Privacy Policy
Effective Date: October 5, 2026
Last Updated: September 21, 2026
This Privacy Policy describes how Pojava, LLC ("we," "us," or "our") collects, uses, and protects information when you use the lessms Android application ("App") and the less.ms website ("Website"), collectively referred to as the "Service."
The short version: Your SMS and MMS messages stay on your device. Nothing is sent to us automatically, ever. The one exception is entirely up to you: if you choose to contribute an example to the Spam Library, that single message is stripped of personal details on your device, shown to you for approval, and only then sent. Everything else we collect is what is necessary to manage your account, license, and trial.
- Account information: When you register on the Website, we collect your email address and a password (stored as a salted hash). You may optionally provide a display name and avatar for the community forum.
- Purchase information: None. Focus Edition is a subscription sold through Google Play. Google processes the payment and records the purchase against your Google account; we receive no purchase confirmation, no payment details and no notification that you subscribed. Your subscription is verified on your device, directly with Google Play.
- Forum content: Posts and topics you submit to the community forum.
- Support communications: Emails or messages you send to us.
- Spam Library contributions: If you choose to submit a spam example, we receive the message text after your device or browser has replaced names, phone numbers, email addresses, and link details with placeholders, and after you have reviewed and approved exactly what is being sent. We also receive the sender's number, the type of filter rule that caught it (never the rule's name or pattern), whether the sender is one of your saved contacts (a yes or no only; see Section 1.6), and an identifier for the contribution — a random one for an App installation, or one derived from your account if you contribute from the website. You may also volunteer what the message asked you for. See Section 1.5.
- Android device identifier (ANDROID_ID): Sent to our server only when you start the free trial, and stored solely to enforce one trial per device. It is not linked to your account, is not used for the paid subscription, and is not collected at any other time.
- Phone number: Never sent to us. The app reads your device's own number locally to address outgoing MMS messages correctly, and that value stays on your phone. We previously collected it to support device transfer; that feature no longer exists, because a Google Play subscription follows your Google account to a new phone on its own.
- Trial status: Whether a trial has been started for your device identifier, and the trial start date. Stored on our server so a trial cannot be restarted by reinstalling.
- App version / OS version: May be included in API requests for compatibility purposes.
The following data is processed entirely on your device and is never transmitted to our servers:
- The content of your SMS or MMS messages. The only exception is a message you personally select and approve for the Spam Library (Section 1.5). Nothing is ever sent automatically, in the background, or without you seeing the exact text first.
- Your contacts or contact list. The App reads them on your device only; see Section 1.6.
- Your filter rules or macro configurations, unless you choose to post a rule in the community forum (Section 3).
- Images, GIFs, or media attachments in messages.
- Message metadata (sender numbers, timestamps, thread IDs).
- Your Junk folder contents, except for an individual message you choose to contribute (Section 1.5).
- Your wallpaper settings or theme preferences.
- The names, descriptions or patterns of your filter rules, other than a rule you post in the forum yourself.
- The list of names you configure for masking Spam Library submissions.
1.4 Website Analytics
The less.ms website may collect standard web server logs including IP address, browser type, referring URL, and pages visited. We may use this information to understand usage patterns and improve the Website. We do not use third-party advertising trackers.
1.5 Spam Library Contributions
The Spam Library is a public, community-built collection of spam examples. Contributing is entirely optional; the App never submits anything on its own.
How a contribution is made. Contributing is an action you take in the App, and the App displays what will be sent before you take it. By choosing to submit, you are voluntarily contributing the sanitized text to the less.ms website for publication in the Spam Library.
What happens on your device, before anything is sent. The message is processed locally to replace personal details with placeholders: your name and any names you have listed become {name}, phone numbers become {phone}, email addresses become {email}, and web links keep only their main domain, with the rest becoming {sub} and {path}. The result is displayed to you in full. Nothing is transmitted unless you then choose to submit it.
What is published. Only the placeholder-substituted text. Your name is not attached to it, and neither is your account — there is no account involved at any point. A published entry gives a reader no way to learn who contributed it.
What we retain privately. Each submission carries a random identifier generated for your installation of the App. We keep it so that if a set of submissions turns out to be inaccurate or abusive, we can withdraw them. This identifier refers to the app installation, not to you. It is not linked to your website account, your email address, your phone number, your device identifier, or your name, and reinstalling the App replaces it. We do not use it to build a profile of a contributor, to infer anything about a contributor's interests or characteristics, or for any purpose other than moderating the library.
What the message asked you for. When you contribute, you may optionally tell us what the message asked of you — for example whether it asked for a password, a payment, a donation, or was simply an advert. This covers the message itself and any page it linked to, if you had already opened it. This is voluntary, you can leave it blank, and we never ask you to open a link to find out. We use it to classify the campaign, because a message that is only a link tells a reviewer nothing about its purpose. This answer is never published and never attached to a public entry; it is visible only to reviewers.
Review before publication. Submissions are held for review by a person before appearing publicly, so that anything containing personal information the automatic processing missed can be rejected.
Sender numbers. The sender's number is submitted with the example, because it is often part of what identifies a spam campaign. Bear in mind that spam senders routinely forge numbers, so a number appearing in the library does not mean its rightful owner sent the message.
Contributing from the website instead. You can also submit an example from the less.ms website, which requires you to be signed in. The processing is the same and still happens entirely in your browser: names, phone numbers, email addresses and link details are replaced before anything is sent, and the page shows you the exact text that would be submitted. The original message is never transmitted.
How a website submission differs. A submission made in the App carries a random identifier tied to that installation and to nothing else. A submission made on the website is instead recorded against an identifier derived from your account. That identifier is not your account name, your email address or your account number, it is never displayed anywhere on the site, it is never attached to a published entry, and it cannot be reversed using our database alone. An administrator can derive it in order to withdraw submissions from an account that has abused the library. We do not use it for any other purpose, and it is not used to build a profile of a contributor.
We are describing this plainly because it is a real difference: an App contribution is anonymous to us, while a website contribution is anonymous to other people and to the website itself, but is deliberately linkable by an administrator so that abuse can be undone. If you would prefer the App's arrangement, contribute from the App.
Please note: because a published entry cannot be traced back to you, we generally cannot identify and remove a specific past contribution on request. Review the text carefully before submitting.
With your permission, the App reads the contacts stored on your phone. It uses them only on your device, to:
- Show names and photos in place of phone numbers.
- Match filter rules of the "Contact" type, which you write to allow, block or tag messages from people saved in your contacts. These rules are checked against a contact's name and phone number on your device.
- Tell you, before you contribute a message to the Spam Library, that it came from someone in your contacts. Only that yes-or-no answer is sent with a contribution you approve (Section 1.1); the contact's name, number and other details are not.
- Open a person in your phone's contacts app when you tap their name. That hands the number to your contacts app on your device, not to us.
The App does not add, change or delete contacts. Any change you make happens in your contacts app. If you do not grant the permission, the App shows phone numbers instead of names and Contact rules match no one.
We use the information we collect to:
- Create and manage your website account.
- Issue and validate trial tokens, and enforce one trial per device.
- Operate the community forum and the Spam Library.
- Review contributed spam examples, group related examples into campaigns, and withdraw contributions found to be inaccurate or abusive.
- Respond to support requests.
- Send transactional emails (e.g., account registration confirmation, password reset).
- Detect and prevent abuse of the website.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
We do not sell your personal information. We may share information in the following limited circumstances:
- Public content you choose to publish: Forum posts, community themes, and approved Spam Library contributions are displayed publicly on the Website and are visible to anyone, including search engines. Spam Library entries are published without any contributor identity attached. A filter rule you post in the forum is public in the same way, including whatever its pattern contains: a rule that names a person or a phone number publishes that name or number.
- Service providers: We may share information with trusted vendors who assist us in operating the Service (e.g., email delivery, server hosting). These providers are contractually obligated to protect your information and use it only for the services they provide to us.
- Legal requirements: We may disclose information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Website before your information is transferred and becomes subject to a different privacy policy.
4. Data Retention
- Account data: Retained for as long as your account is active. You may request deletion of your account and associated data at any time (see Section 7).
- License and activation records: None held. We keep no record of who is subscribed — that information belongs to Google Play and is verified on your device.
- Trial records: Retained indefinitely to enforce the one-trial-per-device policy. Trial records are keyed by device identifier only and are not associated with an account.
- Forum posts: Retained until you delete them or request account deletion. Deleted forum posts are removed from public display within 24 hours.
- Spam Library entries: Published entries are retained indefinitely, as the value of the library is its historical record of spam campaigns. Because entries carry no contributor identity, they are not deleted when an account is deleted — there is no link between the two.
- Spam Library submission records: The random installation identifier attached to a submission is retained for as long as the entry exists, so that abusive contributions remain reversible.
- Web server logs: Retained for up to 90 days for security and diagnostic purposes.
5. Security
We use industry-standard measures to protect your information, including:
- Passwords stored as salted hashes (never in plaintext).
- Trial tokens signed with ECDSA-P256 cryptographic signatures and verified offline on your device. Focus Edition subscriptions are verified with Google Play.
- HTTPS encryption for all communication between the App and our API.
- Session tokens with expiration.
No method of transmission or storage is 100% secure. We cannot guarantee the absolute security of your information.
6. Children's Privacy
The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at support@pojava.com and we will delete it promptly.
7. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may update your account information at any time through the Website.
- Deletion: You may request deletion of your account and personal information by contacting us at support@pojava.com. Deleting your account does not cancel a Focus Edition subscription, which is held by Google Play; manage or cancel it in Google Play.
- Opt-out of emails: You may opt out of non-transactional emails by following the unsubscribe link in any email we send, or by contacting us directly.
- Spam Library: Contributing is optional and off by default; simply never use the contribute feature. Because contributions carry no link to your identity or your account, we cannot locate a specific past contribution on request, and deleting your account does not remove Spam Library entries.
To exercise any of these rights, contact us at support@pojava.com. We will respond within 30 days.
8. Third-Party Services
Google Sign-In
The App and Website offer optional sign-in via Google. If you use this feature, Google may collect information per their own Privacy Policy. We receive only your email address and a Google account identifier from this flow.
Mobile Carriers
SMS and MMS messages you send or receive travel through your mobile carrier's network under your carrier's terms and privacy policy. We have no control over and no access to your carrier's handling of your messages.
Payment Processing
Purchases are processed by Google Play. We do not receive or store your payment details, and we are not told when a purchase is made. Please review Google's privacy policy for details on how payment information is handled.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on the Website with a new effective date. For material changes — particularly changes that affect how we handle your SMS-related data or your account information — we will notify registered users by email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Pojava, LLC
support@pojava.com