Operator-payment capture only — SMS or notification, scoped in code to known mobile-money operators. Masked numbers everywhere except the fraud pipeline. Your data is your leverage, not our product.
What we collect
Operator payment confirmations only. The Sentinel app captures a mobile-money payment confirmation the merchant themselves receives, in one of two ways depending on the build:
SMS build (side-loaded): the receiver is scoped to operator sender IDs; non-payment SMS are never read or transmitted, enforced at code level.
Notification build (Google Play): a NotificationListenerService reads only notifications that resolve to a known mobile-money operator — verified against the operator's own app package or the phone's real default SMS app. Every other notification is ignored and never read, stored, or transmitted. The app requests Notification access only after a prominent in-app disclosure, and holds no SMS permission at all.
From either build, only the fields needed to verify the payment (reference, amount, operator, timestamp) are extracted and sent, encrypted in transit, to the merchant's paired KODA account.
Account data: business name, contact details, mobile money number (KYB-light).
Verification, fraud scoring, reconciliation and the audit trail — the product itself.
Customer msisdn is masked everywhere outside the fraud pipeline.
Communications per the event catalogue; mandatory service notices bypass marketing opt-outs, never marketing.
Where it lives
Managed cloud hosting in a primary region, with per-market in-country residency available on Enterprise engagements where mandated. Append-only event store: every verification is replayable for disputes and regulators.
Your rights
Access, export (machine-readable), correction and deletion via Settings or koda@kodajnn.com. DPIA published. Consent copy written by humans, French first.