Updated August 2026 — Covers the NEW 1console.twilio.com
Twilio launched a completely redesigned console in May 2026 at 1console.twilio.com. Every other guide online still shows the old interface. These guides are verified against the new console as of August 2026.

Help Center / Privacy Policy Guide

Writing an SMS-Compliant Privacy Policy

TCR reviewers actually visit the privacy policy URL you submit and check it against a specific set of required language — this is the single most common reason a real A2P campaign gets rejected.

1

Why it matters for A2P approval

Your Campaign registration includes a privacy policy URL. TCR's automated review fetches that page and checks it for specific mobile-data-sharing language — not just "do you have a privacy policy," but "does it say the exact right thing about SMS consent data."

2

The exact required phrase

This needs to appear on your privacy policy page, word for word:

"We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes."

It should appear more than once if your policy has multiple relevant sections — for example as the first sentence of an "SMS/Mobile Messaging" section, again in a "No Sharing of Consent" subsection, and again in your general Data Sharing section.

3

Other required elements

  • Message frequency disclosure
  • "Message and data rates may apply"
  • STOP opt-out instructions
  • HELP instructions
  • What data you actually collect and why
4

Common rejection: error 30908

This is Twilio's specific error code for "privacy policy non-compliant." If you hit it, the fix is almost always adding the exact phrase above, verbatim, rather than a paraphrase of it — reviewers (and whatever automated check runs before a human ever looks at it) match against the specific wording, not just the general sentiment.

⚠️ TCR reviewers visit your privacy policy URL directly — it must be publicly accessible without a login, and it should be the only privacy policy live on your domain. A duplicate or outdated privacy policy sitting at a different URL on the same site can confuse automated review even if the one you submitted is correct.
5

A working example

Linxi's own privacy policy at linxi.app/privacy includes this exact language and has passed A2P review — worth a look if you want a concrete reference alongside the requirements above.