Legal
Privacy Policy
The short version: we collect the minimum an SMS API needs to work, we keep message content only long enough to deliver it and show you your own log, and we never sell data to anyone. The details follow.
1. Who we are
Textmux is operated by Pockadot LLC, a limited liability company organized in the State of Washington, USA. For anything privacy-related, write to dev@pockadot.com.
We handle data in two roles. For our customers' account data, we decide how it is used. For the recipient data our customers send through the API, we process it on the customer's behalf: the customer decides who gets messaged and why, within our acceptable use policy.
2. What we collect
Account data (about you, our customer)
- Your API token identifiers, and your email address if you attach one for dashboard access.
- Billing details, handled by our payment processors. We never see or store your full card number.
- Sender registration details: your business identity, contact information, and the opt-in workflow you describe. Carrier verification programs require this information, and we submit it to them on your behalf.
Messaging data (processed on your behalf)
- Recipient phone numbers and message metadata: timestamps, segment counts, and delivery events (queued, delivered, failed, suppressed).
- Message content, kept only as part of your own message log so you can see what was sent, then deleted on the schedule below.
- Opt-out records: when a recipient replies STOP, we keep that phone number on your suppression list so we never message them again on your behalf.
- Inbound replies to your numbers, relayed to your webhook and kept in your message log.
Website
This website sets no advertising or tracking cookies. The customer dashboard stores only your API token in your own browser to keep you signed in.
3. Why we collect it
- To run the service: deliver your messages, relay replies, show you logs, manage suppressions.
- To meet carrier requirements: register and verify senders, honor opt-outs, and respond to carrier compliance inquiries.
- To protect deliverability: monitor delivery and complaint signals and enforce our acceptable use policy, with reasons always given.
- To bill you: meter segments and process payments.
- To meet legal obligations and respond to lawful requests.
We do not sell personal data, and we do not use your data or your recipients' data for advertising.
4. How long we keep it
| Data | Retention |
|---|---|
| Message content | 90 days in your message log, then deleted. |
| Delivery events and metadata | 90 days, then deleted. |
| Suppression (opt-out) entries | Kept while your account is active. Carrier rules require opt-outs to stick. |
| Sender verification records | Life of the sender registration, as carrier programs require. |
| Aggregate statistics (counts and rates, no personal data) | Kept indefinitely to operate the service. |
| Account and billing records | Life of the account, plus what tax and accounting law requires. |
5. Subprocessors
We use a small number of third-party processors to run Textmux:
- Telnyx LLC: licensed carrier connectivity for delivering SMS and receiving replies, in the United States.
- Amazon Web Services (AWS): hosting infrastructure, in the United States.
- Payment processors for card payments and, for x402 payments, the settlement network involved.
We share data with them only as needed to provide the service. We will update this list here before adding a subprocessor.
6. Your rights
You can ask us what data we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Send data requests to dev@pockadot.com and we will respond promptly.
If you received a text sent through Textmux, reply STOP to stop all messages from that sender immediately, or HELP for the sender's identity and support contact. If a sender is abusing the service, report it to us at dev@pockadot.com; cold outreach and purchased lists are banned here, and reports have consequences.
7. Security
Data is encrypted in transit, access is restricted to what operating the service requires, and webhook payloads are signed so you can verify they came from us. No provider can promise perfect security, so if a breach ever affects your data we will notify you without undue delay.
8. Changes to this policy
The current version always lives at this page, with its effective date at the top. For material changes we will notify account holders before the change takes effect.
9. Contact
Privacy questions and data requests: dev@pockadot.com.