Legal
Privacy policy
Last updated 11 September 2026.
Who we are
Wilma is a fraud detection API operated from Lagos, Nigeria. For questions about this policy or about data we hold, contact winifrednwanyibuife@gmail.com.
The short version
We do not store the messages you send us. They are processed in memory to produce a verdict and then discarded. We keep a record that a request happened, so that usage can be counted, and nothing about what the message said.
What we process
Message content. When you call the classification endpoints, the message text is held in memory only for as long as it takes to return a verdict. It is not written to any database, log or file, and it is not used to train models.
Usage records. For each API call we store the API key identifier, the account identifier associated with that key, which endpoint was called, how many messages were in the request, and the time. This is what billing is calculated from.
Account data. If you hold an API key, we store the key's identifier, a display name you chose, a short non-secret prefix, and the dates it was created, last used and revoked. API keys themselves are stored as a cryptographic hash, so we cannot read your key and neither could anyone who obtained a copy of our database.
Ordinary server records. Our hosting provider records standard connection information such as IP address and request time, as any web server does. Rate limiting uses the calling IP address in memory only, and that record is discarded within minutes.
Cookies
This site sets no cookies and uses no third party analytics or advertising scripts. There is nothing to consent to, which is why you were not asked.
Lawful basis
Where you are our customer, we process your account and usage data to perform our contract with you. Where your customers' messages pass through the service, you are the data controller and we act as your data processor, handling that content only on your instruction and only to return a verdict.
How long we keep things
Message content: not retained. Usage records: retained while your account is active and for as long as we are required to keep billing records afterwards. Account and key records: until you delete the key or the account, after which they are removed.
Who else sees it
We use Hugging Face for hosting and Supabase for the database holding key and usage records. Both may process data outside Nigeria. We do not sell data, and we do not share it with anyone for advertising.
Your rights
Under the Nigeria Data Protection Act you may ask what personal data we hold about you, ask for it to be corrected or deleted, object to how it is processed, and ask for a copy of it. Write to the address above and we will respond. You may also complain to the Nigeria Data Protection Commission.
Changes
If this policy changes materially we will change the date at the top and tell active customers directly.