Legal
Privacy policy
An inventory, not a disclaimer. Every line below says what exists on our side, where it lives and when it disappears.
The short version
- We never ask for a name, e-mail, phone number, address or document. There is no field for them anywhere.
- An account is a hash of your access key and a balance. That is the entire profile.
- Your messages and voicemail live in the panel because you need to read them. They are deleted when you delete them, and always when the line is released.
- We keep no IP addresses in application logs and run no analytics, pixels or third-party scripts.
- The blockchain is public and we cannot change that. What you paid from, and to which address, is visible to anyone: section 6, « Payments and the blockchain ».
- To a legal request we can hand over what exists, which is very little — and we say exactly what that is in section 8, « Requests from authorities ».
The summary is here to save you time, not to replace the text. Where the two disagree, the sections below are what applies.
1What we never collect
In shortNo identity of any kind, at any point, including later. There is no field for it, so there is nothing to leak.
These are not things we promise to handle carefully. They are things that do not exist on our side because nothing ever asks for them:
- Name, address, date of birth. No field, no optional field, no « verify later » step.
- E-mail address. None, not even for receipts or alerts. This is why there is no password reset and no e-mail notification anywhere in the product, including on the status page.
- A phone number to register. Buying a number does not require having one.
- Government ID, selfie, proof of address. No upload exists and none will be asked for later.
- Card or bank details. We take no card payments, so there is no processor file, no billing name and no chargeback record.
The practical consequence is on the other side of the ledger: we cannot recognise you, restore your access, or tell two customers apart. See section 9, « Your rights, without an identity ».
2What an account actually contains
In shortA hash of your access key, a balance, your lines and their settings. Nothing that points at a person.
Creating an access key writes exactly this:
- a SHA-256 hash of the 28-character key, which is what a login is checked against. The key itself is never stored, so we cannot read it, print it or return it;
- the balance and the ledger of what moved it: top-ups credited, lines ordered and renewed, messages sent;
- the lines you hold, with their country, type, expiry and the settings you chose (label, auto-renew, quiet hours, voicemail language, webhook URL, add-ons);
- a creation date, and for each session a token hash with the date it was opened and a short device label such as « Firefox on Linux », so you can sign other sessions out.
Deleting the account from the panel erases all of it, including messages and voicemail, and releases every line immediately. That is not a request queued for review; it happens on the click.
3Messages, calls and voicemail
In shortThey are stored because you need to read them. You delete them when you want; the line being released deletes everything anyway.
A message has to be stored somewhere between arriving and you reading it. Here is the whole lifecycle:
- Inbound SMS is written with its sender, body, arrival time and the extracted code. It stays until you delete it, or until the line is released.
- Outbound SMS keeps the same fields plus the delivery status the carrier returned.
- Call records keep the other number, the direction, the duration and the time. We do not record calls.
- Voicemail keeps the audio, the transcript and, with the add-on, the summary. All three are deleted 30 days after they arrive, automatically, whether or not you listened.
Releasing a line deletes its messages, its call records and its voicemail at the same moment the number goes back to the carrier. There is no archive and no soft delete: the rows are removed, and the next customer on that number never sees a trace of yours.
What we cannot delete is what left our system: a message you received was handled by at least one carrier before it reached us, and the person who sent it has their own copy.
4Technical logs
In shortThe web server logs requests without IP addresses, for 14 days. Error logs are separate and never carry message content.
A service that keeps no operational logs at all cannot be run or debugged, so we keep the minimum and cut what identifies:
- Access logs record the time, the path, the response code and the duration. The client IP address is not written — the field is dropped at the web server, before the line is composed. Logs rotate out after 14 days.
- Error logs record what broke and where in the code. They never contain message bodies, access keys, deposit addresses or webhook payloads.
- Rate limiting works on a short-lived hash held in memory, expiring in minutes, never written to disk.
Our edge provider terminates TLS and sees connection metadata, including IP addresses, as any network operator on the path does. We do not receive that data, we do not enable per-visitor analytics on it, and we do not correlate it with accounts. If that matters to you, reach the site over Tor or a VPN — both are welcome and nothing on the site treats them as suspicious.
5Cookies and scripts
In shortThree strictly necessary cookies for the panel. No analytics, no advertising, no third-party script, no consent banner because there is nothing to consent to.
The site sets three cookies and they all do work you asked for:
nkp_s— your session, so the panel knows you are signed in. Expires after 30 days or when you sign out.nkp_c— a token that protects forms against cross-site submission. Required for the panel to accept anything.nkp_f— a short-lived cookie that carries a one-off message such as « Top-up credited » across a redirect.
There is no analytics cookie, no advertising identifier, no fingerprinting, and no third-party script of any kind: every script, font and image on this site is served from this domain. That is why you have never seen a cookie banner here — we have nothing to ask permission for.
6Payments and the blockchain
In shortWe generate a one-time address and watch it. The chain is public and permanent, which is the part we cannot protect you from.
A top-up creates a deposit address used once. We store the address, the coin, the expected amount, what arrived and when. We do not store where it came from beyond what the chain itself shows, and we ask for no wallet identity.
The honest warning: a public blockchain is a permanent record.
- Anyone can see that an address paid our deposit address, for how much, and when. Chain analysis firms do exactly this.
- If the coins you paid with came from an exchange that knows who you are, the link between that identity and this payment is visible to whoever can read both sides.
- Monero does not have this problem in the same way, which is why we accept it and why we settle to it. If the payment trail is your concern, pay in XMR directly.
We use a payment relay to generate addresses and watch confirmations. It receives the address, the coin and the amount, and a site reference. It never receives your access key, your lines or your messages.
7Who else touches anything
In shortCarriers that deliver the messages, the edge that serves the pages, the payment relay. That is the whole list, and none of them gets an identity because none exists.
We use as few third parties as a phone service can:
- Carriers and numbering operators, one or more per country. They allocate the range and deliver traffic, so they necessarily see the numbers involved and the message content in transit. They are bound by their own licences and by our contracts; they receive no customer identity from us because we hold none.
- Our edge and DNS provider, which terminates TLS and serves static files. It sees requests and IP addresses as any network on the path does.
- The payment relay described in section 6, « Payments and the blockchain ».
- AI transcription and translation, when a line has voicemail transcription or an AI add-on switched on. Audio and text are processed for that purpose and are not used to train anything. A line with the add-ons off never sends audio anywhere.
There is no advertising network, no analytics vendor, no CRM, no e-mail provider and no data broker in that list, and there will not be. We do not sell, rent or share data with anyone, in any form, including aggregated, because the interesting fields do not exist to aggregate.
8Requests from authorities
In shortWe answer lawful orders with what exists. What exists is an account hash, a balance ledger, line metadata and any message still in the panel. There is no identity to hand over.
We are not above the law and we do not pretend otherwise. When a competent authority sends a valid, properly served order, we check it and comply with what it actually covers.
What we can produce, at most:
- that a given number is or was active, and the dates;
- the ledger for the account holding it: top-ups, orders, renewals, with amounts and times;
- the deposit addresses generated for it and what arrived on them;
- messages, call records and voicemail still present in the panel at the moment the order arrives.
What we cannot produce, because it does not exist: a name, an e-mail address, a billing identity, a card, a home address, an IP address from our application logs, or anything you deleted before the request arrived. We do not create new logging in response to a request unless an order specifically and lawfully requires it.
We narrow overbroad requests, refuse ones that are not validly served, and tell the affected customer in the panel unless the order forbids it. Abuse and law-enforcement channels are on the contact page.
9Your rights, without an identity
In shortAccess, export and erasure are all buttons in the panel, and they work instantly. We cannot serve a request by e-mail because we cannot tell it is you.
Data protection law gives you rights of access, portability, correction and erasure. We have implemented them as controls rather than as a request queue:
- Access and portability. The panel and the API expose everything we hold about the account. Export it whenever you want, in JSON.
- Correction. Every field you can set — labels, settings, add-ons — is editable by you. We hold no field about you that you cannot see.
- Erasure. Delete a message, a voicemail, a line, or the whole account. All of it is immediate and irreversible.
The limit is identification: proving that a request by message comes from the holder of an account would require the very identity we refuse to collect. So we do not act on data requests sent outside the panel, because doing so would mean handing one person's data to whoever asked convincingly. Holding the access key is the only proof there is, and if you hold it, you can do all of the above yourself in seconds.
10Changes to this policy
In shortAnnounced in the panel 30 days ahead when they widen what we collect. Immediately when they narrow it.
If a change widens what we collect or keep, we post it here and announce it in the panel at least 30 days before it takes effect, so you can leave first. If a change narrows it, or only clarifies wording, it applies as soon as it is posted, and we still date it.
Previous versions are kept and sent on request. Questions about anything on this page go to contact and are answered by a person, with the section number.
The full name and registered address of the operating entity are provided on request through contact, and to any authority that asks through the channel described in that page.
This document was last changed on 21 September 2026 and applies from 21 September 2026. Previous versions are kept and sent on request. Questions about any clause go to contact — we answer them in plain words, with the clause number.
Any of this a dealbreaker?
Better to know now.
Everything above describes what actually happens. If it fits, a line is live about a minute after you pay.