Privacy Policy
Read in order
Data we process
Depending on the enabled features, OTP Helper may process the extracted OTP, technical identifiers needed to connect your devices, account email and verification state, password hash, protected sessions, device status, plan and payment status, and security events. Operational delivery records may contain an opaque operation identifier, source type, selected profile, linked account and PC, app version and platform, supported protocol version, stage timestamps and a content-free outcome. Passwords, connection tokens and OTP history are excluded from monitoring logs.
On iPhone, a Shortcut may transmit SMS fragments or a one-time code depending on its configuration. OTP Helper for Android processes new SMS, notifications from selected apps, or shared or manually entered text locally. Android sends only the extracted or selected numeric code, without full text, sender or source app name.
Mailbox connections described here belong to Windows PC Agent: mailbox addresses, app passwords and OAuth tokens are stored only on the user’s PC in Windows-protected storage and are displayed in masked form. The Android app does not connect to Gmail APIs or obtain mailbox OAuth tokens; it may process notifications from selected email apps under the Android rules below.
Purpose and retention
Data is used to protect the account, connect authorised devices, deliver a code to the selected PC, apply the plan, process payments and prevent password guessing or channel abuse. The latest OTP awaiting a PC connection is held in Relay memory for up to 60 seconds; a newer code replaces it. Transfers use HTTPS/WSS, but the server processes the plaintext code inside the protected connection: this is not end-to-end encryption that hides it from the server. Android-specific local processing is described below. For service diagnostics and aggregated product metrics, detailed technical delivery stages are kept for up to 180 days; the latest device-presence state remains while the corresponding link or account is retained. These records never contain the OTP, SMS or email text, sender, mailbox address or page URL. OTP Helper does not sell SMS, email or account data and does not create advertising profiles.
Infrastructure
The main service infrastructure is hosted in Russia. Selectel provides hosting, YooKassa processes payments and Better Stack receives service-health telemetry without email addresses, passwords, tokens or OTPs. Encrypted backups are isolated from the running application and rotated automatically.
Only public website pages use Yandex Metrica tag 112281213, including Session Replay and click and link maps. On those pages, Yandex may receive a page path without query parameters or fragments, a referrer unless it identifies a private OTP Helper route, browser and device details, network address and approximate region, technical identifiers stored in cookies or local storage, and actions taken on the page. OTP Helper uses this data only to count visits and improve the website interface; it is not added to the account database or used by OTP Helper for advertising profiles.
On the private /account, /auth, /oauth, /en/oauth, /iphone, and /maket routes, neither the Metrica code nor its fallback image is loaded. Page views, page and referrer addresses, actions, and screen contents from those routes are not sent to Metrica. Navigation between the public and private areas performs a full page load so the tag cannot remain active on a private screen. Yandex processes public-page analytics under the Yandex Metrica Terms of Use; a visitor may restrict it through browser settings or a tag blocker.
Card details are entered on YooKassa’s page and are not stored by OTP Helper.
Google data and Limited Use
Gmail is connected voluntarily through the official Google OAuth flow. OTP Helper requests only https://www.googleapis.com/auth/gmail.readonly. The Windows application checks recent messages locally, extracts a verification code and does not send, modify, delete or mark messages as read.
The connected address and Google refresh token remain on the user’s PC. Email contents, sender and Google credentials are not transferred to the Relay, personal account, analytics, monitoring or server backups. By default, the extracted OTP stays on the same PC and is made available only to the locally connected browser extension.
If a Pro user expressly selects another destination for a particular mailbox, only the extracted OTP may be delivered either to the user’s linked PC through the protected, short-lived Relay channel or to an HTTPS endpoint configured by that user. The mailbox address, message body, sender and Google credentials are never included. The Relay retains a pending OTP only for delivery and deletes it within 60 seconds; a user-controlled external endpoint is governed by its own privacy and security terms.
Google API data is used solely for the visible user-facing feature of locating and delivering verification codes. It is not sold, used for advertising or profiling, used to train general AI or machine-learning models, or made available to employees or unrelated third parties. The use of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Google user data protection mechanisms
- Encryption in transit. PC Agent communicates directly with Google OAuth and Gmail API endpoints over HTTPS/TLS. Any user-selected Relay or external API delivery also requires a protected HTTPS/WSS connection.
- Encryption at rest. The Gmail address and refresh token are stored only in the current Windows user profile inside a Windows DPAPI-encrypted secrets container. The Google access token exists only in process memory and is not written to disk.
- Least privilege and data minimisation. OTP Helper requests only
gmail.readonly, checks only recent messages needed to locate an OTP, and does not request permissions to send, edit or delete email. - Short retention. Message contents are not archived by OTP Helper. An extracted OTP is kept only in volatile memory and is erased no later than 60 seconds after receipt or immediately after confirmed use.
- Secret-free logs and backups. Google tokens, mailbox addresses, message contents, senders and OTPs are excluded from application logs, analytics, monitoring, the OTP Helper account database and server backups.
- Access and revocation controls. DPAPI binds stored credentials to the current Windows account. Users can remove a Gmail connection at any time; PC Agent attempts to revoke the Google grant and always deletes the local token. Suspected unauthorised access is handled by revoking affected credentials and investigating security events without recording Google message contents.
Android application
OTP Helper for Android 1.0.0 helps the phone owner deliver numeric verification codes of 4–12 digits to their linked Windows PC. Before use, the app explains data processing. Automatic forwarding, SMS and notification sources are off by default. You separately enable sources and Android permissions. Notifications are processed only for apps you select; an empty allowlist permits none.
New SMS text, the latest eligible notification from a selected app (including an email app), and text you share or enter manually are processed locally in memory. Only the extracted or confirmed numeric code is sent to the OTP Helper relay over HTTPS. Full message text, sender numbers, notification titles, source app names and attachments are not uploaded. The app does not read SMS history or request contacts, location, microphone recording, phone identifiers or an advertising ID.
The connection link and secret authorise activation, channel checks and delivery. The server associates the channel with your account and PC, uses the connection IP address to limit abusive requests, and records content-free delivery results under the service retention rules above. The relay can read the code inside its HTTPS handler; this is not end-to-end encryption that hides it from OTP Helper servers.
The connection secret is encrypted locally using AES-256-GCM and a separate Android Keystore key. It is stored outside app backups; cloud backup and device-to-device transfer are disabled for app data. Hardware-backed key protection depends on the device and is not guaranteed on every phone. Plain HTTP, cross-address redirects, cookies and HTTP caching are disabled for app requests; system certificate checks remain enabled.
Message text and codes are not written to app files, a persistent sending queue or the event journal. They exist temporarily in process memory; immediate erasure of every managed-memory copy is not guaranteed. Manual input is cleared from UI state when you leave the app screen. Duplicate prevention uses a temporary code fingerprint and a window of up to 60 seconds.
The local journal contains at most 30 entries with time, source type and delivery result, without codes, message text, senders or source app names. It displays the last 24 hours; older stored entries are removed when the journal is loaded or updated, not by a timer while the app is stopped. The success counter remains until the connection or app data is deleted. The journal, counter, settings, consent and selected app list are not uploaded by the Android app. Separate server-side delivery diagnostics are retained as described above.
Camera access is optional and is used only after you choose QR pairing. QR recognition happens locally; images are neither saved nor uploaded. Manual link entry is available. Notification permission shows forwarding status and a pause action, without codes or message text. Optional biometric or device-credential protection uses the system authentication dialog; the app receives no biometric template or PIN. It locks the interface, not previously enabled background forwarding. Release screens are protected against ordinary screenshots and recent-app previews.
You may pause forwarding, disable SMS or notification sources, remove an allowed app, or revoke access in Android settings. A request already sent to the relay may still finish; pausing does not recall a delivered code. Removing the connection deletes its encrypted local link, key, journal, counter and allowed sources and disables forwarding. It does not revoke copies of the link held elsewhere: generate a new link in PC Agent to revoke those copies. System permissions can be revoked separately. Uninstalling or clearing app data removes local settings through Android.
The Android app contains no advertising, analytics, session-replay or crash-upload SDKs. This does not disable the server diagnostics described above. When you open the OTP Helper website in an external browser, its website privacy rules apply. Forward only your own messages and authorised account codes; protect the personal connection link like a password.
Your controls
You may change account credentials, close sessions, unlink a PC, export account data or delete the account. A Gmail connection may be deleted separately in the PC Agent; the application attempts to revoke Google access and always removes the local OAuth token. Contact official@otphelper.com to exercise data rights.
Controller
- Data controller
- Самозанятый АНФИМОВ ОЛЕГ ВЛАДИМИРОВИЧ
- Tax ID (INN)
- 350100439257
- official@otphelper.com
