Privacy Policy

Effective August 25, 2026 Last updated August 25, 2026 v1.0 See Terms of Service →

TL;DR — not a substitute for reading the real thing below

  • We collect what running the Service requires: your account details, order and wallet history, and basic technical logs. No card numbers — we don't take cards.
  • An order shares only what's needed with the provider that fulfils it: the service, the country, and enough to know where to route the code back to.
  • SMS content is purged on a short, fixed schedule after delivery — see §3. We're not building a permanent archive of the messages that pass through your numbers.
  • We don't run third-party ad trackers or sell your data. A small analytics tool tells us aggregate usage, not who you are.
  • You can ask for a copy of your data or ask us to delete it. See §9.

Questions before you agree? support@smsrouter.app

On this page

    01 — introduction

    Introduction

    This Privacy Policy explains what SMSRouter ("we", "us") collects when you use smsrouter.app, our dashboard, and our API (the "Service"), why we collect it, how long we keep it, and the choices you have. We built the Service to route SMS verification through other companies' infrastructure — that shapes this policy more than a typical one, because some of what happens to your data happens on a provider's network, not ours.

    Questions at any point: support@smsrouter.app, or the dashboard's live chat.

    03 — information we collect

    Information we collect

    Account information

    Your email address, a hashed password (we never store it in plain text), and any API keys you generate, stored as a salted hash — we can't read a key back out once it's issued.

    Order & wallet activity

    Which service and provider you ordered, the number you were issued, price paid, and order status. On the wallet side: top-up amounts, the crypto network and transaction hash for each deposit, and your running balance. We don't process card payments and don't store card numbers, because the Service doesn't accept cards.

    SMS content

    The text of a code delivered to a number you ordered is stored just long enough for you to read and copy it, then purged on a fixed schedule — 30 days after delivery, or immediately once you delete the order from your history, whichever comes first.

    Technical & log data

    IP address, browser and device type, timestamps, and API request metadata — see §5.

    Support & contact data

    Anything you send us directly — a support ticket, a live-chat message, an email — including any attachments you choose to include.

    04 — how we use your information

    How we use your information

    • Operate the Service: route your orders, hold your wallet balance, and deliver codes to your dashboard and webhook.
    • Improve provider routing — success-rate and delivery-speed data feeds the "best success" and "fastest" strategies.
    • Prevent fraud and abuse, and enforce the acceptable-use section of our Terms.
    • Send transactional email: balance alerts, order confirmations, security notices. Not marketing unless you opt in.
    • Respond to support requests and security reports.
    • Meet legal, tax, and accounting obligations.
    • Debug and secure the Service itself.

    05 — log files

    Log files

    Like most web services, our servers keep standard logs — IP address, browser type, referring page, timestamps, and pages requested — generated automatically by normal HTTP traffic. We use these for analytics, capacity planning, and diagnosing abuse; they aren't linked to anything beyond what a request itself reveals unless you're signed in, in which case they're associated with your account for security purposes.

    06 — cookies & similar technologies

    Cookies & similar technologies

    We use a small number of essential cookies to keep you signed in and remember interface preferences — like the CRT-mode toggle in the footer — plus a lightweight, privacy-respecting analytics script that reports aggregate usage (which pages, how often) without building an ad profile of you. You can block cookies in your browser; the dashboard requires the session cookie to keep you signed in, so blocking everything will log you out between visits.

    07 — advertising partners

    Advertising partners

    We don't run third-party ad networks or retargeting pixels on the Service, and we don't sell your data to anyone for their own advertising. If that ever changes, this section — and the consent this policy relies on — changes with it under §11, not silently.

    08 — third-party privacy policies

    Third-party & provider privacy policies

    Fulfilling an order necessarily shares a slice of it with the provider assigned to that order — TextVerified, SMSPVA, GetAText, FoxSims, kiwiSMS, SMSPool, or MajorPhones — limited to the service and country requested, so they can issue the number and forward the code. Once a provider issues a number, that provider's own network and privacy practices govern how the underlying carrier data behind it is handled; we encourage you to review a provider's policy if you want the full picture of that leg of the journey.

    Wallet top-ups are processed by our own crypto payment rail; a deposit's on-chain transaction is, by the nature of the networks involved (BTC, ETH, LTC, USDT, USDC), publicly visible on that network's ledger regardless of anything we do.

    09 — your rights

    Your rights

    Wherever you're located, we extend the same core set of rights over your data:

    • Access — request a copy of the personal data we hold about you.
    • Rectification — ask us to correct data that's inaccurate or incomplete.
    • Erasure — ask us to delete your account and associated data, subject to what we're required to keep for accounting or legal reasons.
    • Portability — get your data in a structured, machine-readable format.

    Send a request to support@smsrouter.app; we respond within one month. We may ask for information to confirm you're the account holder before acting on a request.

    10 — children's information

    Children's information

    The Service is not directed at, and we don't knowingly collect information from, anyone under 18. If you believe a child has created an account or otherwise given us data, contact support@smsrouter.app and we'll remove it.

    11 — changes to this policy

    Changes to this policy & contact

    We may update this policy as the Service evolves. We'll post the new effective date at the top of this page and, for a material change to how we collect or use your data, email the address on your account at least 15 days before it takes effect.

    Privacy questions, a rights request or a security report: support@smsrouter.app.

    This policy sits alongside the Terms of Service — together they're the whole agreement.

    Create an account