{
  "id": "POL-104",
  "slug": "pol-104",
  "title": "The policy must say how message content is handled",
  "statement": "The privacy policy must state how message content is stored, for how long, who can read it, and whether it is used for analytics or AI.",
  "rationale": "Two-way programmes accumulate conversations that people treat as private, and the number of platforms now feeding message content to analytics or model training makes silence on this a live consumer question rather than a formality. A business that has never thought about it usually finds the answer is in its vendor's settings rather than in its own practice.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "privacy policy body",
  "severity": "MEDIUM",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "privacy_policy",
  "authorities": [
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Add two sentences to the messaging section covering storage, access and any secondary use. Check what your platform actually does before writing them. Done when the policy describes the real handling rather than the intended handling.",
  "example": "Replies to our texts are stored in our support system for 24 months and are read only by the Acme Coffee support team. We do not use message content for advertising or to train automated systems.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-104/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-104.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
