Textly
TextlyProductPrivacy & security
Privacy & security first

We can't read your messages.

Every other AI inbox works by uploading your messages. Textly doesn't have that option: the models ship inside the app and run on your hardware. That single architectural decision is what makes everything else safe.

Four protections

Security you can check, not just believe.

Scam & phishing detection

An on-device model reads a message the way a suspicious human would: who is it claiming to be, what does it want, and does the link agree with either answer?

  • Couriers asking for a small "release fee"
  • Banks manufacturing urgency about your account
  • Payment links on domains that don't match the sender
  • Family-in-trouble messages from unknown numbers

Flagged messages move to Spam and their links are disabled until you overrule it.

Encrypted on your device

The local message database and every channel credential sit behind the platform's hardware-backed key storage (the Android Keystore, or the iOS Keychain and Secure Enclave), tied to your screen lock.

This is the part most messengers quietly skip: the copy on your phone is usually the easiest one to steal.

End-to-end where the protocol allows

WhatsApp messages stay end-to-end encrypted, and Textly never weakens that: WhatsApp decrypts them on your phone as it always has, and Textly reads the result there without ever contacting WhatsApp. Telegram, Discord and Slack are encrypted to their servers but readable by those services. SMS, on Android, has no end-to-end encryption at all.

No app can change that, and any app claiming it can is misleading you.

Spam filtering without a server

Classic spam filters work by shipping your message to someone else's classifier. Textly's filter is a file inside the app, so nothing is sent away to be judged.

Your corrections train nothing but your own copy.

In plain terms

What leaves your phone

An AI messenger is only as trustworthy as its data flow. Here is the complete list, without the marketing.

DataLeaves your device?Where it goes
Message contentNoStays in the local encrypted store
AI questions & answersNoComputed on your processor
ContactsNoRead on-device to resolve names
Extracted itemsNoStored beside the message they came from
Channel credentialsNoKeystore / Secure Enclave, never transmitted to us
Usage analyticsNothing collectedNo SDK is present in the app
Your repliesYes, necessarilyTo the channel you are replying on
Channel sync trafficYes, necessarilyDirectly to WhatsApp, Telegram, Discord, Slack
SMSYes, necessarilyOver your mobile network operator

The last three rows are the honest part: a messenger that never talked to anything would not deliver messages. What matters is that none of that traffic passes through infrastructure we operate, because we operate none. The privacy policy says the same thing in formal terms.

Commitments

What Textly does and never does

Uploads your messages to a serverNever
Sends anything to an external AI providerNever
Trains models on your conversationsNever
Requires an account with usNever
Shows ads or sells dataNever
Runs its AI models on your own hardwareAlways
Keeps channel logins in hardware-backed key storageAlways
Contacts WhatsApp, Telegram, Slack or Discord serversTo fetch & send
Lets you disconnect a channel and wipe its dataAny time
Scam detection is a safety net, not a guarantee. It will occasionally flag a legitimate message and it will occasionally miss a fraudulent one. Never enter payment or login details from a link in a message, whether or not Textly warned you.

Privacy that survives a look under the hood.

No server, no accounts, no uploads, and nothing you have to take on faith. Try it yourself in airplane mode.