2nd Line · 2nd Line - Fluxai

Privacy Policy

How 2nd Line handles account, calling, messaging, verification, advertising, and support data.

Controller, scope, and contact

This Policy applies to the 2nd Line Android app (com.secondline.phonenumber) and its service layer. The app is published and operated under the 2nd Line - Fluxai name. Privacy and account-deletion requests may be sent to glayzer34@gmail.com. It does not cover third-party services you choose to contact using 2nd Line.

Account and device data

Google Sign-In and Firebase Authentication process your Google account name, email address, profile information, sign-in tokens, Firebase user ID, IP address, and authentication security events. We use the Firebase user ID as the internal account key. For account support and service security, the service records the latest sign-in time, latest activity time, sign-in provider, and coarse country code supplied by Cloudflare from the request; it does not store precise location for this purpose. Firebase Cloud Messaging processes an app-installation identifier and push token. The app also creates a random installation ID for trial and rewarded-ad abuse prevention. App Check and Google Play Integrity process device/app attestation material. We do not collect your Google password.

Numbers, calls, contacts, and audio

We process rented number details, selected line, destination or originating number, call direction, time, status, duration, credit charge, and provider identifiers. Contact access is optional and requested only after you tap the contacts control. If granted, Android's PhoneLookup is used on the device to match saved phone numbers with names in call history and when placing a call. The address book and contact names are not uploaded; only the number you choose to call is sent as the requested destination. If access is denied, the system picker can still share only the single contact you select. Live voice audio is transmitted through Twilio to complete the call. 2nd Line does not record or store call audio. The microphone is requested only when a call needs it.

Messages and SMS verification

For SMS, we process sender and recipient numbers, encrypted message content, delivery state, segment count, error code, time, and credit charge. For SMS verification, we process the selected service and country, assigned verification number, activation state, encrypted received code, provider reference, expiry/cancellation times, and credit settlement. These records are used only to provide the action you request, display its status, prevent duplicate charging, and issue eligible refunds. 2nd Line does not guarantee that an external service will accept a number.

Purchases, wallets, rewards, feedback, and support

Google Play processes payment details. We receive product, order, subscription/base-plan state, purchase token, expiry, acknowledgement, test-purchase, refund/void, and linked-purchase information needed to verify entitlements and prevent fake purchases; sensitive tokens are encrypted or hashed. We keep separate call, message, and verification wallet balances and ledgers. Optional rewarded ads process the chosen wallet, a pseudonymous device hash, signed ad transaction, reward state, and cooldown. If you choose the one-time private feedback offer, we store the selected experience, optional note, rewarded-ad session, credited wallet, bonus amount, and submission time. This feedback is not a Google Play rating or review. Support requests contain the subject, message, status, language, and replies you submit.

Analytics, diagnostics, ads, and consent

Firebase Analytics may process app interactions, device/app information, identifiers, IP-derived approximate region, and campaign information. Crashlytics processes crash traces, app/version and device diagnostics, installation identifiers, and crash time. Google Mobile Ads may automatically collect and share IP address, approximate location inferred from IP, app interactions such as launches, taps and ad views, diagnostics, app-set/device identifiers, and advertising data for ad delivery, analytics, and fraud prevention. The Android advertising-ID permission is removed from this app. Where required, Google's User Messaging Platform presents consent or privacy choices before an optional rewarded ad is loaded.

Recipients and international processing

Cloudflare hosts the API and database; Google provides Sign-In, Firebase, Play Billing, Play Integrity, consent, and rewarded ads; Twilio provides phone numbers, voice, and SMS; Grizzly SMS provides SMS verification inventory. Data is disclosed to these providers only as needed for their contracted function, security, legal compliance, or a transaction you request. We do not sell personal data. Ad-related data is shared with Google as described above. These providers may process data in Türkiye, the United States, the EEA, and other countries where they operate, using their contractual and legal transfer safeguards.

Retention and deletion

Active account data is kept while the service is used and as needed for billing, delivery, security, disputes, fraud prevention, and law. You may delete an individual message; its content is then erased while minimum settlement metadata may remain. You may delete an individual call; its counterparty is erased while minimum settlement metadata may remain. Account deletion immediately starts release of active Twilio numbers, cancellation of eligible pending verification requests, deletion of messages, call destinations, support conversations, push tokens, wallets, and service records, and deletion of the Firebase account. Limited purchase, refund, anti-fraud, security, and provider-cost records may be retained or de-identified where legally or operationally necessary. Firebase states that Authentication deletion is removed from live and backup systems within 180 days, Cloud Messaging installation data within 180 days after deletion, and Crashlytics crash data is retained for 90 days. Other providers apply their published retention rules.

Your controls and rights

In Settings you can sign out, delete your account, open this Policy, manage or cancel Google Play subscriptions, and review advertising privacy choices. Call and message history can be deleted from their screens. You can request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable by using in-app Support or emailing glayzer34@gmail.com. We may verify identity before acting. You may also complain to your competent data-protection authority. Withdrawing consent does not affect earlier lawful processing.

Security, age, changes, and emergencies

Data in transit uses encrypted HTTPS/TLS or provider-secured voice transport. Sensitive provider credentials, message bodies, verification codes, push tokens, and purchase tokens are encrypted or hashed server-side; API requests require authenticated sessions and app attestation is monitored. No method is completely risk-free. 2nd Line is intended for users able to enter a binding agreement and is not directed to children under 13. It is not an emergency calling service. We may update this Policy when features, providers, or law change; the effective date and material notices will be updated. Effective 13 August 2026.