ANDSENT
ANDSENT

Your conversations are yours.

Privacy notice — 20 September 2026. ONICO LTD operates ANDSENT. Contact: [email protected].

Your account and contacts

Google Firebase Authentication processes your phone number for verification and abuse prevention. Your display name and optional profile photo identify you to people you message. Profile photos are stored on our messaging service as profile information and are not end-to-end encrypted. People who know your number can find your ANDSENT account.

Contact sync is optional and needs your permission. Only allowed contact phone numbers are sent over HTTPS to our service and checked with Firebase. We do not retain them as an address book. Names, contact photos and notes remain on your device. Allowed contacts are cached locally and matched again daily when iOS permits background refresh, or when you next open the app. Your default messaging language is stored with your account and shared with people who find you through contact matching, so their iPhone can prepare local translation models. Access can be limited or revoked in iPhone Settings.

Messages and calls

Messages, voice notes and attachments are end-to-end encrypted. Our London Google Cloud server stores encrypted history and processes account IDs, conversation membership, conversation names, timestamps and connection data to deliver the service. Names, membership and delivery metadata are not end-to-end encrypted.

Voice, video and screen-sharing media use end-to-end encryption. Screen sharing starts only after you confirm the iPhone broadcast prompt; other participants can see what you share. Calls are not recorded. Call history is stored on your iPhone. Apple supplies local translation and speech-recognition models; plaintext messages and captions are not sent to a cloud translation service. When you choose Translate text in image, Apple Vision reads text from the decrypted image on your iPhone and the text is translated locally.

Reports and retention

If you report a message, the selected text, message ID, your account ID and your reason are sent to support for review. Other messages are not disclosed. Reports are retained as needed to investigate abuse and meet legal obligations; contact support to request access or deletion.

Encrypted history is retained to deliver conversations unless removed by the service. A disappearing-message setting hides older messages in the chat and schedules server-history cleanup. Saved copies, downloaded media and caches may remain. Encrypted key backups help restore your message history. A recovery key is retained in this iPhone’s protected keychain, including when you sign out, to support signing back in and normal reinstalls on the same phone. Keep your recovery key from Settings for a new or erased device. Recovery cannot recreate encryption keys that have already been lost. Signing out removes the local messaging database; account deletion removes authentication, this recovery key and deactivates messaging. Copies held by recipients can remain.

Your choices

Delete your account in Settings, manage blocked people, limit contacts access, and disable microphone/camera/speech permissions at any time. For access, correction or deletion requests, email support. Processing is used to provide the service, prevent abuse and meet legal requirements. You may also complain to the UK Information Commissioner’s Office.

No advertising or cross-app tracking SDKs are used. Apple and Google process platform/authentication information under their own policies and may process data outside the UK. This notice will be updated when functionality changes.

Notifications

If you enable notifications, your message-notification token is processed by Google Firebase and Apple, and your call-notification token by Apple, to deliver alerts. Push payloads contain conversation/event identifiers, not message text or call encryption keys. Your iPhone retrieves and decrypts messages locally to show previews, subject to your preview settings. CallKit presents incoming calls and can add them to iPhone Recents. We retain notification tokens and your blocked-user list for call delivery for up to 90 days after their last refresh, removing the device registration when you sign out or delete your account.