The Incline Institute Software & Publishing

Home/Cackl for Android/Privacy Policy

Cackl — Privacy Policy (Android)

What Cackl collects, why, and what happens to it.

Effective date: August 7, 2026

Cackl ("the app") is a group voice-messaging (push-to-talk) app operated by The Incline Institute, Ltd., a Nevada limited liability company ("we", "us"). This policy explains what the app handles and why. Questions: contact@inclineinstitute.com.

Summary

Cackl lets you send short voice messages to a small, closed group. It records audio only while you hold the talk button and relays it to your group. Messages you receive are stored on your device so you can replay them. There is no advertising and no third-party analytics. We do not sell your data.

We do keep some information on our server so the service can work: who is in your group, when each member was last online, outstanding invitations, and your profile picture if you set one. Voice messages themselves are held only long enough to deliver them.

What the app handles

Voice recordings. When you press and hold the talk button, the app records from your microphone (or a connected Bluetooth headset) and sends the audio through our relay to the other members of your group. It does not record at any other time.

While you are on a group screen the microphone may be held open so that talking starts instantly when you press. Audio captured in that state is continuously discarded — with one deliberate exception, which we would rather state than gloss over: a fraction of a second of audio from just before your press is included at the start of your message. That is what stops your first syllable being cut off. It is a small fraction of a second, it only ever reaches your own group as the beginning of a message you chose to send, and nothing from the primed microphone is transmitted at any other time or retained anywhere once discarded.

On-device message history. Messages you receive are stored on your device so you can replay them. This history is size-limited, is not uploaded to us, and is removed when you clear the app's data or uninstall it. It is per-device and is not synced between your devices.

Your identity on the service. Your account name and the credential your device uses to connect are stored on our relay so you can be recognised as a member of your groups. Your credential is stored hashed, not in a form we can read back.

Group membership and activity. Our relay durably stores which groups exist, who belongs to them, who created them, and the time each member was last connected — the "Active 2 hours ago" text you see next to a member's name.

Invitations. When someone invites a person to a group, the relay creates an identity for that person and an invite code. Codes are stored hashed, are single-use, and expire. Redeeming a code creates a durable identity on the service.

Location — only while you are sharing. If you grant location permission, the app shares your device's position with the other members of your group while you have a group session open. It is foreground only: nothing is shared when the app is closed or in the background.

This applies to the Wear OS (smartwatch) app as well, which is a full member of your groups in its own right rather than a display for your phone. It asks for location permission separately, on the watch, the first time you open a group there, and shares on the same foreground-only terms — sharing stops when you leave the group screen. Declining is fine: you simply don't appear on the map, and you still see everyone who does. The watch deliberately does not request background location, and its always-running "connected" service is not permitted to collect location, so the sentence above stays true on the wrist as well as in your pocket. Other members' positions appear on the group map. Positions are not stored — our relay keeps only each connected member's most recent position and discards it the moment they disconnect. Location sharing is optional; without the permission you can still see others on the map, but your own position is not shared.

Notification token. So the app can be woken when a message arrives while it is closed, it registers a notification token with our relay via Firebase Cloud Messaging, a Google service. The wake notification contains no message content — it only prompts the app to reconnect and fetch what it missed.

Profile picture. You can choose a photo to display instead of your initials. If you do, the image is uploaded to our relay, stored there, and shown to the other members of your groups — that is the point of setting one. Nobody outside your groups is told it exists.

The image is resized and cropped on your device before it is sent, so what leaves your phone is a small square picture (256×256), not the original photo or anything attached to it. We do not receive the rest of your photo library, and the original file, its location data and its timestamp never leave your device.

Setting a picture is entirely optional. Without one you appear as your initials, which is the default and works exactly as well.

Connection metadata. While you are connected, the relay processes what it needs to route messages: your member id, message ordering, and connection status.

IP addresses. Your device's IP address is visible to our service, as it is to any internet service you connect to. What we record differs by activity, and it is worth being specific:

  • Talking and listening. Our relay's own logs record the address of the network edge sitting in front of it rather than yours, so your IP address does not appear in them.
  • Redeeming an invite code. Here the relay deliberately records your real IP address, both when a code is accepted and when one is refused. It does this to rate-limit guessing attacks against invite codes, which is the one place an attacker can try codes at speed. Where a code is accepted, that entry also records the account it created — so it links an address to an account.
  • Our infrastructure provider (see below) sees your IP address for all traffic, as any network provider must.

These logs live on our own server in a file that rotates as it fills, so entries are overwritten in the ordinary course rather than kept for a fixed period. We do not use them for analytics, advertising or profiling.

What the app does NOT do

  • It does not record when you are not holding the talk button.
  • It does not share your location in the background or when the app is closed.
  • It does not contain advertising, ad identifiers, or third-party analytics SDKs.
  • It does not sell or rent your data.
  • It does not read your contacts, photos (beyond a picture you explicitly pick), messages, or call history.

Who receives what

  • Other members of your group receive the voice messages you send, your display name, whether you are online, when you were last online, your profile picture if you have set one, and — if you enable it — your live location. That is the purpose of the app.
  • Our relay processes messages in transit and stores the membership information described above.
  • Google (Firebase Cloud Messaging) processes your notification token and delivers wake notifications, acting as our notification provider.
  • Cloudflare, Inc. operates the network our relay is served through, and TLS is terminated at its edge, so Cloudflare handles traffic between your device and our server. Cloudflare acts as a data processor on our behalf. We have not enabled request logging, and because voice traffic uses a persistent WebSocket connection, Cloudflare's connection records identify the connection rather than its contents. Any data Cloudflare retains at its edge is governed by Cloudflare's own privacy policy.
  • Nobody else.

Storage and retention

  • Voice messages: held by the relay only transiently, in memory, to deliver them and to replay recent ones to a member who reconnects. They are not archived on the server. The copy you keep is the one on your own device.
  • On-device history: stored on your device, size-limited, removed on uninstall or clear-data.
  • Identity, group membership, last-online, invitations: stored durably on the relay until changed or deleted. These are not removed by uninstalling the app.
  • Notification tokens: held in memory and lost when the relay restarts.
  • Locations: most recent position only, per connected member, discarded on disconnect.
  • Profile pictures: stored on the relay until you change or remove them. Deleting yours removes it from the relay, and other members' devices stop showing it. A copy already downloaded onto someone else's phone is outside our control — we cannot reach into their device to erase it.
  • Server logs: connection events and invite redemptions, as described under "IP addresses". Written to a file on our own server that rotates as it fills, so entries age out by volume rather than on a fixed schedule.

Security

  • All traffic between the app and our service uses an encrypted connection (wss://, TLS). That connection is terminated at our infrastructure provider's network edge, which is how our relay is reached; from there to our own machine the traffic travels inside an authenticated tunnel and is never exposed to the public internet. We mention this because "encrypted in transit" is often written in a way that implies nobody in the middle can see anything, and we would rather say plainly where the encryption ends.
  • Connection credentials and invite codes are stored hashed on the relay.
  • Credentials on your device are held in the app's private storage, readable only by the app.

Permissions and why

Permission Why
Microphone Recording your voice while you hold the talk button. Required.
Notifications Showing the ongoing "connected" notice and waking the app for new messages.
Location (precise, while in use) Sharing your position with your group on the map, on the phone and on the watch. Optional — decline it and everything else still works.
Bluetooth Detecting a connected headset, using its microphone, and responding to a Bluetooth push-to-talk button.
Foreground service (microphone) Keeping the connection and audio alive while a group session is open and the screen is off — a walkie-talkie has to keep working in your pocket. It shows a persistent notification while active.

Children

Cackl is not directed to children under 13, and we do not knowingly collect personal information from them.

Deleting your data

  • On your device: clear the app's data or uninstall it. That removes your message history, your stored credential, and your cached copy of anyone's profile picture.
  • On our service: uninstalling does not remove your identity, group membership or last-online record from the relay. To have those deleted, contact us at contact@inclineinstitute.com and we will remove them.
  • Your profile picture: remove it in the app. It is deleted from our relay, and other members' devices stop showing it. A copy already downloaded onto someone else's phone is outside our control — we cannot reach into their device.
  • A group's owner can remove a member from a group, and can cancel an invitation that has not been used.

Changes to this policy

If this policy changes materially we will update this page and revise the effective date above.

Contact

contact@inclineinstitute.com The Incline Institute, Ltd., Nevada, USA