Privacy Policy
Last updated: June 19, 2026
What We Store
- Email address β used for authentication (magic link login)
- Public resources β information you choose to make publicly visible (stored as plaintext)
- Granted resources β information shared only via links (encrypted when encryption is enabled)
- Private resources β information only you can access (encrypted client-side)
- Access logs β records of who accessed shared resources and when
- Grant metadata β which links you created, their expiry, access count
What We Cannot Access
- Your encryption keys β generated and stored in your browser only
- Content of encrypted resources β we store ciphertext that only you can decrypt
- Bearer tokens for share links β we store only a cryptographic hash
Encryption Status
MyNumber.is enforces client-side encryption for all non-public data. When you mark information as "private" or "shared only," it is encrypted in your browser before being sent to our servers. We store only the encrypted version β we cannot read it. Only you can decrypt it.
Note: Encrypted sharing (allowing a recipient to decrypt via a share link) is planned for a future release. Currently, share links only include public (unencrypted) resources.
Enforcement: Our server rejects any attempt to store non-public data without encryption. Medical, financial, and credential data must always be encrypted when not marked as public. There is no plaintext fallback.
Important: Public resources (information you choose to display on your profile page) are stored in plaintext β this is by design, since they are meant to be visible to anyone.
Medical & Health Information
MyNumber.is allows you to store emergency medical information (blood type, allergies, medications, etc.). This data may be classified as sensitive personal data under LGPD (Lei Geral de ProteΓ§Γ£o de Dados) and GDPR. By default, medical information is stored with "granted" visibility β accessible only through share links you create. You can choose to make it public (e.g., for emergency responders) at your own discretion.
Your Rights
- Access β you can view all your data via the dashboard and API
- Deletion β you can delete resources, revoke grants, or request full account deletion
- Portability β all your data is accessible via JSON API
- Revocation β you can revoke any share link at any time
- Transparency β access logs show who accessed your data and when
Data Retention
- Account data: retained while account is active
- Access logs: retained indefinitely (for audit purposes)
- Deleted resources: soft-deleted (can be permanently removed on request)
- Free numbers: deactivated after 30 days + 30-day grace period
Third-Party Services
- Brevo β transactional email (receives your email address for code delivery)
- Stripe β payment processing (for paid numbers; handles card data directly)
- Umami β privacy-respecting analytics (no cookies, no personal data collected)
Security
We use HTTPS, Content Security Policy headers, HMAC-hashed tokens, and client-side encryption. For a detailed technical description of our security model, see our Security Documentation.
Contact
For privacy-related questions or data deletion requests: privacy@mynumber.is
Risks & Limitations
This platform is in beta. While we take security seriously:
- If you lose your encryption keys without a backup, encrypted data cannot be recovered
- Public resources are visible to anyone with your number URL
- Share links are accessible to anyone who has the URL
- We are a small team and cannot guarantee the same availability as larger platforms
