SMS Permission & Synchronization Scope
SMX uses the restricted Android permissions READ_SMS and RECEIVE_SMS only to provide SMS sync: it imports the latest 100 received and sent SMS messages on your Android device, then syncs new incoming messages to your personal SMX web dashboard. SMX also asks for READ_PHONE_NUMBERS to identify the device SIM line for each message; this optional permission does not block SMS sync if you decline it. SMX does not make or receive calls and does not read your call log.
Collected Data Properties
To provide real-time message syncing, we collect and display SMS text, timestamps, sender or recipient numbers, and the relevant contact name when it is available on your device. We also collect your SIM line number when you grant the optional phone-number permission. Account data includes the verified sign-in identifier, display name, paired-device details, and sharing relationships needed to operate your dashboard.
SMX is designed for current SMS access rather than long-term archiving. The Android app imports only the latest 100 received and sent messages during setup, and the service retains the most recent 100 synced messages per connected device. Older synced messages are automatically removed as newer messages arrive.
Sharing and Service Providers
SMX does not sell, rent, or use SMS content for advertising. Your synced inbox is visible to you and to people you explicitly authorize to view a particular device; those viewers can read only the device you share with them. We use infrastructure providers to host and transmit the service, but they do not receive SMS data for their own purposes. SMX does not include advertising SDKs or third-party behavioral tracking.
Security and Local Storage
SMX sends data between the Android app, web dashboard, and service over encrypted HTTPS connections. On the Android device, the optional offline inbox cache is encrypted with AES-256-GCM. Its encryption key is held in platform-protected secure storage; if secure storage is unavailable, SMX does not create a plaintext cache. Signing out removes the local cache and its key.
Instant Account & Data Wiping
You can permanently delete your account and wipe all synced device profiles, messages, account details, and sharing relationships from SMX. You can also submit an email deletion request. Our Delete Account page explains both options and the limited backup and security-log retention that may apply after deletion.