Last updated 19 August 2026
Account data (name, email, optional phone, hashed password), API metadata (key prefix, hashed secret, usage timestamps) and verification records (channel, destination, purpose, status, timestamps, request IP).
Plain-text passwords, plain-text API secrets and plain-text one-time passcodes are never written to the database or to log files. Only irreversible hashes are retained.
To deliver verification codes you request, to enforce quotas and abuse controls, to provide usage logs, and to secure accounts against fraudulent access.
Destination addresses and numbers are passed to the delivery providers you configure (your SMTP server and your chosen SMS provider) strictly for delivering that message. We do not sell data or use it for marketing.
Verification records and API logs are retained for operational and audit purposes and can be deleted on request. Expired codes are unusable immediately after expiry regardless of retention.
Prepared statements, hardened sessions, CSRF tokens, output escaping, layered rate limiting, HTTP security headers and TLS in transit.
You may request access to, correction of, or deletion of your account and associated records by contacting badshahkumarmahto21@gmail.com.
Questions about this policy: badshahkumarmahto21@gmail.com.