The short version: we collect your phone number to prove you're a real person who really showed up. We don't sell it, we don't run ads against it, and every anti-abuse limit we enforce is published below — the same rules for everyone, in the open.
Thumit is operated by Rare Dynasty LLC, based in Corona, California, USA ("Thumit," "we," "us"). Thumit is a verified-visit rating service: people who provably showed up at a place thumb it up or down. Privacy questions go to privacy@thumit.app.
Your phone number. Your phone number is your identity on Thumit. We use it to send a verification code by SMS and to enforce the core rule: one person, one account, one live thumb per place. We do not use your number for marketing, and we do not sell it or share it with advertisers.
Verification codes — never stored readable. When we text you a six-digit code, we store only a keyed cryptographic hash of it, never the code itself. Codes expire five minutes after they're sent, are deleted on successful verification, and are swept once expired.
The last four digits of your number. Kept separately so a screen can say "code sent to •••1234" without touching your full number.
When you last verified. A single timestamp of your most recent verification. This one fact supports account security — for example, protecting accounts whose numbers may have been recycled by a carrier.
Your visits and thumbs. Verified visits and thumbs are what Thumit is. A place's score — verified thumbs up ÷ all verified thumbs — is public by design, and every thumb links to an audit record. Your identity behind a thumb is held as an opaque identifier, not your phone number.
Anti-abuse counters. To enforce the published limits below, we keep short-lived counts of code requests per phone number and per device. Counters are retained 90 days, then deleted.
Every anti-abuse limit Thumit enforces is listed here. There are no hidden thresholds.
| Limit | Value |
|---|---|
| Verification code length | 6 DIGITS |
| Code lifetime | 5 MINUTES |
| Wrong entries per code | 5, THEN DEAD |
| Wait between resends | 60 SECONDS |
| Codes per phone number per day | 5 |
| Codes per device per day | 10 |
| Anti-abuse counter retention | 90 DAYS |
Thumit sends SMS for one purpose: verification codes you request by entering your phone number. We never send marketing texts. Message and data rates may apply per your carrier plan. Messages are delivered through our SMS infrastructure provider (currently Telnyx), which processes your number solely to deliver the message.
We use a small number of infrastructure providers — SMS delivery (Telnyx) and web hosting (Cloudflare). They process data only on our instructions and only as needed to provide their service to us.
You can request access to or deletion of the personal information associated with your phone number by emailing privacy@thumit.app from a means that lets us confirm you control that number. California residents have rights under the CCPA/CPRA, including the rights to know, delete, and correct; we honor these requests for everyone, not just Californians. We do not "sell" or "share" personal information as those terms are defined in the CPRA.
Thumit is not directed to children under 13 and we do not knowingly collect their personal information. If you believe a child has provided us information, contact privacy@thumit.app and we'll delete it.
Verification codes are stored only as keyed hashes, secrets live in controlled infrastructure, and reading public scores never exposes who cast a thumb. No system is perfectly secure, but minimizing what we store is the first line of defense: data we don't keep can't leak.
Thumit is in beta and this policy will evolve with the service. We'll update the effective date above when it changes, and material changes will be noted here.
Privacy: privacy@thumit.app
Everything else: hello@thumit.app