# POL-121 — The policy must say what it covers

> The privacy policy must state its scope — which sites, apps and offline channels it applies to.

- **Rule ID:** POL-121
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** LOW — Best practice. Worth fixing, rarely fatal on its own.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-121/

## Why this rule exists

A policy scoped to "this app" while the opt-in happens on the website is the wrong document for the programme being registered, and a reviewer reads the scope line before anything else. Businesses inherit the mismatch from whichever product the policy was first written for.

## How to fix it

Open the policy with a scope sentence naming every surface it covers, including the messaging programme. Done when the document plainly covers the surface where consent is collected.

## Example of a compliant value

```text
This policy covers acmecoffee.com, the Acme Coffee mobile app, our stores, and the Acme Coffee text messaging programme.
```
