Skip to content

Your customer data deserves protection.

AutoCampaign helps businesses manage customer conversations, contacts, campaigns, and AI interactions — with security and privacy controls built into the platform.

  • Encrypted in transit and at rest
  • Role-based access
  • Consent and opt-out controls
  • Export and deletion controls

Security built into the way AutoCampaign works.

  • Data protection

    Your data is encrypted in transit and at rest, and every query is scoped to your organization.

  • Access control

    Decide what each team member can see and do, with per-action permissions and custom roles.

  • Messaging compliance

    Consent, opt-outs, and sending limits sit in the sending path — not on your staff’s checklist.

  • AI control

    You decide when an AI Employee drafts, sends, or hands the conversation back to a person.

Your data stays under your control.

Data in transit
Traffic between you and AutoCampaign is encrypted with TLS.
Data at rest
Your data is encrypted at rest. Messaging credentials, API tokens, and outbound notification secrets are encrypted with AES-256-GCM.
Access
Every request resolves to one organization, and every query is scoped to it. Access is role-based and logged.
Data control
Export, correct, and delete your data. Close your account and it is removed within 90 days.

Read our Privacy Policy

Give every team member the access they need — and nothing more.

Roles carry per-action permissions, so front-desk staff can answer texts without being able to export your contact database or touch billing. Build custom roles when the defaults do not fit your team.

Product preview: a roles and permissions matrix with fictional roles — Owner, Manager, and Front Desk — against generic permission names for answering the inbox, sending campaigns, exporting contacts, managing billing, and API keys. Owner holds every permission; Manager holds all but billing and API keys; Front Desk can answer the inbox only.

Built for responsible customer messaging.

Carriers, providers, and your customers all expect the same things of a business sender: provable consent, an opt-out that always works, and a registered sending identity. Each one is system behavior here, visible in the product.

Consent

Every contact carries a consent source from the moment it is created — the keyword they texted, the form they submitted, the import that brought them in. Consent records are kept permanently, so “where did this number come from?” always has a per-contact answer.

Opt-outs

STOP is processed first, ahead of every other feature, and mirrored to your messaging provider so platform and carrier agree. One check sits in front of every send — campaigns, sequences, automations, keyword replies, and inbox messages all pass through it. START is the only path back in.

Sending controls

Set sending limits per number, so no single number carries more volume than you want it to. Sender Pools spread sending across numbers you control. Automated sequences honor quiet hours.

A2P 10DLC

Brand and campaign registration runs inside the product, with status visible as it moves. You register your own brand; carriers control approval, timing, and fees.

Product preview: opt-out settings and a contact timeline side by side — the organization's stop keywords and auto-reply message on the left, and a contact record for fictional business "Harborlight Dental" at "(555) 014-2276" showing consent source, opt-in date, and an "Opted out — honored automatically" event on the right. All sample data fictional.

Consent and opt-out, recorded where you can point at them.

AutoCampaign provides tools and controls designed to help you manage compliant messaging. Following the laws and carrier requirements that apply to your business stays with you and your counsel.

AI works within the boundaries you set.

AI Employees draft replies from the business information you give them, not the open internet. Nothing sends until you approve it — until you switch on Autopilot, and that is a per-conversation choice, not a global switch. You can test-chat with an AI Employee before it ever talks to a real customer.

  1. Your business information
  2. AI Employee
  3. Draft
  4. Approve, edit, or Autopilot
  5. Customer

Hand-off rules bring a person into the conversation with a summary, and your team can take over at any time.

Product preview: an AI Employee draft reply waiting for approval, with Autopilot switched off and Approve and Edit controls. Nothing sends without approval. All sample data fictional.

We do not use your customer data to train AI models — ours or anyone else’s. Our AI providers process your data through APIs under terms that prohibit using it for training.

Your data is yours.

Export
Export your contacts anytime — your list leaves with you, complete.
Correct
Edit contact records directly, so customer information stays accurate.
Delete
Ask, and your data is removed. After you close your account, it is deleted within 90 days.
Access
Control who on your team can reach it, on API keys you can rotate and revoke.

A REST API and signed outbound notifications keep your own systems in sync, on credentials you control.

Read our Privacy Policy

How we protect the platform.

Infrastructure

AutoCampaign runs on Railway and Neon, hosted in the United States. Your information is processed there.

Authentication and access

Every request resolves to one organization, and every query is scoped to it. Roles carry per-action permissions. API keys are hashed, shown once at creation, and can be given an expiry or revoked at any time.

Data protection

Data is encrypted in transit with TLS and at rest. Messaging-provider credentials, API tokens, calendar tokens, and outbound notification secrets are encrypted with AES-256-GCM.

Monitoring and logging

Actions against your organization are recorded with the user or API key responsible, the resource touched, the IP address, and the time.

Backups and recovery

Backups are encrypted. Deleted data cycles out of them within approximately 35 days after deletion.

Incident response

No online service can promise perfect security. If a breach affects your personal information, we notify you without undue delay, as the law requires.

Service providers

We share data only with the providers that make the platform work, each limited to what its function requires: Stripe (payments), Twilio and Telnyx (SMS), Meta (WhatsApp), SendGrid (email), OpenAI (AI responses, no training on your data), Amazon Web Services (file storage), Railway and Neon (hosting and database), and Google and Cal.com for connected calendar, maps, and scheduling features. We do not sell personal information.

For your questionnaire, in one table

The question you’re askedWhat the product does
Can you prove consent per contact?Consent source mandatory at creation; consent records never deleted
What happens when someone texts STOP?Honored automatically, first in line, mirrored to the provider; one check in front of every send
Are you registered senders?Guided A2P 10DLC brand and campaign registration with in-product status
Who can access what?Granular roles and permissions; org-scoped data on every query
Are administrative actions logged?Yes — actor, resource, IP address, and timestamp, scoped to your organization
How do integrations authenticate?Org-scoped API keys — shown once, rotatable, revocable, audited; signed outbound notifications
What limits the damage from a mistake?Per-number sending limits, spend caps, cost estimates before send

Security FAQ

How is my customer data protected?

It is encrypted in transit with TLS and at rest, and every query is scoped to your organization. Access is role-based and logged, and messaging credentials and API tokens are encrypted with AES-256-GCM.

Where is my data stored?

In the United States. AutoCampaign runs on Railway and Neon, and your information is processed there. Our Privacy Policy lists every service provider that touches it.

Does AutoCampaign use my customer data to train AI models?

No — not for our models, and not for anyone else’s. Our AI providers process your data through APIs under terms that prohibit using it for training.

How do I request data deletion?

Delete data from your dashboard, or email support@autocampaign.ai. After you close your account, your data is deleted within 90 days, and it cycles out of encrypted backups within about 35 days after that. Consent and opt-out records are kept longer where the law requires it — they are your proof of messaging compliance.

Does using AutoCampaign.ai make my business TCPA-compliant?

No tool can promise that, and you should be wary of one that does. What the product does: records consent with its source, honors STOP automatically at platform and provider level, and guides A2P 10DLC registration. That is product behavior you can verify — not legal advice. For regulatory questions, talk to your counsel.

Are you SOC 2 certified?

Not yet, and we will not imply otherwise. Meanwhile, this page describes the specific controls in place today, and we answer security questionnaires directly at support@autocampaign.ai.

Want to know how AutoCampaign handles your data?

Our team answers security, privacy, compliance, and data-handling questions — including security questionnaires and requests for documentation.

Talk to Security

Read Privacy Policy

Consent recorded, opt-outs honored automatically.