# POL-104 — The policy must say how message content is handled

> The privacy policy must state how message content is stored, for how long, who can read it, and whether it is used for analytics or AI.

- **Rule ID:** POL-104
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-104/

## Why this rule exists

Two-way programmes accumulate conversations that people treat as private, and the number of platforms now feeding message content to analytics or model training makes silence on this a live consumer question rather than a formality. A business that has never thought about it usually finds the answer is in its vendor's settings rather than in its own practice.

## How to fix it

Add two sentences to the messaging section covering storage, access and any secondary use. Check what your platform actually does before writing them. Done when the policy describes the real handling rather than the intended handling.

## Example of a compliant value

```text
Replies to our texts are stored in our support system for 24 months and are read only by the Acme Coffee support team. We do not use message content for advertising or to train automated systems.
```
