This policy explains what the Temp Number app for Android, published by NasrTech
(“we”, “us”), does with your data: what stays on your phone, what goes to
our server, and what goes to Google and to the third-party services the app relies on.
In short
- There is no sign-up. The app creates an anonymous account ID in the background and never
asks for your name, your email address or your phone number.
- The app has no permission to read the text messages on your own phone.
- To deliver numbers, codes, coins and purchases, our server keeps your orders, the texts that
arrive on your numbers and your coin balance, linked to that anonymous ID and a random device
ID.
- Standard temporary inboxes are created with third-party email services, directly
from your phone. The Pro private-domain inbox runs on our own email service.
- Google services are built in: Firebase Analytics, Crashlytics, Authentication and Cloud
Messaging, Google Play Billing, and — for users without Pro — Google AdMob ads.
- Your history, settings, generated identity, aliases and vault stay on your phone.
- We do not sell your personal data.
What the app never asks for
The app does not request access to your contacts, your location, your camera or microphone,
your photos or files, or the text messages and call log on your phone. It never asks you to type
in your own phone number. Anything you type into the alias generator or the vault stays on your
phone (see Stored only on your phone).
Your anonymous account and device ID
- Anonymous account ID — on first launch the app signs in to Firebase
Authentication anonymously. That creates a random account ID with no name, email address or
password attached. The app sends a token for this ID with its requests for numbers, lines,
coins, purchases and offers, so our server knows which ones are yours.
- Random device ID — the app also generates a random 24-character ID,
keeps it in encrypted storage on the phone and sends it with number and line requests as a
back-up identity. It is not taken from your phone’s hardware or any other identifier.
What our server receives and keeps
Our server is the back end that supplies numbers and lines, keeps coin balances and checks
purchases. It receives:
- Number orders — the service and the country or line you pick, and
the price you confirm. The order record holds the number issued to you, its status and times,
and the text messages delivered to that number, including the code.
- Private lines — the line’s number, country, term and expiry,
and the texts it receives (sender, text and time).
- Coins — your coin balance and a record of each credit, charge and
refund.
- Purchases — after a Google Play purchase the app sends the product ID
and the Google Play purchase token to our server, which checks it with Google Play before
anything is unlocked or credited. The server stores a one-way hash of the token together with
the product, your anonymous ID, the purchase status and dates, so a purchase is never credited
twice and your remaining coins can follow you if you reinstall and Google Play restores the
purchase.
- Introductory price window — the time your personal introductory-price
window for the Lifetime unlock opened, linked to your anonymous ID.
- New-message alerts — if you have Pro and allow notifications, the app
sends your push token together with the temporary address or number you have open (and the
inbox’s access token) so the server can alert you to new messages. The server keeps this
registration in memory only — it is not written to a database — and drops it after
seven days without an update, or when the app tells it you no longer have Pro. Without Pro, the
app sends only the push token, to ask the server to remove any earlier registration.
- Private-domain inbox (Pro) — mail sent to a private-domain address is
received and stored by our own email service, and the app fetches it by address. An hourly
clean-up deletes every message older than two hours. Deleting the inbox in the app removes the
address from your phone; messages it already received are removed by that clean-up.
- App version check — when you open the app it asks our server for the
latest version information. This request carries no personal data.
- Your IP address — like any internet service, our server sees the IP
address of each request. It is used to limit abuse and may appear in the log of a rejected
request; it is not added to your order records.
Number orders, lines, coin records and purchase records are kept only as long as needed to
provide the service — for example, to show you your orders and lines, settle refunds, and
keep coin balances and purchases correct.
Telecom partners and email services
Numbers and lines are operated by our telecom partners; temporary inboxes come from third-party
email services.
- Numbers and lines are obtained by our server from our telecom
partners. They receive what is needed to supply a number — the service
and the country — not your identity. Texts sent to a number are received by the partner
that operates it and passed to our server, then to your app.
- Temporary inboxes are created by the app directly from your phone with
third-party email services. Those services see your device’s IP address and hold
the messages sent to the inbox. The inbox’s login details are kept in encrypted storage on
your phone, and a copy of its access token is kept in the app’s private storage so the
background check below can run. When you delete an address in the app, the app asks the
email service to delete that inbox, where the service supports it.
- Background inbox check — while a temporary inbox is open, the app
checks it for new mail every few minutes, even when the app is closed. It reads the newest
message’s sender, subject and preview on your phone to show a notification, with the code
if it finds one. You can turn this off in Settings → Inbox reminders.
- Opening an email — messages are shown inside the app with scripts
turned off and links blocked. Images in a message may still load from the sender’s
servers, as they would in any email app.
Temporary inboxes are not private. Depending on the email service, anyone who knows an address
may be able to read what is sent to it, so do not use one for anything sensitive.
Google services built into the app
- Firebase Analytics records usage events — for example, that an inbox
was created, a number was ordered, a code arrived, or a purchase started, finished or failed
— with details such as the service and country chosen, the product, the coins spent, the
price and currency paid, how long a code took to arrive, and the error Google Play returned when
a purchase fails. These events never include your email address, a phone number, the text of
your messages or your codes. The SDK also collects standard information: an app-instance ID,
device model, operating system and app version, an approximate location derived from your IP
address (such as country and city), the Google Play install referrer (which link or campaign an install came from) and,
where your device allows it, the Advertising ID. We use this to understand how the app is used,
find what fails, and measure our own Google Ads campaigns.
- Firebase Crashlytics receives crash reports from release builds: device
model, operating system and app version, a Crashlytics installation ID, and the technical error
and stack trace. When a purchase fails, it also receives the product ID and the error message
Google Play returned. The app does not add your messages, codes or numbers to these
reports.
- Firebase Authentication creates the anonymous account ID described
above.
- Firebase Cloud Messaging gives the app a push token so notifications can be
delivered to your phone.
- Google Play Billing processes every payment: subscriptions, the Lifetime
unlock, coin packs and private lines. We never receive or store your card or payment details;
we receive the purchase details needed to verify a purchase. You can manage or cancel a
subscription at any time in the Google Play Store.
- Google Play In-App Review — if you choose to rate the app, the rating
is handled by Google Play.
- Google AdMob shows banner, full-screen and rewarded ads to users without
Pro; with Pro you see no ads. To serve and measure ads, Google’s SDK may collect device
information, your IP address and the Advertising ID. Where the law requires consent (for example
in the European Economic Area, the United Kingdom and Switzerland), Google’s consent form
is shown when the app starts and ads follow the choice you make; where it applies, you can
change that choice at any time in Settings → Ad privacy options.
Stored only on your phone
- The history of addresses you created (the last 15, or 50 with Pro), your current
private-domain address, your settings, and simple counters and dates the app uses to decide
when to show tips and prompts.
- For each address: how many times you copied it, and the domains — not the full
addresses — of the senders that wrote to it.
- The random identity you generated.
- Your alias set, including the email address you typed in to create it. It is never sent
anywhere.
- The vault (Pro): the logins you save — label, email, username and password —
encrypted with a key held by the Android Keystore. It is never uploaded.
- The login details of your current temporary inbox, and your random device ID, in encrypted
storage.
- A local copy of your plan and coin balance, and a short log of recent purchase steps used
for troubleshooting.
- The home-screen widget, if you add it, shows your current address and message count.
Tips, offers and reminders the app shows as notifications are scheduled on the phone itself;
you can turn them off in Settings → Promotional notifications. If Android backup is turned on
for your Google account, Android may include the app’s on-device data in that backup.
Permissions we use
INTERNET and ACCESS_NETWORK_STATE — to reach our server,
Google’s services and the email services, and to run the background inbox check only when
you are online.
POST_NOTIFICATIONS — to show notifications for new mail, codes, reminders
and offers. Android 13 and later asks you first, and you can turn notifications off at any
time.
VIBRATE — to vibrate when a new message arrives.
com.android.vending.BILLING — for Google Play purchases.
com.google.android.gms.permission.AD_ID and Android’s ad-services
permissions — added by Google’s ads and analytics libraries so they can use the
Advertising ID and Android’s ad APIs, such as topics and attribution.
- A few technical permissions Google’s libraries need, such as
WAKE_LOCK
to finish background work, the Google Play services permissions for receiving push messages,
and the Google Play install referrer. None of them gives the app access to your personal
content.
The app does not request SMS, contacts, location, camera, microphone or
storage permissions.
Sharing
We do not sell your personal data. We share it only with the companies that run the
app for us — Google (Firebase, AdMob and Google Play), the cloud services that host our
server, database and email service, and the telecom partners and email services
described above — and only as described in this policy, or when the law requires
it. Our server and these services may process data in countries other than yours.
Children
Temp Number is not directed to children under 13, and we do not knowingly collect personal
information from them. If you believe a child has used the app, contact us and we will delete the
records we can identify.
Your choices and rights
- Turn off background inbox checks (Settings → Inbox reminders), promotional
notifications (Settings → Promotional notifications), or all notifications in Android
settings.
- Change your ad consent in Settings → Ad privacy options where it applies, and reset or
delete your Advertising ID in Android settings.
- Delete an address in the app, clear your history (Settings → Clear History) and remove
vault entries at any time. Uninstalling the app deletes everything it stored on your phone.
- The app has no in-app switch for analytics or crash reporting; uninstalling the app stops
both.
- To ask for a copy of the records our server holds for your app, or for their deletion, email
nasr0animator@gmail.com. Include a Google Play order
number (it starts with
GPA.) or a number you ordered or rented, so we can find the
records. Deleting them also removes any remaining coin balance and your active numbers and
lines.
- Depending on where you live, you may also have the right to correct your data, to object to
or restrict how it is used, and to complain to your data protection authority.
Security
The app talks to our server over encrypted HTTPS. The server verifies the anonymous-account
token that comes with a request, and checks every purchase with Google Play before crediting it.
Your random device ID, your inbox login details and the vault are kept in Android’s
encrypted storage. No method of storage or transmission is completely secure, but we work to
protect your data.
Changes to this policy
We may update this policy; changes will be posted on this page with a new “Last
updated” date.
Contact
Questions about this policy or your data:
nasr0animator@gmail.com
If you send feedback from inside the app, it opens your own email app with a message
addressed to us that includes the category you picked and the app version. Nothing is sent
unless you send that email yourself.
← Back to Temp Number