Privacy Policy
SimNoKYC is designed to be anonymous. No email, no name, no phone number, no ID. Your account is accessed solely through your seed phrase.
1. Operational Records
SimNoKYC does not ask for identity. The service keeps only the technical records required to run anonymous accounts, payments, orders, abuse prevention, and aggregate measurement:
- Account record: bcrypt hash of the access seed plus a 4-character lookup prefix. The seed is never stored in plain text.
- Transaction record: order details, deposit amount, crypto currency, transaction ID, timestamps, and account balance.
- Session record: temporary server-side session identifier for login state, not linked to personal identity.
- Abuse-prevention record: temporary IP-based rate-limit entries for brute-force protection, purged automatically.
2. Identity We Do NOT Ask For
- Name, email address, or phone number
- Precise physical address or GPS location
- Government-issued ID or identity documents
- Advertising pixels or cross-site ad retargeting
3. How Operational Records Are Used
Operational records are used exclusively for:
- Authenticating your account access
- Processing and fulfilling orders
- Managing your account balance and deposit history
- Preventing abuse (rate limiting, fraud detection)
- Maintaining and improving the Service
We do not sell, rent, or share personal identity information for marketing or advertising. We do not have identity information to sell.
4. Cookies & Storage
We use authentication cookies plus limited first-touch attribution cookies to understand which source led to a signup, top-up, or order without asking who you are.
- Session cookies are HTTP-only, secure, and used for account access
- First-touch cookies store source, referrer, landing page, and timestamp for attribution
- The live visitor counter uses local browser storage for anonymous visitor/session IDs
- Do Not Track is honored by the live presence beacon
We use Google Analytics only for aggregate pageview and conversion measurement. We do not use advertising pixels, ad retargeting, or broker tooling.
5. Third-Party Services
The Service interacts with the following external services strictly for operational purposes:
- Blockchain networks (Bitcoin, Ethereum, Solana): To verify cryptocurrency payments. Blockchain transactions are public by nature.
- SMS providers: To provision virtual numbers and receive SMS. The phone numbers and SMS content pass through third-party telecom providers.
- Price APIs: To fetch current cryptocurrency exchange rates.
- Google Analytics for aggregate analytics and conversion measurement
6. Retention
- Account record: Retained as long as the account exists. Inactive accounts (no login for 12+ months) may be deleted.
- Order and transaction records: Retained with the account for your reference.
- Rate limiting logs: Automatically purged after 1 hour.
- SMS content: Stored temporarily and may be purged after the order is completed or expired.
7. Record Security
- All connections are encrypted via TLS (HTTPS).
- Access seeds are hashed using bcrypt and never stored in plain text.
- Session state is stored server-side (Redis) and is not exposed to the client.
- CSRF protection is enforced on all state-changing requests.
8. Your Control
Since accounts are anonymous:
- You can stop using the Service at any time by simply not logging in.
- There is no identity-based deletion request process, because account ownership can only be verified through the seed.
- Inactive accounts are automatically purged after extended periods of inactivity.
9. Changes to This Policy
We may update this Privacy Policy at any time. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service constitutes acceptance of the current policy.