← Alaap
Privacy Policy — Alaap SMS
Last updated: July 17, 2026
Alaap SMS (com.alaap.inbox) is a default SMS inbox app. This policy explains what data we process and
why.
Data we process on your device
- SMS and MMS content — Read and displayed locally so you can use inbox, OTP, offers, and
money features. Message content stays on your device unless you choose to export or back up.
- Contacts — Used to show names and photos for known senders. Not uploaded by Alaap for
advertising.
- App preferences — Theme, language, SIM settings, blocked senders, pinned contacts, and
similar settings stored in on-device preferences.
- Local analytics queue — Event names used for product improvement may be kept briefly on
device for debugging.
- Local Plus entitlement cache — Whether Alaap Plus is active (from Google Play or an
approved alternative payment) is stored on device so premium features stay unlocked offline. This is not
your card or wallet PIN.
Optional cloud features
- Google Sign-In — Used for your in-app profile and for Google Drive cloud backup. We receive
your email and display name from Google when you sign in.
- Encrypted Drive backup — If you enable cloud backup, an encrypted backup file is stored in
your Google Drive app data folder (not visible in normal Drive UI). You choose the
passphrase; we do not store it on our servers.
- Firebase Analytics — When Firebase is configured, anonymous usage events (for example
paywall shown, subscription purchased) may be sent to Firebase. No SMS bodies are included in these events
by design.
- Firebase Authentication (anonymous) — Used when you submit an alternative local-wallet
payment claim so we can attach the claim and Plus entitlement to your device session without requiring a
password.
Payments and subscriptions
Alaap Plus may be purchased in either of these ways. We never receive or store your full payment card number,
bank password, or mobile-wallet PIN.
Google Play Billing
- Subscriptions are processed by Google Play. Google handles payment methods, receipts,
renewals, and refunds under Google’s policies.
- Alaap receives only purchase state from the Play Billing Library (for example whether a
subscription is active, product ID, and purchase token needed to acknowledge the purchase). We do not store
card details.
- You can restore Play purchases on another device signed into the same Google account.
Alternative local-wallet payments (where offered)
In some regions (currently Bangladesh), you may pay for Alaap Plus by Send Money via supported
mobile financial services such as bKash, Nagad, or Cellfin,
then submit a payment claim in the app.
If you use this option, we may process:
- Wallet method you selected (bKash / Nagad / Cellfin)
- Transaction ID (TrxID) you enter so we can verify payment
- Plan (monthly or annual) and amount (in BDT) claimed
- Claim status (pending, approved, or rejected) and related timestamps
- A Firebase anonymous user ID linked to the claim and to your Plus entitlement expiry
Claims are stored in our Firebase / Firestore backend for verification and fraud prevention (for example so the
same TrxID cannot be reused). An administrator reviews the claim against the wallet transaction history;
approval grants time-limited Alaap Plus access.
We do not ask for or store your wallet PIN, OTP, or full personal banking credentials for this
flow.
Permissions
Alaap requests SMS, contacts, phone state (for dual-SIM), notifications, internet, and related permissions
required to act as a default messaging app and to sync optional cloud / payment features. You can revoke
permissions in system settings; some features will stop working.
Data we do not sell
We do not sell your personal information or SMS content to third parties.
Affiliate links
When enabled, offer links may be wrapped with affiliate tracking parameters so Alaap can earn a commission. This
does not send your SMS content to retailers.
Children’s privacy
Alaap is not directed at children under 13. Do not use the app if you are under the age required by your local
laws for this type of service.
Retention
- On-device data remains until you clear app data or uninstall.
- Drive backups remain in your Google account until you delete them or disconnect backup.
- Analytics retention follows Firebase / Google policies for your project.
- Manual payment claims and Plus entitlement records are kept as needed to provide the subscription, prevent
duplicate TrxID use, and handle support or disputes. Contact us if you need help with deletion requests
where applicable by law.
Your choices
- Sign out of Google from Settings.
- Disconnect Drive backup and delete the remote backup file.
- Cancel Google Play Alaap Plus in Google Play → Payments & subscriptions →
Subscriptions.
- For local-wallet Plus, access lasts until the entitlement expiry shown after approval;
contact support if you need help with a pending or approved claim.
- Uninstall the app to remove local data (this does not automatically cancel a Play subscription).
Contact
Questions about privacy: alaap@tahins.me
Changes
We may update this policy. The “Last updated” date at the top will change when we do.