The short version: we operate no servers, and none of your messages ever reach us. Everything the app stores lives on your device. Message content leaves your phone in exactly one case: when you deliberately configure syncing — which is the entire point of the app — and that is covered in detail in section 3.
There is one thing the app sends by itself, and it carries no messages. When TextBridge crashes or hits an internal error, it sends a crash report through Firebase Crashlytics, a Google service. That is a stack trace and some details about the device and the app version — never the content of a message, never a phone number, never your Telegram token. It exists so that a bug which stops your messages syncing can be found and fixed. There is no analytics, no advertising and no tracking of any kind. Section 1 lists exactly what a crash report contains.
Both modes, one policy. TextBridge can run in Simple Mode, which syncs everything, or Advanced Mode, which adds rules, and a retry queue. Advanced Mode does not collect anything extra and does not contact any network of its own — all of it runs on your device, as described in section 4.
Every device is verified. Before anything is sent to a phone number or a Telegram chat, TextBridge sends it a 6-digit code and waits for you to type it back. A device you cannot pick up cannot be added. See section 3.
Intended use. TextBridge is meant for syncing your own messages from your own phone to your own other devices. It is not a monitoring tool, and installing it on another person's phone to read their messages without their knowledge is not a use we support — it is illegal in many countries. While syncing is switched on, the app keeps a permanent notification on screen so that anyone holding the phone can see it is running.
1 What we collect
Crash reports, and nothing else. TextBridge has no account system, no login, no analytics SDK and no advertising SDK. The developer operates no backend server. We cannot see your messages, your devices, your Telegram chats, your rules or how you use the app.
The single exception is crash reporting, handled by Firebase Crashlytics, a Google service. TextBridge runs in the background and copies messages while you are not looking at it, so a crash is easy to miss and expensive when it happens — a bug that stops the app dead is a bug that silently stops your messages arriving. Crash reports are how that gets noticed and fixed.
What a crash report contains:
- The stack trace of the crash or error, and where in the code it happened.
- The app version, and a fixed English description of the failed step — for example "Could not enqueue forward work".
- Device model, manufacturer, Android version, available memory and storage, and whether the device is rooted.
- A random Crashlytics installation identifier, used to tell one crashing install apart from another. It is not linked to you, your phone number or any account, and it is regenerated if you reinstall the app or clear its data.
What a crash report never contains:
- The content of any SMS, in whole or in part.
- Any phone number — yours, a sender's, or a device you sync to.
- Your Telegram bot token or chat ID.
- Your rules, templates, filters or sync history.
- Your name, email, contacts, location or advertising ID.
This is deliberate rather than incidental: the app's internal reporting helper takes a fixed description and an error, and is never given the message it was carrying. Analytics collection is switched off in the Crashlytics configuration, so no usage or behavioural events are gathered alongside the crash. Google processes this data on our behalf as described in the Firebase privacy documentation.
2 What is stored on your device
All of the following is stored locally, inside the app's private storage area, and is removed when you uninstall the app:
- Syncing settings — whether syncing is on, which channels are enabled, your SIM routing choices, and which mode the app is in.
- Your verified devices — the label and phone number of each device you added, and a record that it passed verification.
- Telegram configuration — the bot token and chat ID you entered for each Telegram device.
- Sync history — for each synced message: the sender, the message text, the time it arrived, which SIM received it, and whether each channel succeeded or failed. Kept for as long as you choose — see section 7.
- Rules and templates — the rules you wrote, including any sender names or keywords they match on, and any message templates. Rules only run in Advanced Mode; templates apply in both. Stored separately from everything above, which is why switching modes leaves them intact rather than deleting them.
- The retry queue — if a Telegram send fails on a bad connection and you have the retry queue switched on, the message text is held on the device until it is delivered or the app gives up. This is the one place message content is stored other than your history, and it is emptied as soon as the message gets through.
- Loop-protection fingerprints — a short list of one-way hashes of recently synced text, used to recognise a message the app sent itself and avoid syncing it in circles. These are hashes only; the text itself is not stored, and they expire after ten minutes.
- Verification records — which devices have passed verification, and any code still waiting to be entered. A pending code is held for ten minutes at most and is deleted the moment it is used, expires or is refused too many times. Removing a device forgets that it was ever verified, so adding it back asks for a fresh code. These records never leave the device and are never sent to us — there is no "us" to send them to.
TextBridge does not read your contacts. A device is added by entering its number and confirming the code we text to it, so your address book is never opened and the app does not hold the Contacts permission at all.
3 What leaves your device
Message content leaves your phone in exactly three ways, every one of which you switch on yourself. One more thing leaves it — a verification code — and that is described below too.
SMS syncing
When enabled, each incoming message is re-sent as an ordinary SMS from your SIM to the devices you verified. It travels over your mobile carrier's network like any text you send, and your carrier handles it under their own terms. These messages are charged at your carrier's normal rate.
Telegram syncing
When enabled, the app sends the message to Telegram's servers using the
Bot API, over an encrypted HTTPS connection to
api.telegram.org, using the bot token you supplied. The data
sent consists of the sender, the full message text, the time it was
received, the SIM label on dual-SIM phones, and the chat ID it went to.
Please read this carefully. Incoming SMS often contains sensitive material — one-time passcodes, banking alerts, delivery codes, private conversations. If you enable Telegram syncing, that content is transmitted to and stored by Telegram, and Telegram's privacy policy then governs it. Anyone with access to that chat can read it. Neither TextBridge nor its developer can retrieve or delete messages once Telegram has them.
Device verification
Before a device can receive anything, TextBridge sends it a 6-digit code and waits for you to type it back. That send is the only thing the app transmits to a device you have not yet confirmed, and it contains no message content — just the code and a line explaining what it is for.
To a phone number, the code goes as an ordinary SMS from your own SIM, and your carrier charges for it at the normal rate. To a Telegram chat, it goes through your own bot over the same encrypted connection described above. If a send fails, or you back out, the code is discarded straight away.
The point of the code is that it can only be read at the device itself. It is what stops a number or chat that is not yours from being added, and it is why the app can honestly say it syncs your messages to your own devices rather than to anywhere you type in.
If you use a custom template, it changes how the synced text is worded — the sender, the message, the date, the time and the SIM label are placed however you choose. It does not change where the message goes, and it cannot send anything to a device you have not configured.
With no Telegram chat configured, the app sends no message content over the network at all — in either mode. The only other time it reaches the network to carry your data is to deliver a verification code to a Telegram chat you are adding. Advanced Mode adds no new device and contacts nothing of its own: rules and templates are all evaluated on the device. The one thing it can add is repetition — with the retry queue switched on, a send that failed is attempted again, to the same chat you already configured.
The app does make one other kind of network request, unrelated to your messages: sending a crash report to Firebase Crashlytics, and fetching that service's own configuration when it starts. Those requests happen whether or not you have configured any device, and they never carry message content — see section 1 for exactly what is in them.
4 Rules run on your phone
Advanced Mode lets you write rules that decide which of your messages are synced and where each one goes. It is worth being explicit about what a rule can look at, because "the app understands my messages" is exactly the sort of claim that should make you suspicious.
A rule matches on three things, all of which you choose yourself: the sender, a keyword you type in, and which SIM the message arrived on. That is the whole list. TextBridge does not work out what a message is — there is no category for bank alerts, payments, adverts or verification codes, and no rule can single one out. The app ships no vocabulary of its own to match against.
Whole messages are copied, never parsed. A one-time code travels inside the message body like any other text — the app never pulls it out, stores it separately or displays it on its own.
Everything here happens on the device. The rules you write are stored and evaluated locally, no message is uploaded, no third-party service is consulted, and no machine-learning model is downloaded or run. Templates change how a synced message is worded before it is sent to the devices you chose — they do not change where it goes. Statistics are counted from the history already on your phone. Turning Advanced Mode on adds no network activity of any kind. You can check how any message would be handled, without sending anything, using the tester built into the app.
5 Permissions and why
| Permission | Why it is needed |
|---|---|
| Receive SMS | To detect a message the moment it arrives, and to read its sender and body from the broadcast Android delivers. This is the core function of the app. TextBridge does not hold Read SMS, so it cannot open your stored message history — only messages arriving while it runs. |
| Send SMS | To send the synced copy to the phone numbers you verified, and to send the one-time code that verifies a number in the first place. Telegram devices do not use this permission. |
| Phone (read phone state) | Optional. Identifies which SIM a message arrived on and lets you send from a specific SIM. Declining it means SIM features are unavailable; syncing still works. |
| Internet / network state | Used to reach Telegram when Telegram syncing is enabled, and to send crash reports. With no Telegram chat configured, no message content is sent over it. |
| Notifications | Used to show a permanent notice on the device for as long as syncing is switched on, so it is always visible that the app is running. Declining it does not stop syncing, but it does hide that notice. |
| Run at startup | Re-arms syncing after the phone restarts, so messages are not missed. |
| Wake lock / run background task | Requested by the Android background-work library the app uses. It keeps the phone awake for the second or two it takes to send a copy, so a message is not lost because the screen went off mid-send. |
6 What we never do
- We do not sell, rent or share your personal data with anyone.
- We do not run advertising, and there are no ad or tracking SDKs in the app.
- We do not collect analytics or usage statistics. Nothing records which screens you open, which features you use or how often you open the app.
- We do not put message content, phone numbers or your Telegram credentials into a crash report. Crash reports carry a stack trace and device details, and are listed in full in section 1.
- We do not use the advertising ID, and we do not build a profile of you. The only identifier involved is a random Crashlytics install ID that resets when you reinstall.
- We do not upload your messages or settings to any server we control — we operate none.
- We do not read or transmit messages to any device other than the ones you configure yourself. We do not add, suggest or default to a device of our own — there is no TextBridge server to send anything to.
- We do not send your messages anywhere to be classified, scored or analysed — nothing in the app works out what a message is.
- We do not send anything to a device you have not verified — number or chat. An unverified device receives nothing at all, not even once.
7 Retention and deletion
You choose how long sync history is kept. The window is set in Settings and offers 7 days, 30 days, 3 months, 6 months and 1 year, with 1 year as the default. Anything older is deleted from the device automatically — when a new message arrives, and again whenever you open the history, so a quiet month still clears out on schedule. There is no cap on how many messages are held inside the window; what bounds the history is its age, not its size.
The same list offers Never delete. Choosing it means exactly what it says: nothing is removed on a schedule, and the message bodies stay on the device until you clear them yourself or uninstall the app. It is worth choosing deliberately rather than by default — incoming SMS often carries one-time codes and banking alerts, and a history that is never pruned keeps all of it. Nothing about that choice sends anything anywhere; it only governs how long the copy on your own phone survives.
You can also erase the entire history at any time from Message History, and remove devices and Telegram chats whenever you like from their own screens. Deleting a rule or a template removes it immediately.
Queued Telegram messages are removed from the retry queue once they are delivered, and you can clear the queue by hand at any point. Loop-protection fingerprints expire on their own after ten minutes. A pending verification code expires after ten minutes and is deleted as soon as it is used; removing a device deletes the record that it was verified.
Crash reports are held by Google for 90 days under Firebase Crashlytics' own retention schedule, then deleted. They contain no message content and nothing that identifies you personally, so there is nothing in them to look up or hand back on request.
Uninstalling TextBridge permanently deletes all settings, credentials and history from your device. Because we hold none of your messages or settings, there is no separate deletion request to make of us.
Note that copies already delivered to your other devices, or already posted to a Telegram chat, are outside the app's control and are not affected by clearing history, by the retention window, or by uninstalling. Deleting them is a matter for the device or the chat that received them. The same is true of a backup file you have already written — see section 8.
8 Backup and restore
TextBridge can write your setup to a single file so you can carry it to a new phone. It is entirely manual: nothing is backed up unless you open Settings → Backup & Restore and ask for it, and there is no automatic, scheduled or cloud backup of any kind.
What the file contains. Your syncing preferences and channel switches, your saved devices and their labels, your Telegram bot tokens and chat IDs, your rules and templates, your SIM routing choice, your history retention setting and your theme.
What it deliberately leaves out. Your message history. The retry queue. The loop-protection fingerprints. The master switch — a restored setup arrives switched off, so you can read what came back before a single message moves. The SIM filter, because SIM slots describe one specific pair of trays and would silently sync nothing on a different handset. And your verified badges: proof that a device belongs to you is evidence about a phone, and a file is not that phone, so every restored device asks for a fresh code before it receives anything.
It is encrypted, and the password is yours alone. The file is sealed with AES-256-GCM under a key derived from a password you choose, using PBKDF2-HMAC-SHA256 at 210,000 iterations with a random salt. A backup carries Telegram bot tokens, so a password is required rather than offered. We do not know it, it is not stored anywhere, and it is not recoverable — lose the password and the file cannot be opened, by you or by anyone else.
Where it goes is your choice, and only yours. The file is written through Android's own document picker, to whatever location you select — local storage, an SD card, or a cloud drive you have connected. TextBridge has no server, uploads nothing, and never receives a copy. Once the file exists it is an ordinary file outside the app's control: if you place it in a shared folder or send it to someone, its safety rests on the password and on wherever you put it. Restoring reverses the process — you pick a file, type the password, and see a summary of what it holds before anything is written.
9 Security
App data is held in Android's private per-app storage, which other apps on the device cannot read. Requests to Telegram use HTTPS, and so do crash reports sent to Firebase Crashlytics.
Android's automatic backup is switched off for this app, so your settings, your Telegram bot token and your sync history are never copied into your Google Drive or moved to a new phone behind your back. The only way any of it leaves this device is the backup file described in section 8, which you create deliberately and protect with your own password.
Your Telegram bot token is stored on the device so that syncing can work without the app being open. Treat it as a credential: anyone with physical, unlocked access to your phone, or with root access to it, could obtain it. If you believe a token has been exposed, revoke it through @BotFather in Telegram and enter a new one.
10 Children
TextBridge is not directed at children and is not intended for use by anyone under 13. We do not knowingly collect information from children — and in fact collect nothing from anyone that identifies them, only the crash reports described in section 1.
11 Changes to this policy
If this policy changes, the updated version will be published on this page with a new date at the top. Material changes affecting how message data is handled will also be noted in the app's release notes.
12 Contact
Questions about this policy or about how the app handles data: [email protected]