Privacy policy

This policy explains what we collect when you use the service, why we hold it, and what we do with it.

What we collect

  • Account details. The username and email address you register with, and a hash of your password. We never store the password itself and cannot read it back. Your profile can also hold a display name and one contact handle — a Telegram username, for instance — both optional and both yours to change.
  • Usage records. The numbers issued to you, the services you ordered them for, order timestamps, prices charged and your balance history.
  • Messages. The text of SMS messages received by a number while it is rented to you. This is the product: we cannot deliver a verification code without holding it long enough to show it to you.
  • Payments. Deposit amounts, times and the transaction reference returned by our payment processor. Payment is made in cryptocurrency on the processor's own pages — we never see or store a card number, a wallet seed or a private key.
  • Technical data. IP address, browser user agent and request times, kept for security and abuse prevention.
  • Support messages. Anything you send us through the contact form, a support ticket or live chat.

We do not ask for an identity document, a postal address or payment card details, and you should not send them to us.

Why we hold it

To run your account and show you your codes, to take payment and keep your balance correct, to answer support requests, to detect fraud and abuse, and to meet a lawful request where one is properly made.

Who else sees it

  • Upstream number providers. Ordering a number passes the request to the carrier network that supplies it. They handle the number and the message itself.
  • Our payment processor. A deposit is handled by Cryptomus, under their own privacy policy.
  • Service providers we run the site on. Hosting, email delivery, live chat and analytics, each acting on our instructions.

We do not sell your personal data. Your account details, the numbers issued to you and the messages they receive are never handed to an advertiser — the measurement tools described below see page visits, not the contents of your account.

Cookies and analytics

A session cookie keeps you signed in — the site does not work without it. We also use analytics and advertising measurement tools that set their own cookies and record page views. You can block these in your browser without losing access to your account.

How long we keep it

Account and transaction records are kept while your account exists and for as long afterwards as we need them for accounting and fraud prevention. Received messages and expired numbers are retained only for a limited period and are then deleted.

Security

Passwords are stored hashed and cannot be read back, by us or by anyone with database access. API tokens are stored encrypted and can be rotated or deleted from your dashboard at any time, which cuts off anything using the old one immediately.

Anyone who can sign in to your account can read the codes it received, so use a password you have not used elsewhere.

Your choices

You can change your profile and your password from your dashboard, and rotate or delete an API token there. To change your email address or to have your account and its data deleted, contact support and we will do it. Deleting an account does not refund a remaining balance — see the terms.

Children

The service is not intended for anyone under 18 and we do not knowingly hold data about a child.

Changes

We may update this policy. Material changes will be announced on the site, and continued use after a change constitutes acceptance.

See also the terms and conditions, which cover payment and our no-refund policy.