Skip to content

Privacy Policy

Last Updated 2026.09.16

Zerogic Inc. provides Android applications, the SMS Forwarder web app, and related services to users.

This page is used to inform visitors regarding my policies with the collection, use, and disclosure of Personal Information if anyone decided to use my Service.

If you choose to use my Service, then you agree to the collection and use of information in relation to this policy. The Personal Information that I collect is used for providing and improving the Service. I will not use or share your information with anyone except as described in this Privacy Policy.

The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, which is accessible at our apps unless otherwise defined in this Privacy Policy.

 

Information Collection and Use

[Common] Account Management and Data Synchronization
We process the following information to synchronize subscription status and app data across devices via Google Login.
- Purpose of use: User identification, synchronization of premium subscription status, backup and restoration of app settings and data
- Collected items: Google account information (email address, name, profile picture URL), Firebase Authentication UID
- Retention and usage period: Until account deletion or service termination
- Processing entrusted to: Firebase Authentication (Google LLC)

[SMS Forwarder Android and Web Apps] Diagnostic Records and Contact Us
We record diagnostic information on your device to support service operation and troubleshooting. Local diagnostic records intended for support inquiries are not automatically sent to us; we receive them when you choose to submit them through Contact Us. Separate error-reporting services used by the Android app are described under Log Data and Service Providers.
- Purpose: Responding to inquiries and investigating errors
- Common information submitted: Reply email address, inquiry text and attachments you provide, app version, and diagnostic records
- Additional Android app information: Device model, operating system version, carrier, app settings and permissions, and account, subscription, purchase and other service information attached to the inquiry
- Additional web app information: Signed-in email address and Firebase UID, and diagnostic events such as processing times, stages, success or failure, and error codes. Automatically attached web diagnostic records exclude message contents, phone numbers, authentication tokens and private encryption keys. Inquiry text or attachments you provide may contain personal information.
- Retention: Uploaded log files are deleted after 30 days from upload. Inquiry and reply emails, including account identifiers and inquiry contents within them, are deleted after 30 days from each email's receipt or sending date. Information that must be retained by law is stored separately for the legally required period.
- Processing: Logs are uploaded to Firebase Storage (Google LLC); inquiry contents and log links are sent to support staff by email through our inquiry processing system.

[Common] Use of Rewarded Ads
We process the following information to provide the rewarded ad feature in the SMS Forwarder and Capture Note apps.
- Purpose of use: To provide and manage rewards (premium feature usage) based on ad viewing
- Collected items: Unique user identifier (UID) generated through Firebase Authentication, email address, ad viewing time, reward issuance and expiration time, IP address
- Retention and usage period: 90 days after the last login
- Related third-party service providers: AdMob, AppLovin, Pangle, Unity Ads, Firebase
- Processing entrusted to: Firebase Authentication (Google LLC)

[Common] Subscription and In-App Purchase Management
We use RevenueCat to manage subscriptions and in-app purchases in the SMS Forwarder and Capture Note apps. The following information is processed:
- Purpose of use: Subscription status verification, premium feature provisioning, purchase history management, and customer support
- Collected items: App User ID, purchase receipts and transaction history, subscription status (active, expired, renewal, etc.), product identifiers, purchase date and time, device platform information, IP address (for country/currency determination)
- Retention and usage period: Until subscription cancellation and refund completion, then retained as required by applicable laws
- Processing entrusted to: RevenueCat, Inc.

[SMS Forwarder Android App]
Mandatory : No
Optional : Contact List, Read SMS, Send SMS, Read Phone Number, Google account

[Push Service]
Collected items : Email address, Firebase authentication information (UID, authentication token, FCM token)
Collection method : Collected through Firebase Authentication when creating an account and logging in within the app
Purpose of use : User verification and account management for push service usage, account linkage and service usage record management, prevention of fraudulent use, and security enhancement
Retention period : Immediately deleted upon account deletion
Processing entrusted to : Firebase Authentication (Google LLC)

[App Data Backup]
Collected Items: App usage settings (user-defined options), app activity records, backup data files
Collection Method: When performing a backup after signing in with a Google account within the app
Purpose of Use: Data restoration and maintenance of user environment when reinstalling the app or changing devices
Retention Period: Until the user deletes the data from Google Drive
Processing entrusted to : Google Drive (Google LLC)

Contact List It is required to verify the contact name registered in the address book based on the phone number.
(Message Template, display address book name, Email Subject)
It is required to read your Google email information.
Read SMS It is required to receive and read SMS.
Send SMS  It is required to send SMS.
Read Phone Number It is required to read network information to send SMS or read dual SIM information.
Google account It is required to save app data to your Google Drive.
(Only reads or writes to backup data.)
It is required to create a push service account.

Optional Information : When the push service is activated, “Your Google email address” is stored on the Google firebase server.
Push messages are processed in encrypted form through Firebase servers for delivery. We do not provide a server message archive for restoring conversation history. Encrypted MMS images are stored temporarily and deleted when downloads by the recipient devices are confirmed complete. Files with incomplete downloads become eligible for scheduled deletion 10 days after upload.

Limited Use Policy
Scopes 1 https://www.googleapis.com/auth/drive.appdata
Scopes 1 Info See, create, and delete its own configuration data in your Google Drive
Purpose It needs write access in order to create backup files so that my app can back up its settings data.
It needs read access in order to read backup files so that my app can restore settings data.
A narrower scope would not be sufficient because the backup file must be readable and writable.
Scopes 2 https://www.googleapis.com/auth/gmail.send
Scopes 2 Info Send email on your behalf
Purpose The app uses it to send messages to Gmail.
Policy (App’s) use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

SMS Forwarder Web App (Push Service)

This section applies to the web app at smsfwd.app, including when installed on a home screen. You sign in with a Push Service account previously created in the Android app. The web app does not create new accounts.

Sign-in and notification registration
We process your email address, Firebase UID and authentication information, account Pincode, notification token, Firebase installation identifiers, public encryption key, web device classification and service activity timestamps for account verification, recipient device registration and management, message delivery and security. These are processed when you sign in with Google or register for notifications. Account information is used until account deletion or service termination; recipient device registration information is used until deregistration or account deletion. Information needed to maintain your sign-in and private message decryption keys is stored in the browser.

Conversations and images stored on your device
Received messages, sender details and phone numbers contained in conversations, downloaded images and reply results are stored in that browser's local storage. Signing out does not delete conversations. You can remove them using the web app's message, conversation or account-history deletion controls, or by clearing site data in the browser. When you switch accounts, only the signed-in account's conversations are shown. Deleting the server account does not remotely erase browser data on all devices or exported backup files.

Message delivery and notifications
Messages and attachments use the Push Service delivery and temporary storage described above. Remote Reply requests are forwarded to a connected Android device to send SMS. If you allow notifications, they are displayed through browser and operating-system push services. You can manage their visibility, including on the lock screen, in your device settings.

File backup and restore
The web app creates a backup file containing conversations and images already downloaded to the device. You choose its destination or recipient through sharing or downloading. Backups are not uploaded to our servers or automatically saved to Google Drive. If you choose a third-party service such as iCloud, that service's policies apply. Backup files are not themselves encrypted and should be stored securely. You manage and delete exported or shared copies yourself. Restore reads a web app backup for the same account in your browser and imports it into local conversations.

External processing for service delivery
We use Google LLC's Firebase Authentication, Cloud Messaging, Realtime Database, Cloud Functions, Cloud Storage and Hosting for sign-in, device registration, message delivery, attachment storage and hosting. IP addresses, browser information and installation identifiers may also be processed to provide and secure these services. Google's processing locations and service-specific retention and deletion practices are described in Firebase's privacy and security information. The web app does not include the Android app's advertising, subscription billing, Analytics or Crashlytics SDKs.


[CapturePopup(AllPopup)]
Mandatory : Display over other apps, Notification, Storage(Android version 9 and below)
Optional : No

Display over other apps It is required to display an image or text on the screen.
Notification It is required to display a menu for controlling popup.
Storage It is required to save the image to the gallery.

[Capture notes]
Mandatory : Display over other apps, Notification, Storage(Android version 9 and below)
Optional : Contacts, Google account

[App Data Backup]
Collected Items: App usage settings (user-defined options), app activity records, backup data files
Collection Method: When performing a backup after signing in with a Google account within the app
Purpose of Use: Data restoration and maintenance of user environment when reinstalling the app or changing devices
Retention Period: Until the user deletes the data from Google Drive
Processing entrusted to : Google Drive (Google LLC)

Display over other apps It is required to display an image or text on the screen.
Notification It is required to display a menu for controlling popup.
Contacts It is required to read your Google account.
Google account
(Google drive)
It is required to save app data to your Google Drive.
(Only reads or writes to backup data.)
Storage It is required to save the image to the gallery.
Limited Use Policy
Scopes https://www.googleapis.com/auth/drive.appdata
Scopes Info See, edit, create, and delete only the specific Google Drive files you use with this app
Purpose It needs write access in order to create backup files so that my app can back up its data.
It needs read access in order to read backup files so that my app can restore data.
A narrower scope would not be sufficient because the backup file must be readable and writable.
Policy (App’s) use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Note that apps distributed on Google Play are also subject to the Google Play Developer Distribution Agreement.

Ads in our Android apps are served through the AdMob, AppLovin, Pangle, and Unity Ads networks. These ad networks may use and collect anonymous data about your interests to customize advertising in our App and in other sites and apps. To do this, they use the unique, user-resettable Advertising ID provided by Google Play services. Interest and location data may be linked to your device, but is not linked to your identity. To learn more about the privacy policies and opt-out choices for each network, please review their individual policies. You can find links to them in the list of third-party service providers below.

Privacy policies of external service providers used by our apps. Advertising, subscription billing and automatic error-reporting services apply to the Android apps that use those features. Services used by the web app are identified in the web app section above.

 

Log Data

Android apps that use external error-reporting services may collect technical information when an error occurs, such as device information, operating system version, app state, event times and error details, under the relevant service provider policies. This is separate from local diagnostic records submitted through Contact Us. The web app does not include the Analytics or Crashlytics SDKs and does not automatically upload its local diagnostic records.

 

Cookies

Cookies are files with a small amount of data that are commonly used as anonymous unique identifiers. These are sent to your browser from the websites that you visit and are stored on your device’s internal memory.

The web app uses browser storage, including IndexedDB and local storage, to maintain sign-in, preferences such as language, and conversations. You can clear this data in your browser settings; doing so may remove your sign-in state, preferences and local conversations. External services such as Google sign-in may use cookies or other storage technologies for authentication and security. Blocking these technologies may restrict some features.

 

Service Providers

I may employ third-party companies and individuals due to the following reasons:

  • To facilitate our Service;
  • To provide the Service on our behalf;
  • To perform Service-related services; or
  • To assist us in analyzing how our Service is used.

I want to inform users of this Service that these third parties have access to your Personal Information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

 

Data retention and deletion

Uploaded inquiry log files are retained for 30 days from upload and then deleted, including files whose inquiry submission did not complete. Inquiry and reply emails are retained for 30 days from each email's receipt or sending date and then deleted, including the account identifiers and inquiry contents they contain. Information that must be retained by law is stored separately for the legally required period.

Android local data can be removed by clearing app data or uninstalling the app. Web conversations can be removed using the web app's deletion controls or by clearing browser site data. Signing out does not delete local conversations. You must delete exported backup copies yourself. Personal information we hold is deleted using methods that prevent recovery when its applicable retention period expires.

Reward information is deleted after 90 days of last use.

Subscription and purchase information is retained until subscription cancellation and refund completion, then as required by applicable laws.

 

Security

Android apps use operating-system app storage protections, and the web app uses browser site storage protections. We use HTTPS for communications with our servers and encryption for Push Service message delivery. Authentication information is managed through Firebase Authentication. This does not mean that local web conversations or exported backup files have separate file encryption. No method of transmission or storage can guarantee absolute security.

 

Links to Other Sites

This Service may contain links to other sites. If you click on a third-party link, you will be directed to that site. Note that these external sites are not operated by me. Therefore, I strongly advise you to review the Privacy Policy of these websites. I have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

 

Children’s Privacy

These Services do not address anyone under the age of 13. I do not knowingly collect personally identifiable information from children under 13. In the case I discover that a child under 13 has provided me with personal information, I immediately delete this from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact me so that I will be able to do necessary actions.

 

Changes to This Privacy Policy

I may update our Privacy Policy from time to time. Thus, you are advised to review this page periodically for any changes. I will notify you of any changes by posting the new Privacy Policy on this page.

This policy was last updated on September 16, 2026.

v1 (https://zerogic.com/en/archive/privacy_v1.html)
v2 (https://zerogic.com/en/archive/privacy_v2.html)
v3 (https://zerogic.com/en/archive/privacy_v3.html)
v4 (https://zerogic.com/en/archive/privacy_v4.html)
v5 (https://zerogic.com/en/archive/privacy_v5.html)
v6 (https://zerogic.com/en/archive/privacy_v6.html)

 

Contact Us

If you have any questions or suggestions about my Privacy Policy, do not hesitate to contact me at [cs@zerogic.com].