Legal document

Privacy Policy

Effective Date and Scope

This Privacy Policy explains how 2nd Line collects, uses, stores, shares, and protects information when you use the mobile app, backend services, admin tools, support channels, telecom features, subscriptions, token purchases, virtual numbers, messaging, calling, and one-time verification number features. This document is provided in English.

Information You Provide

We may collect information you provide directly, including name, email address, password credentials handled through authentication providers, date of birth or age confirmation, real phone number for verification, support messages, abuse reports, account deletion requests, business or website information if required for compliance, and any information you choose to submit in forms or support conversations.

Authentication and Account Data

When you sign in, we may process Firebase Authentication identifiers, Google Sign-In identifiers, Apple Sign-In identifiers, email verification status, provider IDs, display name, email address, account creation time, last sign-in time, verified phone number status, and related authentication metadata. We use this data to create accounts, authenticate you, prevent account takeover, enforce policy, and support account recovery.

Telecom and Usage Data

When you use telecom features, we may process virtual numbers assigned to you, destination numbers, sender and recipient routing data, call timestamps, call duration, call status, message timestamps, delivery status, carrier or provider error codes, country, region, number type, one-time code activation records, provider transaction IDs, token charges, cancellation records, refund records, and abuse-risk signals. Message or code content may be processed and stored when needed to display it to you, deliver the feature, investigate abuse, handle support, or comply with law.

Device, Network, and Security Data

We may collect device identifiers or installation identifiers, IP address, approximate location derived from IP or device settings, locale, app version, operating system, device model, push notification tokens, crash data, diagnostics, analytics events, screen interaction metadata, request metadata, rate-limit counters, fraud signals, and logs. Firebase Analytics may help us understand usage patterns such as active users, screens viewed, feature engagement, app version adoption, and retention. Firebase Crashlytics may collect crash reports, stack traces, device state, operating system details, app version, and limited identifiers needed to diagnose failures. These help us secure accounts, detect automated behavior, prevent repeated abusive signups, enforce country and provider restrictions, improve reliability, and troubleshoot failures.

Advertising, AdMob, and Privacy Choices

The app may use Google Mobile Ads SDK, Google AdMob, and Google User Messaging Platform (UMP) to show optional rewarded ads and to manage advertising privacy choices. Google, AdMob, and their advertising technology partners may process data such as the device advertising identifier where available, IP address, approximate location, device and app information, ad request data, ad impressions, ad clicks, reward events, consent signals, and other information needed for ad delivery, fraud prevention, frequency capping, aggregated reporting, and ad measurement. Depending on your region, consent choices, device settings, and Google policies, ads may be personalized, non-personalized, or limited. Where required, the app requests or refreshes advertising consent before requesting ads and provides an in-app advertising privacy choices entry point when Google UMP indicates that one is required. You can also use your device or Google settings to reset, delete, or limit use of your advertising identifier where supported.

Rewarded Ads and Token Rewards

Rewarded ads are optional. If you choose to view a rewarded ad, we create a signed server-side reward session before the ad is shown and may send a non-sensitive session identifier and account identifier to Google AdMob for server-side verification. Tokens granted for rewarded ads are non-cash, non-transferable, usable only inside 2nd Line, and are granted by us, not by Google. A reward is added only after the required ad action is completed and verified. If the ad is skipped, dismissed, unavailable, fails to load, fails verification, or is rejected by anti-abuse checks, the token reward may not be granted. We may limit rewarded ad availability by account, device, time window, region, risk signals, or provider response to prevent fraud and invalid activity.

Sponsored Videos and External Links

The app may show optional sponsored, promoted, or editorial video cards that link to external services such as YouTube. These cards are labeled in the app and may be configured through our admin tools. A card may load a public thumbnail or preview image from YouTube, Google, or another external host. If you choose to open the video or external link, the destination service, browser, or YouTube app may process information such as your IP address, device and browser details, interaction with the link, cookies or identifiers, and account state under their own privacy policies. We do not send your SMS content, call content, telecom routing details, verification-code content, or private account messages to a sponsor through these video cards.

Contacts and Permissions

If you choose to pick a number from your contacts, the app may request contacts permission only for that user-initiated action. Contact data should be used to fill the selected recipient field and is not required for basic browsing. Microphone permission may be requested for voice calls. Notification permission may be requested for incoming call, incoming SMS, support, or account notifications. Permission availability and prompts depend on the operating system.

Purchases and Subscriptions

Purchases may be processed by Google Play Billing, Apple App Store billing, RevenueCat, and related payment infrastructure. We may receive purchase tokens, product identifiers, entitlement status, renewal status, cancellation status, transaction IDs, price region, and subscription metadata. We do not receive full card numbers from app stores. We use purchase data to grant tokens, subscriptions, entitlements, refunds where applicable, and billing support.

Third-Party Providers and External APIs

We may share or receive data with Firebase Authentication, Firebase Cloud Functions, Cloud Firestore, Firebase Cloud Messaging, Firebase Analytics, Firebase Crashlytics, Google Cloud, Google Sign-In, Sign in with Apple, Google Play, Apple App Store, RevenueCat, Google Mobile Ads SDK, Google AdMob, Google User Messaging Platform, Google advertising technology partners where applicable, YouTube, Google-hosted video or thumbnail services, sponsored or promoted video link destinations, Twilio, Grizzly SMS, telecom carriers, hosting providers, logging providers, support systems, app store review systems, and security tools. Data is shared only as needed for authentication, push delivery, telecom routing, verification-code activation, billing, rewarded ads, ad consent management, sponsored or promoted link display, analytics, support, security, compliance, fraud prevention, debugging, reliability monitoring, or legal obligations.

How We Use Information

We use information to operate the Service, authenticate users, provide numbers, send and receive SMS, place and receive calls, show verification codes, calculate token charges, process purchases, show optional rewarded ads, verify ad rewards, provide support, enforce acceptable use rules, prevent fraud, detect spam, respond to abuse reports, improve reliability, comply with provider and app store rules, maintain financial records, respond to lawful requests, and protect users, recipients, providers, and the platform.

Content Filtering and Abuse Prevention

We may scan or evaluate usage patterns, destinations, provider error codes, message categories, links, keywords, velocity, country, device, IP address, and account history to prevent fraud, spam, phishing, harassment, illegal activity, and provider abuse. We may block or review messages, calls, activations, accounts, or numbers when risk signals indicate potential misuse.

Legal Bases Where Applicable

Depending on your location, we may process data because it is necessary to provide the Service, perform a contract, comply with legal obligations, protect vital or public interests, prevent fraud and abuse, resolve disputes, enforce our Terms, or because you gave consent. You may withdraw consent for optional features such as certain permissions, but some services may stop working without required data.

Retention

We keep ordinary account profile data while your account is active. Telecom traffic records, provider transaction records, token records, purchase records, security logs, device and IP risk logs, support tickets, abuse reports, deletion requests, and compliance evidence may be retained after account deletion where needed for fraud prevention, billing, tax, provider reconciliation, legal claims, audits, dispute handling, or lawful requests. Retention periods may vary by record type, provider requirement, legal requirement, and risk level.

Account Deletion and Data Removal

When you request account deletion, we delete or anonymize ordinary profile data where reasonably possible. We may preserve limited records such as verified phone hashes, account identifiers, device/IP risk records, purchase records, virtual number assignments, message and call metadata, provider transaction IDs, abuse reports, support history, deletion action logs, and legally required records. This preservation helps prevent repeat abuse, handle disputes, and answer lawful inquiries about specific numbers or incidents.

Law Enforcement and Legal Requests

If a competent authority, court, provider, app store, payment processor, or legal process requests information related to a number, message, call, verification-code activation, payment, abuse report, or account, we may preserve and disclose relevant records when legally required or when disclosure is necessary to protect users, recipients, providers, the platform, or the public. We may disclose logs showing which account, verified phone number, device, IP address, purchase, and provider transaction were linked to an incident.

International Transfers

The providers that support the Service may process and store data in different countries. By using the Service, you understand that data may be transferred to and processed in countries that may have different data protection rules than your country. We use reputable providers and reasonable safeguards appropriate to the service.

Security

We use reasonable administrative, technical, and organizational safeguards to protect information. Provider API keys and telecom secrets are intended to be stored on backend systems, not in the mobile app. No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account, device, email, app store account, and password secure.

Your Choices and Rights

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal data. You can use in-app account, export, deletion, support, report, permission, and advertising privacy choices tools where available. You may also control certain advertising settings through your device settings, Google settings, or any consent form shown by the app. Withdrawing or limiting advertising consent may reduce or prevent ad availability but does not remove records we must keep for completed rewards, fraud prevention, billing, provider reconciliation, security, or legal compliance. We may need to verify your identity before acting on a request, and some data may be retained when required for legal, security, billing, fraud-prevention, or provider-compliance reasons.

Children

The Service is not intended for children or users under 18. We do not knowingly allow users under 18 to create accounts or use paid telecom features. If you believe a minor has provided information, contact support through the app.

Changes to This Policy

We may update this Privacy Policy as the Service, providers, law, app store requirements, or compliance practices change. Continued use after an update means the updated policy applies. Material changes may be communicated in the app where appropriate.

Contact

For privacy requests, account deletion, support, abuse reports, or questions about this policy, use the in-app support, export, deletion, and report tools. We may request account identifiers, verified phone information, purchase details, or other information needed to verify and process the request.