Privacy Policy

Last updated 8 September 2026

This is a working draft describing how the platform actually operates. It has not been reviewed by a lawyer. If anything here matters to you, ask us before relying on it.

AkomaSMS is a messaging platform for businesses. Two different groups of people are involved: our customers, who hold an account with us, and their recipients, who receive the messages our customers send. This policy covers both.

What we hold about our customers

  • Account details: name, email address, phone number and company name.
  • Authentication data: a hashed password, and two-factor secrets if enabled.
  • Billing records: payments, credit purchases and wallet transactions.
  • API keys, stored as hashes so we cannot read them back to you.
  • Technical logs: IP address, browser and the actions taken in the dashboard.

What we hold about message recipients

When a customer sends a message we store the recipient's phone number, the message text, and its delivery status. We hold this on our customer's behalf: they decide who is messaged and what is said. We do not sell it, and we do not use it to market to recipients.

Why we read message content

Every outgoing message is screened for fraud before it is sent. This is automated and pattern-based. A message that looks like a scam may be held for a member of our team to review, or refused. We do this to protect the people receiving messages through our platform and to meet our obligations to the networks that carry them.

Who else sees the data

  • Our SMS provider, which carries the message to the recipient's network.
  • Paystack, which processes card and mobile money payments. We never see or store full card details.
  • Our hosting and email providers, as part of running the service.

How long we keep it

Message records are kept while the account is open so customers can see their sending history. Audit logs are kept for six months. Backups are encrypted and retained on a rolling schedule of up to six months. Closing an account removes the account data; anonymised counts may remain in aggregate reporting.

Security

Traffic is encrypted in transit. Passwords are hashed, API keys are stored as hashes, and webhook secrets and verification codes are encrypted at rest. Access to production data is limited to staff who need it, and admin actions are recorded in an audit log.

Your rights

You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. If you received a message through our platform and want it stopped, contact us and we will pass the request to the sender and record the opt-out.

Contact

Email support@akomasms.com with any question about this policy or the data we hold.