SimlyX is architected on a privacy-first telecommunications infrastructure. We never sell, rent, monetize, or trade your personal information, phone numbers, contact address books, SMS payloads, or voice call streams to third-party advertising networks, data brokers, or marketing entities.
1. Introduction & Entity Scope
This Privacy Policy explains how SimlyX ("we", "us", "our", or "the Company") collects, uses, encrypts, processes, and safeguards personal data when you use our mobile applications (iOS and Android), web dialers, and website located at simlyx.com (collectively, the "Services").
SimlyX provides Over-The-Top (OTT) virtual telecommunication services, including virtual telephone number provisioning (USA, UK, Canada, Australia, and 50+ international destinations), Voice-over-IP (VoIP) calling, and SMS Two-Factor Authentication (2FA) reception.
By creating an account, provisioning a virtual line, or accessing our Services, you acknowledge that you have read, understood, and agreed to the practices outlined in this Privacy Policy.
2. Information We Collect
To deliver real-time telecommunication connectivity and ensure network reliability, SimlyX collects specific categories of personal information:
A. Account & Profile Information
When you create a SimlyX account, we collect your verified email address, customer identification number (e.g. SIM-XXXXXX), and cryptographically hashed authentication tokens. We do not store plain-text passwords.
B. Telecommunications & Call Detail Records (CDRs)
As required to route phone calls and SMS messages across the Public Switched Telephone Network (PSTN), our servers automatically record standard telecommunications metadata:
- Call Detail Records: Originating phone number, destination phone number, timestamp of call start/end, call duration, call disposition (answered, busy, failed, voicemail), and transit carrier session identifiers.
- SMS Transit Metadata: Sender and recipient phone numbers, message timestamps, delivery receipts, and character length.
- Media Streams: Live VoIP voice audio is transmitted ephemerally via encrypted WebRTC/SRTP. SimlyX does NOT record, listen to, or archive voice telephone conversations.
C. Payment & Transaction Data
When you purchase a virtual number subscription or wallet credits, transactions are processed directly by certified Level-1 PCI-DSS payment gateways (Stripe, Apple In-App Purchases, Google Play Billing, Binance Pay). SimlyX stores only transaction reference IDs, top-up amounts, currency, and renewal expiration dates. We never receive or store complete credit card numbers, CVVs, or bank account credentials.
D. Device & Network Telemetry
To prevent fraud, account takeover, and abusive automated robocalling, we collect hardware model, operating system version, client IP address, mobile network carrier code, and push notification tokens (Apple APNs, Google FCM, OneSignal).
3. Device Permissions & Address Book Contacts
Our mobile applications require specific system permissions to function as a full-featured telecommunications dialer. We adhere to the strictest app store privacy standards:
If granted permission, SimlyX accesses your device’s address book strictly locally on your device to display saved contact names in your dialer, call history, and SMS inbox. SimlyX DOES NOT copy, sync, upload, store on remote servers, share, or sell your contacts to any third party. You may revoke contact access at any time in your device settings.
Used strictly during active, outgoing or incoming VoIP phone calls to capture voice audio. Microphone is never accessed when idle or in background.
Used to wake the application for incoming voice calls, missed call alerts, voicemail notifications, and incoming SMS 2FA verification codes.
4. Legal Bases for Processing Data (GDPR Article 6)
We process personal data under the following lawful bases established by European and global privacy frameworks:
- Performance of a Contract: Provisioning dedicated virtual phone numbers, routing VoIP call packets, and delivering SMS verification codes to fulfill our user agreement.
- Legitimate Business Interests: Detecting and mitigating fraudulent robocalling, securing cloud infrastructure, enforcing our Acceptable Use Policy, and maintaining telecommunications quality.
- Legal & Regulatory Obligations: Maintaining transaction ledgers for accounting and taxation, and complying with lawful court orders or telecommunication carrier retention directives.
- Consent: User authorization for optional mobile permissions (push notifications, local contact resolution).
5. How We Use Your Information
SimlyX uses collected data exclusively for operational, security, and customer service purposes:
- Allocating, activating, and renewing virtual numbers (Direct Inward Dialing / DID) across worldwide carrier networks.
- Transmitting and receiving real-time SIP/WebRTC voice calls and SMS text messages.
- Sending real-time push alerts for incoming communications.
- Verifying account authentication and preventing credential stuffing or unauthorized account takeover.
- Processing subscription billing, recurring auto-renewals, and balance top-ups.
- Providing direct customer support via our dedicated email desk (support@simlyx.com).
6. Third-Party Carrier Infrastructure & Processors
To interconnect with the worldwide telecommunications grid, SimlyX partners with licensed Tier-1 carriers and certified cloud service providers:
PSTN voice interconnect, DID number allocation, and CTIA/10DLC SMS transit.
PCI-DSS compliant payment processing, subscription management, and crypto settlements.
Encrypted token-based dispatch of real-time call ringing and SMS delivery notifications.
7. Data Security & Encryption Architecture
SimlyX deploys enterprise-grade security protocols across every layer of our telecommunications stack:
- Transport Layer Security (TLS 1.3): All API signaling, user authentication, and web sessions are encrypted in transit.
- SRTP Media Encryption: VoIP voice audio is transmitted using Secure Real-Time Transport Protocol (SRTP) to prevent wiretapping and eavesdropping.
- AES-256 Storage Encryption: User database records, encrypted authentication hashes, and session metadata are encrypted at rest with AES-256 standards.
- Access Controls: Strict role-based access control (RBAC), multi-factor admin verification, and isolated virtual private cloud (VPC) subnets.
8. Data Retention & Call Detail Records
We retain personal data only as long as necessary to provide services and fulfill statutory obligations:
- Active Account Data: Retained while your account remains active and in good standing.
- Call Detail Records (CDRs): Retained for up to 12 months for billing reconciliation, carrier settlement, and fraud investigation, after which records are automatically anonymized or purged.
- Released Numbers: When a virtual number subscription expires or is cancelled, all association with your account is detached and the number enters a carrier quarantine period before release.
9. Your Global Privacy Rights (GDPR & CCPA/CPRA)
Regardless of your geographical location, SimlyX extends comprehensive data privacy rights to all registered users:
You may request a machine-readable export of all personal data and transaction records linked to your account.
You may update or correct inaccurate account profile details directly in the app or via support.
You have the absolute right to request permanent account deletion and purging of your personal records.
We will never deny services, charge different prices, or degrade quality if you exercise your statutory privacy rights.
10. Account & Data Deletion Instructions
In compliance with Google Play Developer Policies, Apple App Store Review Guidelines, and GDPR Article 17, SimlyX provides simple, permanent account deletion:
"Account Deletion Request - [Your User ID]". Our team will verify and complete the data purge within 30 days.
11. Children's Privacy (COPPA & Global Standards)
SimlyX is strictly intended for individuals aged 16 and older (or 13 where permitted by local law with parental authorization). We do not knowingly solicit or collect personal information from children. If we discover that a minor under the minimum legal age has created an account without parental consent, we will promptly delete all associated data and terminate the account.
12. Emergency Services (911 / 112 / 999 / 000) Limitation Notice
SimlyX is an Over-The-Top (OTT) Voice-over-IP telecommunications service and is NOT a traditional fixed-line or cellular mobile telephone carrier. SimlyX DOES NOT support emergency calling to public emergency response dispatch centers (including 911 in the USA/Canada, 999 in the UK, 112 in the EU, or 000 in Australia). You must maintain traditional cellular or landline service for emergency calls.
13. Policy Updates & Official Contact Desk
We may periodically update this Privacy Policy to reflect carrier compliance changes, regulatory updates, or software enhancements. When material revisions occur, we will update the "Effective Date" at the top of this document and notify users via in-app banner or registered email.
If you have any questions, GDPR/CCPA data requests, or compliance inquiries regarding this Privacy Policy, please contact our dedicated support team:
Response SLA: All data privacy and compliance requests are reviewed and addressed within 24 to 48 business hours.