Back to apps SMS Forwarder - Android App

Privacy Policy

Effective Date: September 29, 2026

Trei ("we", "us", "the developer") built SMS Forwarder, an Android app that forwards text messages received on your own phone to destinations you configure: an email address, Telegram, a webhook URL, or another Android phone that you own. This policy explains what data the app processes, who else handles it, how long it is kept and how you can delete it.

The short version: your forwarding rules stay on your phone. When you use Trei's email or Telegram relay, or a paired phone, the message passes through api.trei.dev only so it can be delivered. We do not store or log the text of relayed email or Telegram messages, and paired-phone messages are end-to-end encrypted, so our server sees only ciphertext. We do not sell your data. There is no sign-in: your account is an anonymous device ID.

This policy covers the version on Google Play. A separate direct APK download from trei.dev has one extra behavior, described in the section "Direct APK from trei.dev".

Data the App Uses

  • SMS message content and sender number - read on your device when a message arrives, to decide whether a rule matches and to build the forwarded message.
  • Notification content (optional) - only if you turn on notification access and pick apps. It is treated exactly like an SMS.
  • Contacts (optional) - only to show a contact name instead of a number. Contact data is not uploaded.
  • Destinations you enter - email addresses, Telegram chat links, webhook URLs and headers, your own bot token or SMTP/Gmail app password. Your own bot token, SMTP password and webhook details are used on your phone to send directly and are not sent to Trei.
  • Forwarding rules, settings and history - kept on your device.
  • Anonymous device account - when you use a Trei relay or pairing, the app registers an install ID, a device ID, a hashed device secret, the app version, whether it is the Play or direct build, and a push token used by Firebase Cloud Messaging.
  • Usage counters - the number of relayed forwards per day, used to apply the free daily limit and the Premium fair-use limit.
  • Purchase status - whether you have Premium, managed by RevenueCat using your anonymous device ID. When you start a purchase, or a purchase fails, the app tells Trei (product, plan and error code, with your device ID) so we can fix billing problems.
  • App usage - one "app opened" event a day with a random install ID, used to count active users. The app has no crash-reporting SDK and never includes message content in these events.

SMS Permission and Prominent Disclosure

SMS access disclosure SMS Forwarder asks for the RECEIVE_SMS permission to detect text messages that arrive on this phone and forward the ones that match your rules to the destinations you choose, which can include Trei servers when you use the email or Telegram relay or a paired phone. The Google Play version does not request SEND_SMS or READ_SMS, cannot send text messages, and cannot read your existing SMS inbox or call log. The app explains this and lets you decline before Android shows the permission prompt.

Notification access is optional and separate. It is used only to forward notifications from the apps you select. You can revoke either permission in Android settings at any time; forwarding from that source then stops.

Where Your Data Goes

  • Webhook, your own Telegram bot, your own SMTP or Gmail - the message is sent directly from your phone to the service you configured. It does not pass through Trei.
  • Email via Trei relay - the message is sent to api.trei.dev and handed to our email provider, Resend, which delivers it to the address you verified. We do not store or log the message text.
  • Telegram via the Trei bot - the message is sent to api.trei.dev and delivered by the Telegram Bot API to the chat you linked. We do not store or log the message text. Telegram handles it under its own privacy policy.
  • Another Android phone - the sending phone encrypts the message with a key shared only with your receiving phone before it leaves the device. Our server holds the ciphertext in an inbox, sends a push through Firebase Cloud Messaging to wake the receiver, and deletes the message after delivery or after 7 days at the latest. We cannot read it: pairing checks the receiving phone's key from the QR code (or a safety number you compare on both phones), so a message can only be opened on the phone you paired.

Your mobile carrier and any email, Telegram, Slack or Discord service you choose as a destination handle messages under their own terms. Message content is never used for advertising.

What We Keep and For How Long

  • Email verification codes - valid for 10 minutes, then discarded.
  • Verified email addresses and Telegram links - kept with your device account so relay works, until you remove them or delete your data.
  • Paired-phone inbox - encrypted, deleted after delivery and never kept longer than 7 days.
  • Usage counters - kept for the daily limit and fair-use checks.
  • Device account - kept until you use "Delete my data".

Service Providers

  • Resend - delivers relay email and verification codes.
  • Telegram - delivers messages sent through the Trei bot.
  • Firebase Cloud Messaging (Google) - push notifications for paired phones.
  • Google AdMob - banner ads on the History and Settings screens for free users. AdMob may use an advertising ID and device information under Google's policies, subject to your consent choices. Message content is never shared with ad providers. Premium users are not shown ads and the app makes no ad requests for them.
  • RevenueCat and Google Play Billing - manage Premium subscriptions and free trials. They receive purchase and subscription status, not message content.
  • Google Play - app installation, updates and platform security.

Sensitive Messages

OTP, banking, password and authorization messages are sensitive. OTP messages are blocked from forwarding by default. If you choose to forward them, only send them to an account or phone that you own and control. Anyone who receives your OTPs can reach your bank and accounts. If someone on a call asks you to install an SMS forwarding app, it is a scam.

Data Deletion

In the app, open Settings > Delete my data. This removes your device account and the relay data the server holds for it: verified emails, Telegram links, pairings, inbox and counters, and signs the app out of RevenueCat. Billing events and daily app-opened events contain no message content and are kept for accounting and usage statistics; Google Play keeps your purchase history under its own terms. Rules, settings and history live on your phone and are removed by deleting them in the app, clearing app storage or uninstalling. You can also ask us to delete server data by writing to contact@trei.dev, including your device ID from Settings if you can no longer open the app.

Direct APK from trei.dev

The APK offered for download on trei.dev, and not the Google Play version, also lets you forward a message to another phone number as a normal text message. For that it additionally uses the SEND_SMS permission. Those text messages are sent from your phone through your carrier and do not pass through Trei servers. Everything else in this policy applies to both versions.

Children

SMS Forwarder is not directed to children and is intended for adults aged 18 and over. We do not knowingly collect data from children.

Changes

If we change how data is handled we will update this page and the effective date, and ask again inside the app where a new permission or disclosure is needed.

Contact

For privacy or support questions, email contact@trei.dev or use trei.dev/feedback.