In short. We keep what the service needs to work: who you are on Telegram or Google, the numbers you rent and the SMS delivered to them, and your wallet. We never see your card or bank details, we do not sell your data, and the number providers never learn who you are.
Who we are
OTPKart is a temporary-number service. You rent a phone number in a country of your choice, and the SMS verification code sent to it is delivered to you in our Telegram bot, on our website at https://dev.otpkart.com, or through our API. The operator of OTPKart is responsible for the data described on this page.
Telegram - when you use the bot, or sign in with Telegram on the website: your Telegram user id and your first name as Telegram sends it. We do not keep your phone number, your Telegram username or your profile photo.
Google - when you sign in with Google: Google's account id for you, your e-mail address and your first name.
Your settings: the default country you pick, your favourite services, and your API key once you activate one.
If you joined through a referral link, the account of the person who referred you is noted on yours.
ORDERS
numbers and codes
Every number you rent: the service, the country, the server, the price, the time and the outcome.
Every SMS delivered to a number you rented: the sender, the text and the code taken from it. It is kept with your order history so the bot can resend a code, the website can show it, and support can check a dispute.
These SMS pass through our system and are readable by us. Do not use a temporary number for anything you would not want logged.
WALLET
points and payments
Every credit and debit of your points, as a ledger that is only ever appended to.
For each top-up: the amount, our order number, the payment gateway's reference and the status. For a UPI transfer that we match on our own bank statement, the bank's transaction reference (UTR); for a USDT transfer, the on-chain transaction id.
Never a card number, a bank account number, a UPI PIN or a wallet key - the payment side handles those and we do not receive them.
TECHNICAL
logs, cookies, counters
On the website and the API, the web server writes your IP address, the address you requested, the time, the result and your browser's name to its access log. The query string is never logged, so an API key never lands in a log file.
Rate-limit counters, keyed by IP address or by account, live for a few minutes.
The website uses cookies - see Cookies below.
The bot never sees your IP address or your device: it talks to Telegram, and Telegram talks to you.
The SMS Checker (paste an SMS, learn which service sent it) keeps nothing about you; the pasted text is used only to find the sender - see Sharing.
Why
To run the service: hand you the number, deliver the code, resend it on request, show your history.
To keep your balance right: match a payment to your order and credit it, refund a number that got no code, pay a referral bonus.
To prevent abuse and fraud: keep one account per person, catch referral farming, keep a blocked account blocked.
To support you when you ask us to look at an order or a payment.
To keep the accounting records a business has to keep.
Sharing
Telegram and Google are your sign-in providers. They tell us who signed in; we send them nothing about your orders. Each has its own privacy policy.
The payment gateway that collects a top-up (at the time of writing NoxPay, for UPI and USDT) receives the amount, our order number and a numeric account reference - your Telegram user id, or an internal account number. It never receives your name or your e-mail address. It has its own privacy policy.
The number providers we rent numbers from receive the service and the country of an order - nothing about you.
The SMS Checker sends the text you paste to one number provider's SMS-identification service so it can name the sender. Nothing about you goes with it.
Referrals: if you joined through someone's link, that person is told your first name when you join and when a top-up of yours earns them a bonus.
Hosting: the data sits on a server we rent from a hosting provider.
We do not sell or rent your data and we do not use it for advertising. We disclose data when the law requires it, or to investigate abuse of the service.
Cookies
Cookie
Where
What
How long
web.sid
the website
keeps you signed in; holds only a session id
up to 30 days from your last visit (renewed on every visit)
connect.sid
the operator's admin panel
the operator's own login; holds only a session id
until the browser closes (24 hours on the server)
Both are set with httpOnly, SameSite=Lax and Secure over HTTPS. There are no advertising or analytics cookies. Your browser's own storage keeps your light / dark theme choice and, on the API documentation page, the API key you paste into its History tab - that stays in your browser and is never sent to us.
Retention
Your account, your orders, the SMS delivered to them and the wallet ledger: as long as the account exists (see Your rights).
Server logs: rotated daily and kept for about two weeks.
Sessions: 30 days (website) or 24 hours (panel) after the last request.
Rate-limit counters: minutes.
Security
Every connection to the website and the API is encrypted (HTTPS). The bot is reached through Telegram, which encrypts its own connection to you.
Sign-ins are verified before an account is opened: Telegram's signature on the login, Google's signed identity token. Sessions live on our server; the cookie carries only an id.
Website pages carry a strict Content-Security-Policy, and no page builds HTML from data such as an SMS text.
Access to the data is limited to the operator. The admin panel is password-protected.
Your API key can spend your balance - keep it private. You can replace it at any time in the bot (Profile, API Access) or on the website (Account); the old key stops working at once.
Your rights
Ask support to see, correct or delete the data we hold about you. On the website's Account page you can remove a linked Google sign-in yourself, as long as another way to sign in remains.
Deleting an account removes its sign-in links (the Telegram id, the Google identity, the name), so nobody can sign in to it and it no longer identifies you. The wallet ledger and the payment records stay, because the law on payments requires us to keep them. Points cannot be withdrawn - see the terms.
Children
OTPKart is not for anyone under 18. We do not knowingly keep an account for a minor - tell support and it will be removed.
Changes
When this policy changes, the new version is published on this page with a new date at the top. Larger changes are announced in the bot when possible.