Privacy Policy
Last updated and effective: .
This policy covers Multi Messages for Android and iOS, its optional keyboards, and this website. For privacy questions or requests, contact multimessagesapp@gmail.com.
Saved messages and keyboard reply generation are handled on your device. The app also uses third-party services that can transmit technical data for advertising, diagnostics, and service delivery. Local processing of message content does not mean that the entire app collects no data. The details below distinguish these activities.
1. Messages and other local content
The app stores your saved messages, recipient names and phone numbers that you enter or select, optional photos and birthdays, reminder schedules, and preferences locally. These support organizing messages, preparing replies, and scheduling local notifications. You do not need a Multi Messages account, and we do not operate a server that stores or synchronizes this content.
Keyboard drafts, context that you provide, permitted Android notification context, and generated suggestions are processed locally. We do not send that content to AdMob, or a remote AI service. When you choose to share, export, or send content, it is provided to the app, recipient, or device you select; their handling of it is governed by their own policies. QR exports can contain selected messages and contact details, including phone numbers if you enable that option.
Optional voice dictation
When you tap the microphone in a chat, you can dictate text instead of typing. Dictation requires microphone permission and, on iOS, speech-recognition permission. You can decline these permissions and continue typing, stop dictation with the microphone control, or revoke access in your device settings.
Dictation uses the operating system's speech-recognition service: Apple on iOS and the speech provider configured on Android, which may be Google or another provider. Depending on the device, language, provider, and settings, audio and recognition data may be sent to that provider's servers to produce the transcription. This feature does not require recognition to stay on the device, so dictation should not be assumed to work entirely offline. The provider's privacy policy and settings govern its processing and retention; see Apple's Privacy Policy and, when Google is the provider, Google's Privacy Policy.
Multi Messages does not save dictation audio files or operate a server that receives the audio. It receives the recognized text and adds it to your draft. Text that you keep as a message follows the local storage and deletion practices described in this policy; text that you choose to send or share goes to the destination you select. The app does not provide dictation audio or transcripts to its advertising SDK. Voice recognition is separate from the local keyboard reply generation described below.
2. Third-party SDKs and technical data
The following Google services are distinct from local message storage. Technical identifiers can distinguish an app installation or device and should not be assumed to be anonymous.
- Usage analytics: the current app version does not include usage analytics SDKs. Earlier versions could include them; removing the SDK does not delete data already received by a provider.
- Google AdMob / Google Mobile Ads: when ads are requested, Google can receive IP addresses (and infer approximate location), available device/advertising identifiers, ad impressions and interactions, and diagnostic/performance data, including crash information. These support advertising, measurement, and fraud prevention and may be shared with advertising providers. Available identifiers depend on the operating system and privacy settings. See Google's disclosures for Android and iOS.
- ML Kit / Gemini Nano on Android: reply generation runs on-device. ML Kit nevertheless sends Google device and app information, hardware capabilities, identifiers (including installation identifiers and, for GenAI, user/device identifiers), latency, API/feature configuration, input/output sizes, download or initialization events, and error codes for diagnostics and usage analytics. This telemetry is separate from message text. See ML Kit's data disclosure and the on-device Prompt API.
Google documents HTTPS/TLS protection for these SDK transmissions. Retention and further processing follow the relevant Google service terms and configuration; the local context expiration described below does not delete data already received by a provider. See Google's Privacy Policy.
3. Model downloads and local AI
Android offers optional models downloaded from the selected provider, including Hugging Face, and Gemini Nano managed by Android/AICore. Downloads initiated in the app require confirmation; the catalog download flow supports a Wi-Fi-only preference. Fetching a catalog or model requires internet access and exposes your IP address, requested model/file, and ordinary request metadata to the download host. It does not upload your conversation context. After a compatible model is installed, reply generation runs locally.
If you supply a Hugging Face token for a restricted model, it is stored using secure device storage and sent to the provider to authorize access. You can remove the saved token in the model settings. Provider logs and account data follow the Hugging Face Privacy Policy. Downloaded catalog models can be deleted in the app; system-managed models and their updates are controlled by Android or iOS.
On supported iPhones, the keyboard uses Apple's on-device Foundation Models when available. Basic offline suggestions remain available when a compatible model is unavailable. System model availability and downloads depend on the device and operating system.
4. Optional Android and iOS keyboards
You enable the Multi Messages keyboard in system settings. It uses the limited text around the active input field that the operating system makes available, your reply preferences, and optional context you provide. It cannot read the full conversation displayed in another app. The Android keyboard suppresses suggestions in fields recognized as sensitive, such as password fields.
On iOS, choosing a suggestion inserts text; you send it using the receiving app. Android also offers an explicit send action and, where available, direct replies through a messaging notification. Messages sent this way are transmitted by the receiving messaging app.
5. iOS Allow Full Access
Full Access is optional. It lets the keyboard share settings, user-supplied context, and cached suggestions with the main app through an App Group on the same device. The keyboard remains usable without it, with shared features limited. Although iOS warns that Full Access can permit network access, our iOS keyboard extension contains no networking, advertising, or analytics SDK and does not upload typed text. The main app's SDK practices are described separately above.
Revoke it in Settings > General > Keyboard > Keyboards > Multi Messages > Allow Full Access. Turning it off restricts shared access; use the app's context and cache deletion controls to remove previously saved content.
6. Optional Android notification access and replies
Notification access is disabled by default and is separate from permission to show reminders. You must enable the feature in the app and grant notification access in Android settings. The app then processes messaging notifications from the apps you enable, including notifications already visible when the listener connects. This can include message text, sender or conversation labels, source app, and timestamps. The app keeps a limited local context to prepare suggestions, including in the background; it does not upload notification content.
Notification context can be incomplete and does not identify the chat currently open on screen. Direct replies use the messaging app's notification reply action. Automatic replies are off by default; if you enable them, replies may be sent without an individual tap according to your selected conversations, schedule, and limits. Sent replies are also added to local context. Conversation hashes and send times are stored locally to enforce those limits.
You can disable capture and automatic replies in the app, change enabled messaging apps, and revoke notification access in Android settings. Revocation stops future access; delete existing context and cached suggestions separately as described below.
7. Other permissions
- Microphone and speech recognition: transcribe the voice input you choose to dictate in chats, using the system speech service as explained above.
- Notifications: show local reminders that you schedule.
- Camera and photos/storage: take or select an optional contact image; a QR reader may request camera access when you choose to scan a transfer.
- Contact selection: the system picker supplies the contact details you choose for a local recipient. We do not upload your address book or modify system contacts.
- Network and background operation: support ads, SDK services, model downloads, and local work such as reminders and context cleanup.
The current app does not read your SMS inbox or call history and does not use a direct SMS-sending permission. Opening an SMS, phone, or messaging app passes the details you select to that app. You can manage available permissions in your device settings.
8. Context retention, protection, and deletion
- Android: saved manual and notification context and cached suggestions are encrypted at rest with AES-256-GCM using non-exportable keys in Android Keystore. The notification store keeps up to 20 recent conversations and up to eight messages per conversation; the suggestion cache keeps up to eight result sets.
- iOS: shared context and suggestions are stored in the local App Group using UserDefaults and the operating system's storage protections. They do not have the additional application-level AES encryption used for Android keyboard context.
- Expiration: the default context retention and suggestion-cache lifetime are 15 minutes. Context controls offer 5 minutes, 15 minutes, 1 hour, or retention until manual clearing. New incoming Android notifications renew that conversation's retention period. Expired records are no longer used and are removed when read; Android also schedules periodic context cleanup, whose timing is controlled by the system.
- Manual deletion: use the keyboard's context screens to clear manual context or individual/all Android notification contexts, and the keyboard settings to clear cached suggestions. On Android, clear the suggestion cache as well as the source context to remove both. Stop notification capture first if you do not want new notifications to create new context.
Saved messages, recipients, photos, reminders, and preferences remain until you delete them or remove the app's local data. These ordinary app records do not use the Android keyboard context's additional encryption. Deleting the app or clearing its storage removes its local app data, subject to operating-system behavior; backups, exported copies, secure-storage credentials, and content already shared with another app may need separate deletion. Device/cloud backups and transfers follow your system settings and provider policies. We cannot remotely erase copies held on your device or by recipients.
9. Advertising choices and privacy requests
The current app uses Google's User Messaging Platform to request advertising choices where required and to determine whether ads may be requested. Where available, use the app's advertising privacy options to revisit your choice. The current iOS configuration requests non-personalized ads and does not request App Tracking Transparency permission. Non-personalized ads still involve technical data processing. Accepting this policy does not replace a separate advertising consent request.
You can also use Android advertising-ID controls or iOS privacy settings. Disabling a keyboard, denying notification access, or clearing local context does not disable the main app's SDKs or erase data previously transmitted. Older app versions may have different controls.
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal data, withdraw consent, or complain to a data protection authority. Contact multimessagesapp@gmail.com to make a request. We will explain what we can identify and act on and how to contact a provider where needed. You do not need to send us your messages or keyboard context to request help.
10. Website, support, and international processing
This website uses Firebase Hosting and externally hosted assets. Their providers receive connection data such as IP addresses to deliver content and protect their services. Firebase states that Hosting retains IP data for a few months. If you email us, we receive your email address and whatever information you include, and use it to respond and manage your request. We retain support correspondence as needed to resolve it and meet applicable obligations; you can request its deletion.
Google, model hosts, and other services you choose may process data in countries other than yours under their own privacy terms. Follow the provider links above for their retention, safeguards, and available controls. No storage or transmission method can guarantee absolute security.
11. Children and policy changes
Multi Messages is not directed to children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and address it. We will publish policy changes on this page and update the effective date. Both the English and Spanish versions describe the same practices.