Is an App That Calls Your Friend When You Oversleep Breaking Robocall Law?

A two-axis legal test, consent and dialer type, for why apps that auto-call a friend when you miss your alarm sit in a different bucket than spam robocalls under the TCPA.

In this article6 sections

Short version: probably not, and the reason has nothing to do with what the call sounds like. It comes down to two questions a court actually asks: did the person on the other end agree to get calls from this number, and did a machine pick that number out of a list on its own. Most wake-up-call apps land on the safe side of both.

A handful of alarm apps let you name a friend who gets an automated phone call if you don’t check in by a set time. Several of the more established ones compare closely on exactly this feature, and the pitch is obvious: a ringing phone is harder to ignore than a push notification. What’s less obvious is that “automated call to a number the app didn’t originally dial from a marketing list” is, on paper, close to the fact pattern the Telephone Consumer Protection Act was written to regulate. So which is it: a clever accountability feature, or a robocall with a nicer interface?

The law was not written with alarm clocks in mind

The TCPA dates to 1991, aimed at telemarketers running automatic dialers through residential lines. Its core prohibition covers calls made using an “automatic telephone dialing system,” or ATDS, without the called party’s prior express consent. For decades, companies and courts argued over what counted as an ATDS, because almost any modern calling software could plausibly fit a broad reading of the statute’s original language.

The Supreme Court narrowed that argument in Facebook, Inc. v. Duguid (2021), holding that an ATDS is equipment with the capacity to store or produce numbers using a random or sequential number generator, then dial those numbers. A system that calls one number a user typed in and saved themselves is placing a single, pre-designated call to a number a human already chose. That distinction is the whole ballgame for most consumer apps in this category, and it’s why Duguid gets cited constantly in TCPA defense filings for anything that isn’t a mass-dialing operation.

Consent is the second variable, and the one app designers actually control. The FCC has said prior express consent for a non-marketing, informational call can be established simply by the called party knowingly providing their number in a context related to the reason for the call. Adding a friend’s number as your emergency wake-up contact, with that friend’s knowledge, is a fairly clean case of contextually appropriate consent: closer to giving a dentist’s office your number for an appointment reminder than to a marketer buying a lead list.

A two-axis test, not a yes-or-no rule

Treating “does the TCPA apply” as one yes-or-no question is what confuses people, because the statute turns on two variables that don’t always move together.

Axis one: consent. Did the recipient affirmatively provide their number for this purpose, or did the number come from somewhere else (a purchased list, a referral, a contact synced without that contact’s knowledge)?

Axis two: dialer type. Is a human placing the call, or does a system store and produce the number, then dial it, without a person choosing that number in that moment?

Plotted against each other, the four resulting quadrants explain most real disputes in this space better than either axis alone.

  • Opt-in consent, a single stored number dialed automatically on a trigger. This is where a “call my contact when I miss my alarm” feature sits. Low legal exposure, because a human chose and saved the number, and the person being called agreed to be in that role.
  • Opt-in consent, a human physically placing the call. A friend calling a friend. This never implicated the TCPA to begin with, since the statute governs automated and prerecorded calls rather than manual ones. It’s included mainly to show that the dialer-type axis matters on its own, apart from consent.
  • No real consent, automated dialing from a generated or purchased list. Classic robocall spam. This is the pattern the statute was built for, and where most enforcement actions and class-action settlements live.
  • No real consent, a human dialer. Cold-calling by a live person is regulated too, mostly by the Telemarketing Sales Rule and state do-not-call statutes rather than the TCPA’s autodialer provisions. Not a robocall doesn’t mean no rules apply at all.

An app that lets you add a contact, notifies that contact when they’re added, and only ever calls the number that person agreed to receive calls at sits in the first, lowest-risk quadrant. The feature people assume is legally risky because it involves an automated call to a third party is, structurally, closer to a calendar reminder than to a telemarketing blast.

Where the quadrant model breaks

This framework has real edges, worth naming rather than smoothing over. Consent can be revoked, and an app with no reliable way to remove a contact on request, or one that keeps calling after being told to stop, moves back toward risk regardless of how the number originally got there. Courts have found liability for continued automated or prerecorded calls after a clear stop request even when the underlying system wouldn’t meet the narrow post-Duguid definition of an autodialer, because the TCPA separately restricts artificial-voice and prerecorded-message calls on their own terms. A synthetic voice reading a script is treated more cautiously than a live connection for the same reason. This isn’t legal advice for any one product, either: a feature that syncs a user’s entire contact list without each contact’s individual knowledge reintroduces the exact consent problem the quadrant model assumes has already been solved.

The FCC’s one-to-one consent rule, which would have required a separate consent for every individual company relying on a shared lead rather than one blanket agreement covering a referral chain, is the wrong fight to import into this conversation, even though it dominated TCPA news for two years. The Eleventh Circuit vacated it on January 24, 2025, in Insurance Marketing Coalition Ltd. v. FCC, finding the agency had exceeded its statutory authority, and the FCC withdrew the rule later that year rather than keep defending it. That dispute was about lead-generation networks reselling one consent across dozens of buyers, a problem that doesn’t exist in a two-person arrangement where the contact already knows exactly who is calling and why.

State law adds a second layer that federal courts don’t settle

Duguid only interprets the federal ATDS definition. A number of states, including Florida, Oklahoma, and Washington, have their own mini-TCPA statutes with broader autodialer definitions that some courts have read to cover systems Duguid would exclude at the federal level. A wake-up-call feature that’s fully compliant under the federal test can still face a claim under a state statute if it operates for users in one of those states, which is one reason larger consumer apps in this category tend to build consent flows conservative enough to satisfy the stricter state definitions too, rather than engineering to the federal floor alone. This is the part of the analysis a purely federal reading of Duguid will miss entirely, and it’s the detail most likely to matter if a product ever gets sued rather than just discussed.

Florida’s Telephone Solicitation Act is the sharpest example, because it defines an autodialer broadly enough that several federal district courts sitting in Florida have applied it to systems that store and dial numbers from a list, without requiring the random-or-sequential-generator element Duguid now demands federally. A wake-up feature built only to the post-Duguid federal standard, with no attention to where its users actually live, could clear the national test cleanly while still facing a viable claim from a single state’s residents. Building the consent flow, not just the dialing logic, to the stricter of the two standards is the cheaper fix, and it costs nothing extra for the overwhelming majority of users who were never going to file a complaint either way.

Why this matters beyond one feature

This isn’t really about alarm apps specifically. It’s a case study in a broader pattern: a law written to stop one kind of automated abuse gets applied, by reflex, to any software that automates a phone call, the same reflexive suspicion that shows up whenever a synthetic voice does the talking, even in contexts closer to a personal favor than a marketing campaign. The two-axis test is a more useful way to reason about these products than asking “is it automated,” because automation was never the sole trigger. Consent was always doing at least half the work, and it’s the half a product can actually control, the same underlying point that comes up whenever a consumer product has to satisfy two overlapping regulatory regimes at once instead of one clean rule.

FAQ

Does the TCPA apply to an app that calls my emergency contact instead of me? Potentially, yes. The statute protects the person who receives the call, not the person who set up the alarm. If an app dials a contact’s number using stored-number automated technology and that contact never separately agreed to receive calls from the app, the call is analyzed under their own consent status, regardless of what the app’s actual user agreed to when signing up.

What changed with the Facebook v. Duguid decision? The 2021 Supreme Court ruling narrowed what counts as an “automatic telephone dialing system” under the TCPA to equipment that uses a random or sequential number generator to produce or store the numbers it calls. A system that only dials a number a user manually entered and saved falls outside that narrower definition, which is why most consumer apps with a “call my contact” feature were never the kind of system the statute’s autodialer provisions were built to catch.

Did the one-to-one consent rule change anything for these apps? The FCC’s 2023 rule would have required a separate consent for each individual company placing autodialed calls, rather than one broad consent covering a whole referral chain. The Eleventh Circuit vacated it on January 24, 2025, in Insurance Marketing Coalition v. FCC, ruling the agency had exceeded its statutory authority, and the FCC formally withdrew the rule later that year. That fight was almost entirely about lead-generation and marketing calls; it has no real bearing on a two-person app where the contact already knows the caller.

Could an app get in legal trouble for a wake-up call even if the contact agreed to be added? The risk returns if consent is withdrawn later and the calls keep coming. Courts have found liability for continued automated or prerecorded calls after a clear stop request, even for a system outside the narrow autodialer definition, under the TCPA’s separate rule against artificial-voice messages made without consent. An app with no way to remove a contact, or one that plays a synthetic voice instead of connecting a real person, carries more of this risk than one that places a plain, opt-in call.

Keep reading