Legal

Privacy Policy

Last updated: May 11, 2026 · Effective: May 11, 2026

SMSPilot.ai ("SMSPilot," "we," "our," or "us") respects your privacy. This Privacy Policy describes the personal information we collect, how we use and share it, your rights, and the choices you have when you use the SMSPilot platform, website (smspilot.ai), and related services (collectively, the "Service").

1. Information we collect

We collect the following categories of information:

  • Account information: Name, email address, phone number, company name, password (stored hashed), and billing information when you create an account.
  • Contact data you upload: Phone numbers, names, property addresses, and other lead/contact data you import into the Service from your texting platform or upload manually.
  • Conversation data: SMS messages exchanged between your campaigns and your leads, including text, timestamps, and metadata.
  • Usage data: Actions you take in the platform, bot activity logs, feature usage, login events, IP address, browser and device information.
  • Payment data: Payment card data is collected and stored by our payment processor (Stripe); we do not store full card numbers.
  • Communications: Support requests, feedback, and any other correspondence you send us.

2. How we use information

We use information to:

  • Provide, operate, and improve the Service, including running the AI conversation engine, lead scoring, valuation lookups, and buyer/builder lookup.
  • Process payments and manage your account, including token wallet balances and Stripe top-ups.
  • Send service-related notifications (e.g., deal alerts, account alerts) to phone numbers and email addresses you have provided.
  • Respond to support requests and communicate with you about the Service.
  • Detect, prevent, and address fraud, security, technical issues, and abuse.
  • Comply with legal obligations and enforce our Terms of Service.
  • Develop and improve our AI models using aggregated, anonymized usage signals (we do not share customer conversation content with third-party model vendors for their own training; see Section 3).

3. AI processing & third-party models

The Service uses large-language-model providers (currently OpenAI) to power conversation handling, intent classification, valuation analysis, and buyer/builder lookup. When we send prompts to those providers:

  • Provider data is processed under their data-processing terms (in OpenAI's case, API inputs and outputs are not used to train their models by default).
  • We do not send your password, full payment card numbers, or other secrets to AI providers.
  • We may store AI inputs and outputs as part of your account to display conversation history and improve our prompts.
  • AI-generated outputs are not guaranteed to be accurate, complete, or appropriate; you are responsible for reviewing and acting on them.

4. SMS messaging

When you opt in to receive SMS deal alerts and notifications from SMSPilot:

  • We send automated SMS messages to the phone number you provide, including deal alerts, hot-quote notifications, and account notifications.
  • Message frequency varies with your campaign activity; multiple messages per day are possible during active campaigns.
  • Message and data rates may apply depending on your mobile carrier and plan.
  • You can opt out at any time by replying STOP. You will receive a confirmation and no further messages will be sent.
  • Reply HELP for support contact information. Reply START or YES to resubscribe.
  • Your mobile information will not be sold or shared with third parties for promotional or marketing purposes.
  • The above categories exclude text-messaging originator opt-in data and consent, which we never share with third parties.
  • We may share opt-in or consent status with vendors that help us deliver messages (e.g., SMS gateways, telephone carriers) solely to send the messages you have opted in to receive.
  • Your consent to receive SMS messages is not a condition of purchasing any goods or services.

5. How we share information

We do not sell your personal information. We share information only in the following cases:

  • Service providers and sub-processors that operate the Service on our behalf (see Section 6). These vendors are contractually required to protect your data and use it only as instructed.
  • With your direction: when you connect a third-party texting platform or integrations, you authorize us to exchange data with that service.
  • Legal requirements: when required by law, subpoena, court order, or governmental authority, or to protect our rights, your safety, or the rights and safety of others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to the acquirer agreeing to honor this Privacy Policy.

6. Sub-processors

We rely on the following categories of sub-processors. Specific vendors may change; this list is current as of the date above:

  • Cloud hosting: Hetzner (servers located in the EU and US).
  • AI model providers: OpenAI (conversation handling, lookup, classification).
  • Payments: Stripe.
  • SMS delivery: Telnyx and your selected texting platform integration partners.
  • Email delivery: SMTP relay providers for transactional email.
  • Analytics & error tracking: minimal, used to monitor uptime and performance.

7. Cookies & tracking

We use first-party cookies and similar technologies for essential authentication (keeping you logged in), CSRF protection, preferences, and basic site analytics. We do not run third-party advertising or cross-site tracking trackers on our site. You can disable cookies in your browser settings, but doing so may break login.

8. Data security

We use commercially reasonable technical and organizational measures to protect your information, including:

  • TLS encryption in transit for all web and API traffic.
  • Encryption at rest for sensitive fields and backups.
  • Hashed and salted password storage; we cannot read your password.
  • Access controls and audit logging for staff with production access.
  • Regular dependency updates and security reviews.

No system is perfectly secure. You are responsible for keeping your account credentials confidential.

9. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service. After account closure:

  • Account and conversation data is retained for up to 90 days, then deleted or anonymized, unless you request earlier deletion or a longer retention is required by law.
  • SMS opt-in / opt-out records are retained for the period required by applicable law and to honor unsubscribe requests.
  • Billing and tax records are retained for the period required by applicable accounting and tax law (typically 7 years).

You may request earlier deletion of your data by contacting us at the address in Section 16.

10. Your rights

Subject to applicable law, you have the right to:

  • Access, correct, update, or download a copy of your personal information.
  • Request deletion of your personal information.
  • Opt out of SMS notifications at any time by replying STOP.
  • Withdraw consent for data processing where processing is based on consent.
  • Object to or restrict certain processing.
  • Lodge a complaint with a supervisory authority (where applicable).

To exercise any of these rights, contact us at support@smspilot.ai. We will respond within the timeframes required by applicable law.

11. California (CCPA / CPRA) rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act, including the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share.
  • Request deletion of personal information we have collected from you.
  • Request correction of inaccurate personal information.
  • Opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell or share personal information as those terms are defined under the CCPA.
  • Limit the use of sensitive personal information.
  • Be free from retaliation for exercising any of these rights.

You may exercise these rights by contacting us as described in Section 16. You may also designate an authorized agent to make a request on your behalf.

12. International users

SMSPilot is operated from the United States. If you access the Service from outside the United States, you consent to having your data transferred to and processed in the United States and other countries where our sub-processors operate. We rely on appropriate legal mechanisms (such as standard contractual clauses) for international data transfers where required.

13. Children's privacy

The Service is not directed to and is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

14. Data breach notification

In the event of a confirmed security incident affecting your personal information, we will notify you and applicable regulators without undue delay and as required by applicable law. Notice will describe the nature of the incident, the categories of data involved, and the steps we are taking in response.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date at the top and, where required, provide additional notice (such as by email or a notice in the platform). Your continued use of the Service after the changes take effect constitutes acceptance of the updated policy.

16. Contact us

If you have questions about this Privacy Policy or our practices, please contact:

SMSPilot.ai
Email: support@smspilot.ai
Mail: 16441 Pleasant Mill Rd, Wedowee, AL 36278

Quick note. This policy is written in plain English on purpose. If anything here is unclear, please email us and we'll explain.