SSMS IQ

Legal · SMS IQ for Android

Privacy Policy

SMS IQ is built local-first: your messages are read, organized, and acted on in an on-device database, and nothing leaves your phone unless you explicitly turn on a feature that sends it somewhere. This policy explains exactly what that means, feature by feature.

Effective August 24, 2026 Applies to SMS IQ (Android) Contact [email protected]
01

Overview

This policy is written by the developer of SMS IQ ("we," "us") to explain how the app handles data on your Android device. SMS IQ is a single-developer app, not a large company product — read this as a plain, specific account of what the code actually does, not boilerplate.

Stays on your device

Message storage, categorization, extraction, rules, blocked senders, labels, on-device AI, and scheduled sends. All of this works with no network connection.

Leaves your device only if you turn it on

Cloud AI tasks, webhook automations you configure, Play purchase verification, ads, and anonymous analytics/crash reports.

02

Information we process

To function as an SMS app, SMS IQ reads and stores, locally on your device, in an encrypted-at-rest Android app database:

  • SMS and MMS content — sender/recipient number, message body, timestamps, and thread structure, so the app can display, categorize, and let you search your conversations.
  • Contact names — looked up against your device's contacts, best-effort, purely to show a name instead of a raw number next to a conversation. The app degrades gracefully (falls back to the number) if contacts access isn't granted.
  • SIM / carrier state — used only to label which SIM a message came from on multi-SIM devices.
  • Rules, labels, categories, blocked senders, custom fields, and webhook/automation configuration you create inside the app.
  • Purchase history and AI usage counters — logged locally so the app can show you your own purchase and quota history.

None of the above is transmitted to us or to any third party as part of normal use. It only leaves the device through the specific, opt-in pathways described in sections 4–7 below.

03

On-device AI

By default, SMS IQ's AI features (message categorization, summaries, reply suggestions, field extraction) run entirely on your device using a bundled small language model (currently a LiteRT-LM runtime). Message content given to the on-device model never leaves your phone — there is no network call involved in generating that output.

04

SMS IQ Cloud (cloud AI)

SMS IQ Cloud is an optional, opt-in mode you can select in Settings when you want higher-quality AI output than the on-device model provides. When a task is routed to SMS IQ Cloud, the following happens:

  • The relevant message content for that task — for example a sender and message body, a short conversation excerpt, a contact name (if available), or field labels you've defined for extraction — is sent from the app to our backend service.
  • Our backend authenticates the request (using an on-device integrity check and a signed request, not your identity — see below), enforces your plan's daily quota, and forwards the content to a third-party AI/language-model service to generate the result, which is returned to the app and never stored as a persistent conversation on our side beyond what's needed to serve that one response and enforce quota.
  • Requests are tied to an anonymous, per-install device identifier (a Firebase Installations ID), not to your name, phone number, email, or a user account — SMS IQ has no account or sign-in system. This identifier resets if you uninstall/reinstall the app or clear its data.
Provider may change without notice

We select and operate the third-party AI service(s) behind SMS IQ Cloud, and we may change the underlying AI provider or model at any time, without prior notice or additional consent, including switching providers per request for load, cost, quality, or availability reasons. This policy governs SMS IQ Cloud regardless of which provider is in use behind it at a given moment.

Because content is processed by a third party we don't control end-to-end, avoid routing highly sensitive information (e.g. government ID numbers, financial account credentials, health details) through SMS IQ Cloud — use the on-device model for that content instead, which never leaves your phone.

05

Automations & webhooks

SMS IQ lets you build automation rules that forward message data to a URL you provide (a webhook). This is entirely user-configured: nothing is sent anywhere unless you write a rule that says so, and it is sent only to the destination you specify.

  • Any authentication secret you enter for a webhook (bearer token, API key, basic-auth password) is encrypted at rest on-device using the Android Keystore before it's stored, and is only decrypted in memory to attach it to your outgoing request.
  • We do not see, log, or have access to your webhook URLs, payloads, or secrets — the request goes directly from your device to the endpoint you configured.

See Terms of Use §6 for the responsibilities that come with configuring your own webhook destination.

06

Purchases & billing

Subscriptions and one-time addon packs are sold through Google Play Billing. When you complete a purchase, the app sends the Play purchase token to our backend, which verifies it against the Play Developer API and records your resulting plan/credits against your anonymous device identifier — again, not against a name or account. A local record of your purchase attempts is kept on-device for the in-app purchase history screen.

07

Advertising

Free-tier SMS IQ shows banner and interstitial ads served through Google AdMob. AdMob may collect device and advertising identifiers and use them for ad delivery and measurement under Google's own privacy terms — we don't receive your message content for ad targeting, and ad frequency capping is computed locally on-device.

08

Analytics & diagnostics

We collect a small set of anonymous, aggregate product events (app opens, paywall views, completed purchases, quota-limit prompts) and crash/diagnostic reports, to understand what's breaking and which features are used. These events carry app version and event type only — never message content, contact names, or phone numbers.

09

Android permissions

Here's what each permission SMS IQ requests is actually used for:

PermissionPurpose
RECEIVE_SMS / READ_SMS / SEND_SMSCore messaging — receive, read, and send texts as your default SMS app.Local
RECEIVE_MMS / RECEIVE_WAP_PUSHReceive picture/multimedia messages.Local
READ_PHONE_STATELabel which SIM a message belongs to on dual-SIM phones.Local
READ_CONTACTSBest-effort sender name lookup; the app works fine without it.Optional
POST_NOTIFICATIONSShow new-message and delivery notifications.Local
INTERNET / ACCESS_NETWORK_STATEOnly used by opt-in features: webhook automations, SMS IQ Cloud, purchase verification, ads, analytics.Opt-in
SCHEDULE_EXACT_ALARMDeliver a message you scheduled at the exact time you chose, even if the device is dozing.Local
RECEIVE_BOOT_COMPLETEDRe-arm scheduled-message alarms after a reboot (the OS clears them otherwise).Local
WAKE_LOCKKeep the device awake briefly while a scheduled message actually sends.Local
10

Storage & security

Your messages and app data live in a local database inside SMS IQ's private app storage, not accessible to other apps. Webhook secrets are additionally encrypted with a hardware-backed Android Keystore key using AES-GCM, so a copied database file yields ciphertext, not usable credentials.

Android auto backup

SMS IQ currently allows Android's standard cloud backup for app data, which means your device's OS may include SMS IQ's local database in your encrypted Google Account backup, subject to your own Android backup settings. You can turn this off for the app in your device's system Backup settings if you'd rather your local SMS IQ data never leave the device this way.

11

Retention & deletion

Local data (messages, rules, labels, history) stays on your device until you delete it in-app or uninstall SMS IQ. Deleting the app removes its local database, subject to any Android backup copy as described above. Server-side, we retain only what's needed to enforce quota and entitlements against your anonymous device identifier, plus the transient content of a cloud-AI or purchase-verification request for as long as it takes to process it. To request deletion of server-side records tied to your device identifier, contact us (below); note that we cannot look this up by name or email since none is collected.

12

Children's privacy

SMS IQ is not directed at children and we do not knowingly collect personal information from children under the age applicable in your jurisdiction (13 in the US, 16 in parts of the EEA). If you believe a child has used the app in a way that resulted in data reaching SMS IQ Cloud, contact us and we will address it.

13

Your choices & rights

  • Stay fully local — leave AI set to the on-device engine, and never configure a webhook, to keep all message data on your phone.
  • Access & delete — every category of local data is visible and deletable inside the app itself (messages, rules, webhooks, labels, history).
  • Contacts permission — revocable anytime in Android Settings; the app falls back to phone numbers.
  • Ads — you may see an ad-personalization opt-out at the OS level via your Google account's ad settings.
  • Regional rights — depending on where you live (e.g. GDPR in the EEA/UK, CCPA/CPRA in California), you may have rights to access, correct, or delete data we hold about you server-side, or to object to processing. Contact us to exercise these; because we hold no name/email/account, we can act on requests scoped to your device identifier.
14

International transfers

Our backend runs on Google Cloud/Firebase infrastructure, and SMS IQ Cloud's underlying AI provider may operate its own infrastructure, either of which may process data in a country other than your own. By using SMS IQ Cloud, purchases, or analytics, you understand your data may be processed outside your country of residence.

15

Changes to this policy

We may update this policy as SMS IQ's features change. Material changes will be reflected by updating the "Effective" date at the top of this page. Continued use of the app after an update constitutes acceptance of the revised policy.

16

Contact

Questions, deletion requests, or anything else about this policy: [email protected].