# Crypton.sh privacy rating

Phone numbers backed by physical SIM cards hosted in the cloud, for receiving and sending SMS through a web interface, API or Android app, plus eSIM data plans. Stored messages are encrypted with a user key.

## Summary

Crypton.sh scores 63 out of 100 (grade C) on the virtual phone numbers criteria. It meets 3 of 8 criteria: no ads or data sales, transparency report and TLS configuration. It partly meets open source, no trackers or telemetry, tells users about requests and security headers. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.

- Website: https://crypton.sh
- Source code: https://gitlab.com/rinzler-labs
- Jurisdiction: United Kingdom. Five Eyes member. GDPR-style data protection law. CLOUD Act data access agreement with the US.
- Home page trackers: Cloudflare Web Analytics (cookieless analytics), Trustpilot (not scored)
- Category: [Virtual phone numbers](https://privacyratings.com/virtual-phone-numbers/)
- Grade: C (63/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | The Android app is GPL-3.0 and the self-hosted BYOD platform is source-available; the main service is closed source. | https://gitlab.com/rinzler-labs/crypton-android-app/-/blob/main/LICENSE |
| No trackers or telemetry | Partial | No third-party advertising trackers, but store builds of the Android app send crash reports to a self-hosted Bugsink server. | https://gitlab.com/rinzler-labs/crypton-android-app/-/blob/main/app/src/main/kotlin/sh/crypton/app/CryptonApplication.kt |
| No ads or data sales | Yes | Paid service; the privacy policy states data is not sold or used for advertising. | https://crypton.sh/privacy |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | Yes | Publishes yearly counts of government and law enforcement requests and whether data was provided. | https://crypton.sh/transparency |
| Tells users about requests | Partial | Affected account IDs are listed in the transparency report for users to check, but there is no promise of direct notice. | https://crypton.sh/transparency |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=crypton.sh&hideResults=on |
| Security headers | Partial | Grade B (70/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=crypton.sh |
| Modern web standards | Not tested yet | Not tested yet. |  |

Source: https://privacyratings.com/virtual-phone-numbers/crypton-sh/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/virtual-phone-numbers/crypton-sh.md
