MarioSMS

Privacy and the Law: Where MarioSMS Draws the Line

Updated · MarioSMS team

Services in this niche tend to be vague about what they stand for, because vagueness sells to everyone. We’d rather be precise, even if precision costs us some customers. This is the position MarioSMS operates on.

The mission half

We think the phone-number habit of the modern internet is broken. A sign-up form needs to know one thing (that a human, not a script, is registering) and it answers that question by demanding a permanent identifier that will outlive the account, feed data brokers, and ring with spam for years. That trade is bad, and refusing it should not require technical skill.

So the product is exactly that refusal, packaged: a real number for the one minute the verification takes, then nothing. The service you signed up for gets its code; your actual number stays with the people who genuinely need to reach you.

The law half

Privacy is a right. Anonymity while committing crimes is not, and a privacy tool that shrugs at abuse doesn’t stay a privacy tool for long: it becomes a fraud tool with better marketing, then a shut-down company with a subpoenaed database. We’d rather run the boring, durable version. Concretely:

  • We follow KYC rules where they apply. Some service-and-country combinations legally require identity verification. When yours does, we say so before you spend, the check runs once through our verification partner (Veriff), and we store the result rather than your documents. Details in the privacy notice.
  • We observe sanctions. The service is not offered in jurisdictions under comprehensive OFAC, EU, or UK sanctions. No exceptions, no workarounds.
  • The acceptable use policy has teeth. Impersonation, fraud, harassment campaigns, CSAM-adjacent activity, and evading lawful bans get accounts terminated, and where the conduct is criminal, we cooperate with properly served law-enforcement requests. The full list is in the acceptable use policy.
  • We minimize what we hold. No advertising trackers, no data sales, activation records kept only as long as tax and accounting law requires. What we don’t store can’t leak.

Why both halves belong together

These two halves aren’t in tension; they’re the same design constraint. A verification service survives only if platforms’ abuse teams, payment processors, and regulators can live with it existing, and only if its users trust that their data isn’t the product. Every rule above serves both audiences at once.

The practical summary for you as a user: use a rented number anywhere you’d otherwise surrender your real one for a single code. Keep your real number for your bank and your family. And if your use case requires that nobody, anywhere, can ever connect an account to you while you break a platform’s rules, then we’re the wrong tool, on purpose.