1. Permitted purpose
Subject to account approval and the Terms of Service, you may use MeraOTP for legitimate authentication events such as:
- verifying a mobile number a user has just submitted;
- confirming a sign-in, password reset, or account recovery attempt;
- applying step-up authentication before a sensitive account action; or
- confirming device enrolment or a comparable user-initiated security event.
The MeraOTP-generated OTP must be connected to the specific user and action, short-lived, single-use, and invalidated after success or expiry. MeraOTP approval does not certify your application or make an otherwise unlawful use lawful.
Separate Payment Tools use
If you subscribe to Payment Tools, you may create UPI QR codes or links only for your own authorised Paytm Business VPA and genuine orders that the payer understands. You must use your own valid Paytm MID, reconcile status with your merchant records, fulfil paid orders, handle refunds and disputes, and provide the payer with legally required business identity, price, tax, cancellation, privacy, and contact information.
You must not create misleading payment requests, impersonate another merchant, alter the payee presented to a payer, solicit payment for prohibited or nonexistent goods or services, falsely mark an order paid, recycle an order ID to misattribute a deposit, or use links for phishing, laundering, unauthorised collections, donation fraud, advance-fee scams, or evasion of Paytm, banking, tax, KYC, consumer, or other legal controls.
2. Messaging that is not allowed
You must not use, attempt to use, or help another person use the Service for:
- advertising, promotions, offers, coupons, lead generation, cross-selling, political campaigns, fundraising, surveys, engagement, or bulk announcements;
- cold messaging, purchased or scraped lists, unsolicited communication, or any message unrelated to a current recipient-requested authentication event;
- general transaction alerts, balance alerts, delivery notifications, KYC results, account-ban notices, deposit or withdrawal messages, or other non-OTP content;
- credential collection, password requests, payment solicitation, requests to reveal an OTP, remote-access instructions, or social engineering;
- messages that include promotional copy, deceptive urgency, unrelated URLs, shortened links, callback numbers, or content intended to evade template review;
- repeated OTPs a recipient did not request, OTP bombing, harassment, or retries that continue after reasonable failure limits; or
- traffic intended to test stolen number lists, inflate volume, manipulate billing or delivery metrics, or degrade a network.
3. Illegal, deceptive, or harmful activity
You may not use the Service in connection with activity that is unlawful, fraudulent, deceptive, exploitative, or harmful. This includes:
- phishing, impersonation, identity theft, account takeover, scams, money-mule activity, laundering, or unauthorised financial transactions;
- illegal gambling, trafficking, controlled substances, weapons, malware, stolen goods or credentials, or other prohibited products or services;
- content that threatens, harasses, defames, discriminates, exploits, or violates another person's privacy, confidentiality, safety, or rights;
- child sexual abuse material, sexual exploitation, non-consensual intimate content, or content that endangers a child;
- infringement of intellectual property, passing off, or unauthorised use of a brand, sender identity, header, domain, template, or phone number;
- evasion of a court order, sanction, regulatory direction, telecom restriction, recipient preference, or provider block; or
- an industry use that requires an approval or licence you do not hold.
4. Platform and security abuse
You must not:
- probe, scan, exploit, reverse engineer, overload, disrupt, or bypass authentication, authorisation, rate limits, source controls, monitoring, or other safeguards;
- access another account, data set, API key, administrative area, or system without clear permission;
- share, sell, lease, publish, or embed API credentials, or operate a public proxy that lets unapproved third parties send through your account;
- misrepresent a server IP or application label, rotate infrastructure to evade a block, or use an allowlisted IP on behalf of an undisclosed service;
- upload malware, malicious code, automated abuse tools, or data intended to cause unauthorised execution or disclosure;
- create multiple or false accounts to evade verification, pricing, limits, suspension, investigation, or payment obligations; or
- use the Service to benchmark or build a competing messaging service without written permission.
Good-faith security research must be authorised in writing before testing. Do not test against production accounts, recipient numbers, or data without specific permission.
5. Recipient, consent, and privacy safeguards
You are responsible for your relationship with each recipient. You must:
- have a lawful basis and any required permission to collect the number and send the OTP;
- provide a clear privacy notice explaining your identity, purpose, providers, retention, and user choices;
- send only to the number supplied or confirmed for the relevant action and take reasonable steps to prevent number enumeration;
- avoid collecting or placing unnecessary personal or sensitive data in a message;
- protect recipient data and restrict it to personnel and systems with a legitimate need; and
- maintain evidence reasonably necessary to show the authentication request and legal compliance.
If your product is directed to children or processes a child's information, you must determine and satisfy applicable parental-consent, notice, age-assurance, and safety requirements before using the Service.
6. OTP content requirements
The OTP message uses fixed verification wording, a brief validity period, a non-sharing warning, and the Codegully signature. It must match the approved sender and content template exactly.
Your OTP for verification is 123456. This OTP is valid for 10 minutes. Do not share it with anyone.
Codegully
Only the OTP value is variable. Do not replace the verification wording or Codegully signature, and do not insert promotional, identifying, or unrelated content into the variable field.
You must not claim that MeraOTP, a telecom operator, a regulator, a bank, or another organisation sent or endorsed your message unless that statement is accurate and authorised.
7. Technical and operational controls
You must use reasonable safeguards proportionate to the risks of authentication messaging, including:
- server-side API calls over HTTPS and secrets stored outside source code;
- production server IP allowlists and their application labels kept current;
- correct use of MeraOTP's server-generated OTP, expiry, one-time verification, attempt limits, and safe application-session binding;
- per-user, per-number, per-IP, per-device, and global request limits appropriate to your threat model;
- cool-down periods, bounded retry logic, bot and abuse detection, and safe recovery paths;
- masked logs and no plaintext OTPs in URLs, analytics, crash reports, or support messages;
- prompt secret rotation, incident containment, and notification to MeraOTP after suspected compromise; and
- compliance with documented request formats, size limits, and provider restrictions.
You may not rely on SMS OTP as the only control for a risk where your applicable law, regulator, contract, or security standard requires stronger or additional authentication.
8. Development and testing
Localhost may be allowed as a development origin. This convenience does not disable other account, API-key, recipient, wallet, rate, or abuse controls. Use test numbers you own or are explicitly authorised to use, keep volumes low, and never test by sending unsolicited OTPs to the public.
Before production, add each public server IP with an accurate domain or application label, rotate any credential used in an insecure development environment, remove debug logging of secrets and OTPs, and confirm your sender/template compliance.
9. Monitoring and enforcement
To protect the Service and recipients, MeraOTP may use automated and manual signals such as volume, velocity, failure rate, duplicate recipients, source changes, complaints, provider feedback, content patterns, payment risk, and account history.
If we reasonably suspect a violation, we may request information, impose limits, reject requests, rotate or disable credentials, quarantine traffic, suspend features or the account, preserve evidence, reverse promotional access, or terminate the Service. Serious or urgent threats may be addressed without advance notice.
We may disclose relevant records to affected providers, rights holders, regulators, law enforcement, courts, or other authorised parties when required by law or reasonably necessary to investigate or prevent harm. Refund eligibility after enforcement is governed by the Refund and Cancellation Policy.
10. Reporting abuse
Report suspected misuse to support@meraotp.in with the subject “Abuse report”. Include the sender header, date/time with timezone, masked recipient number, a screenshot or exact message text, and why you believe it violates this policy. Do not send an OTP, password, API key, full payment credential, or unrelated sensitive data.
For an immediate threat to life or safety, contact the appropriate emergency or law-enforcement authority first.