Data you send us
When you call the API we receive a phone number, a purpose string and a channel preference. We hash and store the phone number for log lookups; the raw value is not retained beyond the time needed to deliver the verification.
Data we collect about you
- Account: name, email, org name.
- API usage: counts, latency, delivery and verification status, country prefix.
- Logs: redacted recipient (last 4 digits only), purpose, channel, status — kept for 30 days.
What we do not do
- We do not sell or share recipient data with third parties.
- We do not use OTP content to train models.
- We do not read the verification codes after they leave our delivery layer.
Subprocessors
We use a small set of subprocessors to deliver messages and run the service. The current list is published in our Terms (section 9) and changes are announced 14 days in advance via the dashboard.
Your rights
You can request export or deletion of your account data at any time by writing to privacy@tambua.me. We respond within 14 days.
Contact
For questions about this policy: privacy@tambua.me.