Legal

Privacy Policy

Last updated 19 August 2026

1. Data we collect

Account data (name, email, optional phone, hashed password), API metadata (key prefix, hashed secret, usage timestamps) and verification records (channel, destination, purpose, status, timestamps, request IP).

2. What we never store

Plain-text passwords, plain-text API secrets and plain-text one-time passcodes are never written to the database or to log files. Only irreversible hashes are retained.

3. Why we process it

To deliver verification codes you request, to enforce quotas and abuse controls, to provide usage logs, and to secure accounts against fraudulent access.

4. Sharing

Destination addresses and numbers are passed to the delivery providers you configure (your SMTP server and your chosen SMS provider) strictly for delivering that message. We do not sell data or use it for marketing.

5. Retention

Verification records and API logs are retained for operational and audit purposes and can be deleted on request. Expired codes are unusable immediately after expiry regardless of retention.

6. Security

Prepared statements, hardened sessions, CSRF tokens, output escaping, layered rate limiting, HTTP security headers and TLS in transit.

7. Your rights

You may request access to, correction of, or deletion of your account and associated records by contacting badshahkumarmahto12@gmail.com.

8. Contact

Questions about this policy: badshahkumarmahto12@gmail.com.