Skip to content

Policies

Acceptable use, in brief

What passcode.sh is for, what it's never for, and what happens when an account breaks the rules. A plain-language summary.

Last updated
Updated
Reading time
1 min read
On this page3
  1. Good uses
  2. Never allowed
  3. What happens when rules are broken

This is a plain-language summary. The full Acceptable Use Policy and Terms are what actually apply.

Good uses

  • Signing up for services without handing over your personal phone number.
  • Keeping a separate number for a side project, a test account or a marketplace listing.
  • Testing your own product's SMS verification, by hand or through the API.

Never allowed

  • Fraud of any kind — payment fraud, scams, impersonation, or false claims to get refunds.
  • Account takeover — receiving codes for accounts that aren't yours, or getting around someone else's verification.
  • Financial and government verification — opening or verifying bank, payment, crypto, government or healthcare accounts, including through "Any other service".
  • Abuse at scale — creating accounts in bulk for spam, fake reviews, vote manipulation, or farming promotions and free trials.
  • Harassment, threats, or anything else that's illegal where you are or where the service is.
  • Attacking passcode.sh — probing for vulnerabilities, scraping outside the API, or trying to get around rate limits or the refund rules.

What happens when rules are broken

We may refuse orders, revoke API keys, or disable accounts that break these rules. A disabled account can't sign in, use the API or place orders, and the API answers its requests with account_disabled.

Note

Seen passcode.sh numbers being used for abuse? Email support@passcode.sh with what you saw, including the number and the time if you have them.