apple.com — 72/100 (Medium privacy risk)

Last analyzed

Run a new analysis on another policy

Apple Inc. · apple.com

Report details

Medium privacy risk

Apple's Messages privacy disclosure shows strong encryption and short data retention but leaves critical EU compliance gaps—no mention of international transfers, GDPR user rights, or whether message metadata trains AI models.

Apple's iMessage service benefits from end-to-end encryption and a 30-day retention limit on most metadata, which is privacy-positive. However, the document is a narrow feature-level notice that defers entirely to Apple's general Privacy Policy on key EU requirements like international transfer safeguards, data subject rights, and AI training disclosures. The spam-filtering 'sender lookup' mechanism is vaguely described, and the document is silent on whether Apple processes data outside the EEA or uses it for model improvement.

Last analyzed
SourceURL

Category Assessment

Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.

Data MinimizationGood

Content is end-to-end encrypted so Apple cannot access it; metadata retention is capped at 30 days for most categories, and spam filtering uses on-device rules.

TransparencyFair

The document clearly explains encryption and retention periods but is vague on what 'information about your use of iMessage' means and defers key disclosures to the general Privacy Policy.

Third-party SharingFair

SMS/MMS/RCS is carrier-provided (not Apple), and sender lookup claims not to disclose sender/recipient to Apple, but no subprocessor list or detail on other recipients is provided.

International TransfersPoor

No mention whatsoever of where data is processed or stored, nor of any transfer mechanism (SCCs, adequacy, etc.).

Key Findings

Notable clauses, issues, or positive practices discovered (critical first)

Critical

No international transfer safeguards disclosed

There is no mention of where Apple processes or stores the 30-day metadata, scheduled messages, or spam reports. No reference to Standard Contractual Clauses, adequacy decisions, or transfer impact assessments — a clear GDPR Chapter V gap.

Warning

Vague metadata collection scope

Apple states it may 'record and store information about your use of iMessage in a way that doesn't identify you' but does not define what this information includes. Under GDPR Art. 13, the categories of data must be specified, not just described as non-identifying.

Warning

No GDPR user rights described

The document mentions you can turn off iCloud Backup and Messages in iCloud, but it does not reference any GDPR rights (access, rectification, erasure, portability, objection). It defers entirely to the general Privacy Policy, which is insufficient as a standalone notice under Art. 13.

Warning

Sender lookup mechanism lacks transparency

'Filter Spam uses a combination of on-device rules, message patterns, and sender lookup to filter out spam.' The policy claims 'Sender lookup does not disclose the message sender or the recipient information to Apple,' but does not explain what sender lookup actually queries, what server it contacts, or what data is transmitted during the lookup.

Warning

Silent on AI/model training use

The document says Apple may use collected information 'to operate and improve Apple's products and services' but never explicitly states whether iMessage data or metadata is used for AI model training. Given Apple Intelligence integration, this ambiguity is concerning.

Info

Name and photo stored on Apple servers with encryption Apple cannot see

The policy states the name and photo selected for messages 'will be sent to Apple, and stored on Apple's servers encrypted in a way that Apple cannot see.' While privacy-positive, no detail is given on the encryption scheme, key management, or whether this constitutes processing under GDPR.

Consumer Takeaway

Your iMessage content is well-protected by encryption, but Apple collects some metadata for 30 days and the policy doesn't clearly explain your GDPR rights or where your data goes.

Compliance Posture

Partial compliance — strong on security and data minimization for content, but missing explicit GDPR-mandated disclosures on transfers, rights, and automated decision-making.

EU Transfers

The document is entirely silent on international data transfers. No reference to SCCs, adequacy decisions, or transfer impact assessments. This is a significant gap under GDPR Chapter V.

Detected Signals

Specific data points and practices identified in the text

Data Collected
Phone numbersEmail addressesiMessage usage metadataSatellite messaging statusSpam and junk reportsScheduled and undeliverable iMessagesName and photo for sharingDevice eligibility status
Processing Purposes
Operating iMessage serviceSpam and fraud preventionMessage deliveryImproving Apple products and services
Third-party Sharing
SMS/MMS/RCS handled by carrierSender lookup contacts external servers but claims no sender/recipient disclosureNo subprocessor list provided
International Transfers
No mention of international transfers or safeguards
AI / Model Training
'Operate and improve Apple's products and services' language is ambiguous on AI trainingNo explicit opt-out for model trainingNo explicit statement that data is not used for training

Evidence Snippets

Direct quotes from the policy supporting these findings

Apple may record and store information about your use of iMessage in a way that doesn't identify you, including when you send and receive messages over satellite.

Apple may store these phone numbers and email addresses associated with your account, for up to 30 days.

Filter Spam uses a combination of on-device rules, message patterns, and sender lookup to filter out spam from unknown senders. Filtering does not reveal any message content to Apple. Sender lookup does not disclose the message sender or the recipient information to Apple.

Apple may record and store some information related to your use of the Messages app and the iMessage service to operate and improve Apple's products and services.

Missing or Unclear

  • GDPR data subject rights (access, erasure, portability, objection, restriction)
  • DPO contact details
  • Legal basis for processing under GDPR Art. 6
  • International transfer mechanisms and safeguards
  • Automated decision-making or profiling disclosures
  • Data retention schedule beyond the 30-day metadata window
  • Subprocessor or third-party processor list

Questions to Ask

  • What specific metadata fields does Apple record about iMessage use, beyond satellite status and eligibility?
  • Does 'improve Apple's products and services' include training AI or machine learning models on iMessage metadata or reported spam content?
  • Where geographically are the 30-day metadata, scheduled messages, and spam reports stored and processed?
  • What transfer mechanism (SCCs, adequacy decision, etc.) applies to any iMessage data transferred outside the EEA?
  • What encryption scheme protects the name and photo stored on Apple's servers, and who holds the keys?
  • How does 'sender lookup' work technically — what server is queried and what data is transmitted during the lookup?
  • What is Apple's legal basis under GDPR for processing iMessage metadata and spam reports?
This analysis is generated by AI and is not legal advice. Always consult a qualified legal professional for compliance decisions.

Share this analysis

Anyone with this link can view the result above.

Built by DentroChat

100% European AI chat for everyone

Chat with AI, work with files, generate images, and search the web. Data stays in Europe.

EU-hosted infrastructureText, files, images & web searchFast, Thinking & Creative modesPrivacy-first by defaultNo data leaves Europe
Try free →
View all