1. Scope and roles
This notice applies to the 2nd Line application. It does not replace the privacy terms of a recipient, app, website, carrier, or third-party service that you contact or use. When a 2nd Line customer sends a message to a recipient, that customer is responsible for having a lawful purpose and valid consent for the communication.
2nd Line is intended for adults. It is not directed to children under 18, and we do not knowingly permit them to create accounts.
2. Information we collect
- Account and identity: Firebase user ID, sign-in provider, email address, display name, account status, language, and security events from Google or Apple sign-in.
- Number and communications: assigned numbers, destination and originating numbers, message content, MMS attachments, delivery and opt-out events, call participants, timestamps, duration, status, and provider identifiers. We do not advertise call recording and do not intentionally record call audio.
- Recipient consent: the recipient number, consent source, evidence reference, purpose, review status, and opt-out history required to decide whether outbound messaging is allowed.
- Code requests: selected service and country, allocated number, request state, time window, and received code content while it remains available.
- Wallet and purchases: token ledger entries, product ID, store, transaction and refund state, reward eligibility, and an opaque billing subject. Payment card details are handled by the applicable app store, not by us.
- Support and safety: support conversations, abuse reports, risk signals, administrator actions, disputes, and records needed to investigate fraud or protect the service.
- Device and service data: app version, platform, notification token, App Check or device-integrity results, ad-consent state, advertising identifiers where allowed, IP-derived security data, request timestamps, and diagnostic failures. If you opt in to Usage & diagnostics, Firebase may also process anonymous screen and feature events, crash stack traces, performance measurements, device/OS details, and a coarse country derived from network information.
Device contacts and photos
Contact permission is optional. Names and phone numbers are read on your device only after you grant permission; 2nd Line does not upload your address book as a contact list. When you choose a contact, the selected destination number is processed to place the requested call or message. Photo access is requested only when you choose an MMS attachment, and the selected media is uploaded for delivery and protected archival retention.
3. How we use information
We use information to authenticate accounts; provide and secure numbers, calls, messages, code requests, notifications, support, rewards, and purchases; verify recipient consent and opt-outs; calculate token charges; reconcile uncertain provider outcomes; detect spam, fraud, and prohibited activity; comply with carrier, platform, tax, accounting, and legal obligations; enforce our terms; and improve service reliability.
Optional Usage & diagnostics data is used to identify crashes, slow startup or screens, device-specific failures, and regional reliability trends. It never includes contacts, phone numbers, message or support text, verification codes, or call destinations.
We do not use message content or phone contacts to build advertising profiles. Ad personalization, when legally available, is controlled through Google’s consent interface and your device settings.
4. When information is disclosed
We disclose the minimum information needed to providers acting for us, including Google Firebase and Google sign-in for hosting, authentication, security, notifications, and app infrastructure; Apple for sign-in and platform services; Twilio and telecommunications carriers for numbers, calls, SMS, and MMS; verification-number service providers for a code request you initiate; RevenueCat and the relevant app store for purchase validation; Google AdMob for ads and server-verified rewards; and professional security, legal, accounting, or support providers where necessary.
We may disclose information to comply with valid legal process, protect users or the public, investigate abuse, establish or defend legal claims, or complete a corporate transaction subject to appropriate safeguards. We do not sell personal information for money.
5. Mobile numbers, consent, and SMS privacy
We do not sell, rent, or share mobile numbers, SMS opt-in data, or messaging consent with third parties or affiliates for their marketing or promotional purposes. We may provide mobile information only to service providers and carriers that process it on our behalf to deliver, secure, support, or comply with the requested messaging service. Those providers may not use it for their own marketing.
Message frequency varies based on recipient requests and conversation activity. Message and data rates may apply. A recipient can reply STOP to opt out and HELP for help. Opt-out requests are applied to the applicable sender and purpose. Proof of consent may be retained as required by law and carrier policy, including after consent is withdrawn.
6. Ads and optional rewards
Rewarded ads are optional. Google’s privacy choices are presented before ads load where required, and can be revisited from Settings. Eligibility and the hourly reward limit are checked using server time. Google may process advertising identifiers, approximate location, device information, ad interactions, and consent signals under its own policies. 2nd Line grants tokens only after a valid server-side reward confirmation.
After a verified rewarded ad, we may invite you to submit optional private feedback for a one-time token reward. If you participate, we store your written feedback, selected reason, optional 1–5 rating, language, platform, app version, account identifier, reward status, and submission time. The rating is internal, is not a public app-store review, and does not affect reward eligibility. Positive and negative feedback are treated equally.
7. Retention and account deletion
We keep active-account information while it is needed to provide the service. User-visible deletion of a call or message hides it from the app but does not erase the protected record immediately. This separation is used for safety, consent evidence, billing disputes, abuse prevention, and legal obligations.
You can delete your account from Settings in the app or at our account-deletion page. Access is revoked and user-facing account data is removed. Limited transaction, communication, consent, fraud-prevention, and security archives are retained for up to 365 days after the deletion request and then automatically purged. Certain purchase and refund records may remain for up to 400 days or longer when tax, accounting, chargeback, or other law requires it. A documented, time-limited legal hold may pause deletion for a valid official request, dispute, or investigation; holds are audited and reviewed.
Released phone numbers may be reassigned by carriers. Verification codes are displayed only for a limited period and are then made unavailable to the user.
8. Your choices and rights
- Enable or disable Usage & diagnostics at any time in Settings.
- Change language, notification, contact, photo, and ad-privacy permissions through the app or device settings.
- Request access, correction, or deletion through Settings → Support.
- Delete your account in-app or through the public deletion page.
- Withdraw messaging consent by replying STOP to the applicable sender.
- Depending on where you live, object to or restrict processing, request portability, appeal a decision, or complain to a data-protection authority.
We do not discriminate against you for exercising a privacy right. We may verify identity before completing a request and may retain the minimum record needed to document the request.
9. Security and international processing
We use access controls, encryption in transit, restricted archives, signed and short-lived media access, provider-isolated Twilio subaccounts, audit logging, App Check, webhook verification, and server-controlled token ledgers. No system is perfectly secure. Data may be processed in the United States and other countries where our providers operate, with protections required by applicable law.
10. Changes
We may update this notice when the service, providers, or law changes. We will update the date above and provide additional notice when a material change requires it. We will not materially expand use of previously collected mobile opt-in data for marketing without new consent.
11. Contact
For privacy, data, or support questions, open Settings → Support in the app. If you cannot access the app and want to close the account, use the public account-deletion page. See the Support page for the secure contact path.