Privacy Policy

Last updated 2026-09-26

1. Who we are, and what this policy covers

This Privacy Policy explains how Sun Media Limited, a company registered in Nigeria ("Sun Media", "we", "us", "our"), collects, uses, shares, and protects information in connection with the InvolveMe mobile application (the "Service"). It should be read alongside our Terms of Service.

2. Information we collect

Account information: your phone number (used for one-time-passcode login and as your primary identifier), and any display name, avatar, or "about" status text you choose to add.

Message and status content: the text of messages you send and status updates you post. For a conversation that has not turned on end-to-end encryption, message content is stored so it can be delivered and displayed to its recipient, and Sun Media has the technical ability to read it (see Section 9). For a conversation that has turned on end-to-end encryption, we only ever receive and store content already encrypted on your device — we do not have the technical ability to read it (see Section 9 for exactly what that does and doesn't mean).

Identity verification data: if you complete identity verification, we receive a verification result from our KYC provider and store the verified name it returns, plus a one-way cryptographic hash of your BVN or NIN (never the raw number itself — see Section 8 of our Terms).

Payment and financial data: your credit purchase, spending, earning, transfer, and withdrawal history within the app, a tokenized reference to any bank account you link (not the raw account number, beyond what our payment provider needs to process a payout), and a provider-issued customer identifier from our payment processor.

Device and fraud-prevention data: a one-way hash of a stable device identifier (computed on your device before it is ever sent to us — we never receive or store the raw hardware identifier), used to detect when multiple accounts share a device, as part of fraud prevention.

Push notification data: a device push token, if you enable notifications, used solely to deliver notifications to your device.

Usage and technical data: standard technical metadata generated by using a mobile app (such as timestamps of activity), used for security, fraud prevention, and operating the Service.

3. How we use your information

To provide the Service: deliver messages, display your profile to conversation partners, process top-ups, escrow releases, transfers, and withdrawals, and show you accurate balance and pricing information.

For fraud and abuse prevention: to detect patterns consistent with wash-trading, collusion, spam/farming, or multi-accounting — including through device-fingerprint linkage, transaction-pattern analysis, and automated content moderation — and to enforce our Terms of Service.

For identity verification and financial compliance: to meet Know-Your-Customer and anti-money-laundering obligations under Nigerian financial regulation before releasing withdrawals.

For customer support: to respond to your requests, including account deletion requests.

For legal compliance: to meet record-keeping, reporting, or disclosure obligations under applicable law.

We do not use your information to serve third-party advertising, and we do not sell your personal information.

4. Our legal basis for processing your information

Under the Nigeria Data Protection Act, we process your information on the following bases: performance of a contract with you (delivering the Service you signed up for); compliance with a legal obligation (KYC/AML requirements, financial record-keeping); and our legitimate interests in operating a safe platform (fraud and abuse prevention, content moderation), balanced against your rights and interests.

5. Who we share information with

We share information with the following categories of third party, only as needed to provide the Service:

• Payment processors (currently Flutterwave), to process top-ups and withdrawals. They receive the payment details necessary to process a transaction.

• Identity verification providers (currently Prembly), to perform BVN/NIN verification. They receive the identity number you submit for verification and return a verification result and matched name to us; we do not store the number itself, only a hash.

• Content moderation providers (currently OpenAI), which receive message and status text for automated screening as described in our Terms of Service, Section 11 — this applies only to conversations that have not turned on end-to-end encryption. For an end-to-end-encrypted conversation, there is no plaintext for us to send anywhere, so nothing from it reaches our moderation provider.

• Push notification infrastructure (currently Expo), to deliver notifications to your device.

• Law enforcement, courts, or regulators, where we are legally compelled to disclose information, or where necessary to investigate fraud or protect the rights and safety of our users.

We do not sell your personal information to anyone, and we do not share it with third parties for their own independent marketing purposes.

6. How long we keep your information

While your account is active, we retain your information as needed to provide the Service. If you delete your account, we retain your financial and ledger transaction records for the period required by applicable Nigerian anti-money-laundering regulation, even though your profile information is deleted or anonymized at that point — this is a legal retention obligation we cannot waive on request, not a discretionary choice.

Message content is retained for as long as the relevant conversation thread exists in the app, or until you or the other participant deletes your account (subject to the financial-record retention above for anything with a monetary consequence, such as a paid message’s billing record, which is distinct from the message text itself).

7. Your rights

Under the Nigeria Data Protection Act, you have the right to access the personal information we hold about you, request correction of inaccurate information, request deletion of your account (Section 13 of our Terms), and object to certain processing. To exercise these rights, contact us at the address in Section 13 below.

Some rights are subject to the financial record-keeping obligations described in Section 6 — we cannot delete financial/ledger records we are legally required to retain, even at your request.

8. How we protect your information

Data is encrypted in transit between your device and our servers. Sensitive identifiers — your BVN/NIN and your device fingerprint — are never stored in raw form; only a one-way cryptographic hash is stored, computed with a secret value we control so the original value cannot practically be recovered from the hash.

Access to financial and identity-verification data within our systems is restricted to what is operationally necessary. No system is perfectly secure, and we cannot guarantee absolute security, but we design our data handling around minimizing what raw sensitive data exists in the first place, not just protecting it after the fact.

You can also turn on end-to-end encryption for an individual conversation, an additional, optional layer specifically for that conversation's message content — see Section 9 for exactly what it protects and what it does not.

9. End-to-end encryption (optional, per conversation)

You can turn on end-to-end encryption for an individual one-on-one conversation from that conversation's menu. It is off by default for every conversation, it is not currently available for group chats, and once turned on for a conversation, it cannot be turned back off for that conversation.

Once a conversation has end-to-end encryption turned on, its message content is encrypted on your device before it ever leaves it, and can only be decrypted by you and the other participant. Sun Media Limited does not have the technical ability to read that content — not to investigate an abuse report, not in response to legal process, not for any reason — because we never receive or possess a readable copy of it, only the encrypted form. This is a genuine, meaningful difference from a conversation that has not turned this on (see Section 2), and we want to be equally plain about what it does not do:

• It does not moderate your conversation. Our automated content-moderation system (Terms of Service, Section 11) screens message text before sending — it cannot do that for content it cannot read, so moderation does not run at all on an end-to-end-encrypted conversation. The same is true of our ability to review a specific message if you or the other participant later reports it — we can see that a report was made, but not the content being reported. Use ordinary caution in these conversations for that reason, the same caution you would use in any conversation the platform itself cannot see into.

• It does not hide who you are messaging, when, or how often. We can still see conversation metadata — the participants, timestamps, and message length (used to calculate its cost) — because that information is what lets the Service function and remain billable, and our fraud- and abuse-detection systems (Terms of Service, Section 10) continue to operate on that metadata exactly as they do for any other conversation.

• It is a newly introduced feature, built following the same public Double Ratchet/X3DH cryptographic design other end-to-end-encrypted messaging apps use, implemented by us rather than licensed from an existing provider. It has not yet been reviewed by an independent, external security audit. We are disclosing this so you can make an informed choice about when to rely on it, not to discourage its use.

For a conversation that has not turned on end-to-end encryption, message content is encrypted in transit and stored on our servers, and Sun Media Limited has the technical ability to access that content — for example to investigate abuse reports, respond to legal process, or operate the content moderation described in Section 11 of our Terms.

10. Children’s privacy

The Service is not directed to, and may not be used by, anyone under 18 years old — see our Terms of Service, Section 2. We do not knowingly collect personal information from anyone under 18. If we become aware that an account belongs to someone under 18, we will suspend it.

11. International data transfers

Some of our infrastructure and service providers (including parts of our cloud database infrastructure and our content moderation provider) operate outside Nigeria. Where we transfer personal information outside Nigeria, we rely on the transfer mechanisms and safeguards recognized under the Nigeria Data Protection Act.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "last updated" date shown in the app when we do, and will highlight material changes in-app.

13. Contact

Questions about this Privacy Policy, or requests relating to your personal information, can be sent to support@sunmedialimited.com.ng.