Legal

Privacy Policy

We believe in clear language. This policy explains what data EK SMS collects, why, and how it is protected - for both the web platform and the EK SMS Gateway Android app.

Who we are

EK SMS is a product of Ek Ra Sunya Inc, a company registered in Kathmandu, Nepal. We operate the SMS gateway platform at sms.ekrasunya.com and publish the EK SMS Gateway Android app (package com.ekrasunya.sms) on Google Play.

If you have questions about this policy or want to exercise your data rights, contact us at [email protected].

What the EK SMS platform collects

When you create an account or use the web platform, we collect and process:

  • Account data - your name, email address, and company name provided during registration. We use this to identify your account, communicate with you about the service, and issue invoices.
  • Message data - recipient phone numbers, message content, sender ID, and scheduled send time that you submit when queuing messages. This data is processed solely to deliver the messages you requested. Delivery status and timestamps are stored as part of your message history.
  • Billing records - credit balance, top-up transactions, and per-message charge records. These are retained for financial and audit purposes.
  • Usage logs - API request logs (timestamp, endpoint, response status) used for debugging, rate limiting, and security monitoring. These are not linked to message content.

We do not sell your account data, message content, or recipient lists to third parties. We do not use message content to train machine-learning models or for advertising.

EK SMS Gateway Android app - permissions and data access

The EK SMS Gateway app turns an Android device into a physical SMS gateway that sends messages queued by the paired EK SMS account over the device SIM card. Below is a plain description of every permission the app uses and why.

SEND_SMS (core functionality)

Used solely to transmit messages that the paired account has queued. The app receives a dispatch instruction from the EK SMS backend, calls the Android SMS API to send that specific message, and reports back the delivery status. No message is sent without an explicit instruction from the paired account. The app never composes or initiates messages on its own.

READ_PHONE_STATE (SIM selection)

Used to enumerate available SIM subscriptions on dual-SIM devices so that the correct SIM slot can be selected when sending. This permission is not used to read call logs, track calls, or identify the user beyond SIM selection.

Device phone number

The phone number of the SIM installed in the gateway device is entered manually by the operator during the pairing step in the app. This number is transmitted to the EK SMS backend to label the device in your account dashboard. It is not read programmatically from the device.

Battery and network status (heartbeats)

The app periodically sends a heartbeat to the EK SMS backend that includes battery level, charging state, network connectivity type, and signal strength. This lets the dashboard display whether the gateway device is online and healthy. No location data is included in heartbeats.

Device credential (authentication token)

A unique device credential (a secret token) is issued by the EK SMS backend when the device is paired and is stored in app-private storage on the device (Android internal storage, not accessible to other apps). This credential is used to authenticate the device with the backend and can be revoked from the dashboard at any time, which immediately disables that gateway device.

What the app does NOT do

  • - It does not read, collect, store, or upload your personal SMS inbox.
  • - It does not access your contacts list.
  • - It does not access or upload your call logs.
  • - It does not track your location.
  • - It only sends messages explicitly queued by the paired EK SMS account and reports their delivery status back to that account.

How we share data

We share data only in the following circumstances:

  • Message delivery - recipient phone numbers and message content are transmitted to the recipient via the gateway device SIM or licensed SMS provider networks (NTC, Ncell) as part of delivering the SMS you requested.
  • Push notifications - Google Firebase Cloud Messaging (FCM) is used to deliver dispatch instructions to gateway devices. Message content passed to FCM is limited to what is required to trigger delivery on the device.
  • Hosting and infrastructure - our platform runs on cloud infrastructure providers. These providers access server data only as needed to operate the infrastructure and are contractually bound to keep it confidential.
  • Legal compliance - we may disclose data if required by Nepali law or a valid legal order. We will notify you if permitted by law.

We do not sell personal data to any third party.

Data retention

Message records and delivery logs are retained for operational and billing purposes, typically for a minimum of 90 days and up to 2 years for billing audit trails.

Account data is retained for the lifetime of your account. If you wish to delete your account and associated data, send a request to [email protected]. We will process account deletion requests within 30 days, subject to any legal retention obligations.

Gateway device credentials are removed from our servers when a device is unpaired or when you delete your account. Revocation takes effect immediately.

Security

We protect your data with the following controls:

  • Encrypted transport - all communication between your browser, the gateway app, and our servers uses HTTPS/TLS. Plain-text connections are not accepted.
  • Credentials at rest - account passwords are hashed using a cryptographic hashing algorithm with per-user salts and are never stored in plain text.
  • Revocable device credentials - each gateway device has a unique secret token that can be revoked instantly from the dashboard. Revocation immediately prevents the device from receiving or sending further instructions.
  • App-private storage - device credentials on the Android app are stored in app-private internal storage, isolated from other apps on the device.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email to the address on your account or via a notice in the dashboard. Continued use of the platform or the gateway app after the effective date constitutes acceptance of the updated policy.

This policy was last updated on 2026-07-12.

Questions about your data?

Contact us at [email protected]. We respond to all privacy requests within 30 days.