The short version
Never collected
- Your name
- An email address
- A password
- A phone number for you
- A company or tax number
- Any identity document
- A card or bank account
- Third-party analytics or advertising identifiers
Held while you use the service
- A SHA-256 hash of your account token
- Your balance and its ledger
- Campaigns you created, with their recipient lists and text
- Delivery results per message
- Deposit records and the coin used
- API key hashes and their last-used time
Your account
Your account is a 160-bit token your browser generates locally. It is sent to us only to be hashed and compared; the column in our database is a SHA-256 digest. A copy of that database logs into nothing, which is the same property that means we cannot help you if you lose the token.
There is no email address, no password and no profile — not as a setting you can turn off, but because no field exists to hold them. Nothing on this platform links two of your accounts together, and nothing links an account to a person.
Messages and lists
Campaign text, recipient numbers and per-message delivery results are stored because the dashboard has to show them back to you and the ledger has to be explainable. They are visible to your account and to nobody else's.
-
Deleting a campaign deletes its recipients and its text. The ledger line survives as an amount and a timestamp, because a balance with unexplainable movements is worse than useless.
-
We do not sell, rent or share recipient lists. There is no second party in this business model to share them with.
-
Recipient numbers necessarily reach carriers. Delivering an SMS means handing the number to the network that owns it; that is what delivery is.
Payments
Deposits are settled through a crypto payment orchestrator. We record the invoice, the coin, the amount, the address issued to you and the confirmation state — enough to credit your balance and to explain a ledger line later.
There is no card processor and no bank in this path, so no statement, no billing address and no cardholder name exists anywhere in our records. What happens on a public blockchain is public by design and is outside our control; Monero is the option with no public transaction graph.
Technical data
-
Web server logs record requests, including the address they came from, and are kept briefly for abuse and capacity work.
-
Cookies: one session cookie once you sign in, and nothing else. The marketing pages set no cookie at all, including the support form.
-
No third-party analytics. No Google Analytics, no advertising pixel, no session recorder, no external font or script that would report your visit to somebody else.
-
An anonymous presence signal counts concurrent visitors across the network of sites. It carries no identifier, sets no cookie, and honours Do Not Track.
-
The support form keeps a hash of the address it was sent from, to spot a flood. The address itself is not stored.
Third parties
Three, and each one is here because the service cannot work without it.
- Mobile carriers and aggregators — receive the recipient number and the message, because that is delivery.
- The payment orchestrator — receives the deposit amount and coin, and returns an address. It is not told who you are, because we do not know.
- A CDN and DNS provider — terminates TLS and serves this page, and therefore sees the request.
No data broker, no advertising network, no analytics vendor, and no “trusted partner” category that expands quietly over time.
Legal requests
A demand for “everything you hold on this customer” can be answered honestly and completely, and the honest complete answer is a token hash, a balance, and whatever campaigns that account has not deleted.
There is no name to hand over, no email address, no payment card, no address and no phone number, because none of it was ever collected. This is not a promise about how bravely we would resist such a request — it is a description of a database that does not contain the answer.
Where a valid order compels production of what does exist, we comply with what exists. We do not build new collection to satisfy one.
Deletion
-
Delete a campaign and its recipients and message text go with it.
-
Abandon the token and the account becomes unreachable to everyone, including us. There is no recovery path, by construction.
-
Ask us to erase an account from support with its reference and we will remove the row and its campaigns.
Conventional data-subject rights — access, portability, rectification — assume a provider that can identify you. Here the dashboard already shows you everything associated with your account, and no third party could ever be told who you are, because nobody knows.