SMS

Privacy

SMS Verification — Privacy Policy

What this app collects, why it collects it, and what you can ask us to delete.

Effective 9 September 2026. This policy explains what SMS Verification (the "app", bundle id com.smscode.verify) collects, why, who receives it and how long it is kept. The app gives you temporary virtual phone numbers that receive one-time verification codes from apps and websites.

Who we are

The app is published by GOWALK - FZCO. Questions and requests about this policy go through the support page linked from the app's store listing and from Settings → Support, or by email to the support page.

What the app collects and why

The app works without an account, email address or your own phone number.

| Data | Why it is used | Where it goes | | --- | --- | --- | | Anonymous installation identity: a random Firebase user id, a device-generated signing key and an install id | Recognises your installation, signs every request to our server and prevents replayed or forged requests | Our server (smsact.gowalk.com), Google Firebase Authentication | | Device attestation tokens (Firebase App Check: App Attest on iOS, Play Integrity on Android) | Confirms requests come from the genuine app | Apple or Google, Google Firebase, our server | | Numbers you request: service, country, the issued temporary number, its status, timestamps and provider cost | Provides the number, tracks the 20-minute window, refunds and your weekly allowance | Our server and our number provider, HeroSMS | | Text messages received on a temporary number, including any verification code | Shows you the code and pushes it to your device | Our server; delivered to your device through Apple Push Notification service or Firebase Cloud Messaging | | AI readings of received messages (code extraction, type, language, translation, a one-line instruction) and free-text service searches | Explains the message and finds the right service when a name does not match | Sent by our server to OpenRouter and the model it routes to; the message text is treated as untrusted data and is not used to train models under our data-collection-deny setting | | Subscription proof: Apple transaction id or Google purchase token, product id, expiry | Verifies your Pro subscription with Apple or Google before paid actions and caches the result | Our server (references stored encrypted), Apple App Store Server API, Google Play Developer API | | Push token | Delivers codes to your lock screen when you allow notifications | Our server, Apple or Google push services | | Favorites and recent services, appearance and copy-code preferences | Personalises the app | Favorites are mirrored to our server for export and deletion; other preferences stay on the device | | Usage analytics and crash reports (Firebase Analytics, Firebase Crashlytics): screen views, feature events such as number requested, code received, purchase, restore; device model, OS version, app version, crash traces | Understand aggregate use and fix defects | Google Firebase |

The app never reads your own SMS inbox, contacts, photos or location. Received messages are those sent to the temporary numbers you requested.

Payments

Subscriptions are sold and charged by the Apple App Store or Google Play. We never see your card or payment details. We receive only the store's proof of purchase needed to verify the subscription.

Retention

  • Installation identity, numbers, received messages and their AI readings are kept while your installation exists, so your history stays available in the app.
  • Request nonces are deleted after 15 minutes; rate-limit counters after 2 days; webhook logs keep only a 512-byte preview of the provider event.
  • Subscription proofs are refreshed at most every 24 hours and kept while the installation exists.
  • Firebase Analytics and Crashlytics retain data according to Google's Firebase retention settings (up to 14 months for analytics).
  • Our number provider keeps its own activation records under its terms.

Your choices and rights

  • Delete everything: Settings → Delete my data removes your installation, numbers, received messages, AI readings, favorites, push tokens and the subscription cache from our server immediately. Active subscriptions continue through the store until you cancel them there.
  • Export: Settings → Export my data shows all records our server holds for your installation.
  • Notifications: allow or revoke at any time in system settings; the app still shows codes when opened.
  • AI reports: every AI reading can be reported in the app; reports are reviewed and deleted after review.
  • Where required by law (including the GDPR and CCPA), you can also request access, correction, deletion or portability through the support page.

Security

Requests to our server are authenticated with Firebase Authentication, Firebase App Check, a per-installation signature and one-time nonces. Purchase references are encrypted at rest. Traffic uses HTTPS.

Children

The app is not directed at children under 16 and we do not knowingly collect data from them. It carries a 4+ / Everyone age rating: it has no objectionable content, no advertising, and no open browser — the only in-app web views are the onboarding and paywall pages served from our own origin, which cannot navigate anywhere else.

Changes

This page always shows the current policy; material changes are announced in the app's release notes.