Activating your SMS pool: get the code — and why it belongs on the device, not in the link
With an SMS-pool code you verify online accounts (Signal, Telegram, WhatsApp, …) without exposing your real number. Here’s how to obtain and activate the code — and, importantly, where to keep it so your purchase can’t be linked to your new identity.
What an SMS-pool code is
An SMS pool gives you access to a throwaway phone number at which you can receive a confirmation code (OTP). You use it for a one-off verification of an account — your own number stays out of it. Important: such numbers are shared and temporary. They suit pseudonymous / throwaway accounts, not a durable identity (for Signal, see our separate guide).
Where you get your code — and the decisive choice
At checkout you decide in the configurator (step “Software & Setup”) how your code is delivered. This choice isn’t cosmetic — it determines your anonymity:
- In the order link (convenient): the code appears in your anonymous
/order/link. Handy, but the code then sits in the purchase record. - On the device, with FDE (maximum anonymity, recommended): we place the code encrypted on your phone, not in the link. The purchase record then contains no code.
Why “on the device” is safer — the threat model
Suppose your SMS-pool code sits in the order link. Anyone who sees that link (or the code in it) could in theory ask the SMS-pool provider, via a legal request/subpoena, for the number tied to that code. Through the number, the accounts registered with it can be found — and the code hangs off the same order record as your (e.g. Bitcoin-paid) purchase and your device. That would let your new, supposedly anonymous identity be linked to the purchase.
If instead you put the code on the device (with FDE), it is not part of the purchase record:
- The order link reveals nothing about the code → no chain “purchase → code → number → identity”.
- The device is fully encrypted (FDE) → if it’s seized or lost, nothing is readable without your passphrase.
Hence our recommendation: code on the device + enable FDE. The convenience of the link costs you a piece of the separation between purchase and identity.
Activating the code (step by step)
- Get the code: depending on your choice, either from your
/order/link (under “Your codes”) or it’s already on the device (a folder/note we show you during setup). - Open the SMS pool: go to the provider portal (link/instructions are included), enter the code/voucher and pick a service + country for the number.
- Receive the number: you’re shown a temporary number.
- Verify: in the target app (e.g. Signal) start registration with that number; the confirmation code appears in the SMS-pool portal — pick it up there and enter it in the app.
- Secure it: right afterwards, harden the account (for Signal: PIN + Registration Lock + username; see the dedicated guide). For pool numbers: for permanent accounts, prefer a number that belongs to you.
FDE — don’t forget device encryption
When codes or credentials live on the device, only full-disk encryption (FDE) protects them against physical access. Enable it during initial setup (strong passphrase, not a short PIN). Without FDE your codes would sit in plaintext on storage — readable on loss/seizure. If you choose “code on the device”, we explicitly recommend (and remind you of) FDE.
Quick checklist
- ☐ Delivery chosen: device + FDE (max. anonymity) instead of the link
- ☐ FDE enabled with a strong passphrase
- ☐ Code redeemed in the SMS pool, number received
- ☐ Target account verified
- ☐ Account hardened (PIN/Lock/username)
- ☐ For permanent accounts: considered your own number instead of a pool one
Want us to set everything up privacy-friendly for you (code on the device, VPN, hardening, FDE)? We offer that as a setup service — pick it in the configurator.