SmsNoKYC Privacy Statement
Anonymity is the default at SmsNoKYC. One seed phrase opens your account. We never ask for an email address, a name, a phone number, or any identity document.
1. The Records We Keep
Identity plays no role here. To operate anonymous accounts, settle payments, fulfil orders, block abuse, and measure aggregate traffic, SmsNoKYC retains a minimal set of technical records:
- Account row: a bcrypt hash of your access seed together with a 4-character lookup prefix. The plain seed never touches our storage.
- Payment and order rows: what was ordered, the deposit amount, the coin used, the on-chain transaction ID, timestamps, and the resulting balance.
- Session entry: a short-lived server-side identifier that keeps you logged in, tied to nothing personal.
- Anti-abuse entry: transient IP rate-limit counters that stop brute-force attempts and erase themselves automatically.
2. What We Never Collect
- Your name, your email, your phone number
- Street address or GPS coordinates
- Passports, ID cards, or any KYC paperwork
- Ad pixels or cross-site retargeting profiles
3. Why Those Records Exist
Each record serves exactly one of these operational jobs:
- Verifying that a seed matches an account
- Executing number orders and delivering codes
- Tracking balance movements and deposit history
- Stopping abuse through rate limits and fraud checks
- Keeping the platform stable and making it better
Nothing identity-related is ever sold, rented, or handed to marketers. There is nothing of that kind in our systems to begin with.
4. Cookies and Browser Storage
Two cookie families exist on smsnokyc.com: authentication cookies that keep your session alive, and first-touch attribution cookies that tell us which channel produced a signup, top-up, or order — without ever revealing who you are.
- Login cookies carry the secure and HTTP-only flags and exist purely for account access
- Attribution cookies hold the traffic source, referrer, landing URL, and a timestamp — nothing more
- The live visitor widget writes anonymous visitor and session IDs to local browser storage
- The presence beacon respects the Do Not Track signal
Google Analytics runs in aggregate-only mode for pageview and conversion counts. No ad pixels, no retargeting scripts, no data-broker tooling — ever.
5. External Systems We Talk To
A small set of outside systems is contacted, each for a single operational reason:
- Blockchain networks such as Bitcoin, Ethereum, and TRON — used to confirm incoming crypto deposits. Anything written to a public chain is visible to everyone by design.
- Telecom and SMS suppliers — they provision the virtual numbers and relay incoming messages, so number assignments and SMS text transit their infrastructure.
- Exchange-rate APIs — polled for live crypto pricing so deposits convert at current market value.
- Google Analytics, limited to aggregate traffic and conversion counting
6. How Long Records Live
- Account row: kept for the life of the account. Skip logging in for 12 months or more and the account becomes eligible for deletion.
- Orders and payments: stay attached to the account so you can consult your own history.
- Rate-limit counters: self-destruct within one hour.
- Message content: held only briefly and cleared once an order completes or expires.
7. Safeguards
- Every connection to the site runs over TLS encryption.
- Seeds exist in storage only as bcrypt hashes — never in readable form.
- Session state lives in server-side Redis, out of reach of the browser.
- Every state-changing request must carry a valid CSRF token.
8. What You Control
Because no identity is attached to an account:
- Walking away is instant — just stop logging in.
- Identity-based deletion requests cannot exist here, since the seed is the only proof of ownership we can accept.
- Accounts left dormant long enough are wiped on their own.
9. Policy Updates
This policy can change whenever needed. The Last updated stamp above always marks the active version, and continuing to use SmsNoKYC means you accept it.