Effective 18 September 2026
Privacy Policy
This policy explains how Tuma processes the information needed to run a WhatsApp messaging API account and deliver the messages you send.
Information we process
We process your account details (name, email), the WhatsApp number and session metadata you connect, the message content and recipient numbers you send through the API, delivery statuses, hashed API keys, subscription payment references and statuses, and operational audit logs.
How we use it
We use this information to authenticate you, route and deliver your messages, show delivery status and logs, enforce plan limits, bill your subscription, prevent abuse, and keep the service reliable.
Messages and recipients
You choose the messages and recipient lists you send. You are responsible for your recipients’ data and for having a lawful basis to contact them; Tuma processes that data only to deliver the messages you request.
Service providers
WhatsApp carries message traffic to your recipients. Safaricom (M-Pesa / Daraja) processes your subscription payments. Hosting and database providers store application data. Each provider handles information under its own terms.
Retention and security
We retain operational records while your account is active and as reasonably required for security, disputes, accounting, and legal obligations. API keys are stored hashed, credentials are encrypted at rest, and access is restricted by role.
Your choices
You can manage your numbers, keys, message log, and account data from the dashboard. Requests to access, correct, export, or delete account information should be directed to the operator through the support contact provided in the service.
Changes
We may update this policy as the service changes. The effective date above identifies the current version.