Scheduler Proby UTK Apps

Legal

Privacy Policy

What Scheduler Pro keeps on your phone, what it sends over the network, and to whom.

Last updated 25 September 2026 Effective 21 September 2026

1The short version

Scheduler Pro is built so that what you write, who you write it to, and what you attach never leaves your phone.

  • There is no account and no sign-up to use the app. You can sign in to Google if — and only if — you want the optional Drive backup (§7).
  • We operate no servers of our own. There is nowhere for us to send your data, and we could not read it if we wanted to.
  • We collect no analytics and no telemetry — no usage statistics, no crash reports, no event logs.
  • Your scheduled messages, contacts, attachments, auto-reply rules and settings are stored in this app’s private storage on your device.
  • The app shows ads. They are served by Google AdMob, and to choose an ad Google’s Mobile Ads SDK reads your device’s advertising ID. This is the one part of the app that shares anything with a third party for its own purposes, it is described in full in §6, and in the EEA and UK you are asked before any of it happens.
  • The app’s outbound network requests are: to the AI provider you configure (§5), to Google’s ad servers (§6), to Google Drive if you turn backup on (§7), and to your device’s own speech recognizer if you use voice typing (§11). There are no others.

Everything below is the detail behind those statements.

2Who this policy is from

UTK Apps (“we”, “us”) publishes the Android application Scheduler Pro (the “App”), package name com.whatsscheduler.pro. This policy covers the App only.

3What the App stores, and where

All of the following is stored on your device, in the App’s own private storage. None of it is transmitted to us, because we have no servers to transmit it to.

What Where it is stored Why
Scheduled messages: recipients, message text, chosen time, repeat and time-zone settings On-device database To send them at the time you chose
References to attachments you pick On-device database To attach them to a scheduled send
Auto-reply rules: names, keywords, reply text, targets, cooldowns On-device database To match and answer incoming messages
Recent conversation turns (sender, message text, timestamps) On-device database Auto-reply cooldowns, reply-once-per-conversation, and AI context if you enable it
Contacts you select as recipients (name and number), and your own Custom Groups On-device database So a schedule knows who to send to
Names of WhatsApp group chats the App has seen a notification from On-device database Groups cannot otherwise be selected — see §9
App settings and preferences On-device preferences To remember your choices
Your Google account’s email address, name and profile-photo URL — only if you sign in for backup (§7) On-device preferences To show you which account backups are going to. No access token is ever stored — one is requested at the moment it is used and discarded.
Your AI provider API key Encrypted, Android Keystore To authenticate to the provider you chose
Your device PIN — only if you enable auto-unlock Encrypted, Android Keystore To unlock the screen at send time — see §10

Retention. It stays until you delete it. Deleting a scheduled message, rule or group removes it. Clearing the App’s storage, or uninstalling the App, removes all of it. Recorded conversation turns are additionally purged automatically after 7 days by a periodic cleanup task, whether you delete anything or not.

Backup — please read this one. Three different things happen here, and we would rather be precise than reassuring:

  • Your two secrets are never backed up. Your AI provider key and your device PIN are explicitly excluded from Android cloud backup, from device-to-device transfer, and from the App’s own Drive backup (backup_rules.xml, data_extraction_rules.xml). They cannot leave the device even via the system.
  • The rest of the App’s data participates in Android’s normal backup. The App has Android auto-backup enabled, which means your schedules, the recipients you selected, your auto-reply rules and your settings may be backed up by Android to your own Google account, and restored when you set up a new device. That backup belongs to you and is governed by Google’s privacy policy — it does not come to us, and we cannot read it. If you would rather this did not happen, you can turn off backup for this app in your device’s backup settings.
  • The App’s own Drive backup is separate, and off until you switch it on. It is described in §7.

We call this out because “nothing leaves your phone” would be a tidier sentence than the truth. What is true is that nothing about your messages, recipients or attachments is ever sent to us, and that the two things worth protecting most are locked to the device.

4What we do not collect

To be explicit, the App does not collect, generate, transmit or store any of the following:

  • An account, an email address, a username or a password for us — we have no accounts. (If you sign in to your own Google account for backup, see §7.)
  • Your phone number, your IMEI, or an install identifier
  • Location data of any kind
  • Analytics, usage statistics, event logs, heat maps or session recordings
  • Crash or diagnostic reports sent to us
  • Your WhatsApp credentials — the App never signs in to WhatsApp and never sees them
  • The contents of your WhatsApp conversations (see §8)

One identifier is read, and we will not bury it: the Android advertising ID, by Google’s Mobile Ads SDK, in order to serve the ads described in §6. We never receive it, and it is never joined to anything else in this app. The App contains no analytics SDK, no crash-reporting service and no social SDK.

5Network use, and the AI provider you choose

The App requests the INTERNET and ACCESS_NETWORK_STATE permissions. The full list of things it reaches over the network is:

  1. Checking whether you are online, using Android’s own connectivity APIs. This is a local question to the operating system; it sends nothing anywhere. It exists so a message that comes due with no connection is held rather than attempted and failed.
  2. The AI provider you configured — described just below.
  3. Google’s ad servers, for the ads in §6.
  4. Google Drive, if and only if you have signed in and switched backup on (§7).
  5. Your device’s own speech recognizer, if you use voice typing (§11) — which may or may not involve the network, as that section explains.

There is nothing else, and in particular there is no call to any server of ours, because we have none.

If you enable AI auto-replies, then when a rule using AI matches an incoming message, the App sends to the provider you selected (OpenAI, Google Gemini, Anthropic, or any OpenAI-compatible endpoint you point it at):

  • the incoming message text,
  • your system prompt,
  • optionally, recent messages from that same conversation as context (a setting you control),
  • your API key, for authentication.

That request goes directly from your device to that provider. It does not pass through us. Once it reaches your provider, that provider’s privacy policy and data-retention practices apply, not ours — including whether they retain or train on the content. Please read the terms of whichever provider you choose. You are responsible for their charges.

If you never enable AI replies, no message content is ever sent to any AI provider.

6Advertising

The App is free, and it is paid for by ads served by Google AdMob. There are three kinds, and there are no others:

  • ads shown within the Dashboard, Schedule, Auto-reply and Settings screens — drawn in the App’s own style among that screen’s content, and each one marked “Ad”. There is at most one on each of these screens;
  • banner ads — one fixed across the top of the Custom Group editor, one fixed across the top of a message’s delivery report, and one at the foot of the Settings screen, which you only reach by scrolling to the end;
  • a full-screen ad, shown occasionally as you leave a screen — after you save a scheduled message or an auto-reply rule, or when you open AI provider, Custom Groups, Auto-unlock or Backup & restore from Settings. It is shown at most once a minute, and never while a scheduled message is being sent.

What is shared. To select and measure an ad, Google’s Mobile Ads SDK reads your device’s advertising ID and coarse technical information about your device (such as device model, operating-system version, language, and coarse location inferred from your IP address), and Google may use this to personalise ads and to measure their performance. This happens between your device and Google. We do not receive it, and we see nothing but an aggregate earnings figure in our own AdMob account.

What is never shared. The ad SDK is never given — and has no access to — your messages, your recipients, your contacts, your attachments, your Custom Groups, your auto-reply rules, your AI API key or your device PIN. None of those are sent anywhere except as described in §5 and §7.

If you are in the European Economic Area or the UK, you are asked before any of this happens. Google’s own consent message appears the first time you open the App, no ad is requested until you have answered it, and you can change your answer at any time in Settings → Ad privacy options.

Everywhere, you can reset or delete your advertising ID, or opt out of ad personalisation, in your device’s own Settings → Privacy → Ads. Google’s policy at policies.google.com/technologies/partner-sites describes what Google collects when you use apps that use its services, and this AdMob page lists the ad technology providers Google may work with.

7Google account and Drive backup

Drive backup is optional and off by default. A fresh install backs up nothing and is signed in to nothing. You are offered it once at the end of first run, and you can say no; you can turn it on or off later in Settings → Backup & restore.

If you sign in and switch it on:

  • Your scheduled messages, auto-reply rules and Custom Groups — and, if you choose, their attachments — are copied to a hidden, per-app folder in your own Google Drive, on the frequency you pick (Daily, Weekly or Monthly).
  • That folder is Drive’s appDataFolder: it does not appear in your Drive listing, and other apps cannot see it.
  • The only permission the App ever asks Google for is drive.appdata — the narrowest scope Google offers that can store anything. It cannot read, list, open or modify any other file in your Drive, and we deliberately do not ask for one that could.
  • The backup never comes to us. The App talks to googleapis.com directly, with a token issued to your own account. There is no server of ours in the path.
  • Your account’s email address, name and profile-photo URL are stored on the device so the App can show which account is in use. No access token is stored — one is requested at the moment it is needed and discarded.
  • Your backup settings go with it: how often to back up, and whether to include attachments. That is all the App’s own settings the backup contains; your account, and the time and result of the last backup, stay on the device that made them.
  • Your AI key and your device PIN are not included in the backup, ever.

Restoring merges rather than replaces: nothing already on the device is deleted, and an item that has already been restored is updated rather than added a second time. A restore also applies the backup settings above, but only ever towards backing up more: this device keeps whichever backup frequency is more frequent, and attachments end up switched on if either this device or the backup had them on. Because the device PIN is never backed up, the App reminds you after every restore to enter it again in Settings → Auto-unlock when locked if you use auto-unlock. Your AI key, if you use AI replies, has to be entered again in the same way, in Settings → AI provider.

You can sign out, switch backup off, or delete the backup at any time from Settings → Backup & restore, and you can revoke the App’s access to your Drive entirely at myaccount.google.com/permissions. What is in your Drive is governed by Google’s privacy policy.

8Accessibility Service — what it does and does not do

The App includes an Android Accessibility Service (Scheduler Pro — Send action). Android requires us to be explicit about it, and we want to be.

What it is used for, and only this:

  1. Tapping the “Send” button inside WhatsApp. WhatsApp provides no API for another app to send a message on your behalf. At the scheduled time the App opens the correct chat using an official wa.me link, and the Accessibility Service performs that single tap. It then observes whether WhatsApp reacted, so the App can report honestly whether the message went.
  2. Selecting a group chat from WhatsApp’s own chat picker, when sending to a group.
  3. Entering a PIN — only if you have enabled auto-unlock (§10). This covers your device’s lock screen and WhatsApp’s own App Lock prompt.

What it does not do:

  • It does not read, collect, store, log or transmit the contents of your conversations.
  • It does not send anything about the screens it reads to us, to an advertiser, or to anyone else.
  • It reads screen content only while a send you scheduled is actively in progress.

On its scope. The service is deliberately not restricted to WhatsApp alone, because auto-unlock has to interact with your device’s lock screen and the system credential prompt, which are not part of WhatsApp. This is why the service can technically observe other screens. It is used exclusively for the purposes listed above, and you can revoke it at any time in Settings → Accessibility, at which point the App can no longer send anything.

9Notification access — what auto-reply reads

The App includes a Notification Listener Service, used only if you want auto-replies.

  • It inspects WhatsApp notifications only. Notifications from other apps are ignored.
  • From a WhatsApp notification it reads the sender’s name (or the group’s title) and the message text, to decide whether one of your rules should answer.
  • It also records a group chat’s title so that group can appear in the recipient picker. WhatsApp does not let apps read your list of groups, so this is the only way a group becomes selectable.
  • That text is processed on your device. It is not sent anywhere — with one exception you control: if a matching rule uses AI, the incoming message is sent to your configured AI provider so a reply can be generated (§5). It is never sent to an advertiser.
  • Replies are delivered through the notification’s own reply action, or by the send mechanism in §8.

Auto-reply also depends on WhatsApp being configured to show message content in notifications. That is a WhatsApp setting, not ours.

You can revoke notification access at any time in your system notification-access settings.

10Your device PIN, if you enable auto-unlock

Auto-unlock is optional and off by default. You must switch it on and enter your PIN yourself.

If you do:

  • The PIN is stored encrypted, using EncryptedSharedPreferences backed by the Android Keystore, so the key protecting it is held by your device’s hardware-backed keystore.
  • It is never transmitted anywhere. Not to us — we have no servers — and not to any third party, advertiser included.
  • It is excluded from Android backup, from device-to-device transfer, and from the App’s Drive backup (§3, §7).
  • It is decrypted only in the moment immediately before a scheduled send, to type on the lock screen, and it is used for nothing else.
  • You can delete it at any time: Settings → Auto-unlock → Remove Stored PIN, or by clearing the App’s storage.

We want to be plain about the trade-off. Storing a device PIN on the device is inherently sensitive. Encrypted or not, someone who has your unlocked phone and opens this App is in a position to rely on that stored PIN. The App discloses this in-app before you enable the feature, and the feature exists only because scheduled sending on a locked phone is impossible without it. If that trade-off is not acceptable to you, leave auto-unlock off — every other feature works without it.

11Voice typing and the microphone

Voice typing is optional. When you tap the microphone in the App’s own message box, the App uses Android’s own speech recognition to turn what you say into text in that field.

  • The App does not record, save or upload audio. It receives text back from the recognizer, puts it in the field you are filling in, and keeps nothing of it.
  • Where recognition happens is the device’s decision, not ours. If your device has an on-device recognition model, it stays on the device — the App asks for on-device recognition where it is available. If it does not, Android’s recognizer (usually Google’s) may send the audio to its own servers for transcription, exactly as your keyboard’s microphone key does. That processing is governed by your device or recognizer provider’s privacy policy.
  • The microphone is used only while one of the App’s own editors is on screen and you have tapped the microphone. The App has no background listening of any kind.
  • If you never tap the microphone, the permission is never requested and nothing is recorded.

12Other permissions

Permission Why
READ_CONTACTS To list your contacts in the recipient picker. Contact data is read on-device and is never uploaded. Only contacts you actually select are stored.
RECORD_AUDIO Voice typing only. Requested the first time you tap the microphone, never at first run. See §11.
POST_NOTIFICATIONS To tell you the outcome of a send, and to show the brief notification Android requires while a send runs.
SCHEDULE_EXACT_ALARM To fire a scheduled message at the minute you chose.
RECEIVE_BOOT_COMPLETED To re-arm your schedules after a restart, so nothing is lost to a reboot.
VIBRATE Only for the optional alarm you can attach to a message, which rings or vibrates if that message fails to reach someone.
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Optional. So Android’s power saving does not delay a send.
SYSTEM_ALERT_WINDOW (“Display over other apps”) So a scheduled send can bring WhatsApp forward while the App is in the background, and so Touch Guard can cover the screen during a send.
FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE For the short-lived service that carries out a single send.
com.google.android.gms.permission.AD_ID Added by Google’s Mobile Ads SDK. It is how the advertising ID described in §6 is read.

The App also declares that it interacts with the WhatsApp package, and queries the device’s speech recognition service — both required by Android’s package-visibility rules in order to function.

13Children

The App is not directed at children and should not be used by them. It automates another application, can store a device PIN, and shows advertising. We do not knowingly collect information from anyone — see §4 — and in particular not from children. If you believe a child has used the App on your device, clearing the App’s storage removes everything it holds.

14Third-party libraries and services

The App is built with standard Android and Google open-source libraries — AndroidX and Jetpack (Compose, Room, WorkManager, DataStore, Security), Dagger Hilt, Kotlin Coroutines, kotlinx.serialization, and OkHttp for the requests in §5 and §7. None of these collect or transmit your data on their own. They are local libraries, not services.

Three Google components do talk to Google, and each is described above:

  • the Google Mobile Ads SDK and the User Messaging Platform consent library — §6;
  • Credential Manager and Google’s authorization library, used only to sign you in and obtain a Drive token — §7;
  • Android’s own speech recognition service — §11.

The App integrates no analytics platform, no crash-reporting service and no social SDK.

The App has no affiliation with WhatsApp LLC or Meta Platforms, Inc. It interacts with WhatsApp on your device, as you would, using publicly documented links and Android’s own APIs. Your use of WhatsApp remains governed by WhatsApp’s terms and privacy policy.

15Your control, and how to reach us

You can, at any time:

  • Delete any scheduled message, auto-reply rule or Custom Group inside the App.
  • Change your ad consent choice (Settings → Ad privacy options, where it is offered), and reset or delete your advertising ID in your device’s own privacy settings.
  • Sign out of Google, switch off Drive backup, or delete the backup (Settings → Backup & restore), and revoke the App’s Drive access in your Google account.
  • Remove your stored AI key (Settings → AI provider → Remove key).
  • Remove your stored device PIN (Settings → Auto-unlock → Remove Stored PIN).
  • Revoke the Accessibility Service, notification access, contacts or the microphone in your system settings. The App will tell you which features stop working, and will not work around it.
  • Delete everything at once by clearing the App’s storage or uninstalling it.

Because we hold no data about you, there is nothing for us to export or erase on request — a data access or deletion request is satisfied entirely by the actions above, on your own device, and by the Google controls linked in §6 and §7 for the data those services hold. If you are in a jurisdiction granting you such rights (GDPR, UK GDPR, CCPA and similar), this is the substance of our answer: we are not a controller or processor of your personal data, because we never receive it.

Contact

We aim to respond within 5 business days.

16Changes to this policy

If this policy changes we will update the Last updated date above and publish the new version at the same URL. Material changes — in particular any change to §4, §5, §6, §7 or §14 — will also be noted in the app’s release notes, because those are the sections a user has relied on.