# Privacy Policy

Source: https://joinsimplesms.com/privacy
Index: https://joinsimplesms.com/llms.txt

**Last updated: October 5, 2026**

> **The short version**
>
> - When you send messages through SimpleSMS, the phone numbers and texts
>   are your data. We process them for you, on your instructions.
> - We collect a little about you (account, billing, usage) to run the
>   Service.
> - We do not sell personal data, use message content for ads, or use it to
>   train general-purpose AI models.
> - Automated screening, including AI classifiers, reads messages only to
>   stop fraud and abuse and to honor opt-outs.
> - Got a text from a business on SimpleSMS? Reply STOP. Questions go to
>   support@joinsimplesms.com.

This policy describes how **Truelabel Inc**, doing business as
"SimpleSMS" ("we", "us"), handles personal data in connection with the
SimpleSMS platform and websites (the "Service"). The Service was called
"Delivered" until October 2026; only the name and web address changed.

## 1. Two Roles

**Our customers' data: we are the controller.** For information about the
developers and businesses who use SimpleSMS (accounts, billing, support,
website visits) we decide how it is used, and this policy describes it.

**Message data: we are a processor.** When customers send us phone numbers,
message content, contact lists, or other information through the API or
console, we process it **on the customer's behalf and on their
instructions**, under our [Data Processing Addendum](/dpa). The customer
decides why it is processed and is responsible for having a lawful basis,
such as consent, to message each recipient. If you received a text from a
business that uses SimpleSMS, that business's privacy policy governs how it
uses your information; Section 9 explains how to reach it through us.

## 2. Data We Collect

**Account data.** Name, email, company, and sign-in identifiers (including
the phone number or authenticator app you set up for two-step sign-in);
business
and registration details (legal name, address, tax ID, website, use case)
that carriers require to register your brand and campaigns, and the results
of the automated check we run on the public web pages you submit for
registration (findings and short excerpts of those pages, not the pages
themselves); when you ask us to fill in a registration from your website,
the details we read from those public pages (business name, contact
details, address, industry, and which pages hold your opt-in form, privacy
policy and terms), kept for about 10 minutes so that asking again does not
read your site again, and any draft example messages we suggest, kept with
the registration until you replace or confirm them; the example messages and the description of what you send
that you write for a registration, and a copy of exactly what we filed for
carrier review each time you submit one (your business details, those
examples and description, and how the checks stood), which we keep
unchanged so that you and we can show what was reviewed; the answers you give when you request live access (company,
website, expected volume, message types, how recipients opt in, countries,
and use case), which we take from your registration when you submit one
from a sandbox account instead of asking again; the answers you give when you
request a toll-free number or a short code (business name, expected volume,
and use case); where each of your phone
numbers stands with the carriers (its registration status, the registration
it is linked to, and the history of those changes); the setup path you start in the console (for example moving from another
provider), which only decides which setup steps we show you; team members you invite (we send the invitation to the email
address you give us, and keep that address with the pending invitation until
it is accepted or revoked, or is cleared after it expires). When you sign up we check that your
email address can receive mail (its format, a list of disposable email
domains, and the domain's public DNS records); no outside service sees the
address.

**Billing data.** Plan, invoices, and payment status. Card details are held
by our payment processor, never by us.

**Support data.** What you send us when you contact support.

**Product update subscriptions.** If you sign up for product updates on our
website or in console settings: your email address, where you signed up, and
when you confirmed or unsubscribed. Website sign-ups are double opt-in: we
email nothing but the confirmation link until you confirm, and every update
carries an unsubscribe link.

**Message data (processed for customers).**

- *Message content:* SMS and MMS bodies and media you send or receive.
- *Message metadata:* sender and recipient numbers, timestamps, message
  IDs, delivery status and carrier receipts, routing and carrier
  information, and error codes.
- *Consent records:* opt-ins, opt-outs, STOP and HELP replies, and the
  keyword or phrase that triggered them; the fact and time of any message a
  customer tried to send to a number after it opted out (not its content); and any opt-in evidence a customer
  records with us (how and when consent was given, the page and disclosure
  wording shown, and the IP address and browser user agent of the person who
  opted in), including the opt-in status, date, and source in a contact list
  a customer imports; and each number's subscription preference per topic,
  with when it changed, where the change came from, and who made it.
- *Contact records:* the contacts a customer keeps with us: phone number,
  name, email address, company, state or province, tags, custom fields,
  notes, where the contact came from, and which import added it; the
  segments (saved filters) and subscription topics the customer defines; and
  which broadcasts a number was included in.
- *Verification data:* the number being verified and the outcome. Codes are
  stored only as salted hashes and never logged in plaintext.
- *Lookup data:* numbers you look up and the carrier and line-type results.
- *Customer records:* if you send for other businesses and use the customers
  API, the names, your identifiers, and metadata you store for them, and
  per-customer usage counts.
- *Automation data:* if you use automations, the events you send us about
  your users (the event name, the user's phone number, your own identifier
  for the user, and any properties you attach), the link between your
  identifier and the phone number, the flows you build (including their
  message text), and a record of each run: who it was for, the steps it
  took and when, and why it ended.

**Usage and device data.** API request logs, IP addresses, usage counters,
delivery statistics, and rate-limit and fraud signals; an audit log of
changes to your account (who made each change, when, and from which IP
address); website and console analytics, subject to the consent controls in
Section 8; and account-level usage metrics (Section 8).

**Automated-agent traffic.** We count requests from self-identified AI
crawlers and agents by user agent and path; this contains no personal data.

## 3. How We Use Data

- **To provide the Service:** transmit messages through carriers, verify
  numbers, provision numbers, run the inbox, meter and bill usage, and
  provide support.
- **To keep the network safe:** detect and prevent spam, phishing, SMS
  pumping, fraud, and other abuse; enforce our [Messaging
  Policy](/messaging-policy); maintain opt-out and abuse registries; and
  meet carrier, registry, and regulatory requirements such as A2P 10DLC
  registration.
- **To comply with law** and respond to valid legal requests (Section 7).
- **To improve the Service,** using account and usage data and aggregated
  metadata. We do not read message content to improve the product.
- **To communicate with you** about your account, the Service, and changes
  to it.

We do not sell personal data, use message content for advertising, or
"share" personal data for cross-context behavioral advertising.

## 4. Automated Processing and AI

Most of the Service involves no AI: sending a message through the API is
routing, not analysis. Message content passes through automated systems only
in these cases:

- **Trust and safety screening.** Before a live message is sent, our content
  screen checks it with rules and a third-party AI moderation model for the
  prohibited and restricted content in the Messaging Policy. A blocked
  message, with up to 320 characters of its text, is kept for review.
- **Opt-out detection.** An inbound reply that is not an exact keyword may be
  checked by rules and, if still unclear, by a third-party AI classifier to
  decide whether it revokes consent (for example "please stop texting me").
- **Features you turn on.** If you enable an AI-powered feature, it processes
  the content it needs to do what you asked, and we will say so where you
  enable it.

One feature uses AI on something other than messages:

- **Filling in a registration from your website.** When you ask us to, we
  read the public pages of the website you give us and take your business
  details from them with fixed rules. Where AI drafting is available, a
  third-party AI model also reads the text of those public pages to draft a
  description, suggest your use case and industry, and write example
  messages; the form says so before you use it. The model receives only that
  public page text. It never receives message content, recipient data, or
  anything else from your account. Everything it drafts is a suggestion for
  you to review: drafted example messages stay marked as drafts and are
  never filed until you edit or confirm them, and nothing is filed until you
  submit.

**Neither we nor our AI providers use your message content, or the website
text read for registration suggestions, to train or
fine-tune general-purpose AI models.** Our AI providers process it only to
return a result to us, under terms that prohibit training on it. We will not
train our own models on message content unless you opt in.

## 5. Sharing and Subprocessors

We share data only with:

- **Service providers (subprocessors)** that help us run the Service:
  telecommunications carriers, aggregators, and campaign registries (which
  necessarily receive numbers and content to deliver messages); cloud
  hosting and database providers; our payment processor; AI moderation and
  classification providers; a phone data provider (for lookups); email
  delivery; product analytics (website and console analytics with consent,
  plus account-level usage metrics for business reporting; never message
  content or recipient numbers); and internal operations tooling. The [Subprocessors](/subprocessors) page
  lists each category, what it does, and where it processes data.
- **Carriers and authorities**, when needed to investigate abuse on the
  network or comply with law.
- **A successor** in a merger, acquisition, or sale of assets, under this
  policy.

Carriers may also process message content under their own legal
obligations.

## 6. SMS Opt-In Data and Mobile Information

Mobile phone numbers and text-messaging originator opt-in data and consent
are **not** shared with, sold to, or rented to any third party or affiliate
for marketing or promotional purposes under any circumstances. The sharing
described in Section 5 excludes this information: it is disclosed only to
telecommunications carriers and aggregators as strictly necessary to deliver
the messages a recipient has consented to receive, to maintain opt-out
lists, or to comply with law. Message recipients can revoke consent at any
time by replying STOP, and can reply HELP for assistance.

## 7. Legal Requests

We disclose data in response to subpoenas, court orders, and warrants only
when they are valid, and we require a warrant (or its equivalent) for message
content, except in an emergency involving risk of death or serious physical
injury. Where the law allows, we notify the affected customer first. See
Terms §7.

## 8. Cookies and Analytics

The website and console use strictly necessary cookies for sign-in and
security. Product analytics run only with your consent where the law
requires it, and you can change your choice at any time on [Privacy
Choices](/privacy-choices). We do not use advertising cookies.

Separately, our servers send account-level usage metrics to our product
analytics provider for business reporting: your account identifier, how you
signed up, when your account first sent a message in test and live mode,
hourly counts of messages sent, delivered, and failed, and estimated
charges at our published rates. To measure delivery rates we may also send,
for each message, our internal message identifier, your account identifier,
whether the carrier accepted, delivered, or failed it (with our failure
category), the destination carrier's name, the segment count, and the
customer identifier you assigned in our API, if any. These are counts,
timings, and delivery status about your account's traffic. They never
include message content, recipient or sender phone numbers, or any data
about the people you message, and they set no cookies on your devices.

## 9. Your Rights

Depending on where you live (including under the GDPR and UK GDPR, and the
privacy laws of California, Colorado, Connecticut, Virginia, Texas, Oregon,
and other US states), you may have the right to access, correct, delete, or
port your personal data, to restrict or object to processing, to opt out of
sale, sharing, targeted advertising, or profiling, and to appeal our
decision on a request. We honor these rights without discrimination.

- **Customers:** email support@joinsimplesms.com. We will verify your request
  and respond within the time the law requires (generally 30 to 45 days).
  You may use an authorized agent.
- **Message recipients:** because the business that texted you controls
  that data, email support@joinsimplesms.com with the number that texted you
  and we will pass your request to that business and help it respond. To
  stop messages right away, reply STOP.

## 10. Retention

We keep data only as long as we need it for the purposes above. The
[Data Retention](/data-retention) page lists the periods for each kind of
data, including message content, opt-out records, and closed accounts.

## 11. Security

Data is encrypted in transit with TLS and at rest. API keys and verification
codes are stored as salted hashes. Access to production systems is limited
to personnel who need it and is logged. We notify affected customers of a
personal data breach without undue delay, and within 72 hours of confirming
one where the [DPA](/dpa) applies. More in our [security
documentation](/docs/security).

## 12. International Transfers

We are a US company and process data in the United States. When we receive
personal data from the EEA, UK, or Switzerland, we protect it with the
safeguards in the [DPA](/dpa), including the EU Standard Contractual Clauses
and the UK Addendum.

## 13. Children

The Service is for business use and is not directed to children under 16;
we do not knowingly collect their data.

## 14. Changes

We will post changes here and, for material changes, notify account holders
via the console or email before they take effect.

## Contact

Truelabel Inc (d/b/a SimpleSMS)
5830 E 2nd St, Ste 7000, PMB 35111, Casper, WY 82609, USA
support@joinsimplesms.com
