Supsy

Privacy Policy

Last updated: 2 August 2026

The short version

Supsy was built so that it needs no phone number. We store no number, no address book and no conversation content. A conversation runs directly between the two devices — our server sees that a connection is made, never what is said.

Whoever calls you through a wire remains an anonymous session to us, without a name. And whoever has your link learns nothing about you from us beyond the purpose you wrote yourself.

1. Controller

P&D Abend Media
Bungerstr. 1
66640 Namborn
Germany
Email: hello@supsy.to

2. What data we process

a) Account

For sign-in we process your email address and a random user identifier. We store no password — sign-in works through a one-time code or a sign-in provider.

If you sign in with Apple or Google, we receive your email address and a sign-in identifier from the respective provider — nothing else. We have no access to your Apple or Google account.

If you choose Apple's „Hide My Email", we only receive the relay address generated by Apple. We never learn your real address.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

b) Wires

For each wire we store: the code, the purpose you chose, the expiry rule and its values, the number of accepted calls, your time zone, optionally an availability window, the setting whether a caller must state their reason, and a country code of where it was created.

Codes are never reused. Expired and burned wires therefore stay stored with their code — otherwise an identifier could later pass to another person and an old link would lead to a stranger.

Legal basis: Art. 6(1)(b) GDPR.

c) Calls

For each call we store: the wire concerned, an anonymous identifier of the calling party, the name and concern from the screening question, a country code derived from the IP address, the outcome of the call and its duration.

The country code is an estimate and easily distorted by a VPN. It serves display only („Calling from Germany") and no decision.

We do not store the caller's full IP address. It arises technically when the connection is established and is evaluated only to derive the country code and to enforce rate limits.

Legal basis: Art. 6(1)(b) and (f) GDPR (prevention of misuse).

d) Voice messages

If someone records a message, the audio file is stored with us in encrypted form. Only the owner of the wire can read it. We do not listen to it and do not analyse it.

For each message we also store why it was left — for instance because the availability window was closed or the person called was already on another call. Without that note one message would look just like the next.

Messages are deleted automatically once the retention period ends — after 14 days without Supsy Plus, and with Plus after the period you set in your profile. You can always delete them yourself before that; the recording goes with them.

Legal basis: Art. 6(1)(b) GDPR.

e) Known callers

Anyone who has called through a wire appears in your „Known" list: with the name from the screening question, the anonymous session identifier, the time and the number of calls. You can remember or block entries.

This identifier belongs to the caller's anonymous session, not to a person. If they sign in afresh or reset their device, they are someone new to us next time. That is intentional: there is deliberately no lasting link to a person.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a usable contact list).

f) Camera and microphone

The app asks for two device permissions, each only when you actually use the feature:

You can withdraw either permission at any time in your device settings; the corresponding feature then stops working.

Legal basis: Art. 6(1)(b) GDPR.

g) Push notifications

So that your device can ring on a call and tell you about missed calls and new messages, we store a push service device token (Apple or Google), the platform and the time of the last sign-in for each signed-in device. The content of a message never travels in the push — it only says that something is there.

The device entry also holds the language of the app on that device and the name of the built-in ringtone you chose — so the wake-up call appears in your language and rings with your tone. If you pick a custom ringtone file from your device, it stays there; it is never uploaded, and all we learn is that it is none of the built-in tones.

Whether notifications about new messages and missed calls reach you is your choice under Profile → Notifications; we store that choice on your account. The wake-up for an incoming call is unaffected by it, as it belongs to the core function.

If you sign out or uninstall the app, the token becomes invalid; we delete it as soon as the service tells us so.

Legal basis: Art. 6(1)(b) GDPR.

h) Sending a wire by email

You can have us send a wire by email instead of forwarding it from your own mailbox — that way your address stays hidden. To do so we pass the recipient address you entered and the text to our email delivery service.

We neither store nor log the recipient address. It is used for sending and then discarded; the log only records that a message was sent. Ten such emails per account per hour are possible.

Every such email carries a link with which the recipient can opt out of future wire emails. If it is used, we store not the address itself but only a non-reversible check value computed from it. Before every send this value is compared; if it is on the block list, no email goes out — from any Supsy user. No list of readable addresses comes into being.

As a signed-in user you can also view, set and remove the block for your own account address in the app (Profile → Notifications → Wire emails to me).

Legal basis: Art. 6(1)(b) and (f) GDPR (legitimate interest in stopping unwanted mail).

i) Supsy Plus

If you buy a subscription, our server verifies the purchase receipt with Apple or Google. What comes back is whether the subscription is valid, which product it is and when it runs out. From that we store only an entitlement on your account and the expiry date.

We never see payment data. Name, address, card and invoice stay with the store.

Legal basis: Art. 6(1)(b) GDPR.

j) Voice connection

To establish a connection, technical connection data is exchanged between the devices; it contains IP addresses. This data rests briefly on our server and is deleted automatically after ten minutes.

The conversation itself runs directly between the devices. Only if a direct connection fails due to the network is the audio routed through a relay server (TURN). Even then nothing is recorded or listened to.

Legal basis: Art. 6(1)(b) GDPR.

k) The supsy.to website

The website sets no analytics cookies and embeds no third-party services. Fonts are loaded from our own server, not from Google. When a wire link is opened, an anonymous session is created and stored in a strictly necessary cookie — without it a call could not be attributed.

Legal basis: § 25(2) no. 2 TDDDG (strictly necessary), Art. 6(1)(b) GDPR.

l) Technical diagnostic data during the introductory period

To ensure a reliable connection setup, during the introductory period the app transmits individual technical event reports to our server (such as “connection established”), each with an internal call identifier. Call content, names or reasons are not included.

These reports are subject to the retention period of the server logs (see section 5). Once the introductory period ends, this processing is discontinued.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a reliable service).

3. What we deliberately do not process

4. Recipients and services used

Our servers are located in a data centre in Germany. We run the database, file storage and sign-in there ourselves — there is no big cloud provider reading along.

Data is passed on only where technically unavoidable:

Transfers to third countries occur only within Apple's and Google's sign-in and push services, on the basis of the EU standard contractual clauses or the EU-US Data Privacy Framework.

We do not sell data and do not pass any on for advertising purposes.

5. Retention

If you delete your account, your wires, call history, messages including recordings, device entries and the account itself disappear — including the codes. That also ends the retention of codes described in section 2(b): we keep nothing in order to recognise you again. An old link later leading to a stranger remains practically impossible all the same — codes are drawn at random from around 5.9 × 1014 possibilities, not issued in sequence.

6. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR).

Two of these you can exercise yourself, without asking us — in the app under Profile → Account:

For anything else, write to hello@supsy.to.

You may also lodge a complaint with a supervisory authority. The competent one for us is the Independent Data Protection Centre of Saarland.

7. Security

Transmission runs over TLS throughout. Voice messages are stored encrypted. Access to wires, calls and messages is bound to your account at document level — other Supsy users cannot reach them either.

A wire code has ten characters from an alphabet of 30. That yields around 5.9 × 1014 possibilities; guessing is practically hopeless, and lookup requests are additionally rate-limited.

Invalid, expired, burned and blocked codes all receive an identical answer — otherwise the response would reveal which codes exist and who has been blocked.

8. Children

Supsy is intended for people aged 16 and over. If we learn that an account belongs to a younger person without guardian consent, we delete it.

9. Changes to this policy

We adapt this policy when the processing changes. The current version is available in the app and on supsy.to. We will give separate notice of material changes.