Junkless › Privacy Policy
Privacy Policy
Last updated: 2026-09-16
Junkless is designed so that we need as little of your data as possible. This policy explains what is processed, where, why, for how long, and the rights you have. It applies to the Junkless iOS app, its extensions, our servers at api.junkless.app, this website and email support.
1. Who is responsible
The data controller is Süleyman Ateş, İstanbul, Türkiye ("Junkless", "we", "us"). Contact: support@junkless.app. We have not appointed a data protection officer, as none is required for our processing.
We are established outside the European Union. We have not designated a representative in the EU under Article 27 GDPR because our processing is occasional, does not include special categories of data on a large scale and is unlikely to result in a risk to your rights and freedoms. You can contact us directly about any privacy matter.
2. Summary
- Filtering happens on your iPhone. The text of your messages is not sent to us, unless you turn on Help improve the filter and choose to share a message you report.
- There is no account, no advertising, no analytics and no tracking.
- Reports you choose to send are end-to-end encrypted; our server cannot read them.
- We do not sell or share personal information, and we do not use it for targeted advertising.
- You can delete everything we hold about your device from the app: Settings › Delete my data from the server.
3. Message filtering (on your device only)
When you select Junkless under SMS Filtering, iOS gives the Junkless filter each new SMS or MMS from a sender who is not in your contacts. The filter uses the sender and the message text, on your iPhone, only to decide whether the message is spam, a transaction or a promotion. The result is returned to iOS and the data is discarded. Nothing about the message is written to storage or transmitted.
iOS never shows Junkless iMessages or messages from your contacts.
The proactive filter (look-alike links, links to IP addresses, hidden characters) and the scam database lookup also run on your iPhone. On iPhones with Apple Intelligence, Test a message can explain a decision in plain language using Apple's on-device language model. The message you paste is processed on your iPhone and is not sent to us.
4. Reports you choose to send
Reporting is optional. If you select Junkless under SMS/Call Reporting and report a message, the app creates a report containing the sender's phone number or name, your choice (spam, spam and block, or not spam) and the time. The message text is not included.
The report is encrypted on your iPhone with a public key whose private key exists only in your app (X25519 key agreement with ChaCha20-Poly1305). iOS sends the encrypted report to our server, which stores it until your app collects it and then deletes it. Your app decrypts the report and turns it into a rule on your device. For messages that Junkless's own filter also judges to be spam, the encrypted report includes a short fingerprint (a one-way hash) of the message text; your app uses it only to count the free weekly database update and to count each message once. We cannot read it.
To route reports, the app registers a random device identifier with our server together with a hash of a random secret. These are not linked to your name, Apple Account, phone number or advertising identifier. iOS may add technical information to the request; we do not use it for any other purpose.
Help improve the filter (optional, off by default). If you turn this on in Junkless › Settings, the report screen shows a switch to share the reported message. If you leave the switch on, the app masks the message on your iPhone before iOS sends it: digits in phone numbers, codes and account numbers are replaced with zeros, IBANs and email addresses are removed, and links are shortened to the website name. The shared sample contains the masked text, whether you reported it as spam or not spam, your language and region, the type of sender (the sender name only if it is a business name or short code, never a phone number) and how Junkless had classified the message. Unlike the report itself, the sample is not end-to-end encrypted, and it is not linked to your device identifier. We use samples to review and train the filter model. A message can contain details we cannot mask automatically, such as names, so share only messages you are comfortable sharing.
5. Rules, settings and iCloud
Your rules and settings are stored on your iPhone. If you have Pro and iCloud sync is on, they are synced between your own devices through Apple's iCloud key-value storage in your iCloud account. Apple processes this data under its own privacy policy; we cannot access it. You can turn sync off in Settings › iCloud sync.
6. Downloads, server logs and this website
The app downloads the scam database and model updates from our servers, and communicates with the report relay. These servers run on Cloudflare. As with any internet connection, your IP address, the time and technical request details (such as the app version) are processed to deliver the response and to protect the service from abuse. We do not keep application-level logs of these requests, and we never log report contents.
This website uses no cookies, no analytics, no advertising and no third-party embeds.
7. Purchases
Subscriptions and one-time purchases are processed by Apple as the merchant. We do not receive your payment details, name or Apple Account. The app checks which products you are entitled to on your device using Apple's StoreKit; this information is not sent to us. Optional tips are one-time purchases handled the same way; they unlock nothing.
8. Notifications
If you allow it, Junkless schedules a local reminder once a month on your iPhone.
Instant updates (Pro): the app registers with Apple Push Notification service and sends us its push token and whether it is a test or App Store build, so we can ask your app to check for a new scam database as soon as one is published. These pushes are silent and contain only that instruction. The token is not linked to your device identifier, name or Apple Account. Free users never register a token, and the app removes its token from our server when Pro ends.
9. Support email
If you email us, we process your email address and the content of your message to answer you. We keep support conversations for up to 24 months after the last message, unless a longer period is required by law.
10. Purposes and legal bases (EU, UK, Türkiye)
- Providing the report relay, update downloads and support: performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Instant updates for Pro: performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Sharing reported messages to improve the filter: your consent (GDPR Art. 6(1)(a); KVKK Art. 5(1) explicit consent). You can withdraw consent at any time by turning Help improve the filter off; this does not affect samples already shared.
- Security, abuse prevention and technical operation of servers: our legitimate interests in running a safe service (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Compliance with legal obligations where they apply (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).
Apart from optional message sharing, we do not rely on consent for processing on our servers. Features that involve our servers are optional; you can stop using them at any time as described below.
11. Recipients and service providers
- Cloudflare, Inc. (United States) hosts our servers, website and email forwarding as our processor.
- Apple Inc. provides the App Store, payments, iCloud, push notifications, Apple Intelligence and iOS message filtering as an independent controller under its own privacy policy.
We do not disclose personal data to anyone else unless we are legally required to. We do not sell or share personal information as defined by the California Consumer Privacy Act (CCPA), and we have not done so in the past 12 months.
12. International transfers
Cloudflare processes data in the United States and other countries. For transfers from the EEA, Switzerland and the UK, Cloudflare is certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions and offers the European Commission's Standard Contractual Clauses. Transfers from Türkiye are made in accordance with Article 9 of the KVKK. We are located in Türkiye; data you send us, such as support emails, is processed there.
13. Retention
- Message text: not retained, except samples you choose to share.
- Encrypted reports: until your app collects them, and at most 30 days.
- Device identifier and secret hash: while your app is in use; deleted automatically after 13 months without any contact from the app, or immediately when you delete your data in the app.
- Shared message samples: on our server until we download them for review, at most 180 days. Samples used to train the filter may be kept in our training data for as long as models built from them are in use. Because samples are not linked to you or your device, we cannot find an individual sample later.
- Push tokens (Pro): 60 days after the app last registered them, or immediately when Pro ends or you delete your data in the app.
- Server request data: not retained by us beyond processing the request; Cloudflare may keep security logs for a limited period under its own policies.
- Support emails: up to 24 months after the last message.
14. Your choices and how to delete your data
- Delete your data from our server: in Junkless, open Settings › Delete my data from the server. This deletes your device identifier, any waiting reports and your push token immediately.
- Stop sharing messages: Junkless › Settings › Help improve the filter, turn it off. You can also turn the switch off on the report screen for a single report.
- Stop reporting: Settings › Apps › Phone › SMS/Call Reporting, choose none.
- Stop filtering: Settings › Apps › Messages › Unknown & Spam › SMS Filtering, choose none.
- Stop iCloud sync: Junkless Settings › iCloud sync, or turn iCloud off for Junkless in iOS Settings.
- Deleting the app stops all processing; encrypted reports still on our server expire within 30 days and the device identifier within 13 months.
15. Your rights
Depending on where you live, you have rights over your personal data.
EU, EEA, UK (GDPR): access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests, and the right to lodge a complaint with your local supervisory authority.
Türkiye (KVKK Art. 11): to learn whether your data is processed and request information, learn the purpose and recipients, request correction, deletion or destruction, object to results of exclusively automated analysis, claim compensation, and complain to the Personal Data Protection Board (KVKK Kurulu).
In Türkiye, you must first apply to us; you may complain to the Board if we reject your application, do not respond within 30 days, or you find our answer insufficient (KVKK Art. 14).
California and other US states (CCPA/CPRA and similar laws): to know what personal information we collect, use and disclose, to delete and correct it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising your rights.
To exercise a right, email support@junkless.app. We respond within one month (GDPR), 30 days (KVKK) or 45 days (CCPA). Because we do not know who you are, we may ask for your device identifier, shown in Junkless › Settings, to find your data. For most requests, the in-app deletion is fastest.
16. Automated decisions
Spam classification is an automated decision made on your device to sort incoming messages. It does not produce legal effects. Filtered messages remain available in the Junk folder of Messages, and you can override the filter at any time with your own rules.
AI explanations in Test a message are generated on your iPhone to describe a decision; they do not change it.
17. Children
Junkless is a general-audience utility, not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it.
18. Security
Reports are end-to-end encrypted, shared samples are masked on your device before sending, all connections use TLS, the private key never leaves your device, and database and model updates are cryptographically signed and verified before they are installed.
19. Do Not Track
We do not track you across websites or apps, so browser Do Not Track and Global Privacy Control signals do not change how we process data.
20. Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change materially affects how we process your data, we will also inform you in the app before it takes effect.