Privacy Policy

Last updated: August 28, 2026

1. Scope and who is responsible

This Policy explains how DirectSMSHub (“we,” “us,” or “our”) processes personal data when you use our website, Telegram bot, Mini App, dashboard, wallet, Support, and related digital services. DirectSMSHub is responsible for the personal data it collects to operate those services.

We aim to process personal data fairly, transparently, securely, and only for the purposes described here. This Policy should be read with our Terms of Service and does not replace the privacy policies of payment providers, sign-in providers, suppliers, or third-party platforms.

2. Data we collect

Depending on how you use the Service, we may collect and generate the following data:

  • Account and sign-in data: your Telegram identifier, username, display name and chat identifier; Google account identifier, name and email; or your email address, email-verification status, and securely hashed password if you choose email-password access.
  • Profile and promotion data: language preference, account status, referral code and referral relationship, and eligibility or use of a promotion, discount, referral reward, or wallet credit.
  • Wallet and payment data: wallet balance, wallet ledger entries, deposit amount, currency, payment provider, payment reference, payment channel, and payment status. Card, bank, or other checkout details are handled by Kora Pay; we do not need your full payment credential to credit a confirmed wallet deposit.
  • Order and delivery data: the services, countries, prices, timestamps, statuses, temporary number and SMS content needed to fulfil an SMS order, and the encrypted access credential, listing details, or delivery status needed for a digital account-goods order.
  • Support and communications: support message, reply, reference code, and, for a visitor without an account, the email address they give us so we can respond. We also keep records of service notices and broadcasts we send.
  • Technical and security data: session, device/browser, IP, log, error-reporting, and rate-limit information generated when you use the Service or provided by our hosting and security systems.

3. Optional AI concierge

If you use Direct, our optional concierge, we process the message you send, a short recent conversation history, your live wallet currency and balance, and relevant live catalogue facts to provide read-only guidance. The web app keeps its short chat memory in your browser session and our application does not store a concierge transcript in its database.

Where AI processing is enabled, the current request and limited context are sent to our AI service provider, OpenAI, with a hashed account identifier for safety purposes. Please do not include passwords, payment credentials, full SMS content, or other highly sensitive information in a concierge message. The concierge cannot make purchases or change your wallet.

4. How and why we use data

We use personal data to:

  • create, authenticate, secure, and administer your account;
  • operate the wallet, confirm deposits, price and fulfil orders, and issue refunds;
  • display order, transaction, credential, and support history to you;
  • send transactional notices, support replies, security messages, and service announcements;
  • prevent fraud, abuse, unauthorised access, and misuse of the Service;
  • operate, troubleshoot, improve, and protect the Service; and
  • send non-essential product updates or promotions where permitted. You may ask Support to stop non-essential promotional messages; you will still receive necessary service and transaction messages.

Our grounds for processing include performance of our contract with you, compliance with legal obligations, our legitimate interests in running a secure and sustainable service, and your consent where the law requires consent. If you do not provide data needed for an account, payment confirmation, or order, we may be unable to provide that part of the Service.

5. Who receives data

We do not sell personal data to advertisers or data brokers. We disclose the minimum necessary data to service providers and partners that help us operate the Service, including:

  • Kora Pay for payment checkout and deposit confirmation;
  • Google and Telegram for the sign-in, bot, or notification features you use;
  • SMS-number and digital-goods suppliers to fulfil the order you choose;
  • Resend for email delivery, where email notifications are enabled;
  • OpenAI for the optional concierge as described above;
  • our cloud hosting, database, cache, storage, and error-monitoring providers, including Railway and Sentry where enabled, to host, secure, and diagnose the Service; and
  • authorities, advisers, insurers, or counterparties where required by law or reasonably necessary to prevent fraud, protect rights, or respond to a legal process.

Our providers may process data from locations outside Nigeria. Where a cross-border transfer is necessary, we seek to use an appropriate lawful transfer basis and suitable safeguards for the transfer.

6. Retention and account deletion

We retain data for as long as needed to provide the Service, resolve an issue, maintain accurate financial and audit records, prevent fraud, or meet legal obligations. Retention periods therefore differ by data type and purpose.

You can start self-service account deletion from Settings once your wallet balance is zero and you have no pending deposit or active/unfulfilled order. We verify the request through your verified email address. Deletion removes your sign-in methods and personal profile fields, but we retain an opaque account record and necessary wallet, payment, order, and audit records where needed for accounting, fraud prevention, disputes, or legal compliance.

7. Your privacy choices and rights

Subject to applicable law, you may ask to access, correct, erase, restrict, or object to the processing of your personal data; request portability where applicable; withdraw consent where processing depends on it; or request human review of a decision that was made solely by automated means. Withdrawing consent does not affect processing that was lawful before withdrawal and may prevent us from providing a feature that needs that data.

To make a request, use the in-app Support flow or WhatsApp contact below and state the account email, Telegram identity, or relevant order/support reference so we can verify the request. You may also complain to the Nigeria Data Protection Commission. The rights described here reflect the Nigeria Data Protection Act, 2023; available rights can vary with your circumstances and applicable law.

8. Security and browser storage

We use access controls, authentication safeguards, secure password hashing, encryption for stored digital credentials, and operational monitoring designed to protect data. No online system can be completely secure, so please protect your own sign-in methods and contact us promptly if you suspect unauthorised access.

We use browser storage and similar technologies needed for sessions, security, and preferences such as theme choice and temporary concierge history. We do not use those features to sell behavioural advertising data.

9. Policy changes and contact

We may update this Policy when the Service, our data practices, or applicable law changes. We will post the updated version here with a new “Last updated” date.

For privacy questions or requests, use the in-app Support flow or contact us on WhatsApp at +234 707 415 9687.