Effective Date: August 2026

TextExhibit is developed by Castel Nuovo Systems. This Privacy Policy explains how TextExhibit handles data when you use TextExhibit Desktop for iPhone Backups or TextExhibit Android App.


Our Commitment to Privacy

TextExhibit is designed with privacy as a core principle. Message content, contacts, phone numbers, and exported files stay on your device unless you explicitly choose to share an exported file.


TextExhibit Desktop for iPhone Backups

Data Processing

TextExhibit Desktop for iPhone Backups processes all data entirely on your local computer. Reads Finder backups on macOS and Apple Devices backups on Windows. When you load a text message backup and generate PDFs:

  • The backup file is read from your local storage
  • All parsing and conversion happens in memory on your computer
  • Output PDFs are saved to your local storage
  • No message content is transmitted to any external server

What Data TextExhibit Desktop for iPhone Backups Accesses

  • Backup files you select (Android XML exports, iPhone .textexhibit files from TextExhibit Extractor, or full iPhone backup directories)
  • Message content including text, timestamps, and phone numbers
  • Media attachments (images, videos, audio) contained in the backups
  • Contact names you enter for phone number mapping (stored locally)

What Data TextExhibit Desktop for iPhone Backups Does NOT Access

TextExhibit Desktop for iPhone Backups does not:

  • Access files outside of the backup you select
  • Access your contacts, calendar, or other phone data
  • Access any online accounts or cloud storage
  • Connect to the internet (except for optional license validation and version checking)

Local Configuration Files (Desktop)

  • contacts.json — Phone number to name mappings you create
  • ui_settings.json — Application window state and preferences
  • License information — Your license key (if activated)

These files are stored in your user profile directory and are never transmitted externally.

Network Activity (Desktop)

License Validation: If you purchase and activate a license, TextExhibit may communicate with our licensing server to validate and verify your license key. This communication includes only your license key and a machine identifier.

Version Update Checking: Upon startup, TextExhibit performs a read-only HTTP request to textexhibit.com/version.json to check for updates.

No message content, client data, or personal information is transmitted during license validation or version checking.

TextExhibit Desktop for iPhone Backups does not include any analytics, telemetry, or usage tracking.


TextExhibit Android App

Data Processing

TextExhibit Android App reads SMS and MMS messages directly from your device and generates PDFs locally on your device. All processing happens on-device.

  • Messages are read from the Android SMS/MMS content providers
  • All parsing and PDF generation happens on your device
  • Output PDFs are saved to the folder you select
  • No message content is transmitted to any external server

Data Accessed and Processed Locally

SMS and MMS Messages — The app reads your text messages (SMS/MMS) to convert them into PDF documents. This data is required for the app to function. Message content is processed on-device and written to locally stored PDFs. It is not transmitted off your device.

Contacts — The app reads your device contacts to display names alongside phone numbers in the generated PDFs. Contact data is processed on-device only and is not transmitted off your device.

Under Google Play’s Data safety definitions, this local access is not “collection” because the data is not transmitted off your device.

Data TextExhibit Android App Does NOT Transmit

TextExhibit Android App does not:

  • Upload or transmit message content, contacts, phone numbers, generated PDFs, or exported media to TextExhibit, Firebase, or any other server
  • Access your call history, camera, microphone, or precise device location, or request Android location permission
  • Store message data beyond the PDFs you generate
  • Include advertising or ad personalization

Crash Reporting (Android)

TextExhibit Android App uses Firebase Crashlytics to collect crash logs when the app encounters an error. Crash logs include:

  • Stack traces (code file names, line numbers, method names)
  • Device information (model, OS version, available memory)
  • App state (version, foreground/background status)

Crash logs do not include message content, contact names, phone numbers, or any of your personal data. This data is collected automatically and is required for maintaining app stability.

Analytics (Android)

TextExhibit Android App uses Firebase Analytics to collect usage data that is not intentionally associated with a name, account, message, contact, or phone number. This helps us understand app usage and improve the product. Analytics data may include:

  • App lifecycle and interaction events (for example, app opens, screen views, sessions, engagement, and app updates)
  • In-app purchase events and transaction metadata, such as product, price, currency, and transaction identifier
  • Device information (model, OS version, screen size)
  • App-instance, Firebase installation, Crashlytics installation, and advertising identifiers
  • Approximate location derived from a masked IP address, plus country and language settings

Analytics data does not include message content, contact names, phone numbers, generated PDFs, or exported media. TextExhibit does not display advertising or use these identifiers to personalize ads.

In-App Purchases (Android)

TextExhibit Android App uses Google Play Billing for in-app purchases. Purchase transactions are handled entirely by Google Play. We do not collect or store your payment information.

Local Configuration (Android)

  • Contact display name overrides — Custom names you assign to phone numbers
  • Export preferences — Output folder, device serial number, and other settings

These are stored locally on your device and are never transmitted externally.

User-Initiated Sharing

TextExhibit does not automatically upload exported files. If you choose to share, open, or upload a generated PDF, spreadsheet, verification report, or media file using Android’s share interface or another app, you select the file and destination. The receiving app or service handles that file under its own privacy policy and terms.


Output Files

Generated PDFs, extracted media, and verification reports are saved to the output folder you specify. These files remain entirely under your control on both Desktop and Android.


Your Responsibilities

As the user of TextExhibit, you are responsible for:

  • Securing backup files provided by your clients (Desktop)
  • Protecting output PDFs containing sensitive message content
  • Complying with applicable laws regarding handling of client data
  • Obtaining appropriate consent from clients for processing their data

Third-Party Services

ServicePlatformPurposeData Sent
License serverDesktopLicense validationLicense key, machine ID
Version checkDesktopUpdate notificationsNone (read-only request)
Firebase CrashlyticsAndroidCrash reporting and app stabilityCrash logs, diagnostics, app/device state, installation identifiers
Firebase AnalyticsAndroidUsage analyticsApp interactions, device/app information, approximate location, purchase events, and identifiers
Google Play BillingAndroidIn-app purchasesHandled by Google Play

No message content, contact names, phone numbers, generated PDFs, or exported media is sent to these services.


Data Retention

TextExhibit does not retain message or contact data beyond what you explicitly save. When you close the application:

  • Message data is cleared from memory
  • No cached copies of backups or messages are kept
  • Only your saved configuration preferences remain
  • Temporary files created during export are automatically deleted

To remove local Android app data, uninstall TextExhibit or clear its storage in Android settings. To remove Desktop data, uninstall TextExhibit and delete its configuration folder.

Firebase and Google Analytics retain analytics, diagnostic, and identifier data according to their service settings and policies. Firebase Crashlytics generally retains crash reports and associated identifiers for 90 days before beginning deletion. For more information, see Privacy and Security in Firebase and Google Analytics data practices.


Children’s Privacy

TextExhibit is designed for legal professionals and is not intended for use by children under 18.


Changes to This Policy

We may update this Privacy Policy from time to time. The effective date at the top of this page indicates when the policy was last revised.


Contact Us

If you have questions about this Privacy Policy or TextExhibit’s data practices, please contact us.