A product that receives your MFA codes has to earn your trust.
This page explains who owns the numbers, who can read the codes, where data lives, how long it is kept and what the service may not be used for.
Seven commitments.
Your numbers are yours
Every virtual phone number, email address and TOTP token is assigned to one account for as long as you keep it. Nothing is pooled, recycled between customers or exposed publicly. That is the difference between GetMyMFA and public SMS-receiving sites.
Explicit access, per person
Codes are visible only to the users you name: a teammate, an Apple or Google reviewer, a CI service account. Access is granted per asset and can be revoked at any time. Enterprise plans add user management, fine-grained access control and SSO with SCIM provisioning.
API keys you control
Programmatic access uses API keys that you create and rotate yourself from the console. Requests are authenticated with the x-api-key header over HTTPS only.
Data stored in the EU
The platform runs on AWS in the eu-central-1 (Frankfurt, Germany) region. Personal data and received messages are processed and stored there. Where a provider is located outside the EU, transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.
Encrypted in transit and at rest
All traffic is served over HTTPS with HSTS. Stored data is encrypted at rest, access is restricted by role, and the hosting infrastructure is hardened and monitored.
Messages kept one year, then deleted
Received SMS and email messages are retained for 1 year and then deleted. Account data lives for the life of the account, and you can request deletion at any time.
No tracking, no resale
The website uses strictly necessary cookies only. Personal data is never sold or rented, and processors are bound by GDPR data processing agreements.
All-in on serverless, so the controls are inherited from AWS.
GetMyMFA operates no servers of its own. Compute, storage and message processing run as managed serverless services on AWS in eu-central-1 (Frankfurt, Germany). Physical security, redundancy, patching and infrastructure controls are inherited from AWS, which is audited under SOC 1, SOC 2, SOC 3 and ISO 27001. GetMyMFA does not hold a separate SOC 2 report.
Main subprocessors
Third parties that process customer data on our behalf, each under a GDPR data processing agreement.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Serverless hosting, storage and message processing | eu-central-1, Frankfurt |
| Stripe | Subscription billing and payment processing | EU / US (SCCs) |
Built for apps you own, not for dodging verification.
GetMyMFA is a testing and sharing tool for your own applications, test accounts and team. The terms and conditions restrict virtual numbers to lawful use and forbid sharing individual accounts or bypassing safeguards.
- Sharing a test account with Apple or Google reviewers
- Automating MFA in end-to-end tests and CI pipelines
- Forwarding codes for shared team accounts to Slack or Teams
- Running RPA bots on systems you are authorised to automate
- Creating or verifying accounts on services you do not own
- Sharing an individual person's account credentials
- Bypassing security controls of third-party services
- Any unlawful activity, fraud or abuse
Security FAQ.
Need a security questionnaire filled in or a data processing agreement? Email hello@mymfa.io.
01Is GetMyMFA a public SMS-receiving service?
No. Public SMS sites expose shared numbers to anyone. GetMyMFA numbers belong to a single customer account, are never listed publicly and are readable only by users that account explicitly authorises.
02Who can see the codes received on my number?
Only the users you grant access to for that specific number, email address or TOTP token, plus the API keys you create. Access can be revoked at any time from the console.
03Can GetMyMFA send SMS on my behalf?
No. The platform only receives messages and extracts verification codes. It has no sending capability.
04What is the acceptable use policy?
Numbers and inboxes may only be used for lawful purposes on accounts and applications you are entitled to test or share: your own apps, your own test accounts, your own team. Using them to share individual consumer accounts, bypass safeguards, evade verification on third-party services or support unlawful activity is prohibited and leads to termination.
05How long is my data kept?
Received SMS and email messages are kept for 1 year and then deleted. Account data is kept for the life of the account, usage and security logs for a limited period, and anything required by law for the legal retention period. You can request deletion at any time by emailing hello@mymfa.io.
06Is GetMyMFA SOC 2 certified? Where does it run?
GetMyMFA runs fully serverless on Amazon Web Services in the eu-central-1 (Frankfurt) region and operates no servers of its own. Physical security, redundancy and infrastructure controls are inherited from AWS, which is audited under SOC 1, SOC 2, SOC 3 and ISO 27001. GetMyMFA does not hold a separate SOC 2 report; contact hello@mymfa.io for questionnaires.
07Which third parties process my data?
Amazon Web Services hosts the platform and stores messages in eu-central-1. Stripe processes subscription payments; GetMyMFA never stores card numbers. Both are bound by GDPR data processing agreements.
08How do I report a security issue?
Email hello@mymfa.io with the details. We acknowledge reports within 24 hours and keep you informed until the issue is resolved.
Elevate your testing capabilities.
It is time to stop bypassing security and living with misconfigured test environments. Test multi-factor authentication flows safely, from review to CI.