Second Phone Number 2nd Text

Privacy

Privacy Policy — Second Phone Number 2nd Text

What this app collects, why it collects it, and what you can ask us to delete.

Last updated: 10 September 2026

Second Phone Number 2nd Text ("the app") gives you an additional phone number for calls and text messages, separate from your personal line. This policy describes exactly what the app and its backend service collect, why, who receives it, how long it is kept, and how you delete it.

The service operator is the app's publisher, reachable at the support address in the App Store and Google Play listings. The backend service runs at 2phone.vsetaxi.app.

1. Your identity

The app does not ask for your name, email address or a password.

  • On first launch the app creates an anonymous Firebase account (Google Firebase

Authentication, project second-phone-f9f6a). This is a random identifier; it is not linked to your real-world identity.

  • You may optionally link Sign in with Apple or Google so your number and history

survive reinstalling the app or moving to a new device. If you do, the app receives only the account identifier (and, if Apple provides it, an email address) needed to recognise you again.

  • The app also sends a device identifier header so the backend can associate a

reinstall with the same account.

2. Your phone number

Numbers are leased from Twilio Inc., which is the telecommunications carrier for this service. A number assigned to you is recorded against your account. If a number is left unused for an extended period it is released back to the pool and may be reassigned to another customer — this keeps the service affordable. You are notified in the app before that happens, and you can keep a number in use to retain it.

3. Calls, messages and voicemail

  • Text messages and MMS you send and receive through your second number pass through

Twilio and are stored on the backend so your conversations are still there when you open the app or reinstall it.

  • Calls are carried over the internet by Twilio. The app does not record call audio.

Call metadata (the other number, time, duration, direction, missed/answered) is stored so your recents list works.

  • Voicemail messages left on your number are stored, together with a transcript where

available, until you delete them.

  • Images you attach to a message are uploaded so they can be delivered as MMS, and are

stored with that conversation.

4. The AI compliance check on outgoing messages — please read this

Every outgoing text and MMS is checked by an automated compliance reviewer before it is sent. This is required by our carrier's messaging policy and by US carrier rules, and it cannot be turned off. Its purpose is to stop phishing, fraud, impersonation, unsolicited bulk marketing, threats and other prohibited traffic.

The check runs on our backend and calls an AI model through OpenRouter, Inc.

What is sent to the AI provider:

  • the text of the message you are about to send (up to 1,600 characters);
  • whether the message has an image attached (a true/false flag only);
  • up to the 12 most recent messages in that same conversation, each marked only as

incoming or outgoing;

  • counts of how many messages you sent in the last 24 hours and how many were blocked;
  • automated signals from a local pre-filter (for example "contains a shortened link").

What is never sent to the AI provider:

  • your phone number or the recipient's phone number;
  • any contact name;
  • your account identifier, device identifier, email address or Apple/Google identity;
  • your location;
  • the contents of your address book.

Requests are sent with the provider flag data_collection: "deny", which instructs OpenRouter to route only to model providers that do not retain the content for training. The request carries no account identifier, so the provider cannot associate it with you. The check has a short timeout (about 3 seconds); if the reviewer cannot be reached the message is not sent, and the app tells you to try again.

What we keep: the verdict (allowed, blocked or flagged), the rule category, the reason shown to you, the model used and the response time are recorded for the carrier compliance audit, together with the message text for blocked messages so a decision can be reviewed if you dispute it. You can see every one of these decisions on the Message checks screen in the app.

Repeated violations: blocked messages count as strikes within a rolling window. Enough strikes suspend your ability to send for 24 hours, and further strikes for 7 days. The app warns you before this happens and shows when a suspension ends.

5. Other AI features

The app offers optional AI assistance that you trigger yourself — rewriting a draft, suggesting short replies, and summarising a long conversation. When you use one of these, the relevant message text is sent to the same AI provider under the same terms as section 4 and is not retained by the provider for training. These features are optional; not using them sends nothing.

6. Your contacts stay on your device

If you grant contacts permission, the app reads your address book on the device only, to show a person's name instead of a bare number in your conversations, recents and voicemail.

Your contacts are never uploaded to our servers and are never sent to any third party. The name index is held in memory while the app runs. Denying the permission does not disable any feature — you simply see numbers instead of names.

7. Permissions the app asks for

| Permission | Why | Data leaving the device | |---|---|---| | Contacts | Show names for numbers | None — matched locally | | Microphone | Speak during a call | Live call audio, carried by Twilio; not recorded | | Photos | Attach an image to a message | Only the image you choose | | Notifications | Alert you to calls and messages | A push token (see §8) |

Each permission is optional and is requested only when you first use the feature it serves.

8. Notifications, diagnostics and configuration

  • Firebase Cloud Messaging — a push token is stored so incoming calls and messages can

reach you. Deleted with your account.

  • Firebase Crashlytics — crash reports (stack traces, device model, OS version) so we can

fix defects. Crash reports do not contain your messages or contacts.

  • Firebase Analytics — aggregate usage events (for example, which screens are opened) to

understand how the app is used. Not used to build advertising profiles, and not sold.

  • Firebase Remote Config — delivers configuration to the app; sends no personal data.

9. Purchases

Subscriptions are sold by Apple or Google, not by us. We never see or store your card details. The store gives the app a signed purchase receipt, which our backend verifies to confirm your subscription is active. We store the resulting subscription state and the store's transaction identifier.

10. Who else receives your data

  • Twilio Inc. — carrier for numbers, calls, SMS and MMS. Necessarily receives the

numbers and message content it must transmit.

  • Google Firebase — authentication, notifications, crash reporting, analytics,

configuration.

  • OpenRouter, Inc. — the compliance and assistance checks described in §4 and §5, under

the strict limits listed there.

  • Apple / Google — purchase processing.
  • Law enforcement — only where legally compelled by valid process.

We do not sell your personal data, and we do not share it with advertising networks or data brokers.

11. How long we keep things

| Data | Retention | |---|---| | Messages, call history, voicemail | Until you delete them or delete your account | | Compliance verdicts | Kept for the carrier audit; message text and reason removed when you delete your account | | Push token, blocked numbers, number settings | Deleted with your account | | Released phone numbers | Returned to the carrier pool and may be reassigned | | Crash and analytics records | Per Firebase's retention settings (up to 14 months) |

12. Deleting your account and your data

You can delete your account from Settings → Delete account inside the app. This immediately:

  • releases every phone number on the account back to the pool;
  • deletes your voicemails, blocked-number list, per-number settings and push token;
  • anonymises your compliance record — the carrier requires that the audit record continues to

exist, but the retained message text and reason are removed, leaving no message content;

  • closes the account so it can no longer be used.

Deleting the app alone does not delete server-side data; use the in-app deletion. If you cannot reach the screen, contact support and we will delete the account for you.

13. Security

Traffic between the app and the backend uses HTTPS/TLS. The backend is the only authority on your subscription; the app cannot grant itself access. Credentials for Twilio, Firebase and the AI provider are held only on the server and are never embedded in the app.

14. Children

The app is not directed to children and is rated for users aged 17 and over. We do not knowingly collect data from children. If you believe a child has used the service, contact us and we will delete the account.

15. Your rights

Depending on where you live (for example under the GDPR or CCPA) you may have the right to access, correct, export or erase your personal data, and to object to certain processing. The in-app deletion in §12 satisfies erasure directly. For any other request, contact support using the address on the store listing; we respond within 30 days.

16. Changes

If this policy changes materially we will update this page and note the change in the app's release notes. The "last updated" date above always reflects the current version.

Earlier app versions

This policy describes version 2.0.0. Earlier versions used additional attribution integrations and requested App Tracking Transparency permission. Older installations may retain those integrations until updated. You can manage their tracking permission in iOS Settings under Privacy & Security → Tracking. Version 2.0.0 does not use those legacy attribution integrations.