1. Scope and operator
This policy applies to the 2nd Line iOS app, its communication and account services, and the 2nd Line support pages operated by Glayzer LLC under the Glayzer Studio name. Apple, telecommunications carriers, and the service providers identified below also process information under their own privacy terms.
2. Account information
- Email account. If you register with email and password, Firebase Authentication processes your email address, authentication credentials, verification state, and a user identifier. We do not receive your plain-text password.
- Sign in with Apple. If you choose Apple sign-in, we receive the identifier Apple provides and, depending on your Apple settings, your email address or private relay address.
- Account status. We maintain a service identifier and account status so balances, lines, purchases, support requests, and communication history can be returned to the correct signed-in user.
3. Numbers, calls, messages, and verification data
- Second numbers. We process the country, selected number, line label, provider identifiers, subscription state, renewal status, and assignment history needed to provision and maintain each line.
- Calls. We process the calling and called numbers, selected line, direction, status, timestamps, duration, provider call identifiers, destination country, and token settlement. Live audio is carried by Twilio and telecommunications networks. 2nd Line does not provide call recording and does not intentionally store call audio.
- SMS. We process sender and recipient numbers, selected line, message body, delivery status, segment count, timestamps, provider identifiers, and token settlement. Message bodies are encrypted in our service database and are cleared when you delete the message in the app.
- One-time verification. We process the selected service, country, temporary number, provider activation identifier, status, expiry and cancellation times, token settlement, and the verification code delivered for that activation.
Communications necessarily disclose your selected second number and the destination number to communication providers, carriers, and the recipient. Do not use 2nd Line for confidential communications that require end-to-end encryption.
Before a 2nd Line user can initiate SMS to a US recipient, we may require the recipient to provide verifiable permission through a recipient-specific invitation. We process the invited mobile number, sending line, consent or revocation state, disclosure version, timestamps, invitation expiry, and limited anti-abuse attempts. A recipient may also provide permission by sending the first message. STOP revokes permission and START restores it; HELP requests service information. These controls are enforced before an outgoing US message is accepted.
4. Regulatory identity and document review
Some countries and phone-number types require the actual end user to provide identity, business, address, or supporting-document information before a number can be assigned. The app displays the applicable requirements before payment and asks only for the fields required for the selected country, number type, and individual or business use.
Depending on the requirements returned by Twilio for the selected country and number type, the submitted data may include your legal name, email address, phone number, date of birth, residential or service address, government-issued identifier, nationality, and business or registration information. Supporting files may include government-issued identity documents, proof of address, business registration records, or another PDF, PNG, or JPEG document expressly requested for that number application.
When regulatory review is required, the information and document files you submit are transmitted over encrypted connections through our protected service to Twilio's Regulatory Compliance service. Twilio may make the information available to telecommunications carriers or public authorities where required to review the request. Twilio, the relevant carrier, or the competent regulator—not Glayzer LLC—has final authority to approve, reject, request corrections, or revoke regulatory approval.
Our service stores the provider references, selected market, application status, required-item status, review messages, and timestamps needed to show progress and connect an approved request to the correct account. We do not retain the identity-document file itself after it has been transmitted to the provider. Twilio and any reviewing carrier or authority may retain submitted information for the period required by telecommunications law, fraud prevention, audit, or their own privacy terms. We do not sell regulatory identity information or submitted documents.
5. Purchases, tokens, and rewards
Apple processes payment details. We receive product and transaction identifiers, entitlement and renewal state, purchase history, and related verification information needed to assign a number or credit a call, message, or verification wallet. We do not receive your full payment card number.
For prepaid regulatory verification credit, we also process the selected destination wallet, purchase state, linked regulatory request, provider review state, credit time, and any refund or balance-recovery adjustment. This lets us prevent duplicate submissions, add the disclosed tokens after Apple verifies payment, and respond to App Store refunds.
If you use an optional rewarded ad, Google Mobile Ads and our service process an ad reward session, device-derived anti-abuse value, reward type, cooldown eligibility, and advertising transaction identifier. Where consent or Apple tracking permission is required, the app asks before using data for personalized advertising. You may decline and continue using the app; non-personalized ads may be available.
6. Device permissions and notifications
- Contacts. Contact access is optional and used on your device to select a recipient, display a saved name, or prepare a new contact. We do not upload your address book. The selected phone number is sent only when you request a call or message.
- Microphone. Microphone access is used for live calls. The app cannot place a functional voice call without it.
- Notifications and VoIP calls. We process encrypted push tokens, app environment, locale, and delivery status to alert you about incoming calls, messages, verification codes, cancellations, support replies, and line renewal.
7. Analytics, diagnostics, and security
Firebase Analytics may process product interactions, app version, device and operating-system information, approximate technical location derived by the provider, session events, and basic diagnostic data. We use this information to understand feature reliability and improve the app, not to read the content of your calls.
We also process timestamps, request identifiers, device-derived hashes, provider webhook events, cost and abuse signals, failed requests, and security logs to prevent duplicate rewards, fraud, spam, unauthorized access, and unexpected provider charges.
8. Support information
Support requests created in the app include the category, subject, message, account identifier, locale, status, timestamps, and replies. If you contact us by email, we also receive your email address and anything you choose to attach. Never send passwords, payment card details, or active verification codes.
9. Service providers
- Apple for App Store distribution, Sign in with Apple, purchases, subscriptions, refunds, and push notification delivery.
- Firebase and Google for authentication, analytics, messaging, consent management, and optional rewarded advertising.
- Twilio for number inventory, second-number assignment, calls, SMS, communication status webhooks, regulatory requirements, end-user records, address records, supporting documents, and regulatory review status.
- GrizzlySMS for temporary verification-number inventory, activation status, cancellation, and code delivery.
- Cloudflare for the protected application gateway, encrypted service records, request routing, and security controls.
- Telecommunications carriers and recipients as required to route calls and messages.
We do not sell personal information. We do not disclose communication content for unrelated marketing. Providers may process data in other countries under their own terms and applicable safeguards.
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text messaging services.
10. Storage and retention
Active account, number, wallet, purchase, communication, verification, reward, notification, and support records are retained while needed to provide the service, display history, settle provider charges, prevent abuse, resolve disputes, and meet legal obligations. Provider systems may apply their own operational or compliance retention periods.
You can delete individual call and message history in the app. Deleting a message clears its stored body from our service record. You can also permanently delete your account from Settings. Account deletion closes or releases active provider resources, removes communication, wallet, verification, notification, reward, and support data associated with the account, deletes the Firebase account, and retains only a minimal deleted-status record or records required by law, security, or completed financial obligations.
11. Security
Data is transmitted over encrypted connections. Provider credentials are held on the server rather than embedded in the app. Sensitive provider secrets, push tokens, message bodies, and verification codes are protected at rest. No system can guarantee absolute security, but we use access controls, isolated provider resources, idempotency checks, cost controls, and reasonable safeguards appropriate to the service.
12. Your choices and rights
You may decline contacts, microphone, notification, advertising consent, or tracking permission in iOS Settings, although some features cannot work without the permission they require. You may manage subscriptions through Apple, delete history in the app, delete your account in Settings, or contact us to exercise access, correction, deletion, restriction, portability, or objection rights available in your region.
13. Children, changes, and contact
2nd Line is not directed to children below the minimum digital consent age in their region. We may update this policy when features, providers, or legal requirements change. The effective date above identifies the current version.
Send privacy questions or rights requests through the 2nd Line support page. We may need to verify account ownership before acting on a request.
Contact 2nd Line support