Trust is not claimed. It is shown: in the permissions we don't ask for, the code we don't hide, and the person we made it for.
1. Built for Someone He Loves — Not for a Store Chart
Viruses are a choice. Someone chooses to bundle a miner, a stealer, a shady SDK that harvests contacts at 3 a.m. That choice makes sense if your user is a stranger you will never meet.
MYTH's first user was his female best friend — the same girl who reads dark romance novels at home and tells him which scenes should have gone differently. She installed the very first APK he sent her directly, on her personal phone. Would he give a virus to the person he cares about most — the girl he has a crush on and never said it to? No.
Which means the build you download is the same build he would hand her. Same signature, same binary, same server. There is no "clean version for her, dirty version for others." There is just one APK, and it is safe because it had to be safe enough for her.
2. What MYTH Actually Asks For (and What It Never Asks)
Asks (only when you use the feature):
- Microphone — only the instant you tap record on a voice message or start a voice call. Deny it and chat still works 100%. No background mic access.
- Storage / Photos — only when you pick a character image or change your profile picture. Scoped to the file you chose — not a scan of your gallery.
- Notifications — optional. For nudges ("Raven posted while you were away") and announcements (like 2 September free day). Turn it off and nothing breaks.
Never asks:
- SMS, call logs, contacts, precise location, accessibility, device admin, overlay-on-other-apps. Never.
- No background services that restart after reboot to mine or track. No hidden download of secondary APKs.
If any permission feels wrong, check system Settings → Apps → MYTH → Permissions at any time. You'll see exactly the three above, each revoke-able.
3. Play Protect, Signature, and How to Verify Yourself
- Google Play Protect — even sideloaded APKs are scanned on-device by Play Protect (the same scanner the Play Store uses). If MYTH contained known malware, Play Protect would flag it at install and at daily scans. It doesn't — because there is nothing to flag.
- Signed APK — every release is signed with the same keystore. If a single byte is tampered between our server and your phone, the Android installer fails signature verification and refuses to install. Your OS is the second auditor.
- Served from Convex, not a random mirror — the download button pulls a signed URL straight from Convex storage. No bit.ly hop, no ad landing page, no "click here to continue" funnel.
- How to double-check in 30 seconds: install, open Settings → Apps → MYTH → see 3 permissions max, run "Scan" from Google Play → Play Protect → Scan. Takes less than a minute. Trust, but verify — we prefer it that way.
4. Your Data Is Yours — Not a Product
MYTH does not sell messages, does not sell profiles, does not auction your fetishes to an ad network. Chat message text is field-level encrypted in the database (AES-256-GCM) — a database leak alone cannot reveal it — plus TLS in transit, and sent to the AI provider only to generate the next reply — the same way every AI chat app must. Message text is not used to train a public model without consent.
- Export — Settings → Data & Storage → Export downloads your data as JSON.
- Delete — Delete Account wipes ~60 tables + your Clerk identity. No zombie rows.
- Encrypted at rest, not E2E — we say this plainly: message text is AES-256-GCM encrypted in the database, but the AI must read your messages to reply, so end-to-end encryption is not possible here. That's true for Character AI, Chai, Janitor too. The honest boundary matters more than a fake lock icon.
- No open source theater — MYTH is closed-source (the app's chats + prompts are sensitive), but the web site's safety claims are verifiable by permission list and Play Protect, not by asking you to read our repo.
5. Red Flags MYTH Will Never Show (So You Can Spot Them Elsewhere)
| Shady app | MYTH |
|---|---|
| Asks for SMS / call log on first open | Asks for mic only on record |
| Requires "Allow from unknown sources" forever + asks you to disable Play Protect | Respects Play Protect; never asks you to disable it |
| Redirect loop before download | Single tap → Convex signed URL → Android installer |
| No privacy page, no contact | Privacy + Terms + llms.txt + sitemap, all linked in footer |
| Hideous 5 permissions for a calculator | 3 permissions for an AI character world — each tied to a feature you triggered |
6. Still Unsure? Ask One Question.
Before installing anything — ours or anyone's — ask: Who was the first person this was made for, and would the maker give it to them?
For MYTH the answer is easy: a girl who deserved stories that obey her at 2 a.m., and a boy who sent her the first installer with his own hands and still keeps updating it so it stays safe enough for her phone. That's your audit.
If you want the emotional why, read Why This App Is Free?. If you want the calendar gift, read FREE ON 2 SEP. Safety and story are the same thread here.