Privacy Policy
Effective date: October 1, 2026 · Last updated: October 1, 2026
CoreMessage is operated by Kainotomes LLC, a messaging API relay platform accessible at coremessage.net. This Privacy Policy explains how we collect, use, share, retain, and protect personal information across our website, API services, and consumer-facing messaging programs (SMS, voice, and WhatsApp notification services), as well as our Google integration (Google Apps Script and Google accounts used for authentication or scheduling) and our Chrome extension, where applicable.
We build and operate this service for lawful, transparent purposes. If you are a developer integrating our API or a subscriber receiving reminder messages from a program that uses CoreMessage, this policy is your single reference for how personal and mobile data is handled. Questions or data-subject requests: privacy@coremessage.net.
1. Information We Collect
- Account information: name, email address, username, and password (stored as a salted hash) when you register for CoreMessage.
- API usage data: API keys, request logs, sender recipient identifiers (e.g., phone numbers), message content metadata, delivery status, and routing decisions, to the extent required to operate, bill, and audit the relay service.
- Mobile / SMS opt-in data: phone number, the specific consent you gave to receive automated messages (consent source, date, IP/device fingerprint where lawfully captured), and any opt-out election you later make (e.g., STOP replies).
- WhatsApp contact data: phone number or Meta phone number ID, message template IDs, message status, and conversation opt-in/opt-out state.
- Google-linked data: where you sign in with Google or connect a Google account / Apps Script, only the data needed for the stated purpose (typically account identification and basic profile details such as name and email). We do not store full Google Calendar, Drive, or Gmail content unless you explicitly grant that scope and use that integration.
- Technical data: IP address, user agent, browser version, referring page, and timestamps, for security, fraud prevention, and debugging.
2. How We Use Information
- To provide, operate, and secure the CoreMessage API relay service.
- To deliver automated transactional messages for which you gave explicit opt-in consent (meeting/reminder, billing, security alerts, service status).
- To prevent fraud, abuse, and policy-violating traffic, and to comply with carrier, telecom, and Meta attestation requirements.
- To process payments and send billing invoices.
- To debug errors and improve reliability; we do not use message content for advertising or product development without explicit consent and a separate disclosure.
3. SMS Consent, Opt-In / Opt-Out (A2P 10DLC / TCPA / CTIA)
We participate in the A2P 10DLC (Application-to-Person 10-digit long code) registry and comply with CTIA Principles and carrier requirements. We send SMS/multi-service (MMS/RCS) messages to U.S. mobile numbers only where:
- You (or the consumer end-recipient, where an operator uses our relay) gave express prior opt-in consent that was captured at the point of collection; and
- The first message includes the brand name, a plain-language description of the message type and frequency, a reminder that standard message/data rates may apply, and clear STOP/HELP instructions; and
- Every subsequent message from a shared sender identifies the brand clearly.
Opting out (STOP): Reply STOP to any marketing/promotional SMS to unsubscribe immediately.
An automated confirmation confirms your choice. You may also reply HELP or email
privacy@coremessage.net to request help or a written opt-out confirmation.
Opt-out elections are honored across all CoreMessage programs associated with your number and are not
used for any marketing purpose.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Consent is not a condition of purchase or of receiving any product or service. Where a consumer-facing program we power collects a phone number, that program must separately disclose: the brand, the program purpose, expected message frequency, that standard message/data rates may apply, the STOP / HELP instructions, and links to this Privacy Policy and that program's Terms of Service.
4. WhatsApp (Meta) Business Messaging
- We use the WhatsApp Business Platform (Meta) only to deliver template-based, consent-driven messages.
- Message templates are submitted and approved per Meta policy; we do not send free-form marketing at scale without explicit opt-in.
- WhatsApp opt-in: you receive a message and are told the brand, purpose, and how to opt out. WhatsApp opt-out: reply
STOPwhere supported or contact privacy@coremessage.net. For Meta-managed opt-in, you may also use the "Unsubscribe" feature in the WhatsApp conversation. - We do not transfer WhatsApp message content to third parties except (a) where Meta's terms and applicable law require it, (b) to a consumer-facing brand operator you contracted with, or (c) for legitimate security/legal obligations — and even then, no marketing use by the recipient.
5. Google (Apps Script, OAuth, Chrome Web Store)
5.1 Google API & OAuth — Limited Use
Where we use Google APIs (including Google Apps Script, Calendar, Contacts, or sign-in via Google), we comply with the Google API Services User Data Policy and Google's Limited Use conditions:
- User data received through Google APIs is used only to provide the requested functionality and is not used to build user profiles for advertising, is not used for cross-context personalization, and is not shared with third parties for advertising.
- OAuth access tokens are stored encrypted at rest (at minimum, hashed where possible), are not logged, and are scoped to the minimum necessary permissions.
- You may revoke access at any time via Google account → Security → Third-party apps and site access. Upon revocation or account deactivation, we stop making API calls that depend on that token and delete or purge cached Google data per our retention schedule.
5.2 Chrome Web Store extension
- We declare every requested permission in our Chrome Web Store listing and use each only for the stated purpose (for example, to read a meeting link from an active tab so it can be used for scheduling). We do not use broader permissions (e.g.,
unlimitedStorage,tabs) than are required, and we do not use them to build behavioral or advertising profiles. - The extension does not sell, rent, or transfer user data to third parties, and it does not combine user data with third-party data for advertising.
- If you remove or revoke permissions, we treat that as a data-subject request and stop processing accordingly.
6. Sharing
- No sale of personal information. We do not sell, rent, or lease personal information, and we do not disclose opt-in consent data for any marketing purpose, as required by CTIA carrier attestation and the statements in §3.
- We disclose only where: (a) you consent, (b) we are required by law or by a binding regulator/court/carrier order, (c) to protect safety, prevent fraud or abuse, or enforce the terms of a program, or (d) to a consumer-facing brand operator you contracted with — and even then, only the data needed to serve you and only in a way consistent with §3.
- We use messaging carriers (e.g., Twilio and its carrier partners), payment processors, and cloud infrastructure providers as service providers. Each has a written agreement requiring them to process data under our instructions and to enforce the same no-marketing-share commitments that apply to us.
7. Data Retention & Deletion
- Message logs: retained up to 30 days from delivery (or until you request deletion, whichever is earlier).
- Account data: deleted within 30 days of your account-deletion request, except where we must retain records for tax, billing, or legal reasons.
- OAuth tokens / cached Google data: purged immediately upon revocation or when the integration is no longer used.
- Consumer opt-out elections: we do not delete these records, because they are necessary to prove compliance and honor your choice going forward.
8. Security
We use TLS 1.2+ in transit, AES-256 (or equivalent) at rest, and a layered access model (role-based access, least privilege, audit logging). Secrets such as API keys and OAuth tokens are encrypted at rest. Human access to consumer PII and message content is limited, logged, and monitored. We conduct periodic internal review and respond to credible vulnerability reports through privacy@coremessage.net.
9. International Transfers
Personal information is processed in Texas, United States and may be transferred to other countries for hosting, billing, or message delivery. Where required, we rely on the applicable legal transfer mechanism (for example, the EU-U.S. Data Privacy Framework where applicable) and contractual safeguards.
10. Your Rights
Depending on where you live (and consistent with GDPR/ePrivacy, CCPA/CPRA, TCPA, A2P 10DLC, and other applicable laws), you may request to access, correct, delete, export, or restrict use of your personal data, and you may withdraw consent. Email privacy@coremessage.net from the account address you used to register. We will confirm receipt within 10 business days and respond within 45 days, or the deadline required by your local law if earlier.
11. Children
Our services are not directed to children younger than 16, and we do not knowingly collect personal information from minors. If you believe a child has provided personal information, contact privacy@coremessage.net so we can investigate and delete it.
12. Changes to This Policy
If we make material changes to how we handle personal information, we will update this page and, where appropriate, notify you by email. Continued use after a material change constitutes acceptance; for SMS/WhatsApp opt-in consent, we will not broaden the scope of your existing consent without a new, explicit opt-in.
Contact / Regulatory inquiries
Email: privacy@coremessage.net
Mailing address: 6843 Bears Path Ln, Missouri City, TX 77459-3572, United States
Registered entity: Kainotomes LLC, formed/registered in Texas, United States.
Website: https://coremessage.net
Phone support: CoreMessage does not publish a phone number. For urgent delivery issues or
other time-sensitive requests, use the electronic contact above or open a ticket via the
CoreMessage support portal at coremessage.net.