otpmock is built to hold as little data as possible, for as short a time as possible. This policy explains what we collect, why, who we share it with and what you can ask us to do. "otpmock", "we" and "us" means the operator of otpmock.com and api.otpmock.com, who is the data controller for the account data described below and can be reached at support@otpmock.com.
The short version
- Messages you send to the API are deleted after 10 minutes.
- We don't use analytics, advertising or tracking cookies.
- We don't sell your data, and we don't use it for anything other than running otpmock.
- Payments are handled by Creem. We never see your card details.
What we collect
| Data | Why | How long |
|---|---|---|
| Account data: your email address and plan | To run your account, send you service emails and support you | Until you delete your account |
| API keys | To authenticate requests. We store a hash, not the key itself, wherever we can | Until you revoke the key or delete your account |
| Usage counts: messages per month per account | To apply plan limits and bill correctly | Up to 24 months |
| Test messages: phone numbers, message text, extracted codes and verification state you send to the API | To let your tests and live inbox read them | 10 minutes, then deleted automatically |
| Billing data from Creem: name, email, country, subscription status | To know which plan you're on | As long as tax and accounting law requires |
| Technical logs: IP address, request time and path, kept by our hosting provider | To keep the Service secure and fix problems | Short-term, under Cloudflare's retention |
| Support emails you send to support@otpmock.com | To answer you | Up to 24 months after the conversation ends |
The test messages you send are controlled by you. Please use made-up phone numbers and test content; the Service is not meant to receive real people's data (see our Terms). Where you do send personal data in test messages, we process it on your behalf and only to provide the Service.
Legal bases
If you are in the EU, the UK or another place with similar law: we process account, usage and billing data to perform our contract with you; technical logs and security measures under our legitimate interest in keeping the Service safe; and billing records to meet legal obligations. Turkish users are covered on equivalent grounds under Law No. 6698 on the Protection of Personal Data (KVKK).
Who we share data with
- Cloudflare hosts the website and API, stores data and forwards support email.
- Creem (creem.io) is our Merchant of Record and processes payments, invoices and taxes. Creem handles your payment details under its own privacy policy.
These providers may process data outside your country, including in the United States, under safeguards such as Standard Contractual Clauses. We share data with authorities only when the law requires it.
Cookies and local storage
We don't use tracking or advertising cookies. When you sign in we may set one strictly necessary cookie to keep you signed in. The live inbox remembers your API key in your browser's local storage so you don't have to paste it each time; it never leaves your browser except to authenticate requests to our API. You can clear it from your browser at any time.
Security
All traffic uses HTTPS. Each account's messages are stored separately from every other customer's, and test data expires after 10 minutes. No system is perfectly secure; if we learn of a breach affecting your data, we'll notify you without undue delay.
Your rights
You can ask us to access, correct, export or delete your personal data, or object to or restrict how we use it. Email support@otpmock.com from your account email and we'll reply within 30 days. You can also complain to your local data protection authority.
Children
otpmock is a developer tool and isn't meant for anyone under 18.
Changes
If we change this policy in a meaningful way, we'll update the date above and email account holders before the change takes effect.