Privacy Policy
This page explains what data Otply processes, why, and how long it is kept. If anything is unclear, write to support@otply.store.
1. Data we process
| Data | Why |
|---|---|
| Email address | To create your account and sign you in. It is the only identifier we hold. |
| Password | Stored only as a bcrypt hash. We cannot read it either. |
| Language preference | To send notifications in the right language. |
| Numbers you buy | Service, country, number, date, credits paid — for your history and our accounting. |
| Received SMS code | To show it in the app. Deleted after seven days. |
| Purchase records | Store transaction id and credits granted. Your card details never reach us. |
| IP address | Only for abuse prevention and rate limiting. Not stored permanently. |
| Push notification token | To notify you when a code arrives. |
We do not access advertising identifiers, location, contacts, photos or anything similar. The app contains no third-party advertising or analytics trackers.
2. Who we share with
- Number provider (HeroSMS). The service and country you pick are sent to the provider; the number and the incoming SMS reach us through them. Your email and account details are never shared with the provider.
- Apple and Google. Credit purchases go through the stores. They process your payment details; we only receive confirmation that the purchase is valid.
- Hosting provider. Our infrastructure provider stores the data on our behalf.
We never sell your data and never pass it to third parties for marketing.
3. Retention
| Data | Kept for |
|---|---|
| Received SMS code | 7 days, then deleted automatically |
| Idle push notification token | 180 days |
| Session tokens | 30 days after expiry |
| Account data | Until you delete your account |
| Transaction and number records | Retained after deletion but unlinked from your identity (accounting obligation) |
4. Deleting your account
In the app go to Profile → Delete my account. See the account deletion page for details.
5. Your rights
Under the Turkish Personal Data Protection Law (KVKK, art. 11) and the GDPR you may access your data, ask for correction or deletion, restrict processing, and receive your data in a portable form. Write to support@otply.store; we respond within 30 days at the latest.
6. Security
All connections are encrypted (HTTPS). Passwords are bcrypt-hashed and session tokens are stored hashed, never in plain text. No system is perfectly secure, so please use a strong password unique to this account.
7. Children
Otply is not directed at anyone under 18 and we do not knowingly collect data from them.
8. Changes
If this policy changes the date above is updated; for significant changes we also notify you in the app.
9. Contact
Data controller: Otply · support@otply.store
Note: This text reflects the app’s actual data flows but is not legal advice. Have a lawyer review it before publishing; you may need to add your registered company name, address and data-protection registration details.