Legal documents

Privacy Policy

What data OTP Helper needs, how it is protected and how you control access.

Current versionUpdated: August 18, 2026

Privacy Policy

Read in order

01

Data we process

Depending on the enabled features, OTP Helper may process the extracted OTP, technical identifiers needed to connect your devices, account email and verification state, password hash, protected sessions, device status, plan and payment status, and security events. Passwords, connection tokens and OTP history are excluded from monitoring logs.

Mailbox addresses, app passwords and OAuth tokens are stored only on the user’s PC in Windows-protected storage and are displayed in masked form.

02

Purpose and retention

Data is used to protect the account, connect authorised devices, deliver a code to the selected PC, apply the plan, process payments and prevent password guessing or channel abuse. OTPs are held in memory for no longer than 60 seconds or removed immediately after confirmed insertion. OTP Helper does not sell SMS, email or account data and does not create advertising profiles.

03

Infrastructure

The main service infrastructure is hosted in Russia. Selectel provides hosting, YooKassa processes payments and Better Stack receives service-health telemetry without email addresses, passwords, tokens or OTPs. Encrypted backups are isolated from the running application and rotated automatically.

Card details are entered on YooKassa’s page and are not stored by OTP Helper.

04

Google data and Limited Use

Gmail is connected voluntarily through the official Google OAuth flow. OTP Helper requests only https://www.googleapis.com/auth/gmail.readonly. The Windows application checks new messages locally, extracts a verification code and does not send, modify, delete or mark messages as read.

The connected address and Google refresh token remain on the user’s PC; the token is protected by Windows DPAPI. Email contents, sender, Google token and extracted OTP are not transferred to the Relay, personal account, analytics, monitoring or server backups.

Google API data is used solely for the user-facing feature of locating and locally delivering verification codes. It is not sold, used for advertising or profiling, used to train general AI models, or made available to employees or unrelated third parties. This use follows the Google API Services User Data Policy, including Limited Use requirements.

05

Your controls

You may change account credentials, close sessions, unlink a PC, export account data or delete the account. A Gmail connection may be deleted separately in the PC Agent; the application attempts to revoke Google access and always removes the local OAuth token. Contact official@otphelper.com to exercise data rights.

06

Controller

Data controller
Самозанятый АНФИМОВ ОЛЕГ ВЛАДИМИРОВИЧ
Tax ID (INN)
350100439257
Email
official@otphelper.com