Privacy Policy for the Get-SMS Android Application

Effective date: August 2, 2026
Last updated: August 2, 2026

1. General Provisions

This Privacy Policy explains what data is collected and processed when you use the Get-SMS Android application, why it is processed, with whom it may be shared, how long it is retained, and how you can delete your account and associated data.

The developer of the mobile application and the data controller responsible for personal data processed directly through the application is:

Denis Vladimirovich Fursov

Country: Russian Federation

Email: [email protected]

In this Privacy Policy, the Get-SMS mobile application, its developer, and the technical infrastructure associated with the application are referred to as “Get-SMS,” “we,” “us,” or the “Service.”

This Privacy Policy applies to data processing through the Get-SMS Android application. Use of the get-sms.com website, registration of an account on the website, and balance top-ups are governed by separate documents published on the website.

The mobile application is intended for signing in to an existing account, accessing the virtual phone number service, and receiving incoming SMS codes. Account registration and balance top-ups are not available through the mobile application.

2. Data We Process

2.1. Account Data

When registering on the get-sms.com website, the user provides:

  • an email address;
  • a username;
  • a password.

In the mobile application, the user enters a username or email address and password only to sign in to an existing account.

The password is transmitted to the server over a secure HTTPS connection. The application does not store the password on the device. The password is not stored in plain text on the server; only its hash is stored.

After a successful sign-in, the application receives an authentication token. The token is stored in the application’s private storage on the device and is used to maintain the session without requiring the user to enter the password again. A hash of the authentication token is stored on the server.

2.2. Application Instance Identifier

When the application is launched for the first time, it generates a random UUID that is used to identify that particular installation of the application.

This UUID:

  • is not an Android ID, IMEI, device serial number, or advertising identifier;
  • is not derived from the device’s hardware or system identifiers;
  • is used to associate a session and push notifications with a particular application installation;
  • makes it possible to terminate a session or revoke access for a specific device;
  • is stored in the application’s private storage and transmitted to the Get-SMS server.

Uninstalling the application removes the local copy of the UUID but does not, by itself, delete the user’s account or data previously transmitted to the server.

2.3. Device and Application Information

When the user signs in, the application transmits:

  • the device manufacturer and model;
  • the Android platform;
  • the installed version of the application;
  • the date and time when the session was created and last used.

This information is used to manage connected devices, maintain compatibility, provide technical support, and protect the security of the Service.

Get-SMS does not request the device’s IMEI, Android ID, serial number, MAC address, or Android advertising identifier.

2.4. Push Notifications

Firebase Cloud Messaging, provided by Google, is used to deliver notifications about received SMS codes.

For this purpose, the following data is processed:

  • the Firebase Cloud Messaging push token;
  • the Firebase installation identifier;
  • information required to deliver the notification;
  • notification content, which may include an SMS code, a virtual phone number, and the name of the selected service.

The push token is associated with the user’s account and a particular installation of the application. When the user signs out, the active push token for the corresponding device is removed from the Get-SMS server.

Users may disable notifications through the Android settings. Disabling notifications does not prevent users from viewing their orders and received codes directly in the application.

Data required to deliver notifications may be processed by Google LLC and its affiliated entities in accordance with Google’s terms and privacy policy.

2.5. IP Address and Security Data

When the application communicates with the Get-SMS servers, the server automatically receives the user’s IP address.

The IP address and related technical information may be used to:

  • limit the number of requests;
  • protect the sign-in process against password guessing and brute-force attacks;
  • detect fraud and misuse;
  • prevent unauthorized access;
  • maintain the security of the Service;
  • investigate technical and security incidents.

We do not use IP addresses to display personalized advertising.

2.6. Order History

When the Service is used, the following order information may be stored:

  • the selected service and country;
  • the issued virtual phone number;
  • received SMS messages and codes;
  • the date and time when the order was created and completed;
  • the order status;
  • the cost of the order;
  • cancellation or refund information;
  • transaction and order identifiers.

This data is required to provide the Service, display order history, calculate the account balance, handle requests and disputes, prevent fraud, and maintain financial records.

2.7. Payments

The Get-SMS mobile application does not offer purchases, subscriptions, Google Play Billing, or any other payment methods.

A Get-SMS balance can be topped up only through the get-sms.com website using third-party payment systems available on the website.

Payment card information is entered directly on the relevant payment system’s page. Get-SMS:

  • does not receive the full payment card number;
  • does not receive the CVV or CVC code;
  • does not store payment card information;
  • does not process payment card information within the mobile application.

The Service may receive only the information required to record the payment, such as the amount, currency, payment status, date and time, transaction identifier, and the name of the payment provider.

Payment card and other payment information is processed by the relevant payment system in accordance with its own privacy policy.

Use of the website, payment processing, and processing of data by payment systems are also governed by the terms and privacy policies published on get-sms.com and on the websites of the relevant payment providers.

3. Data the Application Does Not Collect

The Get-SMS application does not request or collect:

  • device location;
  • contacts or address book data;
  • call logs;
  • SMS messages stored on the user’s device;
  • photographs, videos, or user files;
  • camera or microphone data;
  • biometric data;
  • the Android advertising identifier;
  • IMEI, Android ID, or other system hardware identifiers;
  • payment card information.

As of the date of the latest update to this Privacy Policy, the application does not use advertising SDKs, Firebase Analytics, or tools for creating advertising profiles of users.

4. Purposes of Data Processing

We process data for the following purposes:

  • authenticating users and maintaining sessions;
  • providing virtual phone numbers and delivering incoming SMS codes;
  • displaying the account balance and order history;
  • sending service-related push notifications;
  • managing connected devices;
  • preventing fraud and password guessing attacks;
  • applying technical rate limits;
  • maintaining the security and stability of the Service;
  • handling user requests;
  • performing our obligations to users;
  • maintaining financial and tax records;
  • complying with applicable laws, government requests, and court orders;
  • protecting the rights and legitimate interests of the developer and users.

We do not sell personal data or use account information to display personalized advertising.

5. Legal Grounds for Processing

Personal data is processed in accordance with applicable laws of the Russian Federation, including Russian Federal Law No. 152-FZ of July 27, 2006, “On Personal Data.”

The legal grounds for processing include:

  • the need to perform an agreement with the user and provide the requested services;
  • the user’s consent, where consent is required by applicable law;
  • the need to comply with legal obligations;
  • the need to protect users and maintain the security of the Service;
  • the need to establish, exercise, or defend legal claims.

Disabling push notifications does not stop the processing of data required to fulfill orders, maintain security, or comply with legal obligations.

6. Sharing Data with Third Parties

Access to data may be provided only to the extent necessary for the relevant purpose and only to the following categories of recipients:

  • Google LLC and Firebase Cloud Messaging, for delivering push notifications;
  • the operator of the server-side component of the Get-SMS service and the get-sms.com website, for authentication, balance display, order processing, and data synchronization;
  • providers of server infrastructure, hosting, and technical maintenance;
  • providers of virtual phone numbers and SMS reception services, for fulfilling orders;
  • payment systems, when the user tops up a balance on the website;
  • government authorities, courts, and law enforcement agencies, when disclosure is required by law or a binding request;
  • specialists and contractors engaged to support the operation of the Service, provided that they comply with applicable confidentiality requirements.

Providers of virtual phone numbers may have access to information about the selected service and country, the issued phone number, and the incoming SMS message. The user’s username and email address are not shared with such providers unless this is required to provide the Service or comply with applicable law.

The use of Firebase Cloud Messaging may involve the transfer of technical data and push notification content to Google servers located outside the Russian Federation. Such transfer is performed solely to deliver notifications and in accordance with applicable requirements governing cross-border transfers of personal data.

We do not sell or disclose personal data to advertising companies or data brokers.

7. Data Retention

Data is retained only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.

The following retention principles apply:

  • email address, username, and password hash: for as long as the account exists;
  • authentication tokens, application UUID, device model, and application version: for as long as the corresponding device is associated with the account or until the account is deleted;
  • Firebase Cloud Messaging push token: until the user signs out, the token is replaced or becomes invalid, or the account is deleted;
  • order history, virtual phone numbers, and received SMS codes: for as long as the account exists or until it is deleted;
  • technical records used to protect the Service against fraud, password guessing, and abuse: for as long as necessary for those security purposes, and no longer than required to investigate an incident, resolve a dispute, or respond to a binding request;
  • backup copies of deleted data: up to 90 days as part of the established backup rotation cycle;
  • anonymized statistical data that cannot be linked to an identifiable user may be retained indefinitely.

If technical security records contain information that can be associated with a deleted account, such information is deleted or anonymized together with the account unless it is required to investigate a specific incident, comply with applicable law, or defend legal claims.

7.1. Financial and Legally Required Records

After an account is deleted, we may retain only the minimum amount of information that must be retained under the laws of the Russian Federation, the requirements of tax or other government authorities, court orders, or for the purpose of confirming completed financial transactions.

Such information may include:

  • the date and amount of a financial transaction;
  • the currency;
  • payment or refund status;
  • the internal transaction identifier;
  • the payment system transaction identifier;
  • information required for tax or financial recordkeeping.

These records are retained for the period required by applicable law, but generally for no longer than 5 years after the end of the calendar year in which the relevant transaction occurred.

If applicable law, a court order, or a binding request from a government authority requires a longer retention period, the data will be retained for that longer period.

Retained information:

  • is separated from the active account to the extent technically and legally possible;
  • is not used for advertising, marketing, or the continued provision of services;
  • is accessible only when required for legal compliance, financial recordkeeping, or the defense of legal claims.

SMS codes, virtual phone numbers, push tokens, password hashes, and device information are not considered mandatory financial records and are deleted together with the account unless their retention is expressly required by law or a binding order from a government authority.

8. Account and Data Deletion

Users can delete their account at any time using the account deletion page:

https://get-sms.com/delete-account.php

The page is publicly accessible and does not require the mobile application to be installed. A direct link to this page is available in the mobile application under “Profile” → “Delete Account”.

To delete an account:

  1. Open the account deletion page.
  2. Enter the username or email address and the password of the account.
  3. Confirm the deletion.

Authentication is required so that an account cannot be deleted by a third party. Users are not required to send an email request or contact customer support in order to delete an account.

Before deleting an account, please note:

  • any remaining account balance is handled in accordance with the Terms and Conditions and Refund Policy. Account deletion itself does not constitute a refund request;
  • an account with active (unfinished) orders cannot be deleted — such orders must be completed or cancelled first;
  • if an active order cannot be completed or cancelled through the user account, the user may contact [email protected] for assistance with completing the deletion process;
  • deletion is irreversible.

After the deletion is confirmed:

  • access to the account is terminated and the password is invalidated;
  • active sessions and authentication tokens are revoked;
  • Firebase Cloud Messaging push tokens are deleted;
  • the username and email address are replaced with a non-identifying value;
  • the password hash and API key are erased;
  • connected device records, including the application UUID, are deleted;
  • virtual phone numbers and received SMS codes are erased;
  • the account balance is set to zero;
  • order history is anonymized and can no longer be linked to the user;
  • technical security records associated with the account are deleted or anonymized, unless their retention is necessary for an active security investigation, legal claim, or binding request;
  • further processing for the purpose of providing services is stopped.

Deletion is performed immediately upon confirmation. Copies of certain data may temporarily remain in backups until they are overwritten as part of the regular backup rotation cycle, but for no longer than 90 days. During this period the data is not used for the normal operation of the Service and may be restored only when necessary to recover information systems, comply with applicable law, or investigate a security incident.

The only exception is information that must be retained under applicable law, a binding request from a government authority, or a court order, as described in section 7.1. Such information is retained separately and only to the minimum extent necessary. It is anonymized or pseudonymized where this is legally and technically possible.

Uninstalling the application or signing out of an account does not delete the account. To delete the account, the user must complete the procedure on the account deletion page.

Account deletion is irreversible. Once the deletion has been completed, the account, order history, virtual phone numbers, and received SMS codes cannot be restored.

9. Data Security

We apply organizational and technical measures to protect data, including:

  • transmitting data over secure HTTPS connections;
  • storing passwords only in hashed form;
  • storing authentication tokens on the server in hashed form;
  • using the application’s private storage for the local token and UUID;
  • restricting access to server systems;
  • limiting the number of sign-in attempts;
  • monitoring suspicious activity;
  • backing up and restoring data.

No method of transmitting or storing information can guarantee absolute security. If a security incident is identified, we take measures to limit its consequences and fulfill the obligations imposed by applicable law.

10. User Rights

Users have the right to:

  • obtain information about the processing of their personal data;
  • request access to their data;
  • request correction of inaccurate or outdated information;
  • request the restriction or deletion of unlawfully processed data;
  • withdraw consent where processing is based on consent;
  • object to processing where permitted by applicable law;
  • delete their account using the account deletion page;
  • submit a complaint to Roskomnadzor or seek judicial protection.

Questions concerning the exercise of these rights may be sent to [email protected] .

Deleting an account does not require prior contact by email: the procedure is completed independently on the account deletion page, a link to which is available in the mobile application under “Profile”.

Withdrawal of consent or account deletion does not prevent the retention of the minimum amount of information when retention is required by applicable law, a court order, or a binding request from a government authority.

11. Children’s Privacy

The Get-SMS application and Service are not intended for persons under the age of 18. We do not knowingly collect personal data from minors.

If you become aware that a minor has provided personal data without appropriate authorization, please contact us at [email protected] . After verification, the data will be deleted unless its retention is required by law.

12. Changes to This Privacy Policy

We may update this Privacy Policy when the application’s functionality, the categories of processed data, service providers, or applicable legal requirements change.

The current version will be published on a publicly accessible page of get-sms.com. The date of the latest update will be stated at the beginning of this document. We may also provide notice of material changes within the application.

13. Contact Information

Developer of the mobile application and data controller responsible for personal data processed directly through the application:

Denis Vladimirovich Fursov

Country: Russian Federation

Email: [email protected]

Website: https://get-sms.com

Account deletion is performed independently on the page https://get-sms.com/delete-account.php , a link to which is available in the mobile application under “Profile”. Deletion requires signing in with the account username or email address and password, and does not require an email request.

Questions about personal data processing, security, or this Privacy Policy may be sent by email.