2doc ("the app") is made by Handrolled Apps ("we", "us"). The app works with data already on your device, and does two things with it: it builds documents — reading your messages, photos, call logs, contacts, calendar events, and device info, and exporting them as a PDF — and it backs up and restores your messages and call history. Your privacy is central to how the app is designed: all source data stays on your device and is never uploaded to our servers. One optional feature, off unless you turn it on, contacts the websites linked in your messages — Section 4 explains exactly what they receive.
This policy explains exactly what we collect, what leaves your device, and who else may receive information about you.
The following sources are read locally to build your documents and backup files. The app itself transmits nothing from these sources to us, and nothing to any third party except through one optional feature you turn on yourself (link previews — see Section 4). Content otherwise leaves your device only when you choose to share or print it:
Generated PDFs and backup files are saved locally on your device. They are never uploaded unless you choose to share them. When you share a document you can set a password: the copy you share is encrypted with AES-256 on your device, and the password is never stored anywhere — the protected copy cannot be opened without it, and the document saved on your device stays as it is. Printing hands the PDF only to the print service you pick in Android's print dialog, and adding a watermark changes the file on your device only.
The Backup feature saves your messages and call history into files you control. Everything below happens on your device — we never see or receive your backups.
What a backup contains. You choose what to back up. A messages backup contains your SMS and MMS, including photos and other attachments embedded in the file. A call-log backup contains each call's number, date, duration, type (incoming, outgoing, missed, and similar), and whether the caller's number was shown or hidden. Contact names from your address book are included in both so the files are readable. Each type is saved as its own file, in the same XML format used by the popular "SMS Backup & Restore" apps — so your backups are not locked to 2doc.
Where backups live. Backup files are stored in the app's private storage on your device, where other apps cannot read them. The app keeps only the latest backup of each type — creating a new one replaces the previous one. Backups are created only when you tap the button: there is no scheduling and no background backup.
Encryption is optional. You can protect a backup with a password. If you do, the file is encrypted with AES-256 and saved as a .2doc file; your password is never stored anywhere, which also means a lost password makes that backup permanently unrecoverable — even by us. If you skip the password, the backup is an ordinary readable .xml file, so treat it with the same care as the messages inside it.
Backups leave your device only when you share them. The app never uploads, syncs, or transmits backup files. The only way a backup leaves your device is the Share button, which hands the file to an app you pick in the Android share sheet. 2doc's data — backups included — is also excluded from Android's own cloud backup and device-to-device transfer.
Restoring. You can restore from the backup stored on this device or from a backup file you pick with the system file picker. Restoring messages writes them back into your phone's message store; Android only allows this while 2doc is your default SMS app, so the app asks you to make it the default temporarily and prompts you to switch your usual app back as soon as the restore finishes. While 2doc is the default, incoming texts are received and saved unchanged into your phone's message store, and 2doc cannot send messages at all; picture messages (MMS) that arrive during this brief window may not be saved. Restoring a call-log backup writes the calls back into your call history.
Restore only adds. Before restoring, the app reads your existing messages or call log for one purpose: to skip entries that are already on your phone. Restore never deletes or modifies anything.
The app uses the following services, each of which may receive limited information:
We use Firebase Analytics to understand feature usage (e.g. "user exported a PDF") and Firebase Crashlytics to receive crash reports. Analytics events contain no personal content from your messages, files, or backups — only anonymised usage signals and a randomly generated device identifier.
Firebase also derives an approximate location — country or region level — from the IP address your device connects from, and uses it for analytics. This is standard Firebase Analytics behaviour rather than something the app asks for: 2doc holds no location permission, never collects precise location, and never links any of this to the content of your messages, documents, or backups.
Manages purchase state. RevenueCat receives your app-store purchase receipt and a pseudonymous user ID to verify Pro access. It does not receive any content from your device sources.
When you connect a Telegram account, the app communicates directly with Telegram's API using your credentials to retrieve messages. Your Telegram session is stored locally on your device only. We never see your Telegram password or messages. You can disconnect your Telegram account at any time from Settings, which signs you out and removes the local session from your device.
Voice transcription is one of the import options when you add a Telegram chat, and it is off unless you turn it on. With it on, 2doc asks Telegram to transcribe the voice notes and video notes in the chat you are importing: the speech recognition runs on Telegram's servers — not on your device, and not on ours. 2doc sends only the chat and message identifiers; the audio is already in your own Telegram cloud, and neither we nor the app upload it anywhere. Telegram meters these requests against your own Telegram Premium subscription or free-trial allowance, so turning the option on can consume it. The transcript that comes back is stored locally on your device and rendered into your document.
When you add a Messages or WhatsApp section to a document, one of the import options is Link previews. It is off unless you turn it on. With it on, 2doc requests each web address found in the messages you are importing directly from that website, over a secure (https) connection, and reads the page's title, description, and preview image so the link can appear as a card in your document. The preview image is downloaded to your device and embedded in the PDF.
Each site receives what it would receive if you opened the link in a browser: the address itself and your device's IP address. No message text and nothing else from your device is sent, and none of it passes through us. With the option off, no request is made and links are added as plain text.
The app requests the following Android permissions only to provide its core functionality:
The default-SMS-app role. This is a role you grant in a system dialog, not a permission, and 2doc asks for it in exactly two places — never on its own, and never in the background:
In both cases 2doc reads or writes only while it actually holds the role, and shows a reminder to switch your usual app back — in the restore flow as soon as the restore finishes, and in the document builder as a banner that stays until you switch back. While 2doc is the default, incoming texts are received and saved unchanged into your phone's message store, and 2doc cannot send messages at all; picture messages (MMS) that arrive during that window may not be saved. Android also requires a default SMS app to register compose and quick-reply components — in 2doc these are deliberately non-functional, because the app cannot send messages.
The app does not request the QUERY_ALL_PACKAGES permission. App-related sections rely on Android's package-visibility rules, so the app can only see apps that appear in your launcher.
We do not store your device data on any server. Crash reports are retained by Firebase Crashlytics for 90 days. Analytics data is retained according to Google's standard Firebase Analytics retention settings (default: 14 months). RevenueCat retains purchase records as required for purchase verification and legal compliance.
Backup files live in the app's private storage and follow a simple rule: only the latest backup of each type is kept, and a backup file is removed only when a newer one replaces it or when you uninstall the app. If you uninstall the app, locally stored preferences, PDF files, and backup files are all removed with it. Copies of backups or PDFs that you have shared out of the app live wherever you sent them and are under your control, not ours. To request deletion of analytics or crash data, contact us at the address below.
The app is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has used the app and you have concerns, contact us and we will take appropriate action.
We may update this policy. When we do, the effective date and version at the top will change. For material changes, the app will ask you to review and accept the updated policy on your next launch. For minor clarifications, we simply update the policy here.
Questions or data requests:
Handrolled Apps
privacy@handrolled-apps.com
To delete data, see the data deletion page.