Effective Date: June 21, 2026
This Privacy Policy explains how AquiferDAO LLC, a Republic of the Marshall Islands limited liability company doing business as TextTree.ai (“TextTree,” “we,” “us,” or “our”), collects, accesses, uses, monitors, analyzes, retains, discloses, and otherwise processes information through TextTree.
This Policy applies to texttree.ai, app.texttree.ai, api.texttree.ai, TextTree APIs, MCP endpoints, dashboards, phone numbers, SMS services, webhooks, applications, and related services.
1. Important Notice: TextTree Is Not a Private Communications Vault
TextTree is not a private vault, confidential communications service, or end-to-end confidentiality provider.
TextTree and the providers used to operate the Service can process message content, recipient information, phone numbers, traffic, routing information, logs, account information, and metadata.
Except where applicable law or a separate written agreement requires otherwise:
- You should not expect information transmitted through TextTree to be confidential from TextTree;
- We may access, inspect, monitor, copy, store, classify, analyze, route, disclose, and otherwise process Service data and traffic;
- Authorized personnel and contractors may review data for support, security, abuse prevention, billing, compliance, product development, or legal purposes; and
- You should not submit information you are not legally authorized to disclose.
Do not use TextTree to transmit trade secrets, legally privileged information, highly sensitive personal information, protected health information, payment-card data, government identification numbers, or other regulated information unless TextTree has expressly agreed in writing to process that information.
2. Information We Collect
Account and identity information
We may collect:
- Name;
- Email address;
- Username;
- Password hash;
- Authentication records;
- Account identifiers;
- Backup-code and token records;
- Organization and workspace information;
- Job role;
- Permissions and scopes;
- Business name;
- Business website;
- Selected use case;
- Wallet address;
- External identity-provider identifiers; and
- Account status.
Contact and recipient information
We may collect:
- Telephone numbers;
- Email addresses;
- Names;
- First and last names;
- Time zones;
- Contact-list membership;
- Tags;
- Custom fields;
- Template variables;
- Consent records;
- Consent sources;
- Opt-in and opt-out dates;
- Suppression records; and
- Other recipient information submitted by customers.
Message and communications information
We may collect and process:
- Outbound message content;
- Inbound message content;
- Replies;
- Sender and recipient numbers;
- Message direction;
- Message status;
- Delivery events;
- Timestamps;
- Message segments;
- Provider identifiers;
- Message metadata;
- Conversation history;
- Campaign information;
- Templates and snippets;
- Webhook payloads;
- Webhook destinations;
- Notes and handoff status;
- Attachments where supported; and
- Failure, filtering, and blocking reasons.
Usage, traffic, and technical information
We may collect:
- IP addresses or hashed representations of IP addresses;
- Device information;
- Browser information;
- Operating system;
- Referring URL;
- Page URL and page path;
- Clicks and interaction events;
- API requests;
- MCP requests;
- Endpoint usage;
- Authentication attempts;
- Access times;
- Request identifiers;
- Error reports;
- Performance measurements;
- Rate-limit information;
- Network information;
- Traffic patterns;
- Security events;
- Fraud and abuse signals;
- Provider events; and
- System logs.
Billing and transaction information
We may collect:
- Subscription plan;
- Billing status;
- Prepaid balance;
- Usage records;
- Spend limits;
- Ledger entries;
- Invoices;
- Payment status;
- Transaction identifiers;
- Checkout-session identifiers;
- Payment-provider customer identifiers;
- Refund and chargeback information;
- Tax information;
- Wallet addresses;
- Transaction hashes;
- Cryptocurrency or stablecoin payment details; and
- Information received from payment processors or merchants of record.
Payment-card details are generally collected directly by the applicable payment provider rather than stored by TextTree.
Information from other parties
We may receive information from:
- TextTree customers;
- Message recipients;
- Telecommunications carriers;
- Messaging providers;
- Payment processors;
- Merchants of record;
- Hosting and infrastructure providers;
- Authentication providers;
- Email providers;
- Analytics providers;
- Wallet and blockchain providers;
- Fraud-prevention providers;
- Regulators;
- Law-enforcement authorities; and
- Public sources.
3. How We Use Information
We may use information to:
- Create and maintain accounts;
- Authenticate users and agents;
- Provide APIs, MCP tools, dashboards, and integrations;
- Send, receive, route, queue, filter, and process messages;
- Provision and manage phone numbers;
- Deliver inbound messages and webhooks;
- Maintain contacts, campaigns, conversations, and suppressions;
- Calculate fees, usage, balance, and taxes;
- Process transactions;
- Provide receipts and account notices;
- Respond to technical and billing requests;
- Detect spam, fraud, abuse, security incidents, and unauthorized activity;
- Enforce limits and policies;
- Investigate complaints and opt-out requests;
- Comply with laws, legal process, carrier requirements, and payment-provider requirements;
- Register and manage sender identities;
- Debug, test, maintain, and improve the Service;
- Develop new products and features;
- Analyze traffic, performance, reliability, usage, and customer behavior;
- Create aggregated, de-identified, statistical, and derived data;
- Train, test, evaluate, and improve automated systems, classification systems, abuse-detection systems, and machine-learning features where permitted by law;
- Communicate about products, features, security, billing, and policy changes;
- Market TextTree products where permitted;
- Protect TextTree, its providers, customers, recipients, and the public;
- Establish, exercise, or defend legal claims; and
- Complete a financing, merger, acquisition, reorganization, or sale.
4. Customer Content License and Platform Data
Privacy rights are governed by applicable law and are not eliminated merely because information is transmitted through TextTree.
However, by using the Service, customers grant TextTree the rights described in the Terms and Conditions to process Customer Content and traffic.
As between TextTree and its customers:
- Customers retain any ownership rights they already have in Customer Content;
- TextTree owns the Service, Platform Data, traffic analytics, logs, usage records, telemetry, security signals, aggregated data, de-identified data, derived data, classifications, models, and product improvements; and
- TextTree may use and commercialize aggregated, de-identified, statistical, and derived information for any lawful purpose.
We may retain derived, aggregated, or de-identified information after the underlying account or Customer Content has been deleted.
5. Legal Bases for Processing
Where applicable law requires a legal basis, we may process personal information based on:
- Performance of a contract;
- Steps taken at a person’s request before entering a contract;
- Our legitimate interests in operating, securing, improving, and protecting the Service;
- Compliance with legal obligations;
- Protection of rights and safety;
- Consent; and
- Any other basis permitted by applicable law.
Where we rely on legitimate interests, those interests may include fraud prevention, network security, service improvement, customer support, billing, enforcement, business analytics, and preventing misuse of communications infrastructure.
6. How We Disclose Information
We may disclose information to:
Service providers
We may use vendors for hosting, databases, telecommunications, messaging, phone numbers, email, authentication, monitoring, analytics, payment processing, customer support, security, fraud detection, blockchain infrastructure, and other operational functions.
These providers may process Customer Content, traffic, account information, and technical data.
Telecommunications providers
Message content, sender and recipient numbers, routing information, and related metadata may be disclosed to telecommunications carriers, aggregators, number providers, registration providers, and other parties needed to process communications.
Payment providers and merchants of record
We may disclose account, transaction, subscription, tax, billing, usage, fraud, and customer information to payment processors and merchants of record, including Paddle or Stripe where applicable.
Those providers process information under their own privacy notices and legal obligations.
Customers and account administrators
Organization owners, administrators, employees, developers, agents, and authorized users may access information associated with their organization or workspace.
Recipients
Messages, sender information, branding, and other content may be disclosed to recipients and their carriers.
Legal and safety disclosures
We may disclose information when we believe it is reasonably necessary to:
- Comply with law, regulation, subpoena, warrant, court order, or legal process;
- Respond to a regulator, carrier, payment provider, or law-enforcement authority;
- Investigate fraud, abuse, spam, threats, or security incidents;
- Enforce our agreements;
- Protect rights, property, systems, safety, or the public;
- Recover amounts owed; or
- Establish, exercise, or defend legal claims.
Business transactions
We may disclose or transfer information as part of a merger, financing, acquisition, investment, reorganization, bankruptcy, sale of assets, or similar transaction.
Affiliates and successors
We may disclose information to affiliates, related entities, successors, and entities under common control.
7. Sale, Sharing, and Commercial Use of Data
Unless this Policy is updated and any legally required notice or choice is provided, TextTree does not sell personal information for money or share it for unrelated cross-context behavioral advertising.
TextTree may:
- Use information for its own product analytics and marketing;
- Disclose information to operational service providers and business partners;
- Use Platform Data for business purposes;
- Create aggregated, de-identified, statistical, and derived information; and
- License, sell, disclose, publish, or otherwise commercialize aggregated, de-identified, statistical, and derived information where lawful.
We may treat information as de-identified when we reasonably believe it cannot be used to identify an individual without additional information. We may commit not to attempt to re-identify such data except where needed to test de-identification, protect security, or comply with law.
8. Automated Systems and AI
Customers may use TextTree with automated software and AI agents.
We may use automated systems to:
- Route messages;
- Detect spam, fraud, abuse, and security risks;
- Apply suppressions and rate limits;
- Classify errors or traffic;
- Review account risk;
- Calculate usage;
- Prioritize investigations; and
- Improve product functionality.
Automated systems may block, delay, restrict, or flag activity.
Where permitted by law, data transmitted through the Service may be used to test, evaluate, train, or improve automated systems and product features. We may apply de-identification, minimization, contractual restrictions, or other safeguards where appropriate.
9. Cookies and Similar Technologies
We may use cookies, local storage, session identifiers, pixels, SDKs, logs, and similar technologies to:
- Maintain sessions;
- Authenticate users;
- Remember settings;
- Prevent fraud;
- Measure website and product usage;
- Understand referrals;
- Record product interactions; and
- Improve the Service.
Browser settings may allow you to block certain cookies, but doing so may prevent parts of the Service from functioning.
TextTree does not guarantee a response to browser “Do Not Track” signals unless required by law.
10. Data Retention
We retain information for as long as reasonably necessary to:
- Provide the Service;
- Maintain message and billing records;
- Support customers;
- Enforce agreements;
- Investigate abuse;
- Maintain security;
- Resolve disputes;
- Preserve evidence;
- Comply with telecommunications, tax, accounting, legal, and payment obligations; and
- Protect legitimate business interests.
Retention periods vary depending on the type of information, account status, legal requirements, provider systems, backup schedules, and operational needs.
Deleting an account may not immediately remove information from:
- Backups;
- Logs;
- Security records;
- Billing records;
- Provider systems;
- Legal archives;
- Suppression records;
- Fraud databases; or
- Aggregated, de-identified, or derived data.
We may retain suppression and opt-out information after account closure to prevent future unwanted messages.
11. Security
We may use technical and organizational safeguards designed to protect information.
No safeguard, network, database, telecommunications system, blockchain, or storage system is completely secure.
We do not guarantee that information will never be:
- Accessed;
- Disclosed;
- Modified;
- Lost;
- Corrupted;
- Intercepted; or
- Destroyed.
You are responsible for securing your devices, systems, credentials, webhooks, integrations, and copies of data.
12. International Processing
TextTree and its providers may process information in the United States, the Republic of the Marshall Islands, and other countries.
Those countries may have privacy and data-protection laws different from the laws where you live.
Where required, we may use contractual, organizational, or other recognized safeguards for international transfers.
By using the Service, you acknowledge that information may be transferred and processed internationally, subject to applicable law.
13. Your Responsibilities
Customers are responsible for:
- Providing recipients and users with legally required privacy notices;
- Establishing an appropriate legal basis for processing;
- Obtaining valid consent where required;
- Responding to recipient requests;
- Limiting information submitted to what is lawful and necessary;
- Configuring access appropriately;
- Maintaining independent records of consent and opt-outs; and
- Entering any required data-processing agreement with TextTree.
Customers must not instruct TextTree to process information unlawfully.
14. Message Recipients
TextTree generally processes recipient information on behalf of the customer that initiated or received a message.
Recipients should first contact the organization or sender identified in the message regarding:
- Consent;
- Message frequency;
- The purpose of a message;
- Access or deletion requests; and
- Opt-outs.
Recipients may reply with a supported opt-out keyword or contact the sender directly.
TextTree may retain and enforce suppression records even where other information is deleted.
15. Privacy Rights
Depending on your location, you may have rights to:
- Request access to personal information;
- Request correction;
- Request deletion;
- Obtain a portable copy;
- Restrict or object to processing;
- Withdraw consent;
- Opt out of certain marketing;
- Opt out of certain automated processing;
- Appeal a denied privacy request; and
- Complain to a privacy regulator.
These rights may be limited by law and may not apply to information we must retain for security, billing, legal, fraud-prevention, suppression, or contractual purposes.
We may verify your identity before responding.
Authorized agents may be required to provide proof of authority.
Requests may be submitted to privacy@texttree.ai.
16. Marketing Communications
We may send account, security, billing, product, onboarding, usage, service, and policy communications.
Some communications are transactional and cannot be opted out of while you maintain an account.
You may opt out of promotional emails using the unsubscribe mechanism provided or by contacting us. Opting out of marketing does not prevent operational or legal communications.
17. Children
The Service is not intended for anyone under 18.
We do not knowingly permit children to create accounts.
If you believe a child has provided information through the Service, contact privacy@texttree.ai.
18. Third-Party Services
The Service may link to or integrate with third-party websites, applications, wallets, carriers, payment providers, AI systems, or other services.
Their privacy practices are governed by their own policies.
TextTree is not responsible for third-party privacy, security, or data practices.
19. Changes to This Policy
We may update this Privacy Policy at any time.
The updated version becomes effective when posted or on the date stated in the updated Policy.
Where required by law, we will provide additional notice or request consent.
Continued use after the effective date constitutes acknowledgment of the updated Policy.
20. Contact
Privacy requests and questions may be directed to:
AquiferDAO LLC, doing business as TextTree.ai
Republic of the Marshall Islands
Privacy email: privacy@texttree.ai
Support email: support@texttree.ai
Website: https://texttree.ai