Privacy Policy
Effective date: 11 September 2026
MiniMoth, a product by AbhiMan Stories ("we", "us"), is a developer tool for WhatsApp and SMS OTP authentication and session management. This policy explains what data we collect, how we use it, and how long we keep it. Our direct customers are developers ("you"), and your end-users' data is processed on your behalf.
1. Data we collect
Developer account data
- Email address and a securely hashed password
- Optionally, and only if you choose to add them: your name, a username, and a phone number verified for your own account (separate from your end-users' phone numbers below)
- Project names you provide, and API keys we generate and issue to you to authenticate API requests (rotatable at any time by regenerating a key, which immediately invalidates the old one)
- Wallet balance, top-up history, and session billing records
End-user data (processed on your behalf)
- Indian mobile phone numbers submitted via the API
- OTP codes — stored only as irreversible hashes, never in plain text
- Session records: phone number, hashed refresh tokens, timestamps
- A persistent identity linked to the verified phone number, for phone numbers verified through our live API — used to recognise the same person across multiple logins within your project over time. This does not apply to phone numbers handled through our Supabase or Auth0 integrations, our sandbox/test API keys, or the Test Group preview feature — see Data retention below for how long this is kept and how to delete it
Website visitor data (cookies)
- When you visit minimoth.dev or app.minimoth.dev, we use third-party advertising cookies to measure which channels and ads bring visitors to the site, and whether that leads to a developer signup
- These cookies are only set after you accept them via the cookie banner shown on your first visit. If you decline, no cookies are stored on your device — our advertising partner may still receive limited, non-identifying signals (such as that a page was viewed) used only in aggregate, not to identify you
- This is separate from, and unrelated to, the end-user phone number and session data described above — it concerns visitors to our own website, not your application's end-users
2. How we use this data
- To deliver one-time passcodes by WhatsApp or SMS to the phone number you provide
- To create and validate user sessions on your behalf
- To calculate and record per-OTP billing against your wallet
- To send you transactional email (account creation, top-up confirmations)
- To investigate abuse, errors, or disputes
We do not sell, rent, or share end-user phone numbers or session data with any third party for marketing or advertising purposes.
3. Third-party processors
We use third-party service providers to operate the platform — including WhatsApp and SMS delivery, payment processing, cloud infrastructure, and transactional email. These providers process data only to the extent necessary to perform their respective functions. We do not store raw card or bank instrument data; payment instrument handling is delegated entirely to our payment processor. We also use a third-party advertising platform for the website visitor cookies described above, to measure ad performance and attribute developer signups to the campaigns that drove them.
4. Data retention
- Phone numbers: retained for up to 45 days across our systems (OTP records, sessions, and related tokens), for billing, dispute resolution, and legal requirements — then automatically deleted. This 45-day limit does not apply to a phone number linked to a persistent identity — see below.
- Persistent identities: a phone number verified through our live API is linked to a persistent identity within your project, so we can recognise the same person across multiple logins over time. Unlike other phone number records above, this link is retained indefinitely and is not automatically deleted — recognising a returning person requires keeping it. You (the developer) can permanently delete a specific identity, and the phone number linked to it, at any time via our API. This does not apply to phone numbers handled through our Supabase or Auth0 integrations (those platforms verify the code and manage the identity themselves, on their own infrastructure), our sandbox/test API keys, or the Test Group preview feature.
- Access tokens: expire automatically after 5 minutes.
- Billing and transaction records: retained indefinitely for financial record-keeping. These do not contain phone numbers.
- Developer account data: retained while your account is active. Deleted upon written request to [email protected], subject to any legal hold obligations.
5. Security
OTP codes and refresh tokens are never stored in plain text — only as irreversible hashes. Access tokens are short-lived (5 minutes) and are never written to permanent storage. All connections to our API are encrypted in transit.
6. Your responsibilities as a developer
You are the data controller for your end-users' data. You are responsible for obtaining any consents required under applicable law before sending OTPs to your users' phone numbers, and for maintaining an appropriate privacy policy for your own application.
If one of your own end-users asks you to delete their data, and their phone number was verified through our live API (see Persistent identities above), you can permanently delete their identity — and the phone number linked to it — via our API. See our developer docs for details.
7. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to registered developers. The effective date at the top of this page reflects the most recent revision.
8. Contact
Questions or requests regarding this policy can be sent to[email protected].