Company and product
MeuLook is a mobile wardrobe app. Users photograph clothing, organize pieces, and build daily outfits. The public website is https://meulook.app. The iOS and Android apps are not in the stores yet (private / pre-launch). This page describes the expected application and the SMS flows already implemented.
Why we send SMS
SMS is used only to deliver a 6-digit one-time password so the user can prove they control a phone number. It is not used for look suggestions, reminders, promotions, or any other notification.
| Purpose | When the user asks for it |
|---|---|
| Verify phone | Account → phone field → request code |
| Sign in with SMS | User requests a login code on a verified number |
| Reset password | Forgot password → SMS → request code |
Message type
One-Time Password, sent through Amazon SNS Publish with AWS.SNS.SMS.SMSType = Transactional. Messages never include promotional or marketing content.
How users opt in
There is no SMS subscriber list and no automatic enrollment. A message is sent only after the user taps an explicit action in the app (verify phone, sign in with SMS, or reset password) and submits their own number. If the account does not exist, MeuLook does not send an SMS.
Message templates
Same shape for every purpose. {code} is a random 6-digit number. TTL is 10 minutes. Single use.
Seu código MeuLook para verificar seu telefone é {code}. Expira em 10 minutos.
Seu código MeuLook para entrar no MeuLook é {code}. Expira em 10 minutos.
Seu código MeuLook para redefinir sua senha é {code}. Expira em 10 minutos.
Region and destination
Messages are published from AWS Region sa-east-1. The only destination country today is Brazil (+55). We use the account default SNS origination (no dedicated short code or Sender ID).
Volume
Volume is user-initiated and low: typically a few messages per person per month (verify once, occasional login or reset). There are no campaigns and no scheduled sends. Spend-limit requests will stay modest and will reuse this URL.
Abuse prevention
- Rate limit per IP and per phone/email identity
- No SMS if the target account does not exist
- Code stored as a hash; never returned in the API response
- Expired or used codes are rejected
- No automatic retry and no fallback to another channel
Opt-out
This is not a recurring SMS program. The user receives a message only when they request one. They can stop receiving SMS by not requesting codes and by leaving the phone unverified or unused for login and reset.
Expected application screens
The product is a mobile app, not a web product. The website is a coming-soon page. The screens below are the flows that trigger SMS.
Verify phone
In Account, the user enters country code (+55) and phone number, then taps to request the code.
Password reset
On Forgot password, the user chooses the SMS chip, enters the phone number, and taps Send code.
Enter the 6-digit code
The app opens a 6-digit OTP screen. The code expires in 10 minutes and can be used once.
