🔒 Privacy Policy
SMS Dock
Last Updated: September 30, 2026
Your SMS Stay on Your Phone and in Your Network
SMS Dock is an SMS app for Android that also serves your messages to the browsers and programs you connect in your own network. It reads, sends and receives SMS and reads your contacts to do this. SMS, contacts and the log are never sent to ScienceSoft e.U. or to any other third party. ScienceSoft e.U. operates no account system, no telemetry endpoint and no cloud service for this app, and the app contains no analytics, tracking, advertising or crash-reporting framework.
What This Means for You
Server on Your Device
The web interface and the API run inside the app on your phone and answer only devices that reach it on your local network
No Developer Collection
No account, no usage statistics, no crash reports and no remote database operated by ScienceSoft e.U.
Password and Encryption
Both interfaces require the password you set and are encrypted with a certificate created on your phone
No Analytics or Ads
No Firebase, Crashlytics, Sentry, Google Analytics, AdMob, advertising ID collection or advertising SDK
Scope of This Policy
This policy describes the SMS Dock Android app, the web interface it serves to browsers and its WebSocket API for programs. It distinguishes between data processed locally by the app, data the app sends to the browsers and programs that you connect, and data that Google processes independently when you use Google Play services such as in-app purchases.
Programs that use the API, including the open-source client libraries published for SMS Dock, run on your own computers. What they do with the messages they receive is decided by whoever runs them.
How the App Works
SMS Dock is the default SMS app of the phone. The phone keeps its SIM card and its number. When you start the server in the app, the phone offers two interfaces to devices on the same Wi-Fi or LAN:
- Web interface (HTTPS, port 8443): a page for your browser that lists conversations and messages, searches and filters them, sends and deletes SMS and shows incoming messages at once
- WebSocket API (WSS, port 9443): the same functions for your own programs, including events for incoming and sent messages. It requires the full licence
- Background service: while the server runs, an Android foreground service with a persistent notification keeps it alive until you stop it. If you switch this on in the settings, the server also starts after the phone has booted
- No cloud dependency: the app needs no internet connection and no developer-operated server. Messages travel directly between your phone and the devices you connect
Data Processed by SMS Dock
Depending on the features you use, the app processes the following categories on your device:
- SMS messages: text, phone number, time, direction, status and SIM card of the messages on the phone. They are kept in the phone's own SMS store, which belongs to Android and not to SMS Dock. As the default SMS app, SMS Dock writes incoming and sent messages into this store and deletes messages there when you ask it to. MMS are not received while SMS Dock is the default SMS app.
- Contacts: names, phone numbers and number labels from your address book, read to show names instead of numbers and to offer contacts as recipients. SMS Dock does not copy your address book and does not change it.
- SIM information: the SIM cards of the phone with their slot, name or operator and, where the phone provides it, their number, so that you can choose a SIM card for sending.
- Record of messages sent through SMS Dock: recipient number, number of parts, SIM card, status, time and a hash of the text. The text itself is not kept in this record. It is used to report the result of a message and to avoid sending the same request twice.
- Log: server starts and stops, logins and failed logins, connections of API clients, sent and deleted messages and changed settings. An entry holds the time, the kind of event, the IP address of the browser or program and, for sent messages, the recipient number, the number of parts and the SIM card. It never contains the text of a message or a password.
- Password: the password you set is stored only as a salted PBKDF2-HMAC-SHA256 hash. Login sessions are random tokens held in the app's memory, and failed login attempts are counted in memory to slow down password guessing.
- TLS identity: one self-signed certificate per installation, generated on the device. The private key is created in and never leaves the Android Keystore.
- App settings: ports, language and appearance, the pop-up default, the start-after-boot switch and the number of messages sent today in the free version, stored in the app's private storage.
- Licence state: whether the full licence has been bought, as reported by Google Play, together with the purchase data Google Play returns for verification, kept in encrypted storage on the device. The app never sees your payment details.
Who Receives Your Messages and Contacts
SMS Dock exists to make your SMS available outside the phone, so this section states exactly where they go:
- Browsers you sign in with: after login with your password, the web interface receives messages, conversations, contact names and numbers, SIM information and the log over HTTPS.
- Programs you connect to the API: after authentication with the same password, a program receives the same data except the log, over an encrypted WebSocket. At most 8 programs can be connected at once.
- Your mobile network operator: an SMS you send is transmitted by the operator of your SIM card to the recipient, as with every SMS app.
- Nobody else: SMS Dock does not transmit SMS, contacts, SIM information or the log to ScienceSoft e.U., to advertisers, to analytics providers or to any other third party, and does not use them for any purpose other than the functions described here.
Security notice: whoever reaches the phone on the network and knows the password can read your SMS, including one-time codes, and send SMS at your expense. Use SMS Dock only on networks you trust, choose a long password, do not open its ports to the internet, and stop the server when you do not need it. The certificate is self-signed; compare its fingerprint with the one the app shows before you enter the password.
Network Connections
SMS Dock sends no data to ScienceSoft e.U. The following network activity occurs only to provide the features you choose to use:
- Web interface and API: while the server runs, the app accepts encrypted connections on the two ports on the network interfaces of the phone. Unencrypted connections are not offered. All pages, scripts and fonts of the web interface come from the phone itself; the page loads nothing from the internet.
- Google Play: opening the licence screen, buying or restoring the full licence communicates with Google Play Billing. Google processes the store account, transaction, device and payment information under its own terms and privacy policy.
- Sharing: if you use the share buttons, the address of the server or the log is handed to the app you choose in the Android share dialog.
- User-opened external links: links on the About and Other Projects screens, for example to flutterdev.app or to app stores, open in your browser only when you select them. The destination then receives ordinary web request data under its own privacy policy.
Storage, Retention, and Deletion
- SMS messages: stay in the phone's SMS store until you delete them in SMS Dock, in its web interface, through the API or in another SMS app. Because the store belongs to Android, the messages remain on the phone when you uninstall SMS Dock.
- Record of sent messages: entries are removed after 30 days.
- Log: limited to five files of 512 KB each; the oldest entries are overwritten. You can clear the log in the app at any time.
- Settings, password hash and licence state: stored in the app's private storage until you change them, clear the app's data or uninstall the app, subject to Android's backup and restore behaviour.
- Sessions of the web interface: the web interface sets one strictly scoped, HTTP-only, secure session cookie named
__Host-smsdock. The matching token lives only in the app's memory, expires after 30 minutes without use, and is invalidated by logout, a password change or stopping the server. After five failed logins, logins are refused for 30 seconds, doubling up to 15 minutes. - Data in your browser: the web interface keeps the chosen appearance, language and pop-up setting and the read state of conversations in the browser's local storage, and unsent drafts in its session storage until the tab is closed. This data stays in that browser; clear the site data of the browser to remove it. Responses of the server are marked as not to be cached.
- Certificate and key: the self-signed certificate and its Keystore-backed private key are replaced when you choose "Regenerate certificate" and removed when you clear the app's data or uninstall the app.
- Store records: Google may retain transaction records according to its own legal obligations and privacy policy. Removing local app data does not delete records maintained by Google Play.
Permissions
The app declares only the Android permissions needed for its features:
READ_SMS,SEND_SMSandRECEIVE_SMS: to show, send and receive SMS as the default SMS app and to serve them to the web interface and the APIRECEIVE_MMSandRECEIVE_WAP_PUSH: required by Android of every default SMS app. SMS Dock does not process MMSREAD_CONTACTS: to show names instead of numbers and to offer contacts as recipientsREAD_PHONE_STATE: to list the SIM cards of the phone so that you can choose one for sendingINTERNET: to accept connections from browsers and programs on your networkACCESS_NETWORK_STATEandACCESS_WIFI_STATE: to show the addresses of the phone and refresh them when the network changesFOREGROUND_SERVICEandFOREGROUND_SERVICE_SPECIAL_USE: to keep the user-started server running while you use other appsWAKE_LOCKandREQUEST_IGNORE_BATTERY_OPTIMIZATIONS: to keep the server answering while the screen is off; the exemption from battery optimisation is requested only with your consentRECEIVE_BOOT_COMPLETED: to start the server after the phone has booted, if you switched this onPOST_NOTIFICATIONS: to show the running-server notification with its Stop action and, as the default SMS app, a notification for each incoming SMScom.android.vending.BILLING: to offer and restore the full licence through Google Play- No location, camera, microphone, call log, storage, Bluetooth or nearby-device permission is declared
In-App Purchase
SMS Dock is free to install. The free version contains the app and the web interface and sends up to 10 SMS per day. The full licence is a one-time purchase through Google Play Billing; it removes the daily limit and unlocks the WebSocket API. Google handles the payment transaction. The app only learns from Google Play whether the purchase exists and keeps the purchase data Google Play returns on the device in order to unlock the functions and to offer a restore. For details about store processing, review the Google Privacy Policy.
Third-Party Services and SDKs
The app uses Google Play Billing for the full licence. It also uses open-source components that run within the app: the NanoHTTPD web server, Flutter packages for preferences, encrypted storage, device information, opening links, sharing and QR codes, and the fonts shipped with the app. These components do not create a developer-operated cloud service.
SMS Dock does not include Firebase, Sentry, Crashlytics, Google Analytics, Facebook SDK, AdMob, Branch, AppsFlyer, advertising ID collection, remote configuration, push notifications or any other tracking or advertising framework.
Data Controller
The provider responsible for SMS Dock and for any personal data sent directly to us, such as a support email, is:
- Company: ScienceSoft e.U.
- Address: Oberzellergasse 12/13, 1030 Vienna, Austria
- Commercial Register: FN 644834k
- VAT ID: ATU60406778
- Email: peter.sauer@flutterdev.app
ScienceSoft e.U. does not receive your SMS, your contacts, your password, the log or the traffic between your browsers, your programs and the phone. Your messages contain personal data of the people you write with. If you use SMS Dock for an organization or connect programs that process these messages, you or your organization are the controller for that processing.
Legal Bases
To the extent ScienceSoft e.U. processes personal data in connection with SMS Dock, we rely on Article 6(1)(b) GDPR where processing is necessary to respond to a request or provide a service you asked for, and Article 6(1)(f) GDPR for our legitimate interests in providing support, operating and securing this policy website, and protecting our legal rights. We do not use app data for advertising or profiling.
Data processed solely on your device or exchanged with browsers and programs on your own network is not sent to us. Google determines its own legal bases for the store data it processes under its privacy policy.
This Policy Page and External Links
This page is part of the FlutterDev website. It uses first-party scripts for functions such as theme switching and does not use analytics, advertising trackers or third-party cookies. The hosting web server may process standard technical log data, such as IP address, browser type, requested page and access time, to deliver and secure the website.
Links to GitHub, Google, app stores or other external sites are governed by the privacy policies of those destinations. We do not control their data practices.
Children's Privacy
SMS Dock is a utility for technically experienced users and is not directed to children. We do not knowingly collect personal data from children through an account or developer server because the app has neither. This applies to children under 13 (COPPA, United States) and under 14 (Austrian data protection law under the GDPR).
Your Choices and Rights
- Choose whether to start the server, which ports it uses, whether it starts after boot, which browsers and programs get the password, and whether to buy the full licence
- Delete messages and conversations, clear the log, change the password, regenerate the certificate, stop the server, choose another default SMS app, clear the app's data or uninstall the app
- Withdraw permissions in the Android settings; SMS Dock then cannot provide the functions that need them
- Contact us to request access, correction, deletion, restriction, objection or portability for personal data that you have directly provided to ScienceSoft e.U., subject to applicable law and any required retention
- Exercise store-related rights directly with Google for data controlled by Google Play
California notice: ScienceSoft e.U. does not sell or share SMS Dock app data for cross-context behavioral advertising and does not use it for targeted advertising. You may contact us using the address below with any applicable privacy request.
Changes to This Privacy Policy
We may update this Privacy Policy when SMS Dock's features, data practices or legal obligations change. The date at the top of this page identifies the latest version. Material changes apply prospectively from the updated date unless applicable law requires otherwise.
Contact Us
If you have questions about this Privacy Policy or want to exercise an applicable privacy right, please contact us:
- Company: ScienceSoft e.U.
- Address: Oberzellergasse 12/13, 1030 Vienna, Austria
- Email: peter.sauer@flutterdev.app
Supervisory Authority
You have the right to lodge a complaint with a competent data protection authority. The Austrian supervisory authority is:
- Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
- Address: Barichgasse 40-42, 1030 Vienna, Austria
- Email: dsb@dsb.gv.at
- Website: www.dsb.gv.at
Our Commitment
At ScienceSoft e.U., we build SMS Dock so that your messages and contacts stay on hardware and networks you control. The app has no tracking or advertising frameworks, needs no account or cloud, and gives you direct controls to stop the server and delete what it stores.