audio-storage path exists in our systems today. This is why our spoken disclosure to Callers says a call “may be transcribed,” not “recorded” — a deliberate and accurate distinction: we produce a text transcript, not an audio recording. A “recording” preference exists in our technical configuration for potential future use but is disabled by default and is not connected to any storage system today.

We want to be precise rather than absolute: as with any live voice system, audio is necessarily held in short-lived technical buffers for the fraction of a second it takes to transmit and process each chunk as it moves through our infrastructure and our vendors’ infrastructure. This transient buffering is not a recording, is not written to persistent storage, and is not retained by us afterward. Our telephony and AI vendors (Twilio and OpenAI) may independently retain limited call audio, metadata, or related data for a period of time under their own security, abuse-monitoring, or operational retention policies, as described in their respective terms — those retention practices are outside our control. We work to minimize vendor-side retention where our vendors offer configuration options to do so, and we will update this section if we obtain a specific, confirmed data-retention commitment from a vendor that we can accurately describe here.

6. Automated AI Decision-Making

ScreenDoor uses an AI voice model to conduct a brief (up to 60-second) screening conversation with unknown Callers and render a verdict of “spam” or “legitimate.” This is an automated process. Known contacts, numbers on your trusted list, and numbers you’ve blocked bypass the AI entirely and are handled by simple rule-based logic (silently disconnected, or connected straight through with no AI involvement).

The AI’s verdict determines whether a call is ended, forwarded to your phone, or routed to voicemail — it does not deny you any legal, financial, housing, employment, healthcare, or similarly significant benefit, and you remain in control: you can review every transcript and summary, override the AI by adding a number to your trusted or blocked list, and adjust your screening mode and quiet hours at any time. If you are a California resident, you may request additional information about the logic involved in this automated processing by contacting us at privacy@tryscreendoor.com.

7. No Voice Biometrics

ScreenDoor does not create, extract, store, or use a “voiceprint” or any biometric identifier derived from a Caller’s or Subscriber’s voice for the purpose of identifying a specific individual. Voice audio is processed only to generate spoken AI responses and a text transcript of what was said; it is not compared against, or used to build, a database of individual voice signatures. We do not knowingly collect biometric identifiers regulated under statutes such as the Illinois Biometric Information Privacy Act (740 ILCS 14).

8. Contacts Are Processed Locally; Privacy-Preserving Matching Data Is Uploaded

Your iOS contact list (names, numbers, photos) is read on your device, with your permission, and the plaintext contents of your address book are never uploaded to our servers. Instead, your device builds a per-account, salted Bloom filter — a compact mathematical structure derived by one-way hashing each contact number together with a secret unique to your account — and uploads only that compact, bit-packed blob (32 KiB or smaller) to our servers. This blob is a derivative data structure built from your contacts, and we treat it as personal information subject to this Policy even though it does not contain readable names or numbers.

The filter is designed to answer only “is this specific number likely a match” against a guessed number, is not designed to contain readable contact names or numbers, and materially reduces exposure compared with uploading a plaintext address book. Like other probabilistic data structures, however, it can produce occasional false-positive matches and should not be treated as mathematically anonymous or a perfect privacy guarantee. The per-account salt is designed to prevent cross-referencing filters between different Subscribers, including in the event of a database compromise. We also round the reported contact count on our servers to reduce the risk that the specific number of contacts you have could be used to single you out.

9. Data Retention

We retain content according to the following system-enforced schedule, applied by an automated daily job:

ContentRetention window
Transcripts and AI summaries of junk calls (spam, hang-ups, missed calls)7 days
Transcripts and AI summaries of connected calls and voicemails30 days
Call log (numbers, timestamps, durations, and outcomes — no conversation content)Retained for the life of your account
All account dataDeleted upon account deletion (see Section 17)

Dormancy safeguard. Transcripts and summaries are normally deleted after the 7- or 30-day windows above, once your device has confirmed it holds a complete local copy. If your device has not synced (for example, because the app has been unused or is offline), we retain that content longer so you don’t lose your only copy of a message — up to a hard ceiling currently set at 365 days, which exists specifically to allow synchronization with your device to complete before content is removed from our servers. We will update this Policy to reflect the actual ceiling in effect at any time we change it; you should rely on this Policy’s current text, not on any expectation of a future change, for the ceiling presently in force.

10. Data Security

We encrypt transcript and summary content at rest (AES-256-GCM) using a key unique to each account. Each account’s key is itself encrypted (“wrapped”) by a master key that exists only in our server infrastructure — never inside the database. As a result, a copy of our database obtained through a breach, a misdirected backup, or a legal process contains only encrypted content and wrapped keys, and cannot be decrypted using anything else found in that copy alone.

Important clarification. This is encryption at rest, not end-to-end encryption. Because the master key exists in our server environment, our systems are technically capable of decrypting your content during the applicable retention window described in Section 9 — for example, to investigate a misclassified call or respond to a support request. We do not claim, and you should not assume, that we are unable to read your content while it exists on our servers. Your personal phone number is also encrypted at rest and is decrypted only when needed for account operations such as displaying your carrier’s forwarding-disable code.

Within the app itself, access to your content is restricted by row-level security so that only you, authenticated as yourself, can read your own calls; other Subscribers and unauthenticated clients cannot read or write another account’s data through the app. Separately, and as described above, authorized Helix Networks personnel may access decrypted content directly through our server infrastructure — outside the app’s normal access controls — only when reasonably necessary for user-requested support, investigating a misclassified or disputed call, security investigations, abuse prevention, or legal compliance, and subject to internal access controls and confidentiality obligations. This backend access capability is what makes this “encrypted at rest,” rather than “end-to-end encrypted,” as clarified above.

11. Your On-Device Archive

Your device keeps its own copy of your transcripts and voicemail text in the app’s private storage, which is included in your standard iOS device backups. This copy is not limited by the server retention windows in Section 9 — you can continue to view your history on your device for as long as you keep the app and your backups, even after the corresponding content is deleted from our servers. The decryption key needed to read this local copy is stored in your device’s Keychain.

Signing out deletes the on-device archive from that device (useful on a shared device); signing back in re-downloads whatever content still exists within the server’s retention window.

12. Push Notifications — Known Limitation

We send call and voicemail alerts through Apple’s push notification service. Voicemail alert previews currently contain plaintext content (for example, a snippet of the message) that transits Apple’s servers and may appear on your device’s lock screen. We are developing a fix so that previews are filled in locally on your device rather than transmitted with content, but that fix is not yet deployed. Until it is, please treat notification previews as potentially visible to anyone with access to your lock screen, and adjust your iOS notification and lock-screen settings accordingly if that is a concern.

13. Caller Disclosure and Consent to Screening

Before any Caller’s audio is sent to our AI vendor, we play a short recorded disclosure — one of five pre-approved scripts (reproduced below), each identifying the answerer as an AI assistant and stating that the call may be transcribed — followed by a beep. No Caller speech is sent to our AI vendor, and no transcript is created, until after that disclosure and beep have played. A Caller who does not wish to proceed may simply hang up before or during the disclosure; no audio from that call is transcribed or retained. (As with any telephone call, the telephone network and our carrier necessarily carry the call’s audio signal, including during the disclosure itself, in order to route and connect the call — that basic call-routing function is distinct from, and does not involve, AI processing or transcription.)

The five disclosure scripts a Subscriber may select (a Subscriber may append an optional, moderation-reviewed personality suffix but may not remove or rewrite the disclosure itself) are:

  1. “Hi, you’ve reached a Screendoor AI assistant. This call may be transcribed. Who’s calling, and how can I help?”
  2. “This line is protected by Screendoor AI. Calls may be transcribed. Please state your name and reason for calling.”
  3. “Hello, Screendoor AI receptionist here. This call may be transcribed. May I ask who’s calling and why?”
  4. “Hey, AI assistant here. This call may be transcribed. Who’s calling, and what’s up?”
  5. “Screendoor AI screening is active. This message may be transcribed. Please leave your name and reason for calling.”

Calls from numbers on a Subscriber’s trusted or contacts list are connected directly to the Subscriber with no AI involvement and no disclosure, because no screening or transcription occurs on those calls. Calls from known-spam or blocked numbers are disconnected before any disclosure is needed.

We provide this notice-and-beep mechanism, and require it on every AI-screened call regardless of where the Caller is located, because a number of states — including California, under the California Invasion of Privacy Act (Cal. Penal Code §§ 630 et seq.) — require the consent of all parties before a call is recorded or its contents captured, and identify an at-the-start spoken notice as a recognized way to obtain that consent. The disclosure and beep are designed to provide notice and to obtain the Caller’s consent before any AI processing or transcription begins; a Caller who continues speaking after the disclosure and beep is proceeding with a brief, transcribed AI conversation on the terms described in this Policy.

14. Callers’ Privacy Rights

Even though you don’t hold an account, you have rights with respect to your Caller information: you may request access to, or deletion of, the transcript, summary, and caller-ID information associated with calls you placed to a ScreenDoor Subscriber, subject to the limitations below.

Verification. Because caller ID can be spoofed, we cannot grant access to, or delete, records based solely on an emailed phone number and approximate call time. Before fulfilling a request, we will take reasonable steps to verify that you actually placed the call in question — for example, by sending a one-time verification code to the number in question and asking you to confirm it, or by requesting other information establishing your control of that number. We may decline a request where we cannot reasonably verify the requester’s identity or control of the number at issue.

Limitations. Content that has already been purged under the retention windows in Section 9 cannot be produced or deleted because it no longer exists. Call log metadata (numbers, times, durations, and outcomes, but no content) is the Subscriber’s own call history and may be retained for the life of the Subscriber’s account; a Subscriber has a legitimate interest in retaining a record of who called them, which may limit our ability to delete a Caller’s number or metadata from another person’s call log even upon a verified Caller request.

Contact us at privacy@tryscreendoor.com with the phone number you called from and the approximate date/time of the call so we can locate the relevant record and begin verification.

15. How Long the AI-Screening Vendor Retains Data

OpenAI receives live audio and text solely to generate the AI’s responses and the transcript, under its own API data-use terms, which (as of this Policy’s date) exclude API content from being used to train OpenAI’s models absent separate agreement. Twilio carries call signaling and audio for the fraction of a second it takes to route each leg, and separately retains its own call detail records and metadata under Twilio’s own retention policies as our telephony provider. We do not control, and are not responsible for, the internal retention practices of our vendors beyond the contractual and technical safeguards we have put in place; see Section 3 for more on our vendors.

16. Where Your Data Is Stored

Our database (Supabase-hosted PostgreSQL) is the primary system of record for account, preference, call, and content data and is hosted in the United States. Our backend (Railway) does not persistently store user data. Your device holds its own local archive as described in Section 11. Twilio, OpenAI, and Apple process data in transit and under their own respective terms and may process or store data outside the United States as part of their global infrastructure.

If you are located outside the United States, you understand that your information will be transferred to and processed in the United States, a jurisdiction that may have different data protection laws than your home country. Where required by applicable law (for example, for individuals in the European Economic Area or United Kingdom), we rely on appropriate safeguards, such as standard contractual clauses, for such transfers.

17. Account Deletion

You can delete your account at any time from Settings → Delete Account in the app. When you do:

  1. The app first shows you the carrier code needed to turn off call forwarding (e.g., ##21# on GSM carriers, *73 on Verizon) so that forwarding does not outlive your ScreenDoor number. You must actually dial this code to stop your calls from being forwarded — deleting your account does not do this for you.
  2. Your dedicated ScreenDoor phone number is released back to our carrier’s number pool.
  3. Your account and its associated data in our active database — call records, transcripts, summaries, preferences, push tokens, and trust/block lists — are deleted.
  4. Your on-device archive is deleted when you sign out.

What “deleted” does and does not cover. Steps 1–3 above delete your data from our active, primary database promptly after you confirm account deletion. This does not necessarily mean every copy of your data is erased everywhere, instantaneously: encrypted database backups may persist for a limited operational period before they are themselves rotated out; Twilio and OpenAI may separately retain call detail records, security logs, or abuse-monitoring data under their own retention policies, which we do not control (see Section 15); and any local device backups (for example, iCloud or iTunes/Finder backups) containing your on-device archive are controlled by you and Apple, not by us. We do not retain data longer than necessary to comply with a legal obligation or valid legal process, where applicable.

Number-release risk. A released phone number is returned to our carrier’s general number pool and may eventually be reassigned to a different customer. If you delete your account, let your subscription lapse, or otherwise cause your ScreenDoor number to be released without first disabling carrier call forwarding, calls to your personal number will continue to be forwarded to that number — which may by then be unused, or may belong to an unrelated third party. We are not responsible for calls that are delivered to, answered by, or otherwise reach a subsequent holder of a released number, or for calls that fail to connect at all, once your number has been released while forwarding remains active. Disabling carrier forwarding before or immediately after deleting your account, or before your number would otherwise be released, is your responsibility and is the only way to prevent this.

18. Children’s Privacy

ScreenDoor is not directed to, and is not intended for use by, children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at privacy@tryscreendoor.com and we will delete it.

19. Your Privacy Rights (Residents of California and Other States)

A note on scope. ScreenDoor is an early-stage company and may not currently meet every threshold that makes a particular state privacy law legally applicable to us (for example, CCPA/CPRA’s revenue or data-volume thresholds). We describe the rights below because we have chosen to offer them voluntarily as a matter of practice, not necessarily because each statute independently compels us to do so today. Where we describe a right as voluntary, it remains subject to identity verification and to the legitimate retention needs described elsewhere in this Policy, and offering it now does not by itself mean a given law currently applies to us.

California (CCPA/CPRA). If you are a California resident, subject to certain exceptions, you have the right to: know the categories and specific pieces of personal information we have collected about you; delete your personal information; correct inaccurate personal information; know the categories of third parties to whom we disclose personal information; limit our use of “sensitive personal information” (which, for purposes of this Policy, we treat call transcripts and summaries as being); and not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, so there is no “opt-out of sale/sharing” link to provide. To exercise any of these rights, email privacy@tryscreendoor.com from the email address associated with your account, or otherwise provide enough information for us to verify your identity; we will respond within the time periods required by law. You may designate an authorized agent to submit a request on your behalf.

Other U.S. states. If you are a resident of Colorado, Connecticut, Virginia, Utah, or another state with a comprehensive consumer privacy law, you may have similar rights to access, correct, delete, and obtain a portable copy of your personal information, and to appeal a denied request. Contact us at privacy@tryscreendoor.com to exercise these rights.

European Economic Area / United Kingdom. If applicable data protection law (such as the GDPR or UK GDPR) applies to your information, you have the right to access, rectify, erase, or port your data; to restrict or object to our processing; and to withdraw consent where processing is based on consent, all as described in this Policy and subject to applicable exceptions. Our lawful bases for processing are: performance of a contract (operating the Service you subscribed to), consent (for AI screening of unknown Callers, obtained via the disclosure in Section 13), and legitimate interests (such as spam prevention and service security). You also have the right to lodge a complaint with your local supervisory authority.

20. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify Subscribers in the app or by email before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

21. Contact Us

Helix Networks LLC
1 Washington St., #1046
Boston, MA 02201
privacy@tryscreendoor.com

Screendoor
How it worksFeaturesNumber lookupPrivacyTermsEULA
© 2026 Screendoor