Privacy notice
MimicCall privacy
Applies to the MimicCall app for iOS and Android (repository name mimiccall): consent-first session recording that runs entirely on your device. The app links here from its About screen.
This service is operated by llab08, Hong Kong, and these terms are governed by the laws of Hong Kong. The section below explains this product’s data handling and current availability.
Local recording storage
MimicCall has no server, no account and no network access of its own: on Android it declares no internet permission, and on iOS it makes no network requests. The video, photos and audio it records are written only to the app’s private storage on the device. You can export a recording from the Recordings screen, which hands a copy to an app you choose through the system share sheet. iOS device backups may also include recordings and imported loop videos; the app does not upload them itself.
Consent
Before the app can be used at all you must accept a consent notice: you are responsible for obtaining the consent of everyone you record, as the law where you are requires. A recording indicator is shown in every session screen style while a capture is running; no style can hide it.
Encryption and the PIN
On first run you choose a 6-digit PIN. It wraps a randomly generated key used to encrypt saved recordings with AES-256-GCM after capture. The camera first writes a temporary unencrypted file; the app then encrypts it and tries to remove the temporary copy. An interrupted or failed save can leave an unencrypted file on the device. The PIN itself is never stored, so a forgotten PIN means the encrypted recordings cannot be recovered — by you or by us. Encryption is a setting: it is on by default, and when you turn it off the app says so plainly on the session screen and next to each unencrypted recording. The short loop clip that plays during a session is stored unencrypted so that it can be played back.
Export and delete
The Recordings screen lists saved captures and lets you export or delete each one, or delete all library entries at once. Those controls do not currently remove every temporary camera or export copy: interrupted operations and failed cleanup can leave unencrypted files outside the library, and Android’s system-share integration keeps an additional temporary copy. These cleanup and deletion limitations are release blockers. Deleting library entries does not remove copies you exported or copies in existing backups. On Android, app backup is disabled. On iOS that exclusion is not in place: captures sit in the app’s private storage, which iCloud Backup and encrypted computer backups may include, so exclude MimicCall from iCloud Backup in iOS Settings if you do not want copies of them there.
Permissions
What the app asks you for: camera and microphone, to record (photo mode holds no microphone at all), and photo-library access only when you choose a video from your gallery as the loop clip. It asks for nothing about your location or contacts, and it has no internet permission — that one is stripped out of the Android build, so the app cannot open a network connection at all.
The Android bundle also carries permissions that the camera, gallery-picker and video-player libraries it is built on declare for themselves, and Google Play lists these on the store page: view network connections, prevent the phone from sleeping, and read your shared storage (on Android 9 and older, write to it as well) — that last one is how the gallery picker reaches your video on devices without the modern photo-library permission. There is also the Android framework’s own app-scoped permission guarding a broadcast receiver inside the app. None of them lets anything leave your phone.
No ads, no analytics, no accounts
The app shows no advertising, contains no analytics or crash-reporting SDK, and has no sign-in. We receive no data from it.
Children
The app is not directed at children under 13 and does not knowingly collect personal data from them.
Contact: hello@llab08.com · Updated 12 September 2026 · All privacy notices