Last updated 7 August 2026
The short version. Sundays lets a child aged 2–7 video call family members a parent has approved. Your child's name, the nicknames you give contacts, and their photos never leave the device — we have no way to see them.
Our server knows only that two anonymous IDs are allowed to talk to each other. We keep no record of who called whom, or when. We show no ads, use no analytics, and sell nothing to anyone.
Sundays is published by Rampart16, which also operates the server the app connects to. That makes us the data controller for the small amount of information described below.
The server's whole job is to check that a device is allowed to call, and then introduce two devices to each other. It holds no names, no pictures, and no content of any kind.
| What | Why it has to exist |
|---|---|
| A random device identifier | So an incoming call reaches the right device. It is a randomly generated value with no connection to you, your child, or your phone's hardware. |
| A password hash | So only your device can act as your device. The app creates a random secret at setup; we store only an Argon2 hash of it, never the secret. |
| Approval links between two device identifiers | So that only people a parent approved can call your child. Both sides must approve. This check has to happen on the server — a check that lived only in the app could be bypassed. |
| A notification token | So the device can be woken when a call comes in while the app is closed. |
| A purchase receipt | So we can confirm the one-time unlock was paid for. One purchase covers up to six devices in a family. |
These stay on your device, and there is nowhere on our server they could be written even if we wanted them:
Contact names and photos are included in Android's own backup, so they can restore to a new phone from your Google Drive without ever passing through us.
| Call history — who called whom, and when | Not recorded |
| Video or audio from calls | Never recorded |
| Location | Not collected |
| Analytics or usage tracking | Not collected |
| Advertising identifiers | Not collected |
| Contacts from your phone's address book | Never read |
The app contains no advertising SDK and no analytics SDK. There is nothing in it that reports your behaviour to us or to anyone else.
Calls are encrypted end to end using WebRTC's mandatory DTLS-SRTP. Nobody in the middle — including us — can watch or listen to a call.
Calls normally travel directly between the two devices. When a home network will not permit a direct connection, the encrypted stream is passed through a relay server we operate so the call can still connect. The relay moves data it cannot read, and stores none of it. Nothing about a call is recorded at any point.
We share data with two Google services, acting on our instructions, and with nobody else. We do not sell data, and we do not share it for advertising.
Sundays is built for children and complies with the Children's Online Privacy Protection Act.
A parent or guardian sets the app up, sets a PIN, and approves every contact. Completing setup is how a parent gives consent for the limited collection above. A child using the app cannot add a contact, change a setting, or reach a purchase screen — all of those sit behind the parent PIN.
Because we never receive names or photos, the information we hold about a child amounts to a random identifier and a list of other random identifiers it may call.
| Camera | Video during calls |
| Microphone | Audio during calls |
| Notifications | To ring when a call arrives |
| Network access | To connect calls |
| Bluetooth | Only to use a Bluetooth headset during a call |
The camera and microphone are opened only once a call has been answered, never before. If you decline any of these, the app keeps working as far as it can without them.
Stated plainly: a breach or a subpoena would produce a list of random identifiers and which ones may call which. No names, no faces, no record of who spoke to whom.
We keep the information above only while you use the app. Call history is not kept at all, because it is never created.
To delete everything associated with a device, email privacy@rampart16.com from any address and include the Device ID, which you can find in the app under Parent Settings. We will delete the device record, and its approval links disappear with it, within 30 days.
If we change how any of this works, we will update this page and change the date at the top. Material changes will also be surfaced in the app.
Questions about privacy, or a request to delete data: privacy@rampart16.com.