Privacy policy
What Kisoasms collects, why, who processes it, how long it is kept, and your rights under Malagasy law and GDPR principles.
Last updated: 19 September 2026
1. Who is responsible for what
Kisoasms is the controller for account data: members' names, emails, and sign-in information. For message content and recipients' numbers, the customer organization is the controller and Kisoasms processes them on the organization's behalf — the organization decides what is sent and to whom.
2. Data collected
Depending on use, Kisoasms handles:
- Account data: name, email, Google profile image.
- Organization and member data, invitations, and API keys (hashed).
- Paired device info: model, battery, signal, SIM carrier and slot, app version.
- Outbound messages: recipient number, text, status history.
- Inbound SMS: sender, text, time.
- Mobile-money records derived from SMS.
- Webhook configuration and delivery logs.
- Audit log of actions — never message text, keys or secrets.
- Technical logs, including IP addresses used for rate limiting.
3. How data is used
Data is used to deliver the service and nothing else: sending and receiving messages, recognizing mobile-money confirmations where enabled, delivering webhooks, enforcing limits, keeping the audit log, and keeping the service safe. There is no advertising use and no sale of data.
4. Who processes data
Cloudflare hosts everything (Workers, D1, Durable Objects, Queues). Google handles sign-in (name, email, profile image). Groq and Google Gemini see masked SMS text only for organizations that enable AI-assisted recognition — one-time codes and phone numbers are masked before anything is sent. The full list is on the sub-processors page.
5. Retention
Received SMS text is kept 90 days by default; each organization can set 1 to 3,650 days, and sender and time are kept after the text is deleted. Webhook delivery events are kept 30 days. Unsent outbound messages expire from the queue after 24 hours.
Retention of account data after deletion is confirmed by the owner and stated here.
6. Your rights
Members can ask what data Kisoasms holds about them and request export or deletion by writing from their account email. Requests are answered individually; where Kisoasms processes on behalf of a customer organization, the organization is involved as its own controller.
7. Applicable law
This policy is written against Madagascar's personal-data protection law (Loi n° 2014-038) and, for EU visitors, GDPR principles — subject to the owner's confirmation.