Privacy Policy
Last updated: 8 June 2026
Sila is a financial service. That means we must collect certain information about you by law, and it means we hold ourselves to a higher bar than a typical app: your data stays inside Sila's own infrastructure, is used to run your wallet — not to profile you for advertising — and is never sold.
1. What we collect
| Category | Examples | When |
|---|---|---|
| Identity | Name, phone number, email, address, date of birth, government ID document, live selfie | Account creation and identity verification |
| Financial | Wallet balance, transactions, top-up references, card activity, bill payments, agent transactions | Generated as you use the Service |
| Device & security | Device model and identifiers, app version, session and login records, biometric enrolment status (the biometric itself never leaves your device) | Login and ongoing use |
| Support | Support tickets, dispute messages, attachments you send us | When you contact us |
| Diagnostics | Crash and error reports from the app (error message, stack trace, app version) | When the app encounters an error |
We do not collect your contacts list without permission, your precise location, or your biometric data (fingerprint/face unlock is verified by your phone's operating system; we only receive a yes/no).
2. Why we collect it
- To run your wallet — executing transfers, maintaining your ledger, generating statements and receipts.
- To verify identity — Sudanese AML/KYC regulation requires us to know who our customers are before offering full service.
- To keep your account safe — fraud detection, device binding, session management, SIM-swap and account-takeover protection.
- To meet legal obligations — sanctions screening, transaction monitoring, record-keeping, and reporting to competent authorities where required.
- To support you — investigating tickets and disputes using ledger records.
- To improve reliability — crash reports tell us what broke so we can fix it.
We do not use your data for third-party advertising, and we do not sell it. Ever.
3. Sanctions & AML screening
As required of financial services, we screen customer identity information against applicable sanctions lists (including UN, and other lists applicable to our banking partners) at onboarding and again whenever lists are updated. We also monitor transactions for patterns indicating fraud or money laundering. Where the law requires, we may file reports with competent authorities without notifying you — this is a legal obligation common to all financial institutions, not a choice we make about you personally.
4. Who we share data with
- Banking partners — to reconcile top-ups and operate the accounts that hold customer funds. They see what is needed to match payments (for example, your top-up reference), not your full profile.
- Regulators and authorities — where Sudanese law requires reporting or where we receive a lawful demand.
- Merchants and other users — only transaction-level information they need: a merchant sees the payment you made to them; a P2P recipient sees your name/@username and the amount.
- Service providers — our hosting provider processes data on our behalf (see below); push notifications are delivered through your device platform's notification service.
We never give third parties bulk access to customer data, and no third party may use Sila data for its own purposes.
5. Where your data lives
Sila's systems are hosted on managed cloud infrastructure in the European Union (Frankfurt), with encrypted databases and automatic backups. Data is transferred from your device over encrypted connections (TLS). Sudanese authorities and our banking partners receive data through the channels described above regardless of hosting location.
6. How we protect it
- Encryption in transit (TLS) for all app–server communication, and encryption at rest for databases and backups.
- PIN + device binding + optional biometric unlock on the app; sensitive credentials are stored in your phone's secure storage.
- Double-entry, append-only ledger — financial records cannot be silently edited, by anyone, including us.
- Strict internal access control: staff access to customer data is role-based, logged in an audit trail, and protected by two-factor authentication.
- Stack traces and diagnostics are redacted before storage to strip credentials and personal identifiers.
7. How long we keep it
Financial regulation requires us to retain customer identification records and transaction records for a number of years after your relationship with us ends. In practice:
- KYC and transaction records — retained for the period required by Sudanese AML law, then deleted.
- Support tickets and disputes — retained while relevant to your account and for the same statutory period where they concern transactions.
- Diagnostics — error reports are retained only as long as needed to fix the underlying problem.
When you close your account, we stop processing your data for service purposes and retain only what the law requires, for as long as it requires.
8. Your choices & rights
- Access — your transaction history and statements are always available in the app; you can ask us for a copy of the personal data we hold about you.
- Correction — you can update your profile details in the app, and ask us to correct anything else.
- Closure — you can request account closure in the app at any time (statutory retention still applies, see above).
- Notifications — you control notification categories in the app's settings.
Note that we cannot delete records the law requires us to keep, and we cannot run your account without the data that regulation obliges us to collect. To exercise any of these rights, contact [email protected] (or [email protected]).
9. Notifications
We send transactional notifications (money received, security alerts, KYC outcomes) by push notification and in-app message. Security-critical notifications cannot be disabled while your account is open, because they protect you. Everything else is configurable per category in the app.
10. Children
Sila is for adults. We do not knowingly open accounts for anyone under 18, and we close any account we discover belongs to a minor.
11. Changes to this policy
We will update this policy as the Service evolves. Material changes will be announced in the app before they take effect. The "Last updated" date at the top reflects the current version.
12. Contact
Privacy questions or requests: [email protected]
General legal: [email protected]
Security reports: [email protected]