Legal

Privacy policy

Last updated 11 September 2026.

This policy is written to be accurate about what the service actually does. It has not yet been reviewed by a lawyer. Before Wilma takes paying customers it should be.

Who we are

Wilma is a fraud detection API operated from Lagos, Nigeria. For questions about this policy or about data we hold, contact winifrednwanyibuife@gmail.com.

The short version

We do not store the messages you send us. They are processed in memory to produce a verdict and then discarded. We keep a record that a request happened, so that usage can be counted, and nothing about what the message said.

What we process

Message content. When you call the classification endpoints, the message text is held in memory only for as long as it takes to return a verdict. It is not written to any database, log or file, and it is not used to train models.

Usage records. For each API call we store the API key identifier, the account identifier associated with that key, which endpoint was called, how many messages were in the request, and the time. This is what billing is calculated from.

Account data. If you hold an API key, we store the key's identifier, a display name you chose, a short non-secret prefix, and the dates it was created, last used and revoked. API keys themselves are stored as a cryptographic hash, so we cannot read your key and neither could anyone who obtained a copy of our database.

Ordinary server records. Our hosting provider records standard connection information such as IP address and request time, as any web server does. Rate limiting uses the calling IP address in memory only, and that record is discarded within minutes.

Cookies

This site sets no cookies and uses no third party analytics or advertising scripts. There is nothing to consent to, which is why you were not asked.

Lawful basis

Where you are our customer, we process your account and usage data to perform our contract with you. Where your customers' messages pass through the service, you are the data controller and we act as your data processor, handling that content only on your instruction and only to return a verdict.

How long we keep things

Message content: not retained. Usage records: retained while your account is active and for as long as we are required to keep billing records afterwards. Account and key records: until you delete the key or the account, after which they are removed.

Who else sees it

We use Hugging Face for hosting and Supabase for the database holding key and usage records. Both may process data outside Nigeria. We do not sell data, and we do not share it with anyone for advertising.

Your rights

Under the Nigeria Data Protection Act you may ask what personal data we hold about you, ask for it to be corrected or deleted, object to how it is processed, and ask for a copy of it. Write to the address above and we will respond. You may also complain to the Nigeria Data Protection Commission.

Changes

If this policy changes materially we will change the date at the top and tell active customers directly.