Privacy Policy

Effective Date: 4 August 2026
Last Updated: 4 August 2026

1. About This Service

SMS-Passcodes ("the Service") is a private, personal, non-commercial hobby project operated by Brendon Lucas ("the Operator") solely for the benefit of members of the Lucas household and immediate family members ("Authorized Users"). The Service is not offered to the general public, is not a commercial product, and generates no revenue.

2. Information Collected

The Service collects only the minimum information required to function:

The Service does not collect location data, device identifiers, contacts, or any other data from a user's device.

3. How Information Is Used

Collected information is used solely to:

Information is never used for advertising, analytics, profiling, or any commercial purpose. The Service has no commercial purpose.

4. Non-Disclosure

The Operator agrees not to share, sell, disclose, or otherwise transfer any Authorized User's information — including phone numbers, message content, or usage logs — to any third party for any purpose, except:

The Service itself does not transmit user information to any third party beyond what is necessary to deliver SMS responses.

5. Infrastructure Providers

The Service relies on the following providers, each of which processes limited data as necessary to deliver messages and host the Service:

No other third parties receive Service data.

6. Data Retention

Operational logs are retained on the Operator's private server for troubleshooting and are periodically discarded. Credential data stored by the Service is encrypted at rest and retained only as long as the corresponding household account is in use. Twilio retains message metadata according to its own retention policies.

7. Security

Credentials stored by the Service are encrypted at rest using authenticated symmetric encryption. The Service is not exposed directly to the public internet; traffic is routed through an authenticated tunnel. Inbound webhook requests are cryptographically verified. Requests from unauthorized phone numbers are silently rejected.

Despite these measures, no system is perfectly secure, and SMS itself is not an encrypted transport.

8. User Responsibility

Authorized Users are primarily responsible for the security of their own information after it leaves the Service. In particular, users are responsible for:

The Operator cannot protect information that has already been delivered to a user's device. Once a message is received, its security depends on the user's own device hygiene.

9. User Rights

Because the Service is used only by pre-authorized individuals known personally to the Operator, any request to access, modify, or delete personal data may be made directly to the Operator through any normal communication channel. No formal request process is required.

Any Authorized User may request removal from the Service at any time, which will result in immediate deletion of their phone number from the authorized list and deletion of any associated logs.

10. Children's Privacy

The Service is not directed to children under 13 and does not knowingly collect information from them. Authorized Users are adult members of the Lucas household and immediate family.

11. Changes to This Policy

Because the Service has a small, personally-known user base, changes to this Privacy Policy will be communicated directly to Authorized Users. The current version is always available at this URL.

12. Contact

Operator: Brendon Lucas
Email: brendon.eric.lucas@gmail.com