Skip to content
Direct Video Call

Privacy Policy

directvideocall.com · Effective August 26, 2026 · Last updated September 4, 2026

This Privacy Policy (this “Policy”) describes processing of information by Direct Video Call, the operator of directvideocall.com (“Provider”) in connection with Direct Video Call (the “Service”). It is incorporated into the Terms of Use. Capitalized terms not defined herein have the meaning set forth in the Terms of Use. IF USER DOES NOT AGREE, USER SHALL NOT USE THE SERVICE.

This Policy describes present practices of Direct Video Call at directvideocall.com.

1. Controller

The controller of personal data processed by the Service, to the extent any is processed, is Provider. Contact: privacy@directvideocall.com.

2. Design of the Service

2.1 The Service is designed so that Session audio and video are transmitted between the two participating devices. Provider does not require an account, profile, or payment instrument, and does not operate a media archive of Sessions.

2.2 That design does not make a Session confidential. The other participant, that participant’s device, and third-party networks may observe technical data and any content User elects to transmit. Provider does not warrant encryption, anonymity, or non-interception.

3. Information User is not required to provide

Provider does not require name, email address, telephone number, government ID, or payment card to place a call. Provider does not, in the ordinary course of the present architecture, record, store, or transcribe Session audiovisual content. Provider cannot delete a recording that exists solely on a device or network Provider does not control.

4. Information processed to operate a Session

  • Room Identifiers in invite URLs. Possession of the URL permits an attempt to join. User shall not include sensitive data in a URL and shall not publish it.
  • Camera and microphone signals captured on User’s device following browser permission, transmitted toward the other participant, and not retained by Provider as a Session recording.
  • Technical data reasonably required to establish a Session, which may include Internet Protocol addresses, ICE candidates, browser and device characteristics, timestamps, and signaling messages, as processed by User’s browser, the other participant, and the processors in Section 7.
  • Local interface position for the local video overlay, held in memory during a Session.

Provider does not intentionally collect precise geolocation. An Internet Protocol address may allow a processor or the other participant to infer an approximate region.

5. Information Provider does not currently collect

Provider does not currently operate first-party analytics, advertising, or marketing pixels on the Service; does not sell personal information; does not share personal information for cross-context behavioral advertising; and does not use Session content to train public artificial-intelligence models. If that changes, this Policy will be updated before such processing begins, and consent will be requested where required.

6. Cookies

Cookies and similar technologies are described in the Cookie Policy. In summary: the application does not set advertising or analytics cookies. Hosting infrastructure may set additional cookies to deliver the website and may load scripts required to serve the page. Advertising, analytics, and cross-context marketing cookies are not used by the Service as presently configured.

7. Processors and third parties

Provider uses independent operators to host and connect the Service. Those operators process information under their own terms. Categories presently involved when User loads the site or starts a Session include:

  • Website hosting and content delivery, which may log Internet Protocol addresses, requested URLs, user-agent strings, and diagnostic events, and may load scripts required to serve the page.
  • Signaling infrastructure used to exchange Session setup messages (including a publicly available PeerJS signaling service).
  • STUN or comparable network-discovery services used to assist connectivity, which presently include services operated by Google and Cloudflare.

Provider is not responsible for independent practices of those parties. If a direct peer path cannot be established, a Session may fail. Provider does not presently operate a media relay. If a relay is introduced, this Policy will be updated.

8. Purposes and legal bases

Where Provider processes personal data, it does so on one or more of the following bases under Article 6 GDPR (and equivalent UK GDPR provisions). A fuller notice appears in the GDPR / Data Protection Notice.

  • Article 6(1)(b): performance of a contract, including providing a Session User has requested.
  • Article 6(1)(f): legitimate interests in operating, securing, and preventing abuse of the Service, where not overridden by User’s rights.
  • Article 6(1)(c): compliance with a legal obligation.

9. Sharing

Provider discloses information only: (a) to the other Session participant as a function of the connection; (b) to processors acting to operate the Service; (c) if required by law, legal process, or governmental request; (d) to protect the rights, property, or safety of Provider, User, or others; or (e) in connection with a reorganization, merger, or transfer of operations, subject to this Policy or successor notice.

10. Retention

Provider does not retain Session audiovisual content. Room Identifiers are coordination tokens, not an archive. Appearance preference remains on User’s device until cleared or changed. Host and signaling logs, if any, are retained by those operators only as reasonably necessary for operation, security, and legal compliance under their own policies. Provider has not established a separate numeric retention schedule for logs Provider does not itself store.

11. Security

Provider implements reasonable administrative and technical measures appropriate to a peer-to-peer web application. No transmission over the Internet is guaranteed secure. Provider does not warrant encryption, anonymity, or that a third party cannot intercept or join a Session. User is responsible for device security and for ending the Session.

12. Children

The Service is intended solely for users eighteen (18) years of age or older. Provider does not knowingly collect personal information from children, including children under thirteen (13) as defined by the U.S. COPPA rule. Upon actual knowledge of such collection, Provider will delete information within its control.

13. International transfers

The Service is offered from infrastructure that may be located in the United States. Personal data may be processed in the United States and in other countries of processors and of the other Session participant. Those countries may not provide the same level of protection as the EEA, United Kingdom, or Switzerland.

Where the GDPR or UK GDPR applies to a transfer to a third country, Provider relies on an applicable mechanism where one is available, which may include an adequacy decision, participation by a processor in a recognized framework, or Standard Contractual Clauses (and the UK addendum, where required). Provider has not represented that it is certified under the EU-U.S. Data Privacy Framework. A copy of any mechanism in Provider’s possession may be requested through the contact details below, subject to redaction.

14. Privacy rights

User may refuse camera or microphone permission, close the browser, or discontinue use. Cookie and similar-technology use is described in the Cookie Policy. User may block or delete cookies in the browser.

EEA, UK, and Swiss rights are described in the GDPR / Data Protection Notice. In summary, subject to legal conditions, they include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and the right to lodge a complaint with a supervisory authority.

California and other U.S. state laws. Provider does not sell personal information and does not share it for cross-context behavioral advertising. Because the Service does not use an account, Provider may be unable to verify or locate a particular consumer’s data. To the extent the CCPA/CPRA or similar state laws apply, User may request to know, delete, or correct personal information within Provider’s control, and Provider will not discriminate for exercising a privacy right. Sensitive personal information is not used to infer characteristics. Appeals of a denied request, where required by state law, may be submitted through the same contact channel.

Requests: privacy@directvideocall.com. Provider may need additional information to verify a request and may refuse a request that is unfounded, excessive, or cannot be matched to stored data.

15. Do Not Track

The Service does not alter its behavior in response to browser “Do Not Track” signals. The Service does not operate a third-party advertising tracker on Sessions.

16. Changes

Provider may amend this Policy by posting a revised version and updating the “Last updated” date. Continued use after posting constitutes acceptance where permitted by law. Where consent is required, Provider will request it again.

17. Contact

Controller: Direct Video Call, the operator of directvideocall.com. Privacy contact: privacy@directvideocall.com.

Questions: privacy@directvideocall.com

© 2026 directvideocall.com · All rights reserved

Terms · Privacy · Legal · Cookies