§ Legal

Privacy Policy

Last updated: October 8, 2026

otpmock is built to hold as little data as possible, for as short a time as possible. This policy explains what we collect, why, who we share it with and what you can ask us to do. "otpmock", "we" and "us" means the operator of otpmock.com and api.otpmock.com, who is the data controller for the account data described below and can be reached at support@otpmock.com.

The short version

What we collect

DataWhyHow long
Account data: your email address and planTo run your account, send you service emails and support youUntil you delete your account
API keysTo authenticate requests. We store a hash, not the key itself, wherever we canUntil you revoke the key or delete your account
Usage counts: messages per month per accountTo apply plan limits and bill correctlyUp to 24 months
Test messages: phone numbers, message text, extracted codes and verification state you send to the APITo let your tests and live inbox read them10 minutes, then deleted automatically
Billing data from Creem: name, email, country, subscription statusTo know which plan you're onAs long as tax and accounting law requires
Technical logs: IP address, request time and path, kept by our hosting providerTo keep the Service secure and fix problemsShort-term, under Cloudflare's retention
Support emails you send to support@otpmock.comTo answer youUp to 24 months after the conversation ends

The test messages you send are controlled by you. Please use made-up phone numbers and test content; the Service is not meant to receive real people's data (see our Terms). Where you do send personal data in test messages, we process it on your behalf and only to provide the Service.

Legal bases

If you are in the EU, the UK or another place with similar law: we process account, usage and billing data to perform our contract with you; technical logs and security measures under our legitimate interest in keeping the Service safe; and billing records to meet legal obligations. Turkish users are covered on equivalent grounds under Law No. 6698 on the Protection of Personal Data (KVKK).

Who we share data with

These providers may process data outside your country, including in the United States, under safeguards such as Standard Contractual Clauses. We share data with authorities only when the law requires it.

Cookies and local storage

We don't use tracking or advertising cookies. When you sign in we may set one strictly necessary cookie to keep you signed in. The live inbox remembers your API key in your browser's local storage so you don't have to paste it each time; it never leaves your browser except to authenticate requests to our API. You can clear it from your browser at any time.

Security

All traffic uses HTTPS. Each account's messages are stored separately from every other customer's, and test data expires after 10 minutes. No system is perfectly secure; if we learn of a breach affecting your data, we'll notify you without undue delay.

Your rights

You can ask us to access, correct, export or delete your personal data, or object to or restrict how we use it. Email support@otpmock.com from your account email and we'll reply within 30 days. You can also complain to your local data protection authority.

Children

otpmock is a developer tool and isn't meant for anyone under 18.

Changes

If we change this policy in a meaningful way, we'll update the date above and email account holders before the change takes effect.