Skip to content
OTPRun

Legal

Privacy Policy

This policy explains what data OTPRun collects when you use the website, the dashboard, the HTTP API and the MCP server, why we need it, who receives it and how you can control it.

01Scope

This policy applies to the OTPRun website, the web dashboard, the HTTP API and the MCP server (together, the service). OTPRun lets businesses send WhatsApp and Telegram messages and one-time verification codes to their own users.

Two groups of people are involved. Customers are the businesses and developers who create an account. Recipients are the people who receive messages that customers send through OTPRun. This policy covers data about both.

02Who is responsible

The service is operated by OTPRun (we, us). For customer account data, we decide how and why the data is processed and act as the data controller.

For recipient phone numbers and message content, the customer decides what to send and to whom. The customer is the controller of that data, and we process it on the customer’s behalf only to deliver messages and show their history. If you received a message and have a question about it, please contact the business that sent it first. We will help where we can.

03Data we process

We process only the data needed to run the service:

  • Account data: your name, email address and password. The password is stored only as a hash, never in readable form.
  • Workspace and project settings, including team members and their roles.
  • API keys. We store only a hash of each key; the full key is shown once, when it is created.
  • Recipient phone numbers, message text and delivery statuses, such as sent, delivered, read or failed.
  • Incoming messages received on WhatsApp numbers you linked to OTPRun.
  • Contacts you save or import: names, phone numbers, aliases and notes, including the names imported from the address book of a linked WhatsApp number.
  • Verification records: recipient, channel, status and time. Verification codes are never stored in plain text, only as a hash.
  • WhatsApp linked-device session keys that keep your numbers connected, encrypted at rest where applicable.
  • Channel secrets, such as Telegram bot tokens, encrypted with AES-256-GCM.
  • Technical logs: IP address, request path without query strings, and user agent.

04Why we process data

We use data only to:

  • provide the service and keep your account working;
  • deliver your messages and verification codes and show their status and history;
  • keep the service secure and prevent fraud, spam and other abuse;
  • handle billing for paid plans;
  • answer your support requests.

We do not sell personal data, we do not show advertising, and we do not use message content for any purpose other than delivering it and showing it to you.

We process data to perform our contract with you, to meet legal obligations, and in our legitimate interest in keeping the service secure and free of abuse.

05Who receives data

We share data only with the parties needed to provide the service:

  • WhatsApp (Meta) and Telegram, which carry messages to recipients. WhatsApp messages are sent from your own linked numbers; Telegram messages are sent through the @OTPRun_bot bot. Their own privacy policies apply to the data they process.
  • Our hosting provider, ps.kz cloud in Kazakhstan, where our servers and databases run.
  • A payment processor, when billing is enabled, to take payments for paid plans.
  • Third-party apps that you connect yourself, as described in the next section.

We may also disclose data when the law requires it, for example in response to a valid order from a court or public authority.

06Connected apps

You can connect third-party apps to OTPRun through OAuth, for example to use the MCP server. An app you authorize gets access only to the project you choose on the consent screen.

You can see your connected apps in the dashboard and disconnect any of them at any time. After that, the app can no longer access your data. What a connected app does with the data it has received is governed by that app’s own terms and privacy policy.

07Where data is stored

Our servers are located in Kazakhstan. If you use the service from another country, your data is transferred to Kazakhstan and processed there. When you send a message, WhatsApp or Telegram may process it in other countries under their own terms.

08How we protect data

  • Connections to the service are encrypted with HTTPS.
  • Passwords, API keys and verification codes are stored only as hashes.
  • Channel secrets are encrypted with AES-256-GCM, and WhatsApp session keys are encrypted at rest where applicable.
  • Verification codes never appear in our logs, and our logs do not record query strings.

No system is completely secure. If we learn of a breach that affects your data, we will notify you without undue delay.

09How long we keep data

We keep data only as long as we need it to run the service and show your history:

  • Account data: as long as your account exists.
  • Message content and delivery records: up to 90 days.
  • Verification records: up to 30 days.
  • Technical logs: up to 30 days.

After these periods the data is deleted. You can delete projects, linked numbers or your whole account at any time. When you delete your account, we delete its data, except records that the law requires us to keep, such as billing documents.

10Your rights

Depending on where you live, you have the right to:

  • access the personal data we hold about you;
  • correct data that is inaccurate;
  • have your data deleted;
  • receive your data in a portable format;
  • object to certain processing or ask us to restrict it.

Many of these actions are available directly in the dashboard. For anything else, write to us from the email address of your account, and we will reply within 30 days. If you are a recipient, you can also contact the business that sent you the message. You also have the right to complain to your local data protection authority.

11Cookies

We use only the cookies the service needs to work: to keep you signed in and to remember your language and display settings. We do not use advertising or cross-site tracking cookies.

12Children

OTPRun is a service for businesses and is not directed at children. We do not knowingly open accounts for anyone under 16.

13Changes to this policy

We may update this policy when the service or the law changes. The effective date at the top shows the current version. If a change significantly affects how we handle your data, we will tell you by email or in the dashboard before it takes effect.

14Contact

For questions about this policy or requests about your data, write to support@otprun.com.