Privacy policy
Effective 12 September 2026. This policy covers the Resender Android app and this website, resender.me.
Resender forwards the SMS arriving on one Android phone to a place you chose. It has no server, so there is no copy of your messages anywhere except on your phone and at the destination you named. This page says exactly what the app handles, what leaves the phone, and what we never see.
Who we are
Resender is made and published by Anton Kriukov, Zirbelstr. 53d, 86154 Augsburg, Germany. You can write to hello@resender.me; a person reads it.
Where data-protection law — the GDPR and laws like it — asks who is responsible for the app, the answer is the person named above. In practice there is nothing for that person to hold: the app sends us nothing, we run no service that receives your messages, and we have no account, no profile and no copy of anything your phone handled.
What the app does
Resender runs on the Android phone that holds the SIM card. When an SMS arrives, the app compares its sender against the rules you wrote in the app. If a rule matches, the app delivers that message to the one recipient the rule names — an email address, sent through the mail account you entered, or an HTTP webhook address you typed. If no rule matches, nothing is sent anywhere.
Everything is set up on the phone itself. There is no sign-up, no sign-in and no account, because there is nothing to sign in to.
What the app handles, and where it stays
All of the following lives in the app's own storage on your phone, and nowhere else:
- Incoming SMS. Read as they arrive, in order to be matched against your rules. Only the messages arriving on the phone the app is installed on — it cannot see any other phone's messages.
- Messages that matched a rule. Sender, text, time of arrival and, on a two-SIM phone, which SIM it came in on. Kept so the app can retry a failed delivery and show you what happened.
- Messages that matched no rule. The sender and the time, and nothing else — the app's storage has no field for the text of an unmatched message, so that text is never written down. This list holds the newest 100 entries.
- Delivery records. For each message and recipient: the status, how many attempts have been made, when the next one is due, and the last error the destination returned. The text of the message is stripped out of that error before it is stored.
- Your rules and recipients. Sender patterns, rule names, the email address or webhook URL each rule delivers to, and any webhook headers you added.
- Your mail account settings. Server, port, encryption mode, user name and From address — plus the password, encrypted (see Security).
- App preferences. The language you picked, the view you prefer, and whether the daily status message is switched on.
- Your purchase status. One flag saying whether Pro is unlocked on this install, and which store said so.
None of it is sent to us. We have no means of reading it, now or later.
What leaves your phone
Only what you configured, and only to the address you configured:
- Forwarded messages, to the recipient named on the rule that matched.
- The app's own notices, to those same recipients: a test message when you press test, a notice when deliveries have been failing and another when they recover, and — only if you switch it on — one line a day saying the app is running on your phone model and how many messages it forwarded. That daily line carries no senders and no message text.
- The network connection each delivery needs: to your mail server, or to the webhook address you typed.
The app contacts no server of ours, because there is not one.
The diagnostics file
The app can write a plain-text diagnostics file and hand it to Android's share sheet, so you can send it to someone helping you. Nothing is uploaded and nothing is sent automatically: the file goes where you send it and nowhere else.
The standard export contains senders, delivery statuses, attempt counts, error texts and the app's own recent log lines. It contains no message text, no passwords, no webhook header values, and a webhook address only as its scheme and host — never the rest of the address, which is often where a secret sits. A second, separate button produces an export with message text, and warns you before it does. Each export replaces the previous one.
Permissions, and what each is for
- Receive SMS. The app's whole function: it is how the app learns that a message arrived and what it says. Used for matching and forwarding, and for nothing else.
- Internet. To deliver to your mail server or your webhook address.
- Run at startup. So that after the phone restarts, anything still waiting in the queue is delivered.
- Phone state. Used for exactly one thing: reading the carrier names of the SIM cards, so a rule can say “SIM 2 — your carrier’s name” instead of an internal number. The app asks for it only on a phone with two SIM slots, and only when you first open the SIM section of a rule. Refuse it and you lose the ability to match on a specific SIM; nothing else changes. No phone number, no device identifier and no subscriber identity is read anywhere in the app.
- Foreground service. On older Android versions, the system's own work scheduler briefly uses one to run a delivery. When a version of the app shows a notification while it is working, that notification exists to tell you the app is running — it collects nothing.
The app asks for no access to contacts, location, files, camera, microphone or your call history.
Third parties
The third parties in this product are the ones you choose, when you choose them.
- Your email provider. When a rule delivers by email, the message travels through the mail server of the account you entered — your own server, or a provider such as Gmail, Outlook or any other. That provider handles the message under its own privacy policy, exactly as it does every other message you send.
- Your webhook endpoint. When a rule delivers to a webhook, the message goes to the address you typed, and what happens there is governed by whoever runs it — usually you.
- Telegram, when you use a Telegram channel. A message delivered to a Telegram bot passes through Telegram's servers under Telegram's own privacy policy.
- Google or Microsoft, when you sign in to a mail account instead of typing a password. The sign-in happens directly between your phone and Google or Microsoft; the resulting token is stored on your device only and is never sent to us, because we have nowhere to send it. Resender's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The only Google permission used is the one that sends mail on your behalf; Resender does not read your mailbox.
- Mozilla's Thunderbird autoconfiguration service, when the app offers to fill in your mail server settings. Only the domain part of the address — what comes after the “@” — is sent, in order to ask which settings that provider uses. Your full address is not sent, your password is not sent, and no message is ever sent there.
- The store you bought Pro from. A purchase is handled entirely by Google Play or RuStore under their own privacy policies. The app receives back only whether this installation is entitled to Pro. We never see your name, your email address or your payment details.
What we do not do
- No server of ours ever sees your messages, because there is no backend and there will not be one.
- No accounts, no registration, no profile.
- No analytics, no telemetry, no crash reporting, no advertising identifier in the app.
- No advertising, in any tier.
- No selling, renting or sharing of your data with anyone. We hold nothing that could be sold.
- No reading of your messages for the app's own purposes: no auto-fill, no scanning, no content-based features. Rules match on the sender, never on what the message says.
- No cloud backup and no sync between devices. That is the price of everything above, and it is deliberate: reset the phone and you set the app up again.
About this website: the landing pages count visits with GoatCounter — no cookies, no personal data, no cross-site tracking. This page carries no script at all. The site has no forms and no comment box, and asks you for nothing.
How long things are kept
- Messages that matched a rule stay in the app's log, with their text, until you clear the app's data or uninstall it. The app does not delete them on a schedule.
- Senders of unmatched messages: only the newest 100 are kept; each new one drops the oldest.
- Rules, recipients, mail settings and credentials stay until you change or delete them in the app.
- A diagnostics file sits in the app's cache until the next export replaces it.
- Uninstalling the app removes all of it. So does Android's “Clear data” for the app, if you want to keep the app but start over.
- Copies that already left — the forwarded message sitting in your mailbox, your chat or your own system — are yours, at the destination you chose. We cannot reach them, and neither can the app.
Security
- Credentials are encrypted at rest. Your mail password and any webhook credential are encrypted with a key generated and held by the Android Keystore, which keeps it in the phone's secure hardware where the phone has it and never hands the key out — not to the app, and not to anything else.
- Email is encrypted in transit. The app requires TLS, and checks that the server's certificate really belongs to the server name you typed. It refuses to fall back to an unencrypted connection, even if the server offers one — a failed send that you can see is better than a silent one that anyone on the network could read.
- Webhooks are encrypted when your address says so. An
https://address is encrypted end to end. Anhttp://address is allowed, because self-hosted endpoints on a home or office network often have no certificate — but the message then travels unencrypted, the app warns you next to the field, andhttps://is the right choice wherever you have it. - No claim beyond that. We hold no security certification and claim none. A phone in someone else's hands is outside what any app can protect: lock the phone that runs Resender.
Children
Resender is not directed at children and is not intended for anyone under 16. It has no content for children, and it collects nothing about who is using it — we could not tell a child from anyone else, because we receive nothing at all.
Your rights
Data-protection law gives you the right to see the personal data held about you, to correct it, to erase it and to take it elsewhere. With Resender you exercise all of them on the device, because the device is the only place the data is:
- See it: the app's screens show your rules, your settings and the delivery log; the diagnostics export writes them into a file you can keep.
- Correct or delete part of it: edit or delete a rule or a recipient in the app.
- Erase all of it: Android Settings → Apps → Resender → Storage → Clear data, or uninstall the app.
We cannot do any of this for you, and there is no request you could send us that would change anything: we hold no copy to show, correct or delete. Questions about this policy go to hello@resender.me. If you are in the EU, the EEA or the UK and think something here is wrong, you can also complain to your national data-protection authority.
Changes to this policy
If the app changes what it does with your data, this page changes with it and the effective date at the top moves. There is no account and no mailing list, so there is no way for us to notify you — the current version is always the one at resender.me/privacy.