apple.com — 72/100 (Medium privacy risk)
Last analyzed
Apple Inc. · apple.com
Report details
Medium privacy riskApple's Messages privacy disclosure shows strong encryption and short data retention but leaves critical EU compliance gaps—no mention of international transfers, GDPR user rights, or whether message metadata trains AI models.
Apple's iMessage service benefits from end-to-end encryption and a 30-day retention limit on most metadata, which is privacy-positive. However, the document is a narrow feature-level notice that defers entirely to Apple's general Privacy Policy on key EU requirements like international transfer safeguards, data subject rights, and AI training disclosures. The spam-filtering 'sender lookup' mechanism is vaguely described, and the document is silent on whether Apple processes data outside the EEA or uses it for model improvement.
Category Assessment
Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.
Content is end-to-end encrypted so Apple cannot access it; metadata retention is capped at 30 days for most categories, and spam filtering uses on-device rules.
The document clearly explains encryption and retention periods but is vague on what 'information about your use of iMessage' means and defers key disclosures to the general Privacy Policy.
SMS/MMS/RCS is carrier-provided (not Apple), and sender lookup claims not to disclose sender/recipient to Apple, but no subprocessor list or detail on other recipients is provided.
No mention whatsoever of where data is processed or stored, nor of any transfer mechanism (SCCs, adequacy, etc.).
Key Findings
Notable clauses, issues, or positive practices discovered (critical first)
No international transfer safeguards disclosed
There is no mention of where Apple processes or stores the 30-day metadata, scheduled messages, or spam reports. No reference to Standard Contractual Clauses, adequacy decisions, or transfer impact assessments — a clear GDPR Chapter V gap.
Vague metadata collection scope
Apple states it may 'record and store information about your use of iMessage in a way that doesn't identify you' but does not define what this information includes. Under GDPR Art. 13, the categories of data must be specified, not just described as non-identifying.
No GDPR user rights described
The document mentions you can turn off iCloud Backup and Messages in iCloud, but it does not reference any GDPR rights (access, rectification, erasure, portability, objection). It defers entirely to the general Privacy Policy, which is insufficient as a standalone notice under Art. 13.
Sender lookup mechanism lacks transparency
'Filter Spam uses a combination of on-device rules, message patterns, and sender lookup to filter out spam.' The policy claims 'Sender lookup does not disclose the message sender or the recipient information to Apple,' but does not explain what sender lookup actually queries, what server it contacts, or what data is transmitted during the lookup.
Silent on AI/model training use
The document says Apple may use collected information 'to operate and improve Apple's products and services' but never explicitly states whether iMessage data or metadata is used for AI model training. Given Apple Intelligence integration, this ambiguity is concerning.
Name and photo stored on Apple servers with encryption Apple cannot see
The policy states the name and photo selected for messages 'will be sent to Apple, and stored on Apple's servers encrypted in a way that Apple cannot see.' While privacy-positive, no detail is given on the encryption scheme, key management, or whether this constitutes processing under GDPR.
Consumer Takeaway
Your iMessage content is well-protected by encryption, but Apple collects some metadata for 30 days and the policy doesn't clearly explain your GDPR rights or where your data goes.
Compliance Posture
Partial compliance — strong on security and data minimization for content, but missing explicit GDPR-mandated disclosures on transfers, rights, and automated decision-making.
EU Transfers
The document is entirely silent on international data transfers. No reference to SCCs, adequacy decisions, or transfer impact assessments. This is a significant gap under GDPR Chapter V.
Detected Signals
Specific data points and practices identified in the text
Evidence Snippets
Direct quotes from the policy supporting these findings
Apple may record and store information about your use of iMessage in a way that doesn't identify you, including when you send and receive messages over satellite.
Apple may store these phone numbers and email addresses associated with your account, for up to 30 days.
Filter Spam uses a combination of on-device rules, message patterns, and sender lookup to filter out spam from unknown senders. Filtering does not reveal any message content to Apple. Sender lookup does not disclose the message sender or the recipient information to Apple.
Apple may record and store some information related to your use of the Messages app and the iMessage service to operate and improve Apple's products and services.
Missing or Unclear
- GDPR data subject rights (access, erasure, portability, objection, restriction)
- DPO contact details
- Legal basis for processing under GDPR Art. 6
- International transfer mechanisms and safeguards
- Automated decision-making or profiling disclosures
- Data retention schedule beyond the 30-day metadata window
- Subprocessor or third-party processor list
Questions to Ask
- What specific metadata fields does Apple record about iMessage use, beyond satellite status and eligibility?
- Does 'improve Apple's products and services' include training AI or machine learning models on iMessage metadata or reported spam content?
- Where geographically are the 30-day metadata, scheduled messages, and spam reports stored and processed?
- What transfer mechanism (SCCs, adequacy decision, etc.) applies to any iMessage data transferred outside the EEA?
- What encryption scheme protects the name and photo stored on Apple's servers, and who holds the keys?
- How does 'sender lookup' work technically — what server is queried and what data is transmitted during the lookup?
- What is Apple's legal basis under GDPR for processing iMessage metadata and spam reports?
Share this analysis
Anyone with this link can view the result above.
Built by DentroChat
100% European AI chat for everyone
Chat with AI, work with files, generate images, and search the web. Data stays in Europe.
Other analysed privacy policies
View allabout.qwant.com
72/100
Medium privacy riskQwant offers strong privacy by default without tracking cookies, but creating an account or consenting to cookies shares significant data with Microsoft, and the policy lacks clarity on international transfers and AI training.
View report →signal.org
72/100
Medium privacy riskSignal genuinely collects almost nothing and encrypts everything, but its legal documentation is outdated and missing critical GDPR-mandated disclosures like transfer safeguards, retention periods, and user rights procedures.
View report →slack.com
72/100
Medium privacy riskSlack collects a wide range of personal and usage data, relying heavily on broad legitimate interests to process it and transfer it globally, though it does provide standard GDPR rights and safeguards like Standard Contractual Clauses.
View report →robotstxt.es
68/100
Medium privacy riskRobotstxt generally respects EU privacy but lacks clear details on legal bases, third‑party processors and AI use.
View report →