Phreeli Review 2026: Signup and Payment Requirements
Phreeli markets a mobile service built around data minimization and separation between payment and phone use. Its current legal documents describe a narrower promise than the earlier version of this article. Mobile service requires a nine-digit residential US ZIP code and a valid payment method. Device orders require a name and mailing address. Phreeli also reserves the right to request more information for legal compliance.
Those facts support a review of reduced data collection. They do not support calling the service anonymous, claiming that it never asks for identity information, or promising protection from carrier, court, or intelligence records.
What the terms require
Phreeli's Terms of Service describe voice, roaming, SMS, and data as its mobile services. Plans are prepaid month to month by default. The eligibility section lists two required items for mobile service: a nine-digit ZIP code for the subscriber's residential address and a valid payment method.
The same section says a device purchase requires the subscriber's name and a valid mailing address. A backup phone number or email address can be supplied for account restoration. The company reserves the right to ask for additional information at signup to comply with legal obligations.
"ZIP only" is incomplete. The current contract requires a valid payment method, uses a nine-digit residential ZIP code, adds name and address requirements for devices, and permits further compliance requests.
Current payment claims are limited
The terms say subscribers can use methods accepted through the website and that these generally include most debit and credit cards. They discuss cryptocurrency only conditionally: "if" the company offers it, network fees and price volatility apply.
That language does not verify a current Monero option, shielded Zcash support, or a particular card unlinkability guarantee. The previous article presented all three as current payment methods. Those claims were removed.
The public privacy claim is data minimization
Phreeli's privacy overview says the company separates payments from phone use, collects the minimum needed for service and legal compliance, and does not sell data or do business with data brokers. These are company statements, not an independent audit.
The detailed Privacy Policy controls the actual data categories, uses, disclosures, retention, and rights. The terms also describe location information for 911, an optional physical address for Wi-Fi calling emergency service, fraud and SIM-swap records, account notices, and service suspension. A useful review must keep those operational records in view.
The white paper separates the full design from launch
Phreeli published a Double-Blind Armadillo white paper describing an architecture intended to separate user payment, authentication, login, and phone-service operations. It builds on Privacy Pass and user commitments to reduce linkability between service components.
The launch section matters. It says the initial version uses a simpler Privacy Pass with user commitments approach instead of the full double protocol. The second Privacy Pass run between the mixing service and phone service is removed. The paper states that this simpler design relies in part on trust assumptions about the mixing service, which maintains a mapping between a user commitment and a phone identifier.
The earlier article described the full design as if every proposed separation operated at launch. The primary document does not support that reading. A protocol design can reduce which component sees which identifier while still leaving payment processors, the mixing service, the mobile network, emergency systems, device records, and account recovery in the broader data path.
What can be said safely
- Phreeli offers prepaid month-to-month mobile service under its current terms.
- Mobile service signup lists a nine-digit residential ZIP code and valid payment method.
- Device orders add a name and mailing address.
- The company can request additional information for legal compliance.
- The company states that it minimizes data and does not sell it to data brokers.
- The published launch architecture is simpler than the full Double-Blind Armadillo design.
What remains unverified
- Current Monero or shielded-Zcash payment availability.
- The underlying mobile network operator and the exact records exchanged with it.
- Session-only eSIM delivery over Tor.
- Automatic deletion of shipping addresses after dispatch.
- Categorical resistance to tower dumps, subpoenas, or National Security Letters.
- Comparative claims that Phreeli is the first or most private US carrier option.
Phreeli's documents show an unusual attempt to reduce data linkage inside a mobile-service workflow. The current evidence supports that bounded description. It does not support an anonymity guarantee. Device identifiers, cellular-network location, account recovery, payment records, emergency-service data, and information requested for compliance remain part of the threat model.
For device-level controls above the carrier layer, see the GrapheneOS privacy phone guide.
Sources
Frequently Asked Questions
What information does Phreeli require for mobile service?
Phreeli terms list a nine-digit residential US ZIP code and a valid payment method. The company reserves the right to request additional information for legal compliance. Device purchases also require a name and mailing address.
Does Phreeli promise anonymous phone service?
Its public material describes data minimization and separation between payment and phone use. The terms still require account and payment information, permit additional compliance checks, and describe location and emergency-service records. These documents support a reduced-data model, not a guarantee of anonymity.
Does Phreeli officially promise Monero or Zcash payments?
The current terms say the website generally accepts most debit and credit cards and discuss cryptocurrency conditionally if offered. The reviewed official pages do not establish current Monero or shielded-Zcash availability, so this article no longer states those options as fact.
Is the full Double-Blind Armadillo design used at launch?
The published white paper says the initial launch uses a simpler Privacy Pass with user commitments design and removes the second protocol run from the full Double-Blind Armadillo architecture. It also states a trust assumption for the mixing service.