1. Introduction
This Privacy Policy explains how personal data is processed when you use the Receive SMS mobile application ("the App", "we", "us", "our"). The data controller is receive-smss.com, Ben Gurion, Tel Aviv, Israel, which operates the App and receive-smss.com; contact details and, where applicable, our EU/UK representatives are in §18. The App lets you read SMS messages sent to free, public, shared phone numbers. It requires no account and no registration. This Policy is provided for transparency; it is a notice, not a consent form — where the law requires consent (for advertising and analytics), we obtain it separately through the in-app consent dialog described in §7. Last updated: July 25, 2026.
2. Summary (plain language)
We don't ask you to provide your name, phone number, or email. The App itself does not build a marketing profile of you — but where you consent, Google AdMob and its partners may use your device advertising identifier to personalize ads, which involves profiling; you can decline at any time (§7). Some personal data (your IP address, advertising and analytics identifiers) is processed automatically, as explained below. Your favorites stay on your device. Every message shown in the App was sent to a public number and is visible to everyone — never send anything private to these numbers.
3. Information you are not asked to provide
The App has no user accounts. It does not ask you to provide, and we do not solicit, your name, email address, personal phone number, contacts, photos, or precise location, and the App never reads SMS from your device — it only displays messages received on our public numbers. Certain personal data is nonetheless processed automatically by us and by our advertising/analytics partners; see §4 and §6. We do not sell personal information for money.
4. Information processed automatically
When the App contacts our servers (for the list of numbers, a number's messages, or remote configuration), our infrastructure receives and briefly logs standard technical data — your IP address, request timestamps, app version, and device type — which we use only to operate the service and to detect and block abuse (our legitimate interest, §10). Separately, the App uses Google Analytics for Firebase to collect usage statistics — screens viewed, feature usage, session length, device type, coarse (country-level) location, and an app-instance identifier. Because this analytics reads/writes identifiers on your device, we rely on your consent for it where the law requires (§7), and it is not activated before consent in the EEA/UK. Analytics data is retained for Firebase's configured period (up to 14 months). This processing is governed by Google's Privacy Policy (https://policies.google.com/privacy).
5. Data stored on your device only
Your favorite numbers, revealed-code state, legal-acceptance record, and cached configuration are stored locally on your device and never transmitted to us. Separately, the Google AdMob and Firebase SDKs store and access their own identifiers on your device to provide ads and analytics, subject to your consent (§7). Uninstalling the App deletes the App's local data.
6. Advertising
The App is free and funded by advertising served by Google AdMob (Google LLC). Where you consent, AdMob and its certified ad-technology partners may collect and process device advertising identifiers (Android Advertising ID / Apple IDFA), coarse location inferred from IP address, device information, and ad-interaction data — and may combine it with other data to build profiles — in order to serve, personalize, measure, and secure ads, including rewarded ads that unlock code reveal. Recipients include Google LLC and its certified partners (list: https://support.google.com/admob/answer/9012903). If you decline, you still see ads, but non-personalized ones. See how Google uses data from apps that use its services: https://policies.google.com/technologies/partner-sites.
7. Your advertising and analytics choices
Where required by law — including the EEA, the UK, Switzerland, and US states such as California — a consent dialog (Google's certified consent framework) is shown before any personalized ads or non-essential analytics run, and you may decline or later change your choice in Settings → Manage ad consent. You can also reset or delete your device advertising identifier in your device settings, and manage Google ad personalization at https://adssettings.google.com. On iOS, the App respects your App Tracking Transparency choice; if you decline tracking, ads are non-personalized. We honor Global Privacy Control (GPC) and similar opt-out signals where applicable.
8. Public messages — important
All phone numbers offered in the App are public and shared, and any SMS sent to them is displayed to every user of the App and of affiliated websites. Message content originates from third parties; we do not control it and act only as a passive conduit that displays it automatically. Do not send, or cause to be sent, any personal, confidential, or sensitive information to these numbers. If a displayed message contains unlawful content or personal data that should be removed, use the in-app Report control or contact us (§18), and we will review and, where appropriate, remove it.
9. Data retention
Only the most recent messages per number (currently up to 30) are available in the App; older messages rotate out of public view. Operational server logs are kept only as long as needed for security and troubleshooting, then deleted or anonymized. Analytics data follows Firebase's configured retention (up to 14 months). Data held by advertising partners is retained under their own published policies.
10. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies: (a) technical server-log data is processed under our legitimate interest in operating and securing the service and preventing abuse (Art. 6(1)(f)); you may object to this processing; (b) advertising identifiers and non-essential analytics are processed on the basis of your consent (Art. 6(1)(a)), which you may withdraw at any time via the in-app consent settings (§7) without affecting the lawfulness of processing before withdrawal or your ability to use the App.
11. Your rights
Depending on your location, you may have the rights to: access your personal data; rectify or correct it; erase it; restrict or object to its processing (including profiling for advertising); data portability; and, where processing is based on consent, to withdraw that consent at any time (§7). You also have the right to lodge a complaint with your local supervisory authority — in the EEA, your national Data Protection Authority; in the UK, the Information Commissioner's Office (ico.org.uk). Because we hold no account data about you, most requests concern advertising/analytics data processed by Google — manage it via the in-app consent screen and your device's advertising-ID settings — but you may exercise any right by contacting support@smss.net. We will respond within the time required by law and will not discriminate against you for exercising a privacy right.
12. US state privacy rights (California and similar)
Categories of personal information processed: identifiers (device advertising ID and app-instance ID, by our partners), internet/app activity (ad and feature interactions), coarse geolocation (inferred from IP), and inferences drawn by advertising partners for personalization. Sources: your device and the SDKs. We disclose/share these categories with Google and its advertising partners for advertising and analytics. We do NOT sell personal information for money and we do not collect "sensitive personal information" as defined by the CPRA (so no "Limit the Use of My Sensitive PI" option applies). To the extent personalized advertising is "sharing" or "cross-context behavioral advertising," you may opt out via Settings → Manage ad consent, which is our "Do Not Sell or Share My Personal Information" control; we also honor Global Privacy Control signals. California and other eligible residents have rights to know, access, correct, and delete, and to non-discrimination; you may use an authorized agent (see §18). See §9 for retention.
13. Children
The App is rated for adults, is not directed to children, and we do not knowingly permit use by, or knowingly collect personal information from, anyone under 18. We do not serve personalized ads or non-essential analytics to users below the applicable digital age of consent (13–16 depending on the EEA member state). In accordance with COPPA, the GDPR, and equivalent laws, if we learn that a child's personal data was processed contrary to this Policy we will delete it; parents or guardians may contact us at any time (§18).
14. Security
We use reasonable technical and organizational measures to protect the service, but no method of transmission or storage is completely secure and we cannot guarantee absolute security. Remember that the core content of the App — messages to public numbers — is public by design. If a personal-data breach occurs, we will notify affected users and authorities where and as required by law.
15. International transfers
Our servers and service providers (including Google) may be located outside your country. Where required, transfers rely on appropriate safeguards such as adequacy decisions or the applicable provider's Standard Contractual Clauses; you may request information about these safeguards via §18.
16. Third-party message content
Messages shown in the App are sent by unknown third parties to public numbers. We do not generate, solicit, review, endorse, or control this content; we display it automatically as a passive conduit. It may be inaccurate, offensive, fraudulent, or unlawful and is accessed at your own risk. Warranty disclaimers and limitations of liability are set out in our Terms of Service and apply to your use of the App to the maximum extent permitted by applicable law.
17. Your responsibility
You are solely responsible for how you use the App and its public numbers. Do not use them for accounts, identities, or communications that matter to you, and do not send or cause to be sent any personal, confidential, or unlawful content to them. Anyone can read messages sent to these numbers.
18. Contact and representatives
Data controller: receive-smss.com, Ben Gurion, Tel Aviv, Israel. Privacy questions, removal requests, and data-subject/authorized-agent requests: support@smss.net (please include enough detail to locate the content or data concerned). If the controller is not established in the EEA/UK, its Art. 27 EU representative and UK representative are: [EU/UK REPRESENTATIVE — appoint and name before EEA/UK launch].
19. Changes to this Policy
We may update this Policy from time to time. For changes that materially affect how we process personal data, we will seek renewed consent or provide prominent in-app notice before the change takes effect; for non-material changes, we will post the updated Policy with a new "last updated" date. Nothing in this Policy overrides mandatory rights you have under the law of your country of residence.