Privacy Policy
SimNoKYC is designed to be anonymous. We do not collect your name, email, phone number, or any personal identification. Your account is accessed solely through your seed phrase.
1. Data We Collect
We collect the absolute minimum data required to operate the Service:
- Account data: A hashed version of your access seed (bcrypt) and a 4-character prefix for lookup. We never store your seed in plain text.
- Transaction data: Order history (service, country, price, timestamps), deposit records (amount, cryptocurrency, transaction ID), and account balance.
- Session data: A server-side session identifier stored temporarily to maintain your login state. This is not linked to any personal identity.
- Rate limiting data: IP addresses are temporarily logged to prevent brute-force login attempts. These records are automatically deleted after 1 hour.
2. Data We Do NOT Collect
- Name, email address, or phone number
- Physical address or location data
- Government-issued ID or identity documents
- Browser fingerprints or tracking cookies
- Third-party analytics or advertising trackers
3. How We Use Data
The data we collect is used exclusively for:
- Authenticating your account access
- Processing and fulfilling orders
- Managing your account balance and deposit history
- Preventing abuse (rate limiting, fraud detection)
- Maintaining and improving the Service
We do not sell, rent, or share data with third parties for marketing or advertising purposes.
4. Cookies & Storage
We use a single session cookie required for authentication. This cookie:
- Is HTTP-only and secure (not accessible by JavaScript)
- Contains only a session identifier
- Expires when you close your browser or log out
- Does not track you across websites
We do not use analytics cookies, advertising pixels, or any third-party tracking tools.
5. Third-Party Services
The Service interacts with the following external services strictly for operational purposes:
- Blockchain networks (Bitcoin, Ethereum, Solana): To verify cryptocurrency payments. Blockchain transactions are public by nature.
- SMS providers: To provision virtual numbers and receive SMS. The phone numbers and SMS content pass through third-party telecom providers.
- Price APIs: To fetch current cryptocurrency exchange rates.
6. Data Retention
- Account data: Retained as long as the account exists. Inactive accounts (no login for 12+ months) may be deleted.
- Order & transaction data: Retained with the account for your reference.
- Rate limiting logs: Automatically purged after 1 hour.
- SMS content: Stored temporarily and may be purged after the order is completed or expired.
7. Data Security
- All connections are encrypted via TLS (HTTPS).
- Access seeds are hashed using bcrypt and never stored in plain text.
- Session data is stored server-side (Redis) and is not exposed to the client.
- CSRF protection is enforced on all state-changing requests.
8. Your Control
Since accounts are anonymous:
- You can stop using the Service at any time by simply not logging in.
- There is no "delete my data" request process tied to a verified identity, as we have no way to verify account ownership beyond the seed.
- Inactive accounts are automatically purged after extended periods of inactivity.
9. Changes to This Policy
We may update this Privacy Policy at any time. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service constitutes acceptance of the current policy.