Last updated: July 2026
Reading DialCode.app requires no account and collects no personal information. We use privacy-friendly, cookieless analytics (page counts, referrers, country-level geography) that does not identify you or follow you across sites. There are no advertising trackers and no third-party ad networks on this site. We currently show no ads; if that ever changes, this policy will be updated first.
Creating an API key requires one thing: your email address, used for magic-link sign-in, quota alerts and service notices. No passwords, no names, no billing details. API keys themselves are stored as SHA256 digests - we cannot read your key back, and neither can anyone who reads our database.
Phone numbers submitted to the API are not stored in plain text. Request logs keep only a SHA256 hash of the number (for quota accounting and abuse detection) and are deleted after 90 days. Bulk CSV upload results are kept for 7 days so you can download them, then deleted.
DialCode sets a single first-party session cookie. It exists for security (protecting forms against cross-site request forgery) and, if you sign in, for keeping your API dashboard session. It identifies a browser session, not a person, and is not used for tracking of any kind. There are no advertising, analytics or cross-site cookies.
All connections are encrypted via HTTPS. Complaint data we serve comes from public government datasets (FTC Do Not Call, FCC consumer complaints); the feeds contain no names or contact details of the people who complained, and we publish only aggregates: report counts, complaint topics and per-state totals.
If you have questions about this privacy policy, please reach out via the contact page.