# POL-097 — The policy must carry opt-out instructions of its own

> The privacy policy must give opt-out instructions inside the policy itself.

- **Rule ID:** POL-097
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Twilio, Ringover, Sakari, MessageDesk
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-097/

## Why this rule exists

The policy is where someone looks when the last message has scrolled away and they want out, so pointing at the messages rather than restating the route leaves them where they started. It costs one sentence and it removes the most common reason a consumer complains to the carrier instead of to the brand.

## How to fix it

Add the keyword and one other route to the messaging section of the policy. Done when a reader who has never received a message still knows how to stop them.

## Example of a compliant value

```text
Reply STOP to any Acme Coffee message to unsubscribe, or email support@acmecoffee.com and we will remove you.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen1) | `30908` | yes |

## Notes

Naming one route as the only one fails POL-117 — list the keyword and say other reasonable requests are honoured too.
