Last updated 24 September 2026
Privacy Policy
1. Our principles
PhoneBorn is a privacy product, so we hold ourselves to a simple standard: collect as little as possible, keep it only as long as needed, and never sell it.
- We do not ask for your name, address, date of birth, identity documents or personal phone number.
- We do not accept card payments, so we never hold card or bank details.
- We do not sell, rent or trade personal data, and we do not use third-party advertising trackers.
2. Information we collect
Account data. Your email address and a salted hash of your password (we never store the password itself). Optionally, a webhook URL you configure for the API.
Usage and order data. The numbers you buy or order, the services and countries selected, timestamps, renewal settings, refund requests and wallet transactions.
SMS content. The content of SMS messages received by your numbers and of SMS you send from them — this is the service you are paying for.
Call and SMS metadata. For every SMS and call: the other party's number, direction (incoming or outgoing), date and time, call duration and status, and message length. We use it to show your history, count your monthly allowance, apply the money-back guarantee and detect abuse. We do not record the audio of your calls.
Payment data. For crypto top-ups: the coin, network, amount, deposit address, invoice number and blockchain transaction hash. Blockchain transactions are public by nature; we do not attempt to link them to real-world identities.
Security logs. IP address and user-agent at sign-in and for security-relevant actions (password changes, API key creation), used to protect your account and prevent abuse.
Support messages. Anything you send us through the contact form, tickets or email.
Bot protection. Sign-up, sign-in and contact forms use Cloudflare Turnstile, which processes limited technical signals to distinguish humans from bots.
3. How we use it
- To create and secure your account and authenticate you (via a strictly necessary session cookie).
- To provision numbers, deliver incoming SMS and calls, send your outgoing SMS and connect your outgoing calls, and process renewals and refunds.
- To measure usage against your plan allowances and check money-back eligibility (whether a number has had any SMS or call activity).
- To credit crypto payments and produce invoices.
- To send essential service emails — verification codes, password resets, receipts and expiry notices.
- To detect and prevent fraud, spam, bulk messaging, robocalls, abuse and other violations of our Terms, including by applying automated rate limits to outgoing traffic.
- To answer support requests and improve the Service using aggregated, non-identifying statistics.
4. SMS content and call records
Messages sent and received on your numbers, and your call history, are stored so you can see them in your dashboard. They are visible only to you — and to authorised staff when needed to resolve a support request or investigate an abuse report. When a number is released, its messages and call records stay in your history until deleted under the retention periods below; they are never shown to a later holder of the number.
Calls are connected in real time and are not recorded. We do not listen to calls or read your messages for advertising or profiling.
6. Retention
- Account data: while your account is active; on deletion your email is anonymised immediately.
- SMS content (incoming and outgoing): up to 90 days after the number is released or the OTP order completes.
- Call and SMS metadata (numbers, direction, time, duration): up to 12 months, for billing accuracy, allowance tracking and abuse investigations.
- Security logs (IP addresses): up to 90 days.
- Wallet ledger, payment records and invoices: up to 5 years, as needed for accounting and fraud prevention.
- Support conversations: up to 2 years.
8. Security
Data is encrypted in transit (TLS). Passwords are hashed with a modern, salted algorithm; API keys are stored hashed and shown to you only once. Access to production systems is restricted and logged. No system is perfectly secure, so please use a unique password and keep your API keys private.
9. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. You can change your email and password and delete your account yourself in dashboard settings. For anything else, email [email protected] from your account email address and we will respond within 30 days.
10. Children
The Service is not directed to anyone under 18 and we do not knowingly collect data from children.
11. Changes
We may update this policy as the Service evolves. The "last updated" date reflects the latest version, and material changes will be announced on the website or by email.
Questions about this policy? Email [email protected] or use our contact form. See also our Terms of Service, Privacy Policy and Refund Policy.