Summary
Sentinela collects no personal data whatsoever. It has no server, no login, no analytics, no advertising and — in this version — asks for no internet permission: technically the app cannot send anything out, even if it wanted to.
Everything the app stores (your whitelist, your settings and, if you want it, the block history) lives in your own device's storage and is erased when you uninstall.
Who publishes the app
Sentinela is an open source project (MIT license) developed and maintained by Sierra Tecnologia and Rica Soluções. The full source code is available at github.com/ricardosierra/sentinela, where anyone can verify that what is written in this policy is what the app does.
This policy applies to the Android application identified as com.sierratecnologia.sentinela.
Data we collect
None. We do not collect, do not receive, do not store on a server and do not share with third parties any information about you — no phone number, no contacts, no device identifier, no usage statistics, no crash report.
This is not a promise about conduct: it is a consequence of how the app was built. With no internet permission declared, the operating system blocks any network connection coming from the application.
Access to contacts
To decide whether the caller is already known, Sentinela can read your address book. The permission is requested with an explanation and can be refused. The reading is 100% local and in memory only:
- Names, photos and numbers from your address book are never written to the app's database.
- No contact data leaves the device — there is no network.
- Without the permission, the app keeps working in filter mode.
What is stored on your device
| What | What for |
|---|---|
| Your personal whitelist | Numbers you added, in international format (E.164), with an optional description — so that those calls always ring. |
| Protection settings | Your choices: policies for unknown numbers, contacts and whitelist, private numbers, blocking mode, notification, retention and dialer mode. |
| Block history (optional) | If enabled, it stores the blocked number, its masked version (used in notifications), date and time, the reason for the decision and the action taken — for the retention period you choose: never store, 7, 30, 90 days or until manual deletion. |
| App open counter | A local number, used only to decide when to show the invitation to rate and support the project. It is never sent anywhere. |
Permissions the app asks for, and why
| Permission or role | Why it is needed |
|---|---|
Call screening (ROLE_CALL_SCREENING) |
It is Android's official mechanism for deciding about an incoming call before the first ring. Without it the app has no function. |
Read contacts (READ_CONTACTS) |
Check, at the moment of the call, whether the number is in your address book. Read in memory, with no storage and no sending. |
Notifications (POST_NOTIFICATIONS) |
Warn about a blocked call — off by default, only if you turn it on. |
Default phone app (ROLE_DIALER and call service) |
Only in dialer mode, which is optional: it enables the app's own call screen and policies per contact. Reversible at any time through Android. |
Make calls (CALL_PHONE) |
Only in dialer mode: place the call you dialled yourself on the app's screen. |
| Full-screen notification | Only in dialer mode: show the incoming call with the device locked, through the official notification path. |
The app does not declare internet permission, does not read the system call log, does not read SMS, does not use accessibility services and does not draw over other apps.
What is never done
- No data leaves the device — no cloud, no "partners", no telemetry, no remote crash report.
- No call is recorded.
- Android's native call history is not read.
- Full numbers never appear in technical logs or in lock-screen notifications — only masked, in the format
+55 11 9****-1234. - No data is sold, rented or handed over to anyone. There is no one to hand it to.
Android backup
Sentinela's database — whitelist, history and settings — is excluded from Google's automatic backup and from device-to-device transfer. If you change phones, use the manual whitelist export available inside the app.
Your choices and your rights
- The blocked-call notification is off by default — you decide whether you want to be told.
- Dialer mode is optional and reversible at any time.
- History retention is your choice, including the option to never store anything.
- In Privacy and about, the "clear all data" option erases whitelist, history and settings.
- Uninstalling the app removes everything from the device.
Since none of your data ever reaches us, we cannot access, correct, export or delete information on your behalf: that control is entirely yours, inside the application itself. For the purposes of the Brazilian General Data Protection Law (LGPD), we do not process personal data of Sentinela users.
Children
Sentinela is not directed at children and collects data from no one — regardless of the age of whoever uses the app.
Future (transparency)
A future version may offer optional synchronisation of lists with a server. If that happens, it will always be opt-in, always explained, and the app will keep working 100% offline for anyone who does not want it. This policy will be updated before any online feature comes to exist.
Honest limitations
Sentinela filters traditional phone calls only. Calls from WhatsApp, Telegram and other voice-over-internet apps do not go through Android's call filter and are not affected. Manufacturer-specific behaviour may vary between devices.
Changes to this policy
When this policy changes, the effective date at the top of the page is updated and the change is recorded in the project's public history on GitHub. Relevant changes to how the app handles data will be communicated inside the application before they take effect.
Contact
Questions about privacy, about this policy or about how the app works:
E-mail: [email protected]
WhatsApp: +55 (21) 99919-3898
Repository: github.com/ricardosierra/sentinela/issues
Responsible: Rica Soluções Tecnologia Ltda. — CNPJ 37.108.077/0001-90 — Rio de Janeiro, RJ, Brazil