Skip to content

Privacy Policy

Last updated: September 10, 2026

This policy describes how Authevo handles data today and is current as of the date above. We may update it before general availability.

1. Who we are and scope

Authevo is a developer-first verification API that confirms the identity of your end users by sending one-time passcodes (OTPs) over WhatsApp. Telegram fallback is automatic only after a recipient completes a one-time link; if the recipient is not linked when WhatsApp delivery fails, the API returns 409 CHANNEL_NOT_LINKED with a one-tap Telegram URL for the integrating product to display.

This policy explains how Authevo ("we", "us", "our") handles information when you, as a developer or business ("you", "our customer"), integrate our API, and how we handle information about the end users you ask us to verify on your behalf.

It applies to the Authevo API, dashboard, documentation, and marketing website. For the personal data of your end users, you are the data controller and Authevo acts as your processor: we only process that data to provide the verification service you have requested.

2. Data we process

We deliberately keep the data we touch to the minimum needed to deliver and verify one-time codes and to bill accurately. We process:

  • Developer account information — the details you provide to create and manage an account, such as your name, work email address, business name, API keys, and WhatsApp Business Account configuration.
  • End-user phone numbers — submitted by you to request a verification. Phone numbers are hashed with SHA-256 and are never stored in plaintext at rest; the plaintext number exists only transiently in memory long enough to dispatch the message for delivery.
  • One-time codes (OTPs) — generated to verify a user. Codes are short-lived and are never stored in plaintext; we keep only what is needed to validate a code during its brief validity window.
  • Delivery and usage metadata — operational records such as verification timestamps, delivery channel (WhatsApp or Telegram), delivery and verification status, and request volume, used for analytics, billing, and abuse prevention.

3. How we use information

We use the information above only to operate and improve the verification service:

  • To deliver and verify OTPs — generating a code, dispatching it over WhatsApp (or Telegram as fallback), and confirming the code your end user enters.
  • For fraud prevention and rate limiting — our Safety Floor and rate-limiting controls protect both you and us against abuse, spam, and runaway spend.
  • For billing — we bill for verification usage (per successful verification on the standard tier, and per message sent for new accounts until their first 500 verifications), so we record the metadata needed to count sends and successful verifications accurately.
  • For product analytics — we use aggregated and operational metadata to understand reliability, troubleshoot delivery, and improve the service.

4. What we do not do

Some commitments about what Authevo will never do with this data:

  • We do not sell personal data to anyone, ever.
  • We do not use end-user phone numbers for marketing, advertising, or profiling.
  • We do not retain plaintext phone numbers or plaintext one-time codes at rest.
  • We do not send SMS or email on your behalf — verification is delivered over WhatsApp, or over Telegram after the recipient has completed the one-time link.

5. How we protect your data

Security is built into the product, not bolted on afterwards:

  • Phone numbers are hashed with SHA-256 before storage, so raw identifiers never sit at rest.
  • WhatsApp Business Account access tokens are encrypted at rest using AES-256-GCM.
  • Outbound webhooks are cryptographically signed so you can verify they genuinely came from Authevo.
  • Rate limiting and the Safety Floor throttle abusive traffic before it reaches delivery.

No method of transmission or storage is ever completely secure, but we work to protect your data using industry-standard safeguards.

6. Data retention

We keep data only for as long as it is needed for the purpose it was collected for.

One-time codes are transient and expire automatically — typically within about ten minutes — after which they can no longer be used to verify a user.

Operational logs and delivery metadata are retained for a limited period — generally around 30 days — to support troubleshooting, billing, and abuse investigation, after which they are deleted or further anonymized. Account information is retained for as long as your account remains active.

7. Sub-processors

We rely on a small number of trusted third parties to deliver the service. Each processes only the data needed for its function:

  • Meta Platforms — the WhatsApp Business Platform, used to deliver one-time codes over WhatsApp.
  • Telegram — used as the fallback channel after a recipient completes the one-time link; unlinked recipients must first be shown the one-tap URL returned by the API.
  • Supabase — our primary database, storing hashed phone numbers, delivery metadata, account information, and encrypted access tokens.
  • Upstash — a Redis service used for rate limiting, session state, and short-lived one-time-code state.
  • Render — hosts our API service.
  • Cloudflare — hosts our marketing site and dashboard, and provides content delivery, network-level security, and privacy-first analytics.
  • Resend — our transactional email provider; it receives your email address and the contents of the account, billing and product emails we send you.
  • Polar — our merchant of record for card payments; it receives the billing and payment details you enter at checkout and processes the charge. Authevo never receives or stores your full card number.
  • Sentry — error monitoring; it receives application error reports with personal data (phone numbers, codes, tokens) scrubbed before they are sent.

Delivery providers necessarily receive the destination phone number in order to deliver the message. Their handling of that data is governed by their own privacy terms.

8. Cookies and analytics

We use two measurement tools, and neither is used for advertising. Cloudflare Web Analytics collects aggregated page-view and performance signals on our marketing website; it sets no cookies and does not fingerprint visitors. Alongside it we run our own first-party analytics on the marketing website and the dashboard, which records which pages are viewed and a small number of named interactions — for example opening the documentation, running the interactive demo, or starting a test verification — so we can see where people get stuck.

Our first-party analytics sends its records to our own servers and stores them in our own database; they are never shared with an advertising network or any third-party analytics vendor. Each record holds the name of the event, the page path, the page you arrived from, your language, and any campaign parameters in the link you followed, together with a random identifier we generate and keep in your browser's local storage. That identifier lets us count one visit across several pages as one visit rather than five; it is not a cookie, is never sent to any other website, and is not linked to your name, email address, phone number or Authevo account. We do not store your IP address on these records. They are deleted automatically after 90 days.

Because neither tool sets advertising or cross-site tracking cookies, the marketing site shows no cookie-consent banner. Our dashboard may set strictly necessary cookies required to keep you signed in and operate the product. We do not use cookies for advertising or cross-site tracking anywhere in Authevo.

9. International users and data

Authevo is built for developers and businesses in Egypt and the wider MENA region, and our service and support are focused on that market.

Because we and our sub-processors operate internationally, information may be processed in countries other than your own. Wherever it is processed, we apply the same protections described in this policy.

10. Egyptian data protection (Law 151 of 2020)

Authevo is operated from Egypt, so we handle personal data in line with Egypt's Personal Data Protection Law (Law No. 151 of 2020) and its Executive Regulations (issued by Ministerial Decree No. 816 of 2025 and in force since 1 November 2025), which are overseen by Egypt's Personal Data Protection Centre.

For the personal data of your end users, you are the data controller and Authevo acts as your processor (see section 1). We process that data only to deliver the verification you request, and we apply the law's core principles throughout — lawful and transparent processing, data minimisation, purpose limitation, accuracy, storage limitation, and security.

Under the law, data subjects have the right to be informed about processing, to access their personal data, to correct or erase it, to restrict or object to processing, to withdraw consent, and to data portability. Because Authevo stores only a SHA-256 hash of an end user's phone number and never the plaintext number or code (see sections 2 and 5), requests about a specific individual are normally handled by the customer acting as controller; we assist our customers with them and act on verified requests sent to support@authevo.dev, including the deletion path described in section 11.

Some of our sub-processors are located outside Egypt (see sections 7 and 9). The law regulates cross-border transfers of personal data; we transfer only the minimum data needed to run the service and rely on providers that offer appropriate security and contractual safeguards. The registration and licensing steps the Executive Regulations require of controllers and processors — including for cross-border transfers — require a registered legal entity, and Authevo is not registered as one yet (our Terms say the same, in section 5). We intend to complete both within the transition period the law allows (to 31 October 2026).

If you believe your data has been handled in a way that does not comply with the law, contact us first at support@authevo.dev. You also have the right to lodge a complaint with Egypt's Personal Data Protection Centre.

11. Your rights and contacting us

Because Authevo processes end-user data on your behalf, requests from end users to access, correct, or delete their information should usually be directed to the business that asked them to verify — that is, our customer, acting as controller. We will support our customers in responding to such requests.

If you are one of our customers and want to access, correct, export, or delete your account information, or if you have any question about this policy, contact us at support@authevo.dev and we will respond promptly.

12. Changes to this policy

We may update this policy from time to time as the product and applicable law evolve.

When we make material changes, we will update the "Last updated" date above and, where appropriate, notify our customers. Your continued use of Authevo after an update means you accept the revised policy.