Privacy policy
Updated on 7 October 2026
This is a translation for convenience. The French version prevails.
eNotif lets the apps you use ask you to confirm on your phone — a sign-in, a forgotten password, a payment — and send you messages. You can also add contacts and write them short messages. eNotif is published by Sahelab. This page says exactly what we keep, why, and how to have it deleted.
In short. A number, a name, a @handle and your phone’s public key. The private key never leaves your phone. Apps receive neither your name nor your contacts. Your short messages are encrypted on our servers, but not end to end. No advertising, no selling of data.
What we keep
- Your phone number, verified once with an SMS code. It identifies your account and lets apps send you a request.
- Your name, your @handle and, if you add one, your photo. They are visible to people who add you and to those you write to, and on your public page
/u/@handleif you share it. - Your trusted phone: its public key, its name (“Pixel 7”), its system, its last activity. The private key is created on your phone, kept in its vault (Android Keystore, or a non-exportable browser key for the web version) and never sent: we never see it.
- The requests you receive: the app, the action, the title, the message and the context lines written by the app (browser, amount…), your answer and its time. The app may attach technical data that is not shown to you.
- App messages stored in your inbox, and whether you read them.
- Your short messages with your contacts: the text, the time, whether it was read.
- Your eNotif contacts: the people you added or blocked.
- A security log: sign-ins, a phone added or replaced, account recoveries, “This wasn’t me” reports, with a hash of the IP address.
- A notification token to tell you about a request.
Your phone book
Only if you allow it. The numbers in your phone book are turned on your phone into hashes (SHA-256) before being sent. We compare them with existing accounts to tell you who is on eNotif, then forget them: these hashes are never stored. A hash of a phone number is not an absolute secret; that is why we do not keep it.
Your short messages: encrypted, but not end to end
Your messages travel encrypted (TLS) and are encrypted on our servers (AES-256). They are not end-to-end encrypted: technically, Sahelab holds the keys that can read them. We do not read them; access is limited to the security of the service (a reported abuse) and to requests from a lawfully empowered authority. End-to-end encryption is planned for a later version. For a secret, do not use short messages.
What apps see
An app that sends you a request already knows your number: it is the one sending it. From us, it only receives:
- an identifier of its own (two apps never receive the same one: they cannot match their users);
- your answer (approved, denied, expired) and its time;
- the fact that you changed your trusted phone, so it can protect your account on its side.
It never receives your name, @handle, photo, contacts, messages or the list of other apps you use. It can only write to your inbox after a first approved request, and you can mute or block it in one tap (Profile › Apps).
What we do not do
- No advertising, no ad trackers, no selling or renting of data.
- No reading of your location, photos or files.
- Never an SMS to confirm an action: the only SMS is the one that links your number to your phone.
Who else has access
- The eNotif team (Sahelab), for security, reports and your requests.
- OVH, which hosts our servers in France.
- Google (Firebase Cloud Messaging) and the browsers’ push services, which deliver notifications. A notification only carries the app’s name and the request’s title, never its details.
- Our SMS provider, which receives your number and the verification code.
Retention
- Account: as long as it exists. On deletion, see what is deleted.
- SMS codes: kept only in irreversible hashed form, for as long as they are valid.
- Events sent to apps: 30 days.
- Record of notifications sent: 60 days.
- Requests, messages and security log: as long as your account exists, for your history and to detect fraud.
Security
Every answer to a request is signed by your phone: a stolen password or session is not enough to answer in your place. Changing phones requires the old one’s approval, or a recovery delay during which the old one is warned and can cancel. Developers’ keys are kept as hashes, never in clear.
Your rights
You can ask for access to your data, its correction, its deletion or a copy. You can delete your account yourself in the app: see Delete my account. You can also contact your country’s data protection authority (in Mali, the APDP; in France, the CNIL).
Contact
Sahelab — write to us from the Contact page.