Anon SMS Journal
Why every app wants your phone number (and what happens to it next)
Your phone number has quietly become your most permanent online identifier — harder to change than an email address and worth more to data brokers than either. This is where it goes after you type it in, and which of the risks are actually worth caring about.
By Ellis Marner · Delivery & privacy lead, Anon SMS
· 8 min read
Your phone number outlived its purpose
A phone number was designed to do one thing: route a voice call to a handset. It does that job perfectly well. But somewhere in the last fifteen years it picked up a second, unadvertised job — being the unique key that identifies you across unrelated systems.
What makes it so useful for that is exactly what makes it awkward for you: it is scarce and it is sticky. You can create a new email address in thirty seconds and abandon it just as quickly. You can clear a cookie, reset an advertising ID, or open a private window. You cannot spin up a new phone number — it costs money, involves a carrier, and in a growing number of countries requires you to show identity documents. Most people keep the same number for a decade or more, carrying it between carriers, jobs, cities and countries.
So a phone number sits in a category almost by itself: a stable, verified, near-permanent identifier that hundreds of separate companies each hold a copy of. Nobody set out to build a national identity system out of mobile numbers. It happened by accident, one signup form at a time.
The four reasons a signup form asks for it
When a form asks for your number, it is doing one of four things. They are not equally defensible, and it is worth being able to tell them apart before you decide what to type.
1. Genuine security
Two-factor authentication and account recovery are real, and SMS is the only second factor that works for essentially everyone with a phone. It is not the strongest option — an authenticator app or a passkey is meaningfully better, because neither can be intercepted or moved to another SIM — but a service that offers SMS 2FA is protecting you far better than one that offers nothing.
Account recovery is the underrated half of this. If you lose access to your email, a verified number is often the only thing that gets your account back. That is a real benefit, and any honest discussion of phone numbers has to start by acknowledging it.
2. Deduplication and fraud control
The second reason has nothing to do with protecting you. A number is the cheapest available brake on one person becoming a thousand accounts: free trials claimed repeatedly, referral bonuses farmed, review scores inflated, marketplaces flooded with fake sellers. Requiring a number does not stop determined abuse, but it raises the price of each additional account from zero to something, and that alone removes most of it.
This is why services care so much which kind of number you give them. They are not checking that you can be reached; they are checking that the number was expensive enough to be scarce.
3. Identity resolution and ad matching
The third reason is commercial. Ad platforms let advertisers upload a customer list — usually as hashed emails and hashed phone numbers — and match it against their own users to target them or to find people who look like them. Hashing sounds protective, and in some senses it is, but a hashed phone number is still a stable identifier: the same number hashes to the same value everywhere, so two companies that have never exchanged a plain number can still work out that their customer is the same person.
The industry term for this is identity resolution, and it is the entire reason a number is valuable beyond the ability to send you a message. It stitches together the profile of you that would otherwise fall apart every time you switched device or browser.
4. Because the field was in the template
The most common reason is the least dramatic. Somebody built the signup form from a template, the template had a phone field, nobody asked why, and now the number sits in a production database for as long as the company exists. There is no plan for it. There is frequently no retention policy either. It will still be there when the company is acquired, when the database is migrated by a contractor, and when it eventually leaks.
Where it goes after you type it in
A number rarely stays where you put it. Typically it takes three onward paths, often all three at once.
It goes to processors and vendors first, and legitimately: the OTP provider that sends the code, the CRM, the analytics tool, the support desk, the anti-fraud vendor that scores whether your number looks risky. Each one is a separate company with its own storage, its own staff and its own breach history. A single signup can place your number in five or six systems before you finish reading the welcome email.
Then there are data brokers and enrichment services, which trade in exactly this: taking one identifier you provided and returning name, approximate address, age range, employer, household members and other numbers linked to you. Brokers assemble this from public records, loyalty schemes, app SDKs, marketing lists and other brokers. You have no relationship with any of them, which is precisely why they are hard to opt out of — you would first have to learn they exist.
Finally there is breach aggregation, and this is the part people underestimate. Breached datasets do not decay. They are collected, cleaned, cross-joined and resold for years. A number that appeared in a 2019 leak alongside your name and email is still, today, a working join key that links that old record to every newer record containing the same number. Rotating a password fixes the password. Nothing you can do fixes the number short of changing it — which is the one part of the record that almost nobody changes.
The specific risks, ranked by how likely they actually are
Privacy writing tends to lead with the scariest scenario, which is backwards — you make worse decisions when everything sounds equally urgent. In rough order of likelihood:
Spam calls and texts: near-certain. This is the ordinary cost. Once a number is on marketing lists it stays there, and the volume only grows. Annoying, rarely harmful, and effectively irreversible.
Cross-service linkage: very likely. Your number quietly connects accounts you would not have connected yourself — a dating profile and a work account, a side project and a personal one, a forum handle and your real name. Nobody attacked you; the systems just worked as designed. For most people this is the risk that actually matters, because it is the one that happens invisibly and cannot be undone.
Recycled-number surprises: occasional. Carriers reissue disconnected numbers. New owners of a number regularly receive password resets and 2FA codes for accounts belonging to whoever had it before. If you have ever had a number that arrived pre-loaded with someone else's notifications, that is why.
SIM swap and port-out takeover: rare, but severe. An attacker convinces or bribes a carrier employee to move your number to their SIM, then walks through SMS-based resets on your email, exchanges and banking. It is uncommon and usually targeted at people with money or a public profile — but the consequences are the worst on this list, which is why an authenticator app is worth the two minutes it takes to set up.
What you can actually do about it
The useful mental model is that you have two numbers' worth of situations and probably only one number. So sort the situations.
Give your real number where recovery genuinely matters. Your bank, your primary email, your government services, your employer. These are accounts where losing access is worse than being profiled, and where you want a human recovery path to exist.
Prefer an authenticator app or passkey wherever it is offered. It is stronger than SMS and it removes the number from the security path entirely, so a SIM swap stops being a route into the account.
Say no when the field is optional. A surprising share of phone fields are not required at all, and nothing bad happens when you skip them.
Use a temporary number for the long tail. For the marketplace you will use once, the forum you want to read, the trial you are evaluating, the delivery app in a city you are visiting — the number is not protecting you, it is a gate. A one-time number opens the gate without adding a permanent row to a database you will never see. That is the whole reason Anon SMS rents temporary numbers for verification, and if you want the mechanics, how it works walks through a single code from purchase to arrival.
What a temporary number doesn't solve
It would be easy to end here and pretend this is a complete answer. It isn't, and the limits are specific.
It is wrong for anything you need to recover. A temporary number is gone shortly after the code arrives. If a service later asks for that number to verify a login, reset a password or unlock an account, you will not have it. Never use one for an account you would be upset to lose — banking, primary email, anything holding money or years of history.
It is not anonymity. It removes one identifier. Your email, payment method, device fingerprint, IP address and behaviour are all still there, and any of them can identify you on their own. Treating a temporary number as a cloak leads people to take risks the tool does not cover.
It is not a route around a ban or a rule. If a service has closed your account, a fresh number does not reopen it — the block is on the account, the device and the payment method too. Creating multiple accounts, evading suspensions and impersonation are against our acceptable use policy and against the rules of the services themselves. The legitimate case is narrow and honest: verifying an account that is genuinely yours, without handing over an identifier you can never take back.
None of this requires alarm. Phone numbers became identifiers gradually and mostly without malice, and the fix is not to stop using them — it is to stop using the same one for everything.
Read next
- Temporary number vs Google Voice vs burner SIM vs eSIM: which one fits your situation
Google Voice, a second SIM, a travel eSIM or a temporary number — a plain comparison table, plus the exact situations where each one is the right answer and where it walls you out.
- Verification code not arriving? The 9 real reasons, and how to fix each one
An OTP crosses six hops before your phone buzzes, and any of them can drop it silently. The nine real causes, a five-minute triage order, and when the number itself is the problem.
