OPEN SOURCE. PEOPLE FIRST.
Privacy policy
Your calls belong to your organisation.
OpenWeb PBX Android app and project website · Updated 9 October 2026
OpenWeb PBX is a nonprofit, open-source project. This policy explains how our Android phone app handles information. The app connects to the PBX server chosen by you and your organisation. That server may be operated by OpenWeb or independently by another organisation. Your PBX administrator controls its users, calling permissions, recordings and retention.
Information used by the app
- Your phone connection: the server address, extension, display name, device name, device connection identifier and credentials are needed to connect your phone. Credentials are encrypted in the app’s private storage using Android Keystore; app backup is disabled.
- Your calls: microphone audio is sent to your chosen PBX during calls, including when the app is in the background. The PBX routes it to the person you call. Calling numbers, direction, time, duration and answered status are sent to the PBX for your recent call history. The PBX may record calls or store voicemail when your administrator has enabled those features.
- Your company directory and voicemail: the app retrieves these from your PBX. It does not read or upload your Android address book. Voicemail audio is temporarily cached for playback and removed when playback stops or the view closes.
- Connection and service information: the PBX receives your network address, authentication requests, app version and device name. Server logs may record connection failures and other operational events. Your administrator controls those logs.
- QR scanning: the camera reads your administrator’s connection code on your phone. Camera frames are not uploaded. The decoded code is sent to the selected PBX to connect your phone. You can enter a connection code instead.
Permissions you control
Microphone access enables calling. Camera access enables QR scanning. Notifications show the phone connection and incoming calls. Bluetooth access lets you select an audio device. You can change these permissions in Android Settings; removing a permission may stop the corresponding feature. A visible phone notification runs while your PBX connection is active. Disconnecting the phone stops that connection.
Where information goes
Phone setup and account requests use HTTPS. Phone signalling uses TLS and call audio between the app and PBX uses SRTP. These protections cover the connection to your PBX; they do not make a call end-to-end encrypted through every telephone network. Your administrator and telephone providers may process call information and audio to deliver the service.
The app includes no advertising, advertising identifier collection or third-party analytics. It does not sell user information. The native calling engine is Linphone SDK; QR decoding uses ZXing. These components support calling and scanning. Release checks contact GitHub for signed release information. GitHub and Google Play receive network requests under their own policies when you use their services. The downloadable APK can obtain its signed update package from GitHub; the Play edition opens Google Play for installation.
Retention and removal
Settings → Disconnect revokes this phone’s access and clears its locally stored account and pending call history after the PBX confirms removal. If the connection is already revoked, local removal still succeeds. Uninstalling or clearing Android app storage removes local app data; it does not erase your organisation’s PBX account or server records.
Server call records, voicemail, recordings, logs and backups follow your PBX administrator’s retention rules. Ask that administrator to explain the applicable period and any required retention before using the service. We do not apply a single retention period to independently hosted servers. Request removal of your account or data; that page also provides a contact when you cannot access the app.
This website
This static website stores your chosen colour theme in your browser. It uses no advertising or analytics scripts. Hosting systems may keep ordinary request logs, including IP addresses, to operate and protect the site. GitHub receives requests when you follow source or download links.
Contact and changes
Contact the OpenWeb PBX project at hello@openwebpbx.com for privacy questions or help identifying the right administrator. Include your PBX address and extension, but never send passwords, connection codes or recordings in a public issue. This page will be updated when the app’s data handling changes.