Privacy Policy
Last updated 2026-07-02
Plain-language summary
SMSKit is a fully-managed, hosted service. You bring the phones and SIMs; we run the platform. We process the message content and recipient numbers you send through us on your behalf and on your instructions — as a data processor. The data you route through SMSKit lives in your account's own isolated database, and phone numbers and message content are masked in our logs.
This is scaffolding pending legal review — not legal advice. Final wording will be reviewed by counsel before launch.
1. What we collect
- Account email address (for passwordless login).
- Recovery phone number (verified via Twilio Verify).
- Message content and metadata routed through the service.
- Device telemetry from paired phones (battery, signal, SIM info, heartbeats).
- Billing information processed by our payment provider (Paystack).
- With your explicit in-app opt-in only: the SMS history already on a paired phone (see section 4, Business SMS archival).
2. Why we collect it
To operate the service: route and deliver your messages, surface delivery state, run the dashboard, bill your account, and secure the platform.
3. How long we keep it
Job history retention follows your plan (1 day on Free, 30 days on Standard). Account data is retained while your account is active.
4. Business SMS archival
Business SMS archival is an opt-in feature. It does nothing unless the
account owner gives explicit consent in the gateway app on the phone itself — a disclosure
shown before anything is read, where you also choose how far back to import. With that
consent, the app reads the SMS inbox and sent history already on the device (using Android's READ_SMS permission) and uploads it to your account's private archive.
- What is stored: sender and recipient phone numbers, the message body, timestamps, and the SIM slot the message belongs to.
- Where it lives: in your account's own isolated database, like all your other SMSKit data — never pooled with other customers'.
- Retention: archived data follows your plan's retention settings and is purged when the retention window lapses.
- Deletion & export: you can delete archived data from the dashboard and via the API at any time — per record or in bulk — and export it (NDJSON/CSV) whenever you want.
5. Isolation & roles
Each account's data lives in its own dedicated database — never pooled with other customers. As a hosted SaaS, SMSKit is the data processor; you, the customer, are the controller of the recipient data you send through us. See our Terms for data-processing terms.
6. Subprocessors
- Paystack — billing.
- Twilio Verify — recovery phone verification.
- Firebase / FCM — push wake-ups to your phones.
7. Your rights
You can access, export, or delete account data. Contact support@smskit.cloud for requests.
8. Contact
Privacy questions: support@smskit.cloud.