YOUR INFORMATION

Privacy policy

Your choices at a glance

Core messaging needs no online account. Cloud AI is optional and needs your separate permission. App usage and crash reports are enabled by default, with independent switches in Settings. Account and data deletion instructions are available without installing the app.

Messages and permissions on your phone

Android remains the source for SMS, MMS and attachments. Facetotext keeps an on-device index, contact display information, selected previews and categories. Messaging and built-in code, event and common-scam detection work without a cloud account. SMS/MMS travel through your carrier and the recipient’s service; they are not end-to-end encrypted by Facetotext. Carrier charges may apply.

The default-SMS role and message permissions let the app read, receive, send and manage messages. Contact access supports recipient selection and contact display. Phone state supports SIM selection. Microphone access supports audio recording when you choose that feature. Selected media and audio can be sent as MMS. Notifications and alarms support message notifications, scheduled actions and reminders. These permissions do not give us a cloud copy of your entire inbox or contacts.

Bookmarks, reminders, scheduled-message drafts, personalization and recovery copies are stored locally. Recently deleted retains deleted messages and downloaded attachments on the device for 30 days, unless you permanently remove them sooner. Clearing app data or uninstalling removes app-owned indexes, preferences, drafts and recovery copies. Android’s SMS/MMS store is separate and is not removed by uninstalling. App-owned data is excluded from Android app backup. Copies you export or send to others remain under your or the recipient’s control.

App usage and crash diagnostics

Google Analytics for Firebase and Firebase Crashlytics are enabled by default to understand basic app activity and improve reliability. In Settings → Privacy and diagnostics, you can turn off Share app usage and Share crash reports separately. These choices are independent of signing in, Premium and cloud AI consent.

Analytics receives basic usage events, such as opening the app or Settings, together with standard SDK app-instance, installation, session, app-version and device information. Google Analytics derives approximate location from IP address information and can automatically report Google Play in-app purchase and subscription events. This is coarse location, not GPS or precise location permission. These events may include product, price, currency and subscription activity; they do not include your payment card details. The app’s custom events have no message or contact parameters. Automatic screen reporting, advertising-ID collection and advertising personalization are disabled. We do not set account IDs or user IDs in Analytics. See Google’s Analytics for Firebase data disclosures.

Crashlytics receives crash code locations, app and device information, installation identifiers and reports of an app becoming unresponsive (ANRs). Before Java crashes reach Crashlytics, the app removes exception messages and replaces them with fixed text. We do not add message contents, contact details, account identifiers, tokens, custom crash keys or free-form logs. ANR reports are generated by the SDK outside this exception filter, so they can contain technical stack and diagnostic information. We do not claim that SDK reports contain no personal information.

Disabling usage stops future Analytics collection and resets local Analytics data. Disabling crash reporting suppresses new app crash reporting and requests deletion of unsent SDK reports. Reports already uploading cannot be recalled. These switches, account deletion, clearing app data and uninstalling do not automatically erase data already received by Google.

Google’s Firebase privacy information describes Crashlytics retention, including 90 days for crash traces and associated identifiers before removal begins. Analytics user and event retention follows the property’s configured retention settings; aggregated reporting can be retained separately. See Google Analytics retention information. For a request concerning already uploaded data, contact us. We do not link telemetry to your account email, so locating a specific installation’s records may require additional information. We will explain what can be identified and removed.

Optional cloud AI classification

When you explicitly enable cloud AI filters and have verified Premium access, eligible message text is sent over HTTPS to our service and TypeSafe AI for classification. You may use a signed-in account or purchase-linked guest access. Text can contain verification codes or sensitive information. Context includes whether the sender is a known contact, sender digit count, short-number status, whether the sender ID contains letters, and numbering regions, attachment types and counts, preceding-message counts and dates, locale, timezone and available device/carrier information. Your custom filter descriptions and category instructions are also sent when used for classification. Raw sender phone numbers, contact names, attachment contents and preceding message bodies are not included as context. Phone numbers may still occur inside the message text itself.

When on-device or server classification rules disagree with AI, our service retains the actual message text, classification results, scores and category criteria for investigation for up to seven days. These records can contain verification codes, phone numbers present in message text and other sensitive content. Diagnostic storage is limited to 10,000 records and 50 MiB of retained payloads across the service; older records are removed sooner when either limit is reached. Records expire after seven days and are purged on classification requests and by hourly scheduled cleanup. The storage limit covers retained payloads rather than database page or backup overhead. Account deletion removes its diagnostic records. We do not retain attachments or sender phone numbers as separate diagnostic fields.

Routine operational logs contain request trace IDs, message sizes, presence flags, validation outcomes, category counts and timings, without message text, extracted codes or body fingerprints. TypeSafe processes text under its own service terms. Facetotext does not collect messages for model training. Turning off classification stops future requests; requests already sent may finish. Classification categories and scores are returned to your app for inspection.

Optional accounts and security

For email or Google accounts, we store your verified email address, a provider-specific normalized mailbox identifier, Google identity when linked, a salted password hash when you use a password, hashed session tokens and usage records. Google provides identity for Google sign-in; Firebase Authentication is not used. Amazon SES delivers verification and recovery emails. Verification codes expire after 10 minutes. Sessions expire after 30 days and can be revoked by signing out, resetting your password or deleting your account.

Guest Premium access creates a pseudonymous service account associated with hashed purchase identifiers, entitlement dates, sessions and usage. It has no email address or password. Guest service records are distinct from the optional email/Google account, and the email deletion form cannot identify them. Contact support for a guest-data request. Account records remain until deleted; session expiry alone does not delete an account.

Cloud usage and retention

Cloud AI allows up to 1,000 historical incoming messages, 300 new or reclassified messages per rolling 24 hours and 3,000 per rolling 30 days. Messages must fit 4,000 Unicode characters and 16 KiB. Retry and service capacity limits also apply. We retain opaque request identifiers and usage for up to 31 days. A keyed mailbox or guest quota digest and historical allowance count remain after deletion to prevent repeated imports or allowance abuse; they do not contain message text and have no automatic expiry. IP addresses are converted into short-lived rate-limit identifiers rather than stored directly by application code. Hosting and email providers may retain their own operational records and backups under their service policies.

Premium purchases

Google Play handles payment; we do not receive card details. Local Premium uses saved purchase state so it works offline. When you use paid cloud processing, your purchase token is sent over HTTPS to our backend and Google Play to verify access. Our backend retains only a token hash bound to an opaque quota identity and entitlement dates, never the raw purchase token. These abuse-prevention hashes remain after account deletion to prevent a shared purchase from multiplying AI allowances. We do not log purchase tokens or Google purchase responses.

Service providers and this website

We use Google for Analytics, Crashlytics, optional Google sign-in and Google Play purchase verification; TypeSafe AI for optional cloud classification; Amazon SES for account emails; and OpenAI Sites with Cloudflare infrastructure to host this website and backend. Providers may process information in countries other than yours. We use these services to operate messaging-related features, secure accounts, prevent abuse, investigate classification errors and improve the app. We do not sell your personal information or use your messages for advertising.

This website does not add advertising or analytics scripts. Hosting providers process connection information, including IP address and request metadata, to deliver and secure the site. The deletion form sends the entered email address and verification code to our account service. If you email support, we receive your email address, message and anything you choose to attach; do not send passwords, verification codes, raw purchase tokens or private message histories. We keep support correspondence as needed to resolve the request and maintain relevant support or security records.

Your choices and requests

Delete your online email/Google account from the account controls in the app’s Smart categories settings, or use our account and data deletion page. The verified deletion action removes its account, password, Google-link, session, entitlement and classification-disagreement records. On-device messages and categories remain; limited anti-abuse identifiers described above remain. Guest data and previously uploaded telemetry require a separate request.

Contact us to request access, correction or deletion of personal information, or ask a privacy question. We may need to verify the request and explain any data we cannot identify or must retain. Account deletion and uninstalling do not cancel a Google Play subscription. Manage or cancel it in Google Play. See subscription terms.

For support or privacy requests, contact gazman1986@gmail.com.

Back to Facetotext