Privacy Policy
Last updated February 4, 2026
This policy explains what data OTP collects, why, how long we keep it, and the choices you have. The short version: we collect the minimum needed to run the service, we never sell your data, and we transmit only the service-and-country pair you choose when sourcing a number — never your identity.
1.Who this policy covers
This policy applies to otp.black and the OTP account, wallet, and API services. It describes our practices as the operator of the service. It does not cover the independent third parties we rely on — payment processors and upstream number providers — each of which handles data under its own policies, as described below.
2.Data we collect
We deliberately collect little. Specifically:
- Account email. Used to sign you in, secure your account, send transactional notices, and contact you about the service.
- Wallet and transaction records. Your balance and a history of top-ups, charges, and refunds, kept for accounting and to show you your own activity.
- Received codes and SMS bodies. The one-time passcode and full message text delivered to a number you leased, so we can show it to you. This is retained for 24 hours after delivery, then permanently purged.
- API key hashes. If you create an API key we store only a one-way hash of it, never the raw key. A leaked key can be revoked but cannot be recovered from us.
- Minimal technical data. Standard server logs needed to operate and secure the service (for example, error and rate-limit events). We do not build advertising profiles.
3.What we do not do
- We do not sell or rent your personal data to anyone.
- We do not share your identity with upstream number providers — sourcing a number transmits only the service and country you selected.
- We do not use third-party advertising trackers or sell profiles to data brokers.
- We do not retain the content of your verification messages beyond the 24-hour window described above.
4.How we use your data
We use the data we collect only to:
- Provide the service — authenticate you, lease numbers, deliver codes, and run your wallet.
- Process payments and issue automatic refunds when a code fails to arrive.
- Secure the service, prevent fraud and abuse, and enforce our Terms of Service.
- Communicate with you about your account, transactions, and material changes to the service.
- Meet legal, accounting, and regulatory obligations.
5.Cookies
We use a small number of cookies, and none for advertising:
- Session cookie. A secure, HTTP-only cookie that keeps you signed in to the dashboard. It is essential to the service and cannot be disabled while you are logged in.
- Theme preference. A cookie or local storage value that remembers your light/dark choice so the site renders correctly on your next visit.
On the public marketing site we do not set advertising or cross-site-tracking cookies.
6.Upstream number providers
To source a number we send a request to an independent upstream provider. That request contains only the service and country you selected. It does not contain your email, your identity, or any account identifier. The provider returns a number and the incoming message; provider identity is anonymized before anything reaches you.
7.Payment processors
Card and cryptocurrency top-ups are handled by third-party payment providers. When you pay, your payment details are collected and processed by that provider under its own privacy policy — we receive only confirmation of the amount and status, never your full card number. We recommend reviewing the policy of the processor you choose at checkout.
8.Data retention
- Received codes and SMS bodies: 24 hours after delivery, then permanently purged.
- Revoked API keys: their hashes are retained for up to 90 days for security and abuse investigation, then removed.
- Account, wallet, and transaction records: kept while your account is active and for as long as needed to meet legal and accounting obligations.
- Server logs: kept only as long as needed to operate and secure the service.
9.Security
We apply industry-standard measures to protect your data, including encryption of sensitive credentials at rest, one-way hashing of API keys, HTTP-only session cookies, and strict internal access controls. No system is perfectly secure, but we design the service to hold as little sensitive data as possible and to delete what it no longer needs.
10.Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can delete most data by closing your account; to make any other request, contact us using the details below and we will respond within the time required by applicable law.
11.International transfers
The service and its providers may process data in countries other than your own. Where we transfer data internationally, we take steps to ensure it remains protected consistent with this policy and applicable law.
12.Children
The service is not directed to anyone under 18, and we do not knowingly collect data from children. If you believe a minor has provided us data, contact us and we will delete it.
13.Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected in the “last updated” date above and, where appropriate, communicated to you. Continued use of the service after an update means you accept the revised policy.
14.Contact
For any privacy question or request, contact us at [email protected]. We take every legitimate enquiry seriously and aim to respond promptly.