Privacy Policy

Last updated: October 9, 2026

USSDK is operated by Not-Gr Technologies in Accra, Ghana. This policy explains how we handle information when you visit our website, use the USSDK platform, or connect an AI assistant through our plugin or Model Context Protocol (MCP) server.

1. Information we handle

  • Account information: your account identifier, email address, name and profile image when supplied by your sign-in provider, along with application memberships and permissions.
  • Application content: application names, flow designs, messages, variables, hook configurations, mock responses, deployments and simulation data you create or submit.
  • USSD session and form data: phone numbers, session identifiers, network and provider details, user inputs, form responses, hook results and timestamps processed by your applications.
  • Billing information: credit purchases, usage, transaction references and payment status. Payments are handled through Paystack; payment details you enter in its checkout are handled by that provider.
  • Connection and support information: OAuth client identifiers, approved permissions, token hashes, expiry and revocation records, connection activity, and information you provide when contacting us.
  • Technical and website usage information: web requests, browser and device information, visited pages and diagnostic information. Our servers and service providers receive network information, including your IP address, when your device connects to them.

2. How we use information

We use information to authenticate users, apply access permissions, save and run applications, support collaboration, process USSD sessions and forms, manage credits and payments, and carry out requests made through connected AI assistants. We also use it to provide support, send service messages, understand website usage, troubleshoot problems and protect the service from abuse. Information may also be needed to meet legal obligations and resolve disputes.

3. AI assistants and MCP access

Connecting an AI assistant requires you to sign in to USSDK and authorize its access. That authorization covers your current and future applications, subject to the permissions you have in each application and the scopes you approve. Depending on those permissions, the assistant can read application content and session information, create or duplicate applications, and make changes on your behalf.

USSDK receives the requests the assistant sends to our MCP server and returns the data needed for those requests. Returned data may include application content, phone numbers, user inputs and hook responses when the requested operation makes them available. The AI provider receives that data and handles it under its own privacy policy and your account settings, including its retention and model-training settings. Review those settings before giving an assistant access to personal or confidential information.

You can revoke access from MCP connections. Revocation stops that connection from making further authorized requests; it does not delete information already returned to the AI provider. Contact that provider to manage its copies.

4. When information is shared

  • With your collaborators: application information is available to people with access, according to their permissions.
  • With integrations you use: telecom providers process USSD traffic, and configured hooks receive session and input data. Simulations can also call those hooks and save form responses. Use synthetic data when testing.
  • With service providers: we use services for hosting, authentication, payments and email delivery, including Firebase Authentication, Paystack and Resend. These services receive information needed for their role, such as sign-in details, payment references or email recipients and messages.
  • For legal and security purposes: information may be disclosed when required by law or necessary to respond to abuse, protect people or the service, or address legal claims.

Providers and integrations may process information in countries other than your own. Their handling of information also depends on their terms and privacy policies.

5. Cookies and website services

We use cookies and browser storage for sign-in, authorization and preferences such as appearance. You can clear or restrict them through your browser, but doing so may sign you out or prevent parts of the service from working.

Our public website loads a usage analytics service from observe.degreat.co.uk and fonts from Google Fonts. Your browser connects to those services when loading the website. Analytics helps us understand visits and improve the site; external font requests also expose connection information to the font provider.

6. Storage and deletion

Application content, session history and form submissions are stored so the service can operate and you can review your work and usage. Retention depends on the type of record, its use in providing the service, and applicable accounting, security or legal requirements.

When you delete an application in the dashboard, the application and its related data are scheduled for deletion. Disconnecting an AI assistant also does not delete your USSDK applications or session data. To request deletion of an account or associated information, contact hi@ussdk.me and identify the account or application concerned. We may need to verify your identity and authority before acting. Some records may need to be retained for legal obligations, security or resolving disputes; you can ask us about the records relevant to your request.

7. Your choices and requests

You can contact us to request access to, correction of, or deletion of your personal information, or to raise a concern about its use. Depending on applicable law, you may also have rights to object to or restrict processing, withdraw consent, or complain to a data protection authority. In Ghana, this is the Data Protection Commission. Withdrawing access or consent does not undo processing that has already taken place.

If you use a USSD application built by one of our customers, contact that application's operator first about its data collection and your requests. The operator chooses what its application collects and how it uses that information. We process application data to provide the platform; application operators are responsible for appropriate privacy notices and permissions for the data they collect.

8. Protecting information

USSDK uses authenticated access, application permissions and revocable OAuth connections to limit access to information. No online service can guarantee complete security. Protect your account, review collaborator and AI access, and avoid placing passwords, payment credentials or unnecessary sensitive data in flows, mock responses or support messages.

9. Changes to this policy

We may update this policy as the service and its data practices change. The current version will be available on this page with an updated date. Where applicable law requires additional notice, we will provide it.

10. Contact us

For privacy questions or requests, email hi@ussdk.me with the subject “Privacy request”. Please do not include passwords or access tokens.

Not-Gr Technologies
#1 Sanshie Ave, East Legon
Accra, Ghana