01What is collected, and for how long
| data | why | kept |
|---|---|---|
| The destination (an email address, a phone number, or a URL) and the message content | To deliver the message and retry if the other side is down | Until the delivery is final, then deleted. In practice seconds to a few hours. |
A masked destination (j***@example.com, +1***45), a hash of the destination, a hash of the content, and the delivery status | So the sender can ask what happened, and so caps can be counted | 7 days |
| A hash of any destination that opted out, bounced, or complained | So the opt-out can be honored forever, for every sender | Indefinitely. The address itself is not kept, only the hash. |
| A hash of any phone number that opted in by text, and the id of the message that granted it | So we can show, if asked, that the person consented | Until they opt out |
| Daily counts of requests per route, and truncated user agent strings | To tell whether the service is being used | 90 days |
Payment happens on a public blockchain by the nature of the x402 protocol, so paying wallet addresses are visible on chain whatever we do. We keep no ledger of who paid beyond what the chain already shows.
02What is never done
- Message content is never read for meaning, scored, profiled, or used to train anything.
- Nothing is sold, rented, or shared for advertising. There is no advertising.
- No cookies are set, no analytics or tracking scripts run, and these pages ship no JavaScript at all.
- No mailing list exists. A destination cannot be added by anyone except the sender who pays to reach it, and for SMS, not even then without the recipient's own opt-in.
03Who else handles a message
Delivery needs carriers. An email passes through our email provider, and a text through our SMS carrier, each under their own terms and each holding the message for their own retention period. A webhook goes directly from our server to the URL the sender named, with nobody in between. We choose providers that are established transactional senders rather than marketing platforms.
04Your choices
If you received something: reply STOP to a text, or use the unsubscribe link in the footer of an email. Either stops every agent that uses this relay, permanently and immediately. See received a message? and how SMS opt-in works.
You can also write to contact@vimabrosta.com to be blocked by hand, to ask what is held about a destination, or to have it deleted. We answer from the operator's address and do not ask why. Because opt-outs are stored as hashes with no reversible copy of the address, a deletion request on a suppression is one we will decline: removing it would let you be messaged again, which is the opposite of what it exists for.
05Changes and contact
This policy may change; the effective date above moves when it does, and the changelog records it. Questions go to contact@vimabrosta.com. Operated by Vima Brosta LLC. The terms of service are at /terms.