Skip to privacy information

Privacy

What the gateway stores and why

Last updated: July 30, 2026

SelfSMSPortal is self-hosted software. The person or organisation running a deployment decides why SMS is sent and is normally responsible for its recipients and message content. This page describes the software's default data flows; your operator should provide any additional notice required for its deployment.

Data handled by the software

  • Account data: username, email address, password hash, plan, and billing references.
  • Gateway data: generated device identifier, device model, Android/app version, SIM labels, permission and connection health, and last contact time.
  • SMS operations: recipient number, message body, routing choice, purpose, queue timestamps, status, errors, and batch metadata.
  • Security records: event time, IP address, truncated user agent, rate-limit records, and administrative actions.
  • Stripe-hosted billing identifiers and subscription state when billing is enabled. Card numbers and CVCs are not collected by this application.

How data is used

The data is used to authenticate users and gateways, route and reconcile SMS jobs, show delivery history, enforce limits, diagnose failures, secure the service, and reconcile an optional Stripe subscription. It is not sold by the software.

Storage, retention, and deletion

Runtime records are stored in the deployment's private persistent storage. Job history remains until the workspace owner deletes the account or the operator applies its documented retention process. Backups may retain deleted records until their own retention period expires. Operators should choose and disclose a retention period suitable for their purpose, legal duties, and recipients.

Processors and diagnostics

Stripe processes billing on its hosted pages when enabled. Sentry crash reporting is optional and disabled unless a deployment supplies a DSN; screenshot attachments are disabled by default and sensitive request, recipient, and message fields are redacted. Hosting, backup, email, and network providers selected by the operator may also process data.

Your choices

Workspace owners can review delivery history, remove gateways, and delete their account. Recipients should contact the sender shown in a message to withdraw marketing consent or object to further messages. Operators must maintain and apply do-not-text requests before new campaigns.

Security

Production deployments require HTTPS, private runtime storage, unique secrets, access controls, verified release artifacts, backups, and timely updates. No system is risk-free; report a suspected issue without including recipient numbers, message bodies, passwords, tokens, or keys.

Contact

For product privacy questions, email sms@support.scratchive.com. For a specific message or deployment, contact the organisation that sent it.