Privacy
Sending an SMS means handling someone's phone number, so this page says plainly what we store, for how long, and who can see it. We process personal data under Georgian personal data protection law. Two roles matter here: you are responsible for the recipients you choose to message, and we process those messages on your behalf.
What we store about the people you message
| Data | Why | How long |
|---|---|---|
| Recipient phone number | To deliver the message and answer status questions | Kept with the message record |
| Message text | To support delivery and diagnose failures | Encrypted at rest and erased after 30 days |
| Delivery status and timestamps | To report honest delivery state | Kept with the message record |
Our API never returns a full phone number: responses show a masked form such as
+9955••••••67. Message text is never returned at all, and neither numbers nor
text appear in our operational logs.
What we store about you as a developer
Your project name, your API keys, and your usage. API keys are stored only as a one-way hash — we cannot read your key, recover it, or show it to you again after it is created. When accounts open for self-service sign-in, we will store the verified email address from your GitHub or Google account, used for support and service notices only. We do not store passwords, because we do not use them.
Who else sees this data
Messages are delivered through GoSMS.ge, our Georgian delivery provider, which necessarily receives the recipient number and the message text in order to deliver it. Our service runs on Railway infrastructure. We do not sell personal data, and we do not use your message content for advertising or for training machine-learning models.
Security
- All traffic is encrypted in transit (HTTPS).
- Message text is encrypted at rest with a key held only in our deployment configuration.
- API keys are hashed with Argon2; the plaintext exists only in the moment it is shown to you.
- Access to production is limited to the operator.
Your choices
You can ask us to delete your project and everything in it, including message records, at any time. If one of your recipients contacts us directly about their data, we will refer them to you, since you decided to message them — but we will act on a lawful request either way.
Contact
Data questions and deletion requests: jemal@leansystems.ge.