Legal

Privacy
policy.

What we collect, why we collect it, and how we protect it.

Last updated: 2026-01-15

1. What we collect

Account data — name, email, phone, password hash.

Usage data — API requests, message metadata (recipient, status, timestamps), and system logs.

Billing data — invoice history and payment confirmations from our payment processor.

2. Message content

OTP codes and SMS bodies pass through our system to be delivered. We do not read, mine, or sell message content. Message bodies are retained only as long as needed for delivery and audit (typically 90 days).

3. How we use data

To operate the service, prevent abuse, bill you accurately, and meet legal obligations. We do not sell personal data to third parties.

4. Sharing

We share data only with: our payment processor, Turkmen mobile operators (to route SMS), and authorities when required by law.

5. Retention

Account records are kept while your account is active and up to 6 years after closure for tax and audit purposes. Message content is deleted after 90 days.

6. Your rights

You can access, correct, export, or delete your personal data by writing to privacy@ugrat.com. We respond within 30 days.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest. API keys are bcrypt-hashed. See our security page for details.

8. Children

Ugrat is a B2B service and is not intended for children under 18.

9. Changes

We will notify account holders by email at least 30 days before any material change to this policy.

10. Contact

Privacy questions? Write to privacy@ugrat.com.