Twoko MMTD (Mobile Message Threat Detection) analyzes the text content of messaging notifications you already receive on your device (Google Messages, Samsung Messages, MIUI Messages, RCS, etc.) and alerts you when it detects potentially malicious links or text, helping you make more informed decisions.
WHAT IS MMTD?
Mobile Message Threat Detection is a protection feature specifically designed to work without accessing your SMS inbox or call log. Instead of reading system messages, it only processes the text visible in the notifications you receive on your screen, with explicit authorization granted through your system settings.
ANTIVIRUS-LIKE ARCHITECTURE: ON-DEVICE PRIVACY
Twoko MMTD works like a modern antivirus. It periodically downloads a signed rule package (whitelist and blacklist of domains, patterns, and keywords by country) and evaluates each notification LOCALLY on your device. The text of your messages is NEVER sent to our servers. In ambiguous cases, the app may query the server by sending only anonymized characteristics (number of URLs, text length, domain hashes) — never the message itself. This cloud query is optional and can be disabled in Settings.
WHAT IT DOES
• Inspects links (URLs) that appear in messaging app notifications.
• Compares each link against verified lists of legitimate domains from banks, telecom companies, retailers, and government agencies in Chile, Ecuador, Mexico, Guatemala, and Spain.
• Resolves suspicious shortened links before notifying you.
• Displays a local notification when it detects a risky link.
WHAT IT DOESN'T DO
• Does NOT read your SMS inbox.
• Does NOT access your call log.
• Does NOT send SMS messages.
• Does NOT access your contacts.
• Does NOT share or sell your data.
REQUIRED PERMISSIONS
• Access to notifications (manual user opt-in in System Settings): to read the visible text of messaging notifications.
• Show notifications (Android 13+): to alert you when we detect a risky link.
PRIVACY
The text of your notifications is NEVER sent to our servers. All analysis occurs on your device against downloaded and signed rules. When the app queries the server for ambiguous cases (optional), it only transmits anonymized features (counts, lengths, SHA-256 hashes of domains), without personal identification or message content. See the full policy at https://twoko.io/privacy
SUPPORT
Email us at support@twoko.io