Privacy Policy
Last updated: October 5, 2026
The short version
- When you send messages through SimpleSMS, the phone numbers and texts are your data. We process them for you, on your instructions.
- We collect a little about you (account, billing, usage) to run the Service.
- We do not sell personal data, use message content for ads, or use it to train general-purpose AI models.
- Automated screening, including AI classifiers, reads messages only to stop fraud and abuse and to honor opt-outs.
- Got a text from a business on SimpleSMS? Reply STOP. Questions go to legal@deliveredsms.com.
This policy describes how Truelabel Inc, doing business as "SimpleSMS" ("we", "us"), handles personal data in connection with the SimpleSMS platform and websites (the "Service"). The Service was called "Delivered" until October 2026; only the name and web address changed.
1. Two Roles
Our customers' data: we are the controller. For information about the developers and businesses who use SimpleSMS (accounts, billing, support, website visits) we decide how it is used, and this policy describes it.
Message data: we are a processor. When customers send us phone numbers, message content, contact lists, or other information through the API or console, we process it on the customer's behalf and on their instructions, under our Data Processing Addendum. The customer decides why it is processed and is responsible for having a lawful basis, such as consent, to message each recipient. If you received a text from a business that uses SimpleSMS, that business's privacy policy governs how it uses your information; Section 9 explains how to reach it through us.
2. Data We Collect
Account data. Name, email, company, and sign-in identifiers (including the phone number or authenticator app you set up for two-step sign-in); business and registration details (legal name, address, tax ID, website, use case) that carriers require to register your brand and campaigns, and the results of the automated check we run on the public web pages you submit for registration (findings and short excerpts of those pages, not the pages themselves); when you ask us to fill in a registration from your website, the details we read from those public pages (business name, contact details, address, industry, and which pages hold your opt-in form, privacy policy and terms), kept for about 10 minutes so that asking again does not read your site again, and any draft example messages we suggest, kept with the registration until you replace or confirm them; the example messages and the description of what you send that you write for a registration, and a copy of exactly what we filed for carrier review each time you submit one (your business details, those examples and description, and how the checks stood), which we keep unchanged so that you and we can show what was reviewed; the answers you give when you request live access (company, website, expected volume, message types, how recipients opt in, countries, and use case), which we take from your registration when you submit one from a sandbox account instead of asking again; the answers you give when you request a toll-free number or a short code (business name, expected volume, and use case); where each of your phone numbers stands with the carriers (its registration status, the registration it is linked to, and the history of those changes); the setup path you start in the console (for example moving from another provider), which only decides which setup steps we show you; team members you invite (we send the invitation to the email address you give us, and keep that address with the pending invitation until it is accepted or revoked, or is cleared after it expires). When you sign up we check that your email address can receive mail (its format, a list of disposable email domains, and the domain's public DNS records); no outside service sees the address.
Billing data. Plan, invoices, and payment status. Card details are held by our payment processor, never by us.
Support data. What you send us when you contact support.
Product update subscriptions. If you sign up for product updates on our website or in console settings: your email address, where you signed up, and when you confirmed or unsubscribed. Website sign-ups are double opt-in: we email nothing but the confirmation link until you confirm, and every update carries an unsubscribe link.
Message data (processed for customers).
- Message content: SMS and MMS bodies and media you send or receive.
- Message metadata: sender and recipient numbers, timestamps, message IDs, delivery status and carrier receipts, routing and carrier information, and error codes.
- Consent records: opt-ins, opt-outs, STOP and HELP replies, and the keyword or phrase that triggered them; the fact and time of any message a customer tried to send to a number after it opted out (not its content); and any opt-in evidence a customer records with us (how and when consent was given, the page and disclosure wording shown, and the IP address and browser user agent of the person who opted in), including the opt-in status, date, and source in a contact list a customer imports; and each number's subscription preference per topic, with when it changed, where the change came from, and who made it.
- Contact records: the contacts a customer keeps with us: phone number, name, email address, company, state or province, tags, custom fields, notes, where the contact came from, and which import added it; the segments (saved filters) and subscription topics the customer defines; and which broadcasts a number was included in.
- Verification data: the number being verified and the outcome. Codes are stored only as salted hashes and never logged in plaintext.
- Lookup data: numbers you look up and the carrier and line-type results.
- Customer records: if you send for other businesses and use the customers API, the names, your identifiers, and metadata you store for them, and per-customer usage counts.
- Automation data: if you use automations, the events you send us about your users (the event name, the user's phone number, your own identifier for the user, and any properties you attach), the link between your identifier and the phone number, the flows you build (including their message text), and a record of each run: who it was for, the steps it took and when, and why it ended.
Usage and device data. API request logs, IP addresses, usage counters, delivery statistics, and rate-limit and fraud signals; an audit log of changes to your account (who made each change, when, and from which IP address); website and console analytics, subject to the consent controls in Section 8; and account-level usage metrics (Section 8).
Automated-agent traffic. We count requests from self-identified AI crawlers and agents by user agent and path; this contains no personal data.
3. How We Use Data
- To provide the Service: transmit messages through carriers, verify numbers, provision numbers, run the inbox, meter and bill usage, and provide support.
- To keep the network safe: detect and prevent spam, phishing, SMS pumping, fraud, and other abuse; enforce our Messaging Policy; maintain opt-out and abuse registries; and meet carrier, registry, and regulatory requirements such as A2P 10DLC registration.
- To comply with law and respond to valid legal requests (Section 7).
- To improve the Service, using account and usage data and aggregated metadata. We do not read message content to improve the product.
- To communicate with you about your account, the Service, and changes to it.
We do not sell personal data, use message content for advertising, or "share" personal data for cross-context behavioral advertising.
4. Automated Processing and AI
Most of the Service involves no AI: sending a message through the API is routing, not analysis. Message content passes through automated systems only in these cases:
- Trust and safety screening. Before a live message is sent, our content screen checks it with rules and a third-party AI moderation model for the prohibited and restricted content in the Messaging Policy. A blocked message, with up to 320 characters of its text, is kept for review.
- Opt-out detection. An inbound reply that is not an exact keyword may be checked by rules and, if still unclear, by a third-party AI classifier to decide whether it revokes consent (for example "please stop texting me").
- Features you turn on. If you enable an AI-powered feature, it processes the content it needs to do what you asked, and we will say so where you enable it.
One feature uses AI on something other than messages:
- Filling in a registration from your website. When you ask us to, we read the public pages of the website you give us and take your business details from them with fixed rules. Where AI drafting is available, a third-party AI model also reads the text of those public pages to draft a description, suggest your use case and industry, and write example messages; the form says so before you use it. The model receives only that public page text. It never receives message content, recipient data, or anything else from your account. Everything it drafts is a suggestion for you to review: drafted example messages stay marked as drafts and are never filed until you edit or confirm them, and nothing is filed until you submit.
Neither we nor our AI providers use your message content, or the website text read for registration suggestions, to train or fine-tune general-purpose AI models. Our AI providers process it only to return a result to us, under terms that prohibit training on it. We will not train our own models on message content unless you opt in.
5. Sharing and Subprocessors
We share data only with:
- Service providers (subprocessors) that help us run the Service: telecommunications carriers, aggregators, and campaign registries (which necessarily receive numbers and content to deliver messages); cloud hosting and database providers; our payment processor; AI moderation and classification providers; a phone data provider (for lookups); email delivery; product analytics (website and console analytics with consent, plus account-level usage metrics for business reporting; never message content or recipient numbers); and internal operations tooling. The Subprocessors page lists each category, what it does, and where it processes data.
- Carriers and authorities, when needed to investigate abuse on the network or comply with law.
- A successor in a merger, acquisition, or sale of assets, under this policy.
Carriers may also process message content under their own legal obligations.
6. SMS Opt-In Data and Mobile Information
Mobile phone numbers and text-messaging originator opt-in data and consent are not shared with, sold to, or rented to any third party or affiliate for marketing or promotional purposes under any circumstances. The sharing described in Section 5 excludes this information: it is disclosed only to telecommunications carriers and aggregators as strictly necessary to deliver the messages a recipient has consented to receive, to maintain opt-out lists, or to comply with law. Message recipients can revoke consent at any time by replying STOP, and can reply HELP for assistance.
7. Legal Requests
We disclose data in response to subpoenas, court orders, and warrants only when they are valid, and we require a warrant (or its equivalent) for message content, except in an emergency involving risk of death or serious physical injury. Where the law allows, we notify the affected customer first. See Terms §7.
8. Cookies and Analytics
The website and console use strictly necessary cookies for sign-in and security. Product analytics run only with your consent where the law requires it, and you can change your choice at any time on Privacy Choices. We do not use advertising cookies.
Separately, our servers send account-level usage metrics to our product analytics provider for business reporting: your account identifier, how you signed up, when your account first sent a message in test and live mode, hourly counts of messages sent, delivered, and failed, and estimated charges at our published rates. To measure delivery rates we may also send, for each message, our internal message identifier, your account identifier, whether the carrier accepted, delivered, or failed it (with our failure category), the destination carrier's name, the segment count, and the customer identifier you assigned in our API, if any. These are counts, timings, and delivery status about your account's traffic. They never include message content, recipient or sender phone numbers, or any data about the people you message, and they set no cookies on your devices.
9. Your Rights
Depending on where you live (including under the GDPR and UK GDPR, and the privacy laws of California, Colorado, Connecticut, Virginia, Texas, Oregon, and other US states), you may have the right to access, correct, delete, or port your personal data, to restrict or object to processing, to opt out of sale, sharing, targeted advertising, or profiling, and to appeal our decision on a request. We honor these rights without discrimination.
- Customers: email legal@deliveredsms.com. We will verify your request and respond within the time the law requires (generally 30 to 45 days). You may use an authorized agent.
- Message recipients: because the business that texted you controls that data, email legal@deliveredsms.com with the number that texted you and we will pass your request to that business and help it respond. To stop messages right away, reply STOP.
10. Retention
We keep data only as long as we need it for the purposes above. The Data Retention page lists the periods for each kind of data, including message content, opt-out records, and closed accounts.
11. Security
Data is encrypted in transit with TLS and at rest. API keys and verification codes are stored as salted hashes. Access to production systems is limited to personnel who need it and is logged. We notify affected customers of a personal data breach without undue delay, and within 72 hours of confirming one where the DPA applies. More in our security documentation.
12. International Transfers
We are a US company and process data in the United States. When we receive personal data from the EEA, UK, or Switzerland, we protect it with the safeguards in the DPA, including the EU Standard Contractual Clauses and the UK Addendum.
13. Children
The Service is for business use and is not directed to children under 16; we do not knowingly collect their data.
14. Changes
We will post changes here and, for material changes, notify account holders via the console or email before they take effect.
Contact
Truelabel Inc (d/b/a SimpleSMS) 5830 E 2nd St, Ste 7000, PMB 35111, Casper, WY 82609, USA legal@deliveredsms.com