BirdsmsNEON
Home

Privacy

Version 2026-09-14 · Birdsms Global Networks Ltd.

What we collect, why we collect it, who else sees it, and how long we keep it. Written against what this system actually stores rather than copied from somewhere — if something here is wrong, tell us and we will fix the page or the system.

This document is not finished. The operator has not yet set a registered address or a governing jurisdiction, and it has not been reviewed by a lawyer. Please ask before relying on it.

Who is responsible

Birdsms Global Networks Ltd., at — registered address not set —, decides how and why your data is used. Write to [email protected] about anything on this page.

What we collect, and why

When you register: your name, email address, phone number, country, and a password we store only as a bcrypt hash — we cannot read it and neither can anybody who obtains the database. Optionally a Telegram username and a WhatsApp number, if you give them, so support can reach you.

Automatically at registration and sign-in: the IP address you connected from, a device fingerprint, and your browser’s user-agent string. These are how we tell one account from twenty accounts run by one person, which is what protects the rates for everybody else.

Every sign-in attempt, including the failed ones: what was typed as the identifier, whether it worked, the reason it did not, the IP address and the user-agent. This is what stops somebody guessing at your password, and it is what lets us answer "has anybody been trying to get into my account". ⚠️ Your password is never recorded, in any form, successful or not.

While you are signed in: a record of the session — a hash of the session token, never the token itself — with the IP address and device it was opened from.

Messages that arrive on numbers rented to you: the sender, the number, the full text, the time, and any code we find in it. This is the service.

Money: deposits with their transaction hash and the amount that arrived; withdrawals with the account number or wallet address you gave us, the amount, and the fee; and a ledger of every credit and charge.

Purchases: what you bought from the store and what was delivered.

Administrative actions taken on your account: a suspension, a tier change, a password issued by an administrator — each with the reason and the name of the administrator who did it. You can ask to see this.

What we do not collect

We do not ask for or store government identity documents, dates of birth, or payment-card numbers.

We do not read your email, your messages elsewhere, or anything on your device beyond the browser characteristics described above.

We do not buy data about you from anybody.

Who else sees it

Our SMS providers, who operate the numbers and deliver the messages to us. They necessarily see the messages that pass through them.

Our payment rails — the blockchain a deposit arrives on is public by design, and a mobile-money provider sees a payout we send through them.

Other users, in part. Message traffic is shown on a site-wide feed with parts hidden. Which parts is set by us and can change; your name and account are never attached to a row on that feed.

A public Telegram channel, where we run one, carrying the same feed under the same rules.

We do not sell your data, and we do not give it to advertisers.

We give data to a law-enforcement or regulatory body where we are legally required to, and we will tell you unless we are forbidden to.

How long we keep it

Messages and the traffic they appear in are kept for a limited window — the screens say how long, and older ones drop off.

Your account, your balance and your money records are kept for as long as the account exists and afterwards for as long as tax and anti-fraud law requires.

Sign-in attempts and administrative records are kept as a security record. They are what answers a question asked months later.

What you can ask for

A copy of what we hold about you.

A correction, where something is wrong.

Deletion of your account. Where we must keep money records for legal reasons, we will say so and keep only those.

An explanation of any automated decision that affected you — a suspension, a limit, a refused withdrawal.

Ask at [email protected]. We answer within 30 days.

Security, honestly

Passwords are hashed with bcrypt. Sessions are signed and stored as hashes. Sign-in is rate-limited per account and per address. Administrative actions are logged with the name of the person who took them.

⚠️ No system is perfectly secure, and anybody who tells you otherwise is selling something. If we discover a breach affecting you, we will tell you what happened, what was exposed, and what to do about it.

Cookies

One cookie, for your session. It is httpOnly, so no script on any page can read it, and it is what keeps you signed in.

We do not use advertising or analytics cookies.

Questions about this page? Write to [email protected] or open support.