Privacy Policy
This Privacy Policy explains how LibOTP (�we�, �us�, �Data Fiduciary�) collects, uses, stores, and shares personal data when you use https://libotp.online and related services (the �Service�). It should be read with our Terms of Service, Acceptable Use Policy, and Refund Policy.
We process personal data in line with India�s Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable law. By creating an account or using the Service you provide the consent and notices described below, except where another lawful basis applies.
1. Who we are
LibOTP is an India-based temporary virtual SMS / OTP number platform founded by Amit Pandey in August 2026. Contact:
- Email: supportlibotp@gmail.com
- Telegram support: @libotponline
- Updates: t.me/libonetp
- In-app support on the Recharge page
2. Information we collect
- Account data: name, email, password hash (never the plain password), Google account ID if you use Google sign-in, wallet ID, display name, ban status.
- Wallet and billing: balance, deposit amounts, order numbers, UPI references / UTR, crypto TxIDs, network (for example TRC20 or BSC), package choice, approval notes.
- Activations: country, service/app, operator, temporary number assigned, status, timestamps, expiry, and SMS / OTP text when received.
- Support: message text, optional contact handle, wallet ID, admin replies.
- Technical data: IP address, user agent, request paths, error logs, and security signals (including CAPTCHA results and rate-limit events).
- Analytics: Google Analytics 4 may record pages viewed, device/browser type, and approximate location. You can control cookies in your browser.
- Preferences: theme, voice language, wallet ID, and similar settings in browser storage.
We do not collect government ID or full card PAN data in the standard LibOTP wallet flow. UPI and crypto payments are handled by third-party rails described below.
3. DPDP Act compliance
Under the DPDP Act we act as a Data Fiduciary for account, wallet, and support data. Number/SMS providers may act as Data Processors or independent fiduciaries for routing SMS. We:
- Collect data for specified purposes (account, billing, OTP delivery, security, support).
- Limit use to those purposes and related legal / fraud-prevention needs.
- Implement reasonable security safeguards.
- Honour Data Principal rights described in section 10, subject to law.
- Do not sell personal data.
- Do not knowingly process data of children under 18.
Where processing is necessary to provide the Service you requested (contract / legitimate use of the platform), we rely on that necessity plus your notice and consent at registration. You may withdraw consent by closing the account, understanding that we may retain limited records for billing, disputes, and legal compliance.
4. Temporary SMS logs � retention
SMS and OTP content is processed only so you can read verification codes in your dashboard. We treat this as sensitive operational data.
- SMS / OTP body: retained for up to 30 days after the activation ends, then deleted or irreversibly redacted from active systems, unless a longer hold is required for an open dispute, abuse investigation, or legal request.
- Activation metadata (country, service, operator, number, timestamps, status, amount charged/refunded): kept with the wallet history typically for 24 months, then archived or reduced to accounting totals.
- Account, wallet, and deposit records: kept while the account is open and for a reasonable period after closure (generally up to 8 years for tax / accounting where applicable).
- Server and security logs: typically 90 days, longer if needed to investigate abuse.
5. Third-party payment gateways
Wallet recharge is processed by independent payment and blockchain systems. We do not control those networks. Typical processors include:
- UPI: your bank / UPI app and the merchant VPA we display. We may store amount, order number, UTR, and a payment screenshot you upload so we can credit the wallet.
- USDT / crypto: public blockchain networks (for example TRC20, BSC) and explorer / verification APIs. TxIDs and amounts are public on-chain. We store the TxID you submit to prevent reuse and to match credit.
- Optional crypto processors (if enabled, for example NOWPayments): they receive payment details needed to complete the transfer under their own privacy policy.
Payment partners may process data outside India. Do not send funds until you have confirmed the address or UPI ID shown in the official LibOTP app.
6. How we use information
- Issue numbers, show SMS/OTP, and manage wallet balance.
- Verify deposits and prevent duplicate or fraudulent UTR / TxID use.
- Price services, prevent bots and abuse, enforce bans, and keep the Service reliable.
- Respond to support and operate the admin panel.
- Comply with law and protect LibOTP, users, and third parties.
7. Sharing
- SMS / number providers � to obtain numbers and retrieve SMS status.
- Payment rails and blockchains � as needed to verify recharge.
- Analytics � Google Analytics 4 as described above.
- Hosting / infrastructure � under confidentiality and security controls.
- Authorities � when required by law or to respond to lawful requests related to fraud or abuse.
8. Data security
We use HTTPS in production, hashed passwords, server-side API keys, admin access controls, CAPTCHA on sign-in and purchase, and rate limits on APIs. No method of transmission or storage is 100% secure. Protect your password and wallet session. Notify us immediately if you suspect unauthorised access.
9. International transfers
SMS providers, cloud hosting, analytics, and payment APIs may process data outside India. We take reasonable steps to ensure such processing is for the purposes in this Policy and is protected by contract or equivalent safeguards where required.
10. Your rights (Data Principal)
Subject to the DPDP Act and fraud-prevention needs, you may request:
- Access to personal data we hold about your account.
- Correction of inaccurate account details.
- Erasure of account data (Settings delete, or email support), except records we must keep for billing, disputes, or law.
- A summary of processing and the grievance process below.
We aim to respond within a reasonable period. We may need to verify the account email or wallet ID before acting.
11. Children
LibOTP is not directed to anyone under 18. We do not knowingly collect children�s data. If a child has used the Service, contact us to remove the account.
12. Cookies and local storage
Browser storage keeps your session, theme, and similar preferences. Clearing it logs you out. Analytics cookies can be blocked in your browser; essential storage is required for the app to work.
13. Changes
We may update this Policy. The �Last updated� date will change when we do. Continued use after an update means you accept the revised Policy.
14. Grievance and support
For privacy requests or grievances, email supportlibotp@gmail.com with subject �Privacy / DPDP�, or use in-app support / Telegram @libotponline. Include your account email and wallet ID. We will acknowledge and work to resolve the request. You may also escalate to the Data Protection Board of India as provided under the DPDP Act.