Privacy starts with where the message goes.
This notice describes the development Android app and this website. Device validation is ongoing; the app is not offered for public download here.
Operator and contact
Avoca · operations@smsrelay.avoca.app
On your phone
Incoming SMS and opt-in message notifications are checked against enabled rules. Credentials, rules, explicitly saved test cases and pending messages are encrypted with an Android Keystore key. Pending messages expire after 24 hours; OS suspension can delay cleanup. Configuration changes discard pending messages. Saved test cases remain until you delete them. No app delivery history or diagnostic logging is kept.
At your destinations
Webhooks and Google Sheets receive sender/title, text, receipt time, source and notification app package where applicable. Sheets also includes a delivery identifier. SMS destinations receive a relay-marked sender/title and text through your carrier. Destination copies follow their own retention. Android, carriers and Google may retain data under their policies. No Avoca server processes messages.
Your controls
Pause forwarding; disable notification relay; edit, clone or delete rules; delete saved tests or destinations; clear local data; revoke SMS/notification permissions or Google access. Local deletion does not remove copies already sent. Notification rules require a specific app package and cannot use the default or known SMS apps as a permission workaround.
This website
This website is hosted on AWS using a private S3 origin and CloudFront. It has no cookies, analytics, trackers, forms or third-party assets. Theme preferences stay in your browser. Website access/request logging and readership summaries are disabled. AWS processes network requests to deliver the pages under its own policies. This website never receives SMS content or controls the Android app.