Privacy Policy
Pamosi AI ("Pamosi", "we", "us") builds tools that help West African traders, cooperatives, clinicians, and families work with their phones — mostly through WhatsApp and a companion mobile app. This policy explains what personal information we collect when you use Pamosi, how we use it, who we share it with, and the choices you have.
1. Who runs Pamosi
Pamosi AI is operated by Pamosi AI Ltd. Our contact for privacy questions is privacy@pamosi.ai.
If you are in Nigeria, Ghana, or another West African jurisdiction, we process your personal data on the legal basis of the contract we enter with you when you sign up (Article 6(1)(b) GDPR-equivalent / Section 25(1)(b) Nigeria Data Protection Act 2023) and, where relevant, your consent (Section 25(1)(a) NDPA 2023).
2. What we collect
We collect only what we need to run the service.
2.1 Account and profile
- Phone number (in international E.164 format) — used to identify your account and to send you WhatsApp messages.
- Business name, owner name, base currency, language, timezone — set during onboarding so replies land in your language and totals are in the right currency.
- Device tokens for push notifications (mobile app only).
2.2 What you send us
When you use Pamosi Business, Health, Clinician, or Cooperative, we receive and store:
- Text messages you send us over WhatsApp or the app, and the replies we send back.
- Voice notes — the audio file and its automatic transcription.
- Receipt photos and other images you snap or upload.
- Transactions you log (sales, expenses, items, amounts, dates).
- Debtor records you create (customer name, balance owed, history).
- Invoices you generate and share.
- Health check-ins (Pamosi Health) — symptoms, cycle dates, medication reminders, ANC visits. Sensitive personal data — see §5 and §6.
- Cooperative and finance records (Pamosi Cooperative) — savings, loan schedules, member roles.
2.3 What we collect automatically
- Message metadata — timestamps, delivery status, WhatsApp message ID, detected language.
- App usage — screen views, actions taken, error reports (for bug-fixing and product improvement).
- Device information — model, OS version, app version.
- Approximate country (from IP) for the landing waitlist form. IP is stored hashed, never raw.
2.4 What we do not collect
- Bank account numbers, card details, or online banking passwords.
- Your WhatsApp contact list.
- Location data beyond approximate country.
- Anything from other WhatsApp chats — we only see messages you send to the Pamosi number.
3. Why we collect it
- Run the service you signed up for — logging sales, sending summaries, tracking debtors, answering health questions.
- Communicate with you — welcome messages, daily summaries you opted into, debtor reminders, appointment reminders, support replies.
- Improve the product — fix bugs, measure whether features work, understand which languages need better support.
- Keep the service safe and lawful — detect abuse, prevent fraud, comply with a court order or law we're required to follow.
We do not sell your personal data to anyone. Ever.
4. Who we share it with
We use a small number of trusted service providers ("processors") to run Pamosi. Each is bound by a data-processing agreement that limits what they can do with your data.
| Processor | What they process | Where |
|---|---|---|
| Cloudflare, Inc. | Server infrastructure (Workers, Pages), request routing | Global edge network |
| Supabase | Database (Postgres), file storage (photos, audio) | European Union (Frankfurt) |
| Anthropic (Claude) | AI inference on text you send us | United States |
| OpenAI (Whisper) | Voice-note transcription | United States |
| ElevenLabs | Text-to-speech for summaries and replies | United States |
| Twilio | WhatsApp message delivery (pilot phase) | United States |
| Meta Platforms (WhatsApp Business) | WhatsApp message delivery (post-pilot) | United States / Ireland |
| Expo / EAS | Mobile app distribution and updates | United States |
Some processors are outside West Africa. Where your data leaves the region, we rely on standard contractual clauses (or equivalent) and only send what is necessary for the service to work.
We also disclose data when required by law — for example, a court order from a Nigerian court, or a lawful request from the Nigeria Data Protection Commission (NDPC).
5. How long we keep it
- Account data — for as long as your account is active, plus 30 days after deletion.
- Transactions and business records — for the life of your account. After deletion, we keep an anonymised, aggregated copy for internal analytics (no personal identifiers).
- Voice notes — 90 days from upload. Transcripts remain with the transaction record.
- Receipts and photos — for the life of your account. Soft-deleted items are purged after a 30-day grace period.
- Health data — as long as the module is active. "Cycle wipe" removes it after a 30-day grace period.
- Waitlist signups — until launch, plus 12 months.
- WhatsApp messages — 24 months for support and dispute resolution.
6. Sensitive data — Pamosi Health
Pamosi Health handles data about your body and health. We treat that data with extra care:
- Stored encrypted; only the parts of the system that need to read it can do so.
- Never sent to advertising networks. Pamosi does not run ads.
- You can wipe your entire health history from within the app at any time. Deletions are irreversible after the 30-day grace period.
- Parental gates and age checks apply for adolescent users (13–17). We do not knowingly collect data from under-13s without a parent's involvement.
- You can lock the app on your device with a PIN.
7. Cooperatives and shared accounts
Pamosi Cooperative and the Business Associate feature let more than one person act on the same account. When you grant an associate access:
- They can see and add records within the permissions you granted them.
- Every action they take is logged against their identity.
- Revoking access is immediate; historical audit records are preserved.
If you are an associate acting for a business owner, that owner can see what you do inside their account. Your personal account remains separate.
8. Your rights
Under Nigerian, Ghanaian, and EU data-protection law, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete data.
- Deletion ("right to be forgotten") — ask us to delete your data.
- Portability — get your data in a machine-readable format.
- Objection — object to certain uses of your data.
- Withdraw consent — for anything you agreed to on the basis of consent.
- Complaint — lodge a complaint with your data-protection regulator. In Nigeria that is the Nigeria Data Protection Commission; in Ghana it is the Data Protection Commission.
To exercise any of these rights, email privacy@pamosi.ai from the phone number or email associated with your account, or use the "Delete my data" option inside the app. We respond within 30 days.
9. How we protect your data
- All connections use HTTPS/TLS.
- Data at rest in Supabase is encrypted.
- Voice, receipt files, and health records are behind time-limited signed URLs.
- Access to the production database is restricted, logged, and reviewed monthly.
- We follow a documented incident-response process. If a breach affects you, we will notify you within 72 hours of confirming it.
No system is ever perfectly secure — we don't pretend otherwise — but we take the responsibility seriously.
10. Children
Pamosi Business, Cooperative, and Clinician are not for people under 18. Pamosi Health has a supervised module for adolescents (13–17) with a parental gate; below age 13, we do not knowingly collect data.
If you believe we have inadvertently collected data from a child, email privacy@pamosi.ai and we will delete it.
11. Cookies and tracking
Our landing page uses no third-party trackers, no advertising cookies, and no analytics that identify individuals. If we ever add analytics, we will use privacy-preserving tools and disclose them here.
12. Changes to this policy
If we make material changes to this policy, we will notify you inside the app or by WhatsApp at least 14 days before they take effect. Prior versions are available on request.
13. Contact
- Privacy questions or data-subject requests: privacy@pamosi.ai
- General support: hello@pamosi.ai
- Postal address: to be added when finalized
- Data Protection Officer: to be added when appointed
For issues we can't resolve, you can contact the Nigeria Data Protection Commission at www.ndpc.gov.ng or the equivalent regulator in your country.
This policy is available in English. Translations into Yoruba, Pidgin, Hausa, Twi, and French will follow. In the event of a discrepancy between translations, the English version governs.