# POL-092 — The policy must say what the messages are for

> The privacy policy must describe the purpose of the texting, consistently with the registered use case.

- **Rule ID:** POL-092
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** AWS, TCR, Twilio, Klaviyo
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-092/

## Why this rule exists

The use case sets the consent standard the campaign is held to, so a policy describing promotions behind a transactional registration tells the reviewer the wrong standard was applied. From the consumer's side it is the difference between agreeing to delivery updates and agreeing to weekly marketing, which is the whole substance of what they consented to.

## How to fix it

Name the message categories in the policy and check them against the registered use case before submitting. Done when the two describe the same programme.

## Example of a compliant value

```text
We use your number to send Acme Coffee promotional offers and rewards balance updates — the programme you joined at checkout — and for nothing else.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen1) | `30908` | yes |
