> ## Documentation Index
> Fetch the complete documentation index at: https://www.offlineprotocol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# SMS Authentication Campaign Privacy Policy

> Privacy policy for one-time authentication code (OTP) SMS messages sent by Offline Protocol, Inc. via Twilio.

**Effective Date:** July 13, 2026
**Last Updated:** July 13, 2026

***

## 1. Introduction

Offline Protocol, Inc. ("Company", "we", "us", "our") uses SMS messaging to deliver **one-time authentication codes (OTPs)** when users choose to sign in or create an account using a phone number. This Privacy Policy describes how we collect, use, store, and share phone numbers and related information **for this SMS authentication campaign only**.

This policy supplements our application privacy policies (for example, the [Fernweh Privacy Policy](/docs/legal/fernweh-privacy-policy)) and applies specifically to transactional SMS messages sent through **Twilio Inc.** as part of our login and sign-up authentication flow.

***

## 2. Campaign Purpose

This campaign is used to deliver one-time authentication codes (OTPs) to users during the **login and sign-up process**. Messages enable users to securely verify ownership of their phone number and access or create an account.

**We do not use this campaign to send promotional, marketing, or advertising messages.**

***

## 3. End-User Experience

1. A user initiates login or sign-up in an Offline Protocol application and **voluntarily provides their phone number**.
2. The user requests an authentication code.
3. We send a single SMS containing a one-time code (for example: `Your Offline Protocol login code is: 123456. It expires in 10 minutes.`).
4. The user enters the code in the application to complete verification.
5. Messages are sent **only in response to the user's authentication request**. We do not send unsolicited messages.

***

## 4. Information We Collect

For this SMS authentication campaign, we collect and process:

| Data Type                        | Purpose                                                | Storage                                                    |
| -------------------------------- | ------------------------------------------------------ | ---------------------------------------------------------- |
| **Phone number**                 | Deliver OTP via SMS; create or authenticate an account | Server-side database (PostgreSQL)                          |
| **One-time authentication code** | Verify phone number ownership                          | Temporary server-side cache (Redis), expires automatically |
| **Message delivery metadata**    | Troubleshooting delivery failures, fraud prevention    | Service logs (limited retention)                           |

We do **not** collect message content beyond the OTP itself, and we do **not** use phone numbers collected through this campaign for marketing purposes.

***

## 5. How We Use Your Phone Number

We use your phone number solely to:

* Send one-time authentication codes when you request them
* Verify that you control the phone number during login or account creation
* Prevent abuse through rate limiting and fraud controls
* Comply with applicable law and carrier requirements

We do **not**:

* Sell or rent your phone number to third parties
* Use your phone number for promotional or marketing SMS
* Share your phone number with advertisers or data brokers
* Use your phone number for purposes unrelated to authentication without your consent

***

## 6. Message Frequency

Messages are **transactional and on-demand**. You receive an SMS **only when you explicitly request an authentication code** during login or sign-up.

Typical frequency:

* **One message per authentication request**
* Additional messages only if you request a new code (for example, if a code expires or you did not receive the first message)

We apply rate limits to prevent abuse (for example, limiting how many OTP requests can be made in a given time period).

***

## 7. Consent and Opt-In

By providing your phone number and requesting an authentication code, you **consent to receive a transactional SMS** containing a one-time code for the purpose of verifying your identity.

Consent is:

* **Explicit** — you initiate the request by entering your phone number and tapping to receive a code
* **Purpose-limited** — authentication only
* **Not a condition of purchasing goods or services** unrelated to account access (where applicable)

If you do not wish to receive SMS authentication codes, you may use alternative sign-in methods where available (such as email-based authentication) or choose not to create an account.

***

## 8. Opt-Out and Help

This campaign sends **transactional authentication messages only**. If you reply **STOP** to an authentication message, you may be unsubscribed from further SMS from our sending number. Note that opting out of SMS may prevent you from using phone-based authentication until you contact us or use an alternative sign-in method.

For help, reply **HELP** to any message from us, or contact us at the address in Section 12.

**Message and data rates may apply.** Contact your mobile carrier for details.

***

## 9. Third-Party Service Provider — Twilio

We use **Twilio Inc.** to deliver SMS authentication messages. When we send you an OTP, we share:

* Your **phone number**
* The **message content** (containing the one-time code)

with Twilio solely for the purpose of message delivery. Twilio processes this data as our service provider under its own privacy practices. For more information, see [Twilio's Privacy Notice](https://www.twilio.com/en-us/legal/privacy).

We do not authorize Twilio to use your phone number for its own marketing purposes.

***

## 10. Data Retention

| Data Type                  | Retention                                                                              |
| -------------------------- | -------------------------------------------------------------------------------------- |
| **Phone number** (account) | Retained for the duration of your account, unless you remove it or delete your account |
| **OTP code**               | Approximately **10 minutes**, or until used — whichever comes first                    |
| **SMS delivery logs**      | Retained only as long as needed for operations, security, and legal compliance         |

When you delete your account, we delete or anonymize associated personal data in accordance with our main application privacy policies, subject to legal retention requirements.

***

## 11. Security

We protect phone numbers and authentication data using industry-standard safeguards, including:

* Encryption in transit (HTTPS/TLS) for all API communications
* Short-lived, single-use OTP codes stored in a secure cache with automatic expiration
* Rate limiting on authentication requests
* Access controls on production systems

No method of transmission or storage is 100% secure. We cannot guarantee absolute security.

***

## 12. Contact Us

If you have questions about this SMS authentication campaign or how we handle your phone number, contact us:

**Offline Protocol, Inc.**
Email: **[legal@offlineprotocol.com](mailto:legal@offlineprotocol.com)**
Support: **[support@offlineprotocol.com](mailto:support@offlineprotocol.com)**

***

## 13. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page. Continued use of phone-based authentication after changes constitutes acceptance of the updated policy.

***

## 14. Related Policies

* [SMS Authentication Campaign Terms of Service](/docs/legal/twilio-sms-campaign-terms-of-service) — terms governing use of SMS authentication
* [Fernweh Privacy Policy](/docs/legal/fernweh-privacy-policy) — full privacy practices for the Fernweh application
* [Fernweh Terms of Service](/docs/legal/fernweh-terms-of-service) — terms governing use of our services
