Privacy Policy
Contents
1. The short version
Textly runs entirely on your device. Your messages, your connected channels, your contacts and every piece of intelligence built on top of them (search, summaries, replies, scam detection, extraction of appointments and invoices) are processed locally on your phone.
We operate no server that receives your message content. Nothing is sent to an external AI provider. There is no Textly account, no advertising and no analytics or tracking SDK.
2. Who is responsible
The controller responsible for data processing in connection with the Textly app and this website within the meaning of Art. 4(7) GDPR is:
- [COMPANY / PROVIDER NAME]
- [STREET AND NUMBER]
- [POSTCODE, CITY, COUNTRY]
- Email: [CONTACT EMAIL]
A data protection officer [has / has not] been appointed. [If applicable: name and contact details.]
3. Data processed in the app
SMS and MMS
On Android, when you select Textly as your default SMS application, the system grants it access to the SMS database. (On iOS this does not apply, because Apple provides no SMS access to third-party apps.) Textly reads your existing conversations in order to display them, writes messages you send, and stores incoming messages in that same system database. All of this happens locally. Message content is never transmitted to us.
Messages from connected channels
Messages retrieved from WhatsApp, Telegram, Discord or Slack are cached in Textly's own encrypted local database so they can be displayed, searched and summarised offline. That cache lives only on your device and is deleted when you disconnect the channel or uninstall the app.
Contacts
If you grant contacts permission, Textly matches phone numbers and channel identities against your address book so conversations show names and photos rather than raw identifiers, and so the same person's threads across different channels can be merged into one history. Contact data is read on the device and is not copied to any server.
Derived data
To power search, summaries and the extraction of appointments, invoices, parcels and tasks, Textly builds a local index and stores the recognised items alongside your messages. This derived data is generated on your device, stays on your device, and is removed together with the messages it came from.
App settings
Preferences such as your selected filter, notification settings and per-channel options are stored locally in the app's private storage.
Crash and diagnostic information
Textly does not include its own crash-reporting service. If you choose to share a crash report through Google Play's built-in mechanism, that report is handled by Google under Google's own privacy policy. [Adjust if you later add a crash-reporting SDK.]
4. Connected channels
Connecting WhatsApp, Telegram, Discord or Slack is entirely optional. Textly is fully usable as an SMS-only application.
There are two technically distinct kinds of channel, and because they differ in what data goes where, they are described separately.
Telegram: a connection to the provider
You authenticate directly with Telegram through its own login flow. The resulting credentials are stored on your device in the platform’s hardware-backed key storage: the Android Keystore, or the iOS Keychain and Secure Enclave. We never receive your password and we never receive your token.
Once connected, the app on your device communicates directly with Telegram's servers in order to receive and send your messages. No traffic is routed through infrastructure operated by us, because none exists. Telegram sees the same activity it would see if you used its own client: your account, your messages, your connection metadata.
WhatsApp, Discord and Slack: reading notifications
These three are not connected at all. None of them offers a way for another application to access your messages, so Textly does not sign in to them, holds no credentials for them, and never contacts their servers. Instead, with your explicit permission, it reads the notifications those apps post on your Android device.
This requires notification access, a permission Android treats as sensitive and which is granted only by you, in a system settings screen that we cannot bypass or pre-fill. It can be withdrawn there at any time. While it is granted, the technical capability is broad, so what we do with it is deliberately narrow:
- Only notifications from the messaging apps you have connected in Textly are processed. Everything else the permission exposes is discarded without being read.
- The content is stored in the same encrypted local database as your other messages, on your device.
- It is never transmitted anywhere, and there is no server it could be transmitted to.
- Disconnecting the channel in Textly deletes what was cached from it.
Because Textly only ever sees what these apps announce, it has no access to your history with them, to anything that arrived while it was not running, or to any conversation you have muted.
Android only. iOS provides no comparable interface, so these channels cannot work this way on an iPhone.
The providers' own terms
Where a connection exists, the provider processes that data as an independent controller under its own privacy policy and terms, over which we have no influence. The same policies govern your use of their own apps, which is where the WhatsApp, Discord and Slack data reaches your phone in the first place:
- WhatsApp (Meta): whatsapp.com/legal/privacy-policy
- Telegram: telegram.org/privacy
- Discord: discord.com/privacy
- Slack (Salesforce): slack.com/trust/privacy
Disconnecting
Disconnecting a channel in Textly deletes the cached messages and the derived data for that channel from your device, along with the stored credentials where any exist. It does not delete anything from the provider's own service. To do that, use that provider's account settings. For Telegram you can additionally end the session under Settings → Devices in Telegram itself. For WhatsApp, Discord and Slack there is nothing to revoke, because nothing was ever connected; withdrawing notification access in Android's settings stops the reading entirely.
5. On-device AI processing
All intelligent features (semantic search, summaries, suggested replies, scam and spam classification, and the recognition of appointments, invoices, parcels, contacts and tasks) are performed by models that are shipped inside the application package and executed on your device's own processor.
- No cloud inference. There is no API call to us or to any AI provider such as OpenAI, Google or Anthropic. The features work in airplane mode.
- No training on your data. Your messages are never used to train, fine-tune or evaluate any model. Corrections you make (for example marking a message as not spam) adjust local behaviour on your device only.
- No prompt logging. Questions you ask the app are answered locally and are not recorded anywhere outside your device.
Because this processing happens entirely within your own device and under your control, it does not constitute a transfer of personal data to us or to a third party.
6. Permissions and why they are needed
- Default SMS app role (Android only). Required by Android for any app that sends, receives and manages SMS. iOS has no equivalent and Textly does not handle SMS there.
- SMS (read, receive, send), Android only. To display your conversations, receive new messages and send yours.
- Internet. To communicate with Telegram's servers once you connect that channel. Used for nothing else; the app makes no analytics or advertising requests, and it contacts no server of ours because none exists.
- Contacts (read). Optional. Used only to resolve identifiers to names and to pick recipients.
- Notifications (posting). To alert you about incoming messages and to allow replying from the notification.
- Notification access (reading), Android only. Optional. This is the mechanism behind the WhatsApp, Discord and Slack channels, and it is the most far-reaching permission Textly can hold, so it is worth stating plainly what it does. Android grants it only through a system settings screen that we cannot bypass, and it is never requested unless you connect one of those channels. Textly processes notifications from those apps alone and discards everything else the permission exposes. Nothing gathered this way leaves your device. Withdraw it at any time under Settings → Apps → Special app access → Notification access; those channels then stop working, and the rest of Textly is unaffected. See section 4.
- Foreground service / background execution. To keep connected channels in sync so messages arrive promptly.
- Phone (optional). To start a call from a conversation, if you tap the call action.
- Photos and media (optional). Only when you attach a file to a message.
You can revoke any optional permission at any time in your device settings. Revoking a permission only disables the corresponding feature.
7. Data we do not collect
- We do not collect or store the content of your messages on any server.
- We do not receive your channel credentials, tokens or account identifiers.
- We do not send your messages to any external AI service.
- We do not collect your phone number, contacts or address book.
- We do not create user accounts or user profiles.
- We do not use advertising identifiers and we do not show ads.
- We do not sell, rent or share personal data with third parties for their own purposes.
- We do not track your usage across apps or websites.
8. Third parties
Google Play. The app is distributed through the Apple App Store and Google Play. When you download, install or update Textly, Apple and Google process data as independent controllers under their own privacy policies: the Apple Privacy Policy and the Google Privacy Policy. We receive only aggregated, anonymised statistics such as install counts through App Store Connect and the Play Console.
Your mobile network operator. Sending and receiving SMS is carried out by your carrier, who processes that data as an independent controller under its own terms.
Connected channel providers. See section 4.
Beyond these, Textly integrates no third-party services: no analytics, no crash reporting SDK, no advertising network, no CDN.
9. This website
Hosting and server logs
This website is hosted by [HOSTING PROVIDER, ADDRESS]. For technical operation and security, the host records standard server log data: IP address, date and time of the request, the requested resource, referrer, browser and operating system version. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation). Logs are deleted after [X DAYS].
Cookies and analytics
This website sets no cookies and uses no analytics or tracking services. [Update if you later add analytics; a consent banner would then be required.]
Fonts and external resources
All fonts and assets are served from this website's own server. No requests are made to third-party CDNs, so no data is transferred to font or CDN providers when you visit.
10. Legal basis (GDPR)
- Art. 6(1)(b). Processing on your device necessary to provide the messaging functionality you requested.
- Art. 6(1)(a). Consent, for optional permissions such as contacts and media access, and for connecting an optional channel.
- Art. 6(1)(f). Legitimate interest, for the secure operation of this website and for protecting users against fraud and spam.
11. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future.
Because message, channel and derived data never leave your device, we normally hold no personal data about you that we could disclose or delete. Requests concerning data on your own device can be fulfilled by you directly, by deleting conversations, disconnecting a channel or uninstalling the app. Requests concerning data held by a connected provider must be addressed to that provider.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, workplace or the place of the alleged infringement.
12. Retention and deletion
Data stored on your device remains there until you delete it, disconnect the channel it belongs to, or uninstall the app.
Uninstalling Textly does not delete your SMS: on Android they remain in the system message storage and are available to your next default SMS app. It also does not delete anything held by WhatsApp, Telegram, Discord or Slack; that data stays with those services.
13. Children
Textly is not directed at children under the age of [13 / 16, as applicable], and we do not knowingly collect personal data from them.
14. Changes to this policy
We may update this policy to reflect changes in the app or in legal requirements, for example when a new channel becomes available. The current version is always at this address, with the date of the last update shown at the top. Material changes affecting your rights will be communicated in the app.
15. Contact
Questions about privacy or this policy: [CONTACT EMAIL]. We aim to respond within [X] business days.