KleanBox Privacy Policy
Last updated: September 5, 2026
Introduction
KleanBox is an iOS app that filters unwanted SMS and MMS messages. It uses Apple's IdentityLookup framework to classify messages on your device. By default, nothing about your messages leaves your device. Two optional features described below send message data to KleanBox, and both stay off until you turn them on.
This policy explains what KleanBox collects by default, what each optional feature sends, what we never collect, and how any collected data is handled.
What KleanBox Collects by Default
KleanBox collects a minimal amount of non-personal data to keep the app stable and to understand how its features are used:
- Crash reports — via Firebase Crashlytics. This includes device model, OS version and crash stack traces. No message content and no personally identifiable information is included.
- Anonymous usage analytics — via TelemetryDeck. We record product events such as a rule being added, edited, toggled or deleted, a rule pack being installed, or a setting being switched, together with non-identifying attributes like the rule type (word or regex), its category and match field, and counts. The text of your rules, your safe senders and your messages are never part of these signals. TelemetryDeck identifies devices only by a salted hash that cannot be reversed.
- Filter definition updates — the app periodically downloads a public definitions file over HTTPS so new spam wording is covered without an app update. This is an ordinary file download; no data about you or your messages is sent with it.
Optional Features That Send Message Data
Both features are off by default. Each is a switch in KleanBox › Settings, and each explains what it sends before you turn it on.
Share Reported Messages
When this is on and you report a filtered message as junk inside Messages, KleanBox sends that message to our server so the same campaign can be blocked for everyone. What is sent: the sender (up to 128 characters), the message text (up to 1,000 characters), the app version and the country or region set on your device. No name, phone number of yours, account, contact list or device identifier is attached, and we cannot tell who sent a report.
Only messages you personally report are sent. Reports are stored aggregated by message, with a count of how often that message was reported, and are used solely to build and improve KleanBox's filter definitions and rule packs.
Check Unknown Messages Online
When this is on and a message from an unknown sender cannot be classified by your rules, your safe senders or the built-in definitions, iOS sends the sender and message text to our server, which compares it against messages other people have reported and answers whether it looks like junk. This uses Apple's network-filtering mechanism for message filter apps. Messages your device can already classify are never sent. Lookups are read-only: the server does not store the messages it is asked about.
iCloud Sync (Optional)
If you turn on iCloud sync, your filter rules and safe senders are stored in the iCloud key-value store attached to your Apple Account so they stay the same on all your devices. This data is handled by Apple under Apple's privacy policy; KleanBox has no access to it. Message content is never synced.
Information We Do NOT Collect
Unless you turn on one of the two optional features above, KleanBox does not collect, store or transmit the content of your messages. All message filtering happens on your device.
In every case, we do not collect:
- Your name, email address, phone number or postal address
- Your location (the region code sent with a shared report is the country set in your device settings, not a location)
- Contacts or call history
- The text of your filter rules or your safe sender list
- Browsing or usage history outside the app
KleanBox has no user accounts, no sign-in and no authentication of any kind, and does not use advertising or tracking SDKs.
On-Device Processing
SMS and MMS filtering is performed on your device by KleanBox's message filter extension using Apple's ILMessageFilterExtension. Your rules, safe senders and the built-in filter definitions all run locally, whether or not you have a network connection.
KleanBox uses the iOS Keychain and App Groups to share your filter rules and settings between the main app and its extensions. This data stays on your device unless you turn on iCloud sync.
Third-Party Services
- Firebase Crashlytics — crash reporting. Firebase Privacy Policy
- TelemetryDeck — anonymous, privacy-first analytics, GDPR-compliant by design. TelemetryDeck Privacy Policy
- Cloudflare — hosts the KleanBox report and lookup service used by the two optional features. Cloudflare Privacy Policy
KleanBox does not use any third-party advertising services.
Data Retention
Crash reports are retained by Firebase Crashlytics for 90 days. Anonymous analytics signals are retained by TelemetryDeck according to their retention policy.
Shared junk reports are kept for as long as they are useful for building filter definitions. Because no identifier links a report to you, we cannot look up reports by person; if you want a specific message you reported removed, contact us with its text and we will delete it. Online lookups are not stored.
Filter rules, safe senders and preferences are stored on your device and are removed when you uninstall the app. Data you chose to sync to iCloud remains in your iCloud account until you turn sync off and delete it, or delete it through iOS Settings.
Children's Privacy
KleanBox does not knowingly collect personal information from anyone, including children under the age of 13. The optional sharing features send only the content of messages you choose to report and carry no identifying information.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with a revised date. We encourage you to review this policy periodically.
Contact Us
If you have any questions or concerns about this privacy policy or KleanBox's data practices, contact us at: