Privacy Policy
Last updated: 7/16/2026
Stockman Digital LLC (“Stockman Digital,” “we,” “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard Personal Information when you:
- visit automessage.app (the “Website”);
- create an autoMessage account or purchase a subscription; or
- install and use our iOS/macOS device agent or related APIs (the “Service”).
This Policy does not apply to the content of the messages you draft or send through Apple Messages — those remain on your own device and are never stored on our servers.
1 — Who We Are
Controller for Account Data
Stockman Digital LLC
privacy@automessage.app
For EU/UK customers we act as “controller” of your account and billing data. For “Customer Traffic” (message content and recipient numbers) we act as “processor” under GDPR and “service provider” under CPRA, processing solely on your instructions.
2 — Information We Collect
| Category | Examples | Source | Typical Purpose |
|---|---|---|---|
| Account Info | Name, email, username, hashed password | You | Create & administer account |
| Subscription & Billing | Billing address, last-4 of payment card, Stripe® transaction IDs | You / Payment processor | Process payments, detect fraud |
| Device & Usage Logs (minimal) | Device model, OS version, IP address, timestamps, API events (success/failure codes only — no message bodies or recipient numbers) | Your device / Service | Debugging, service integrity, analytics |
| Website Analytics (cookies) | Page views, referrer URL, coarse location (city level) | Browser | Improve website, marketing attribution |
| Support Records | Emails, chat transcripts | You | Respond to enquiries |
We do not collect: message bodies, recipient phone numbers, or iCloud backup of your conversations.
3 — How We Use Personal Information
- Provide, bill for and maintain the Service
- Monitor service reliability and prevent abuse (e.g., spam/junk-report spikes)
- Respond to support requests
- Send transactional notices (e.g., receipts, critical updates)
- Conduct aggregate, de-identified analytics to improve features
- Comply with legal obligations (tax, accounting, fraud prevention)
4 — Legal Bases (GDPR / UK GDPR)
- Contract performance — to create your account and deliver the Service
- Legitimate interests — to secure and improve the Service, fight fraud
- Legal obligation — to satisfy tax or regulatory requirements
- Consent — for non-essential cookies or marketing e-mails (you may withdraw any time)
5 — Disclosure & “No Sale” Statement
We share Personal Information only with:
- Payment processor (e.g., Stripe) for secure card handling
- Infrastructure vendors (ISO-27001 cloud providers, log aggregation) under strict confidentiality terms
- Professional advisers (lawyers, accountants) under NDAs
- Authorities when legally compelled (court order, lawful subpoena)
We do not sell or “share” Personal Information for cross-context behavioural advertising as those terms are defined by the CPRA.
6 — Cookies & Similar Tech
Essential cookies keep you signed in; analytics cookies(e.g., Plausible® or Google Analytics 4) help us understand traffic in an aggregated form. You can disable non-essential cookies via the banner or your browser settings.
7 — International Transfers
We host data in the United States. For EU/UK users we rely on theEU Standard Contractual Clauses (2021 modules) and UK Addendum to safeguard transfers.
8 — Data Retention
| Data Type | Standard Retention | Rationale |
|---|---|---|
| Account & Billing | While account is active + 6 years | Tax & audit |
| Device & Usage Logs | 90 days | Debugging & abuse detection |
| Support Tickets | 2 years | Service-quality tracking |
Upon account deletion we pseudonymise or purge data unless retention is mandated by law.
9 — Security Measures
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest for databases and log storage
- Role-based access control, annual penetration testing, least-privilege keys
- Stripe handles full card data — Stockman Digital never stores raw payment credentials
Despite safeguards, no online service is 100% secure; you are responsible for protecting the secrecy of your own passwords and Apple-device passcodes.
10 — Your Privacy Rights
California (CPRA). You may request: (i) access to personal info we hold; (ii) deletion; (iii) correction; (iv) portability. We do not sell/share data, so opt-out is not applicable.
EU/UK (GDPR). In addition to access, erasure, and portability, you may object to processing based on legitimate interests or ask us to restrict processing. You also have the right to complain to your local data-protection authority.
To exercise any right, e-mail us at privacy@automessage.app. We will verify your identity and respond within the statutory timeframe (30 days EU/UK; 45 days CA).
11 — Children
autoMessage is not directed to children under 13. We do not knowingly collect Personal Information from anyone under that age. If you believe a child provided us data, contact privacy@automessage.app and we will delete it.
12 — Changes to This Policy
We may update this Policy. Material changes will be announced via e-mail or in-app notice at least 30 days before they take effect. Continued use after that date constitutes acceptance.
13 — Contact Us
Questions about privacy?
E-mail: privacy@automessage.app