Privacy Policy

Last updated: 20 August 2026

Related: Terms of Use · Delete your Ikofi account

Privacy Policy — Ikofi

Last updated: 20 August 2026

1. Who we are

This Privacy Policy explains how Ikofi App Ltd (“Ikofi”, “we”, “us”, “our”), of Kigali, Rwanda, processes personal data when you use the Ikofi mobile application, www.ikofi.app, and related consumer features.

We are the data controller for that processing. Contact: team@ikofi.app. If we appoint a Data Protection Officer, we will publish their details here. Until then, privacy requests go to that email.

The advertiser portal has a separate privacy notice. This Policy is for people who use Ikofi as consumers (including creators on the consumer app).

2. Rwandan law comes first

We process personal data in line with Law No. 058/2021 of 13 October 2021 relating to the protection of personal data and privacy (the “Rwanda Data Protection Law”) and other applicable Rwandan laws.

Ikofi is not a public authority. We do not replace the Government of Rwanda or the National Cyber Security Authority (NCSA), which is the supervisory authority for this Law through its Data Protection and Privacy Office.

If you are not satisfied with how we handle a privacy request, you may appeal to the NCSA within the time the Law allows (typically 30 days from our response). See “Complaints to the authorities” below. Nothing in this Policy limits a right the Law gives you that cannot be waived.

3. What this Policy covers

It covers personal data we process about you as an Ikofi user: account, money tools, Moments, discovery, ads you see, creator earnings (if any), referrals, and the public website.

It does not cover websites you open after tapping an ad, or your mobile-money operator’s own processing when you confirm a USSD or MoMo PIN flow.

4. Information we collect

Depending on how you use Ikofi, we may process:

Account and identity. Phone number, name, date of birth, gender, email (if you add one), @tag name, profile photo, cover, bio, province or similar location you choose, and interests/topics you pick. We use date of birth to apply age rules (including 18+ for monetization).

Security and session. Passwords or PINs stored hashed, one-time codes, two-factor data, device identifiers needed to keep you signed in, and security logs. The PIN you type for Mobile Money belongs to your operator; we do not store that operator PIN.

Money tools (not a cash wallet). History of USSD actions you started in the app, categories you link, budgets, splits, loans, shopping lists, merchant codes you entered, and whether the line looks like MTN or Airtel so we can launch the right code. We do not hold your MoMo balance. We do not process the payment — the carrier does.

Social. Moments (photo, video, overlays, captions), who you follow, followers, likes, viewers (as the product shows), reports you send or that others send about you, and search queries on Discover.

Creator and referral. Eligibility progress, views and watch-time used for analytics and monetization, earnings ledger, payout requests, MoMo number used for reward payouts, and referral codes and related events.

Advertising measurement. Which ad was shown, whether it was a Moment mid-roll, banner, or after-a-Moment placement, approximate view time, and whether a link was tapped — so we can charge advertisers fairly, pay eligible creators their share, and improve delivery. We do not sell a list of “this person is named X” to advertisers. Audience tools show grouped counts (and hide small groups) so individuals are not listed.

Device and technical. App version, OS, language, crash and performance data (including through error monitoring such as Sentry), IP address, and approximate network type. If you grant permission: camera (Moments and similar), photo library, microphone (video), and contacts (only if you choose Find Friends — we hash numbers on device where the product is built that way, to see who is already on Ikofi, not to upload your full address book as a public list).

Website. If you visit www.ikofi.app, standard server logs (IP, browser, pages). We do not run a third-party advertising pixel on the marketing site as of this date.

Support. What you write to team@ikofi.app.

5. Why we use it (purposes)

We use personal data to: • create and secure your account and verify your line; • launch the correct carrier USSD for send, airtime, or merchant pay, and to power budgets, splits, loans, and lists from history you generate; • show Moments, feeds, profiles, and discovery; • moderate reports, enforce the Terms of Use, and protect safety; • measure and deliver ads, and calculate creator ad-share where you are eligible; • run Refer and Earn; • send service messages (security, payouts, product changes); • fix bugs, understand feature use, and keep the Services reliable; • comply with law, court orders, and competent authorities; • defend legal claims.

We do not sell your personal data. We do not let advertisers download your name and phone to spam you. Targeting is based on attributes you provide or that we derive at a group level (for example age band, gender, topics).

6. Legal bases (Rwanda Data Protection Law)

We rely on one or more of these, depending on the activity: • performance of our contract with you (providing the app you asked for); • your consent, where we ask for it (for example optional contacts access, or certain communications). You may withdraw consent without affecting processing already done; • our legitimate interests, where they are not overridden by your rights (security, fraud prevention, measuring ads fairly, improving the product); • a legal obligation; • another ground the Law allows, where it actually applies.

Sensitive personal data is processed only if the Law permits it. We do not ask you for health, religion, or similar sensitive categories as a condition of a basic account. Interests you pick are used for discovery and ads relevance.

7. Ads and creators

Advertisers pay for views and taps. To operate that, we process ad events and limited profile attributes for targeting and for Creator Hub.

If you are not monetization-eligible, ads may still appear; we keep that inventory. If you are eligible, a stated share of mid-roll ads during your Moments may be credited to you (see the Terms of Use). Payout partners (for example Mobile Money processors) receive the details needed to pay you — typically amount, reference, and the MoMo number you gave us — not your full Moment archive.

8. Who we share data with

We share personal data only as needed: • Your device / operator USSD, when you start a send, merchant pay, or airtime flow the carrier must complete — we do not send the cash ourselves; • payment processors involved only in creator or referral reward payouts (and, on the advertiser side, ad-wallet top-ups — described in the advertiser privacy notice); • hosting, storage, email/SMS, and crash-monitoring providers that process data on our instructions; • professional advisers under confidentiality; • a buyer, if we reorganise or sell the business, under appropriate safeguards; • competent authorities, courts, or law enforcement when the law requires or allows it (including child-safety reports).

Other users see what you choose to make public (profile, Moments while they are live, follow counts). We do not share your spend history as a public feed.

9. Storage and transfers outside Rwanda

Our servers and some processors (for example error monitoring) may be located outside Rwanda. Where the Rwanda Data Protection Law requires safeguards for that transfer, we use appropriate contractual and organisational measures. You can ask us for more detail at team@ikofi.app.

10. How long we keep data

We keep personal data only as long as needed for the purposes above. • Live Moments: typically 24 hours on the feed, then they expire; you may still see your own archive where the product offers it, until you delete it or the account. • Account profile: until you delete the account or we close it. • Security logs: a limited period to investigate abuse. • After account deletion: we anonymise or delete personal identifiers generally within 30 days, except (a) a 90-day phone blocklist to stop instant re-registration abuse; (b) anonymised or limited transaction records needed so other people’s history and financial integrity still make sense; (c) records we must keep for legal claims, tax, or a competent authority; (d) backups that roll off on a short cycle.

When we anonymise, the remaining data should not identify you in ordinary use.

11. Security

We use technical and organisational measures appropriate to the risk: encryption in transit, hashed credentials, access control, and monitoring. No method is perfect. Protect your phone and PIN. We will handle personal-data breaches as the Rwanda Data Protection Law requires, including notifying the supervisory authority and affected people where that duty applies.

12. Children

Ikofi is not for children under 13. We do not knowingly collect personal data from children under 13. If you believe we have, contact team@ikofi.app and we will delete or anonymise that account.

Users 13–17 may use the Services only with parental or guardian consent, as in the Terms of Use. We apply extra care to their data. Monetization, payouts, and advertiser targeting age floors are 18+. Parents or guardians of a user under 18 may contact us to review, correct, or request deletion of that child’s information, subject to verifying their authority and to what the Law requires us to keep.

13. Your rights

Under the Rwanda Data Protection Law you may, as applicable: • access your personal data and receive a copy; • obtain information about purposes, sources, and categories of recipients; • rectify inaccurate data; • request erasure; • object to or restrict certain processing; • data portability, where the Law provides it; • withdraw consent where processing was based on consent; • not be subject to a solely automated decision with legal or similarly significant effects, where the Law protects you; • designate an heir in respect of personal data, where the Law provides that right.

We may need to verify it is you. We may refuse a request only on grounds the Law allows (for example another person’s rights, a legal obligation, or an ongoing investigation), and we will explain why when we can.

To exercise these rights: use in-app settings where they exist, or email team@ikofi.app.

14. How to delete your account (Apple and Google)

If you created an Ikofi account, you can delete it.

In the app (required by Apple App Store Guideline 5.1.1(v) and Google Play): go to Account or Settings → Delete Account, read the consequences, and confirm. This starts deletion of the account and associated personal data we are not legally required to keep. It is not a pause or freeze: you cannot sign back in as that user.

On the web (required by Google Play for a public resource, including if you uninstalled the app): visit www.ikofi.app/account-deletion or email team@ikofi.app with the subject “Account Deletion Request” and the phone number on the account. You do not need to log in to send that email.

Timeline. We generally complete anonymisation or deletion of personal identifiers within 30 days. We will say if a lawful delay applies.

What we may still keep, and why: anonymised transaction traces (other people were in those sends); a 90-day hashed/blocklisted phone number (security and anti-abuse); records a competent authority or the law requires. These practices are disclosed here so store listings and this Policy stay consistent.

15. Device permissions

The app may ask for camera, photos, microphone, contacts, or notifications. We ask so you can post Moments, pick a profile photo, find friends, or receive alerts — not as a condition of merely opening a screen that does not need that access. You can refuse and still use other parts of Ikofi, except the feature that needs the permission. You can change permissions in your phone settings.

16. Cookies (website)

www.ikofi.app is a marketing and deep-link site. We may use strictly necessary cookies or similar storage for security and load. We do not currently use the marketing site to run third-party behavioural advertising. You can control cookies in your browser. The mobile app is not a browser cookie wall; it uses account sessions and device storage as described above.

17. Changes

We may update this Policy. The new version is posted at www.ikofi.app/privacy-policy with a new date. For material changes we will try to notify you in the app or via a contact we have, where practicable. If a change needs consent under the Law, we will ask for it.

18. Complaints to the authorities

Please write to us first at team@ikofi.app so we can try to fix the issue.

If you are not satisfied with our response, the Rwanda Data Protection Law lets you appeal to the supervisory authority: National Cyber Security Authority — Data Protection and Privacy Office https://dpo.gov.rw/contact-us/ complaint@dpo.gov.rw (copy dpp@ncsa.gov.rw) Toll-free: 9080

You may also have rights before the courts of Rwanda. We will cooperate with the NCSA and other competent authorities as the law requires. We do not decide their outcomes.

19. Contact

Ikofi App Ltd Kigali, Rwanda team@ikofi.app

Related documents: Terms of Use (www.ikofi.app/term-of-use) and Account deletion (www.ikofi.app/account-deletion).