Privacy policy
What textsms.io stores, why, and for how long.
When you register: your email address, a username, and a password. A name and phone number are optional and only stored if you provide them. When you use the service: your wallet balance and transactions, and a record of each rental: the service, the number issued, the code received, the price and the time. If you use the API: your API key, and any webhook URL and signing secret you configure.
We do not ask for identity documents, and we do not require your real name to rent a number. We do not read, store or forward any message content beyond the verification code itself.
Passwords are stored hashed, never in a form we can read. Nobody at textsms.io can tell you what your password is, which is why a reset is the only way to recover an account.
The code sent to a rented number is stored against that rental so you can see it in your history, and is sent to your webhook if you have configured one. It is visible to you and to anyone holding your API key. Treat the key accordingly.
Numbers are supplied by a third-party provider. To rent one we tell them which service and country you want, never who you are. Payment processors handle their own payment data under their own policies; we do not store card details.
If you configure a webhook, we send rental events, including the code, to the URL you give us, signed so you can verify they came from us. You choose that destination and are responsible for it. We do not send to private or internal addresses.
We use a session cookie to keep you logged in, and store your light or dark theme preference in your browser. No advertising or cross-site tracking cookies.
Account and rental records are kept while your account is open, and afterwards only as long as needed for accounting and fraud prevention. Webhook delivery logs are kept for a short period so failed deliveries can be investigated, then deleted automatically.
You can view your rental history and wallet activity at any time from your account, rotate or disable your API key, remove your webhook, and request that your account be closed. Contact support to request closure or a copy of your data.
The site is served over HTTPS, passwords are hashed, API keys can be rotated instantly, and webhook payloads are signed. No system is perfectly secure; if we become aware of a breach affecting your data we will say so.
This policy may change. Material changes will be reflected here.