Privacy Policy
Last updated: September 2, 2026
This policy describes how TextCatch ("we," "us"), a product of Apex AI Systems, collects, uses, shares, and deletes personal information. It covers two different people, and they are treated differently throughout: the business client — the contractor who buys TextCatch — and the caller, someone who phoned that contractor, didn't get through, and received an automatic text back.
It also states plainly, in Data retention, what deleting an account does and does not erase today. Read that section if you read nothing else.
If you got a text: who sent it, and how often
You called a local business, nobody picked up, and you got a text back. That text came from that business — its name is in the message — sent through TextCatch, the software they use. TextCatch doesn't choose who gets texted; your call did. The automated missed-call system never texts anyone who hasn't first called one of our business clients, and we don't send marketing on our own account to anyone who reaches us this way. Separately, our own sales team sometimes sends a one-off text to a business we'd like as a client, from our own number — that's TextCatch reaching out directly, not the automated system above, and it always includes a way to opt out.
How often. You get one text right after the missed call. If you don't reply, you may get up to four follow-ups spread over the following week — roughly four hours later, the next morning, day three and day seven. That whole sequence is cancelled the moment you reply, or immediately if you text STOP, and it never starts up again.
One thing that is worth stating precisely rather than absolutely, because it is what the system actually does: if your reply gives a concrete reason to check back once — you ask to be contacted later, or say you need to check a date, a budget, or with someone else — the assistant may schedule a single further message, about four hours after you wrote. One message, not a restarted sequence, and it is cancelled too the moment you reply again or text STOP. So after any reply you send, the most you can receive without replying again is one more text. Once you're in a back-and-forth, frequency just follows the conversation.
When. The first automated text, the follow-ups, and anything the contractor writes and sends by hand are all held to 8:00am–8:00pm in the time zone of your area code — 9:00am–9:00pm, or noon–8:00pm on Sundays, for Texas numbers. An automated message that would land outside that window is held until the next permitted hour rather than sent early. A message the contractor writes by hand is refused outright at that point — they're shown a warning naming your local time, and it only goes out if they deliberately confirm a second time, with every one of those overrides written to an audit log. One thing this doesn't cover: once you've texted in and you're in an active back-and-forth, the assistant's replies within that same conversation go out right away, whatever the hour, since it's responding to something you just sent rather than starting new contact.
Message and data rates may apply, per your own mobile plan — TextCatch does not charge you anything, ever. Carriers are not liable for delayed or undelivered messages. Reply HELP for help or STOP to opt out at any time; see Your rights for the full list of keywords and what each one does.
What we collect
From business clients, at signup and in ongoing use:
| Category | Specific data |
|---|---|
| Identifiers | First and last name, email address, business name, business phone number, personal phone number, the TextCatch phone number assigned to the account |
| Account credentials | A password, stored only as a one-way hash — we cannot read it and cannot recover it for you |
| Commercial information | Plan, billing status, charges, refunds, credit balance, support tickets and their conversation history |
| Business configuration | Services offered, qualification criteria, business hours, service area, booking and payment links, message templates |
| Payment information | Card details go directly to Stripe. We hold only Stripe's customer and payment-method reference. We never receive or store a full card number. |
| Usage and audit data | Logins, actions taken in the dashboard, conversation and message counts |
From callers, when you're texted back after a missed call:
| Category | Specific data |
|---|---|
| Identifiers | Your mobile phone number. It is encrypted in our database, and also stored as a one-way hash used solely to match you against the opt-out list. |
| Message content | The full text of your conversation with the assistant and with the business, encrypted in our database |
| What you volunteer | If you state a company name or a website, we record exactly what you typed. If you give a website, we read publicly available facts from it to make the conversation more relevant. |
| Conversation metadata | Timestamps, conversation status, whether the assistant flagged an emergency, whether a person took over the conversation |
We do not collect payment details in the text conversation. If you agree to work and the business takes payment online, the assistant sends you a link to the business's own payment page — card details go there, never into the message thread and never to us.
From prospects who haven't signed up: when our own team puts together a value estimate to show what TextCatch could recover for a business, we record that business's name, the prospect's first name, and the phone number we send the estimate to. This is a small, one-off outreach tool our sales team uses directly — it's separate from the automated caller-reply system above.
Because we are the sender on that number rather than a contractor, we also keep a record of the messages on it, and it is worth being exact about what that record contains. For every message we send you from it, we store the full text we sent (our own words, not yours), the time, the carrier's message ID, whether it was delivered, and how many segments it used. For a message you send back to that number, we store the time, the carrier's message ID, how many characters it was, a one-way hash of your number and a masked version of it showing only the last four digits — not the text of your message. If you ask us to stop contacting you, we additionally keep, permanently, the specific words in your message that we treated as the request (for example "take me off your list"), so we can prove we honored it — that phrase is kept even after everything else about you is deleted, because it is the record of your opt-out. Where your reply isn't obviously an opt-out, a copy is passed to us as an in-app notification so a person reads it and decides, rather than a filter deciding silently. These records are stored in our own event log in plain text, not encrypted, and are kept small deliberately for that reason. Your carrier and Twilio, our messaging provider, keep their own copies of full message text under their own retention policies — theirs, not ours.
From visitors to this website: nothing that identifies you. This site sets no cookies and runs no analytics, advertising pixels, or tracking of any kind. Our hosting provider, Cloudflare, keeps standard server logs including IP addresses for security and abuse prevention. Our typefaces are served by Google Fonts, which receives your IP address as part of loading them.
How we use it
Business client data is used to run the account: provisioning the phone number, configuring the assistant, billing, support, and alerting you when a caller needs you. Caller data is used to answer your text, understand what you need, route an emergency to the business immediately, schedule or follow up, and record the conversation so the business can see it.
We do not use either for advertising, profiling unrelated to the service, or any purpose you would not expect from the description above. We do not use your data to train AI models, and neither does our AI provider — see below.
Who processes it
These are our service providers. Each receives only what its function requires, processes it only on our instructions, and is contractually barred from using it for its own purposes. All are US-based.
| Provider | What it actually receives |
|---|---|
| Twilio | Carries the SMS, so it necessarily receives the caller's phone number and the full text of every message. Twilio retains message records under its own retention settings — by default, records remain accessible in its systems well beyond the message itself. |
| Anthropic | Receives the text of the conversation and the business's configuration in order to generate each reply. The caller's phone number and name are never included in that request. Under Anthropic's commercial terms, API inputs and outputs are not used to train its models and are deleted within 30 days. |
| Stripe | Receives the business client's name, email and card details directly, and processes payments. Callers' data is never sent to Stripe. |
| Supabase | Hosts the database where records are stored. Phone numbers, callers' names, and message bodies arrive already encrypted by our application. The business client's own name, business name, and email are stored in plain text (needed for search, invoicing, and account management), behind the same production-access controls described below. |
| Cloudflare | Runs the application and serves this website. |
| Cal.com | Powers the "Book a call" scheduling on our site, mainly for prospects who haven't signed up yet, receiving whatever name, email, and message they enter to book. It doesn't pull any data from an existing client's account — but if a client or caller who can't log in uses that same link to reach us (see "Your rights" below), whatever they type into the booking form goes to Cal.com the same way a prospect's does. |
We also disclose information when we are legally required to — a valid subpoena, court order, or law-enforcement demand — and would do so only to the extent actually required.
We do not sell or share your personal information
We have never sold personal information, and we do not "share" it in the specific sense those state privacy laws use — that is, we disclose nothing to any third party for cross-context behavioral advertising, for money, or for any other valuable consideration. There is no advertising technology anywhere in the product or on this website. The companies listed above are service providers acting on our instructions, not recipients of a sale. We also do not knowingly sell or share the personal information of anyone under 16.
How it's protected
Phone numbers, callers' names, and message bodies are encrypted with AES-GCM before they are written to the database; the encryption key is held in the application's secret store, separate from the database itself. The business client's own name, business name, and email are stored in plain text, not application-level encrypted — they're needed in readable form to run the account (search, invoicing, support). They're still protected by the access controls described below, just not by the same application-level encryption phone numbers and messages get. Passwords are hashed, never stored in readable form. Access to production data is limited to TextCatch's own staff, on accounts we control — never handed to a client business or a third party. The site and application are served over HTTPS only, with HSTS.
To be precise about what encryption does and doesn't mean here: our own application decrypts this data in order to run the service, and the text of a conversation is sent to Anthropic to generate each reply. Encryption protects the data at rest in the database. It does not mean nobody processes it.
Data retention
What actually happens today, stated exactly:
- While an account is active: conversations and messages are kept for the life of the account. We do not currently apply an automatic age limit to conversation history.
- If a business client cancels billing (without deleting the account): the service stops. The phone number stays assigned to the account so it's still there if you resubscribe. Account records and conversation history remain in the database.
- If a business client uses "Delete account": this goes further than cancelling — the phone number is released, billing is cancelled, any credit balance is refunded, the account is closed and can no longer be logged into, and every conversation, message, and encrypted contact detail tied to the account is permanently erased from our database (billing records are kept in anonymised form, as required for tax purposes, and opt-out records are kept as described below — deletion never removes those). One known gap we are actively closing: the email address used at signup can still appear in an internal audit-trail record of the account's creation even after deletion.
- On an erasure request: we run a permanent erasure. It destroys stored contact details, credentials, conversation records and message content, and leaves only billing records — stripped of personal identifiers — that we must keep for tax and accounting. It is irreversible. We complete these within 30 days of a verified request. See Your rights for how to make one.
- Opt-out records are kept permanently, on purpose. When you text STOP, we retain your number — encrypted, and as a hash — specifically so that we can keep never messaging you again. Deleting that record would defeat the opt-out, so an erasure request does not remove it.
- Operational records: in-app notifications are deleted automatically after 90 days once read, and after a year regardless; payment-processor event records after 90 days.
- Twilio's copy: Twilio holds its own record of every message sent and received, under its retention settings, which our erasure does not reach.
Your rights and how to use them
Stopping messages (callers). Reply STOP, UNSUBSCRIBE, QUIT, CANCEL, END, REVOKE, STOPALL or OPTOUT at any time — an ordinary phrase like "please stop" or "stop texting me" works too. This is honored immediately and permanently, confirmed back to you, and it cancels every follow-up already queued for you. You do not have to explain why, and it never affects your relationship with the contractor you called.
You do not have to use a keyword. If you simply ask to be left alone — "take me off your list", "remove me", "do not contact me" — the assistant treats that as an opt-out and you get exactly the same result: suppressed permanently, every queued follow-up cancelled, one confirmation back. The assistant makes that judgment rather than a word list, because a word list broad enough to catch every phrasing would also end real conversations over things like "can I cancel my appointment?". Being honest about the limit: this covers clear requests to stop being contacted, and the keywords above are the guaranteed path if you want certainty.
Two other keywords. Reply HELP for the contractor's name, opt-out instructions, rate information and a link you can use to reach a person at TextCatch. Reply START if you previously opted out and want messages again — we keep a record that you opted back in, and when, so a later opt-out and a later opt-in can always be told apart.
Your opt-out applies to the contractor who was texting you, not to TextCatch as a whole. Each business we serve keeps its own do-not-contact list, and your STOP goes on that one. If you later call a different TextCatch-powered business and don't reach them, that business's system will reply to you — texting STOP to one contractor does not silence another. Opting out of texts also doesn't stop you from calling the contractor, or them from returning your call by phone.
Access, correction, deletion and portability. Regardless of whether a particular state's privacy law formally applies to a business our size, we extend these to everyone in the United States:
- Know what personal information we hold about you, the categories, where it came from, why we hold it, and who has received it.
- Correct anything inaccurate.
- Delete it, subject only to the tax and opt-out records described above.
- Receive a copy in a portable format.
- Not be discriminated against for exercising any of these. We do not offer financial incentives in exchange for personal information.
How to make a request. Business clients: open a support ticket from inside your dashboard, or use this booking link. Callers: reply to the text conversation and ask to speak to a person — that reaches a human, not the assistant — or use the same booking link. We verify who you are before acting on a request: for a business client, by requiring the request come from inside your logged-in account (a support ticket) or, if you can't log in, a call where we confirm account details only you would know; for a caller, by confirming control of the phone number the conversation was with. We respond within 45 days and will tell you if we need longer.
An authorized agent may make a request on your behalf with written permission from you, which we will verify with you directly.
If there is ever a data breach
We maintain a written incident-response procedure. If personal information is compromised, we will notify affected people and the regulators that require it, within the deadlines the applicable state law sets — as short as 30 days in some states — and will tell you what was involved and what to do about it. We will notify our business clients whenever their callers' information is affected, whether or not a law requires it.
State privacy laws
US state privacy laws apply to businesses at different sizes, and the thresholds differ from state to state. We monitor whether TextCatch has crossed any of them and will update this policy and add any further mechanisms a law requires as soon as we do. In the meantime, the rights above are offered to everyone in the United States as a matter of practice, not only where a statute compels it. If you are a California resident, this policy is also our notice at collection under California law, and the tables above are the categories, purposes and recipients it requires us to disclose.
Children
TextCatch is a business tool sold to contractors and used to answer calls to a business line. It is not directed to children, we do not knowingly collect personal information from anyone under 16, and nothing in the product asks for age. If you believe a child's information reached us, contact us and we will delete it.
Scope
This service operates within the United States only, and all data is stored and processed in the United States. If you're contacting us from outside the US, this service is not designed for or offered to you.
Changes to this policy
If we change how we handle personal information, we will update this page and change the date at the top. Material changes will be communicated to business clients directly.
Contact
Questions about this policy, or a request under it: book a call with us. Business clients can also open a support ticket from inside the dashboard.
This policy describes what the TextCatch system actually does — it was written against the running code, not from a template, and the retention section above reflects real current behavior rather than intended behavior. It is not legal advice, and a qualified privacy attorney should review it before TextCatch operates at significant scale.