1. Who we are
Y3 Labs LLC is a South Carolina limited liability company doing business as AgentMessage. Throughout this policy “AgentMessage”, “we”, “us”, and “our” mean Y3 Labs LLC. AgentMessage is the product and service name of Y3 Labs LLC; references to AgentMessage in this policy are references to Y3 Labs LLC acting under that brand.
The marketing site for AgentMessage is at agentmessage.io. The API, email, and webhook surfaces are served from agentmsg.io. This Privacy Policy applies to both domains and to every customer-facing surface AgentMessage operates.
When this Privacy Policy says “you”, it means the individual or organization using AgentMessage. When it says “recipient”, it means an end user who receives a message your AgentMessage account sent.
2. Information we collect
We may collect the following categories of information in connection with the Service:
- Account and organization information: business name, organization identifier, billing contact, organization address, plan and tier selection.
- User information: email address, name, profile image URL, role within an organization, identifier assigned by our authentication provider.
- Billing and payment metadata: Stripe customer and subscription identifiers, plan and usage line items, invoice records. Payment instruments themselves are handled directly by Stripe under their own terms.
- Phone numbers: the numbers assigned to your AgentMessage account, the customer webhook URLs you configure for inbound and delivery-receipt routing, and carrier metadata associated with each number.
- Recipient phone numbers: the numbers your account sends messages to, in E.164 format.
- Message content (bodies and media): the body text and any media URLs associated with messages your account sends or receives.
- Message metadata: sender, recipient, channel (SMS or MMS), segment count, status, error code and error message where applicable, timestamps for each lifecycle event, and the carrier-assigned message identifier.
- Delivery records: per-message delivery receipts and the carrier responses associated with them.
- Webhook data and carrier records: payloads we receive from upstream providers and the outbound webhook deliveries we send to your endpoints, including per-attempt status and timing.
- Consent records, opt-out records, and suppression records: per-recipient evidence of consent including source, timestamp, and any subsequent opt-out or re-subscribe events; the audit history of each consent record; and suppression entries that prevent further messaging to opted-out recipients.
- Abuse-review and compliance data: metadata about messages, accounts, and campaigns that we review for policy compliance, including review outcomes, reviewer notes, and related context.
- Support communications: the contents of your support requests and our responses.
- API logs and authentication logs: request paths, response status codes, request identifiers, timing, and authentication events.
- Device, browser, and usage data: IP address, user agent, referrer, and similar technical information collected when you use the website or the dashboard.
3. How we use the information
We use the information described above to provide, secure, monitor, support, and improve the Service. Specifically:
- Authenticate API and dashboard requests and prevent fraud and abuse.
- Provision phone numbers, register brands and campaigns, coordinate with upstream providers and carriers, and route messages on your behalf.
- Maintain consent records, opt-out records, and suppression lists, and enforce them at the API layer.
- Bill you for the Service through Stripe and collect amounts owed.
- Investigate incidents, troubleshoot delivery, respond to support requests, and handle disputes.
- Detect and respond to suspected abuse or compliance violations through automated and manual review.
- Comply with applicable law, carrier rules, and the requirements of our upstream providers.
- Improve the Service through aggregated analysis and product research.
3.1 Message bodies and media
Message bodies and media are processed to provide the Service: to route messages, display history, support customer workflows, detect abuse, troubleshoot delivery, comply with carrier requirements, and enforce our policies. Message body content is retained on our systems for the applicable retention window described in Section 6 and is redacted from primary storage when that window elapses.
3.2 AI-assisted compliance and abuse review
We may use third-party AI providers to assist with abuse detection, compliance review, message classification, account-risk review, and policy enforcement. AI review is part of how AgentMessage operates the Service rather than an optional analytics feature.
We do not intentionally send recipient phone numbers to AI providers for these purposes. However, message content submitted for review may contain personal information if that information appears in the message body. AI review is generally limited to messages, accounts, or campaigns that have been flagged by automated signals, customer reports, carrier feedback, or human review, rather than every message by default.
We do not authorize AI providers to use Customer Data to train their general models. Where the relevant provider tier offers it, we configure providers to minimize retention and disable training. Because abuse and compliance review is part of the Service, customers may not disable all compliance-related processing or all AI-related subprocessors. Customers who require strict data-flow controls beyond those offered by the Service should reach out before using the Service to discuss whether AgentMessage is a fit.
We do not sell your personal information. We do not share your personal information with third parties for advertising purposes. We do not use the contents of your messages or account data to train any AI model that we make generally available outside the Service.
3.3 Marketing inquiries from agentmessage.io
When you submit a form on agentmessage.io (for example, an early-access request, a contact form, a demo request, or a newsletter signup), we collect the information you provide. Typical fields are name, business email, phone number (if you choose to provide one), company, and any free-text message. We use that information to:
- Respond to your inquiry by email and, where you have opted in to SMS, by text message.
- Schedule walkthroughs, demos, and onboarding conversations you have asked for.
- Send occasional product updates that are relevant to the inquiry you submitted.
SMS contact from us is opt-in. We will only send you a text from AgentMessage if the form you submitted included a clearly labeled, separately checked consent box that disclosed Y3 Labs LLC, doing business as AgentMessage, as the sender, the types of messages, the expected frequency, that message and data rates may apply, and that you can reply STOP at any time to opt out. Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Email outreach includes a one-click unsubscribe link.
When AgentMessage sends these messages, AgentMessage is acting as the sender and is using its own platform. The same Messaging Policy and Carrier Compliance Notice that govern customer traffic apply to our own marketing traffic. The full consumer-facing terms for SMS sent by AgentMessage, including brand, message types, frequency, HELP, and STOP, are at SMS Terms & Conditions. To opt out of further SMS outreach, reply STOP to a message we sent you. To opt out of further email outreach, use the unsubscribe link in any email we sent you, or contact privacy@agentmessage.io.
4. Legal basis for processing
Where the law of your jurisdiction requires us to identify a legal basis for processing personal information, we rely on the following bases as applicable: (a) performance of a contract with you (operating the Service for you); (b) our legitimate interests (preventing abuse, protecting our systems and other customers, maintaining records of business activity, and improving the Service); (c) compliance with a legal obligation (responding to lawful requests, retaining records required by law); and (d) consent (where the law requires it for a particular use). You may withdraw consent for processing that is based on consent at any time without affecting prior processing.
5. How we share information
We disclose personal information to subprocessors and service providers that help us provide hosting, authentication, billing, payment processing, messaging delivery, carrier registration, AI-assisted compliance review, logging, support, security, and infrastructure services. The current list of subprocessors is published at /legal/subprocessors. We require each subprocessor to handle personal information consistent with this Privacy Policy and our Data Processing Addendum.
We may also disclose personal information:
- To carriers, registries (including The Campaign Registry), aggregators, and upstream providers as required to originate, register, route, and deliver messages and to meet carrier compliance requirements.
- To regulators, law enforcement, courts, and other authorities in response to a valid legal process, to comply with applicable law, to enforce our terms, or to protect the rights, property, and safety of AgentMessage, our customers, or the public.
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of the assets of Y3 Labs LLC, in which case the successor entity will be bound by terms no less protective than this Privacy Policy.
- With your direction or consent.
6. How long we retain information
We retain personal information for as long as needed to provide the Service, comply with our legal and regulatory obligations, and operate our business. The default retention periods are:
- Message bodies and media are redacted after 90 days by default, unless a different retention period is configured for the customer or required by law, regulation, carrier rule, or signed agreement.
- Message metadata (sender, recipient, status, timestamps, segment count, identifiers) may be retained for up to one year for billing, audit, and troubleshooting.
- Consent records may be retained for as long as reasonably necessary to evidence consent, comply with law, respond to disputes, satisfy carrier requirements, prevent abuse, and enforce our policies.
- Opt-out and suppression records may be retained indefinitely or as long as necessary to honor opt-out obligations.
- Billing, tax, payment, and financial records may be retained for seven years or as otherwise required by law.
- API keys are stored as cryptographic hashes (not plaintext) and are deleted or revoked when no longer needed or upon account deletion, subject to security and backup processes.
- Account records may be deleted from our authentication provider after account or organization deletion, although internal references, logs, billing records, consent records, suppression records, and compliance records may be retained as described above.
- Backups. Where we maintain backups of customer data, those backups are retained only as long as reasonably necessary for continuity and recovery and are then overwritten or deleted in the ordinary course. Information described above may persist in a backup for a limited period after it is deleted from primary storage.
7. Your choices and rights
Depending on where you are located, you may have rights over your personal information, including the right to access, correct, delete, restrict, port, or object to certain uses. AgentMessage offers the following built-in mechanisms:
- Erase a contact. Where legally and operationally permitted, you may use the contact-erasure surface in the dashboard or API to delete or redact message content and certain recipient records associated with a specific recipient phone number in your account. We may retain consent records, opt-out records, suppression records, billing records, security logs, and compliance records as necessary to comply with law, honor opt-outs, prevent abuse, resolve disputes, or satisfy carrier requirements.
- Configure retention. You may configure your message-body retention window between 30 and 365 days from the dashboard, subject to your plan and any regulatory minimums that apply to you.
- Rotate API keys and webhook secrets. Available from the dashboard at any time.
- Export your data. Contact privacy@agentmessage.io and we will work with you on a structured export of the data associated with your account.
- Close your account. Contact privacy@agentmessage.io or your account team. We will terminate the account in accordance with the Terms of Service and retain only the minimum records required by law and the retention periods listed above.
If you are a recipient of messages sent through AgentMessage and want to exercise rights over your data, please contact the AgentMessage customer that sent the messages. AgentMessage processes recipient data on behalf of our customers under their instructions. If you cannot reach the customer, contact privacy@agentmessage.io and we will assist as a processor where we are able.
8. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, encryption at rest, tenant-scoped access controls, access logging, restricted administrative access, and monitoring.
Customer data is logically segregated by organization using tenant-scoped access controls applied at every layer of the Service. AgentMessage does not provide dedicated single-tenant infrastructure unless expressly agreed in writing. We store API keys, webhook secrets, and similar credentials using security controls designed to prevent unauthorized access. Customers are responsible for protecting their own API keys and credentials.
No system is perfectly secure, and we will notify affected customers in the event of a security incident that materially affects their data, in accordance with applicable law and the terms of any signed Data Processing Addendum.
Security certifications. AgentMessage has not completed a SOC 2 examination as of the effective date of this Privacy Policy. We may pursue security certifications or third-party assessments in the future.
9. International transfers
The Service is currently offered to customers in the United States only. We do not currently solicit or onboard customers in the European Economic Area, the United Kingdom, or Switzerland. The provisions below apply in the event a non-United States customer accesses the Service.
AgentMessage is operated from the United States and our infrastructure and subprocessors are primarily located in the United States. If you access the Service from another jurisdiction, your information will be transferred to and processed in the United States. We rely on standard contractual clauses with our subprocessors where applicable. The Data Processing Addendum describes the transfer mechanisms in more detail.
10. Children's data
AgentMessage is not directed to children. The Service is intended for businesses and professional users. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe we have collected information from a child, please contact privacy@agentmessage.io and we will delete it.
11. Customer responsibility for end-recipient information
When you use AgentMessage to send messages to recipients, you are responsible for ensuring that you have the appropriate legal basis to do so, that you have obtained and retained valid consent where required, and that the content of your messages complies with the Messaging Policy. Your use of recipient information through the Service is also subject to the Data Processing Addendum when one applies to you.
12. Cookies and similar technologies
The AgentMessage marketing site and dashboard use a small number of cookies and browser storage. We do not run cross-site tracking, advertising cookies, retargeting pixels, or behavioral-advertising tags. We do measure aggregate site traffic with Google Analytics 4 in measurement-only mode (Google Signals disabled, no advertising-audience export).
Strictly necessary cookies (always on).
- Session and authentication cookies (Clerk). Issued by our authentication provider Clerk to keep you signed in to the dashboard, identify the active organization, and protect the session. These are strictly necessary for the dashboard to function.
- CSRF cookies. Issued by the dashboard and the API to protect against cross-site request forgery on state-changing requests.
- Browser storage for UI preferences. Local storage holds non-sensitive user preferences, such as a partially-completed onboarding draft.
First-party analytics cookies (marketing site only).
- Google Analytics 4 (
_ga,_ga_*).First-party cookies set on agentmessage.io to measure aggregated traffic patterns: page views, sessions, country and region, device type, and referrer source. Google acts as our analytics service provider under Google's Data Processing Terms. We have not enabled Google Signals, ads-personalization features, audience export to Google Ads, or any cross-site identity stitching.
Third-party flows you trigger.
- Stripe checkout.When you enter the Stripe-hosted checkout, billing portal, or payment instrument capture flow, Stripe sets its own cookies under stripe.com to operate that flow and detect fraud. Those cookies are governed by Stripe's privacy notice.
We do not currently display a cookie consent banner. Our cookie use is limited to cookies strictly necessary for the Service to function and first-party site analytics in measurement-only mode. This configuration does not constitute the “sale” or “sharing” of personal information under the CCPA / CPRA. If we ever add cross-site tracking, advertising tags, or behavioral-advertising cookies, we will update this section and provide an opt-out mechanism before doing so.
13. Changes to this Privacy Policy
We may update this Privacy Policy as the Service evolves. When we make a material change we will update the “Last updated” and “Effective date” values at the top of the page and notify the billing contact on file by email. We aim to provide reasonable advance notice, but, while AgentMessage is in startup mode, we may apply changes with as little as 24 hours' notice. Changes required by law or to address a security or compliance issue may take effect immediately. Continued use of the Service after a change becomes effective constitutes acceptance of the updated policy.
14. California privacy rights
This section supplements the rest of this Privacy Policy for California residents whose Personal Information is processed by AgentMessage under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA / CPRA”). Terms such as “Personal Information”, “sell”, and “share” have the meanings given in the CCPA / CPRA.
Categories of Personal Information collected. In the prior 12 months, we collected the categories of Personal Information described in Section 2 of this Privacy Policy.
Categories of sources.We collect Personal Information from (a) the customer; (b) the customer's recipients (for example, inbound message content and opt-out signals); (c) automated technical signals (request metadata, authentication events); and (d) our subprocessors (carrier and registry responses, billing identifiers, authentication identifiers).
Business purposes for collection. We collect and use Personal Information for the business purposes described in Section 3 of this Privacy Policy.
Categories of third parties to whom information is disclosed. We disclose Personal Information to the categories of recipients described in Section 5 of this Privacy Policy and the subprocessors listed at /legal/subprocessors.
No sale or sharing. We do not sell Personal Information and we do not share Personal Information for cross-context behavioral advertising as those terms are defined under the CCPA / CPRA. We do not knowingly collect or process the Personal Information of consumers under 16 for purposes of selling or sharing.
Your rights. Subject to verification and applicable exceptions, California residents have the right to:
- Know. Request the categories and specific pieces of Personal Information we have collected about you.
- Delete. Request deletion of Personal Information we have collected from you.
- Correct. Request correction of inaccurate Personal Information we maintain about you.
- Opt out of sale or sharing. We do not sell or share Personal Information; this right is stated for completeness.
- Limit use of sensitive Personal Information. Direct us to limit the use and disclosure of sensitive Personal Information to purposes specified by the CCPA / CPRA.
- Non-discrimination. Exercise any of the above without receiving discriminatory treatment.
How to submit a request. Email privacy@agentmessage.io with the subject line “California privacy request” and the right you want to exercise. Account-holders may also submit a request from the account they are signed in to.
Authorized agents.You may designate an authorized agent to make a request on your behalf. We will require (a) the agent's written authorization signed by you, (b) verification of the agent's identity, and (c) verification of your identity directly with us before honoring the request.
Verification. We verify requests by matching the information you provide against information already in our records, which may include the email address associated with your account, the organization identifier, and other non-sensitive information that corresponds to the relationship you have with us. For requests that involve sensitive categories of Personal Information, we may require additional verification.
Recipients. If you are a recipient of messages sent through AgentMessage and want to exercise California rights, please contact the AgentMessage customer that sent the messages. AgentMessage processes recipient data on behalf of our customers under their instructions. If you cannot reach the customer, contact privacy@agentmessage.io and we will assist as a service provider where we are able.
15. Contact us
For privacy questions, data requests, or to report a concern, contact privacy@agentmessage.io. For abuse reports, contact abuse@agentmessage.io. For other legal notices, contact legal@agentmessage.io.
Y3 Labs LLC845 Houston Northcutt Blvd #1079
Mt Pleasant, SC 29464
United States
Attn: Legal
legal@agentmessage.io