Privacy Policy
Indirect Number
https://indirectnumber.com
Effective date: August 28, 2026
This Privacy Policy describes how WINJEXA LLC ("Indirect Number," "we," "us," or "our"), doing business as Indirect Number, collects, uses, stores, and shares information when you use the Indirect Number service, website, and related apps at https://indirectnumber.com (the "Service").
Indirect Number is a United States SMS relay for high-conflict co-parenting. A customer verifies their own mobile number, registers each person they want a documented line with (a "protected sender"), and receives a dedicated US long-code. The protected sender texts that long-code from an ordinary phone. They never have to install our app. We store originals, may use AI to summarize logistics and to decide how loudly we notify the customer, and we send a reply to the protected sender only after the customer explicitly approves it.
If you have questions, email support@indirectnumber.com.
1. Who this policy covers
This policy covers:
- Customers — adults who create an Indirect Number account, verify a mobile number, pay for the Service, and register protected senders.
- Protected senders — people whose numbers a customer registers, and who text or receive texts on a dedicated Indirect Number long-code.
- Unknown senders — people who text a dedicated long-code but are not registered on that relationship. We quarantine those messages and do not auto-reply, except for required SMS keywords such as HELP and STOP.
- Website and account visitors — people who browse indirectnumber.com or use the customer account.
This Service is built for adults coordinating about children. It is not for children. See Children.
2. Information we collect
We collect the following categories. We do not collect more message content than the relay needs, and we do not modify originals.
2.1 Phone numbers
- The customer mobile number, verified by a one-time passcode (OTP).
- Each protected sender mobile number, as entered by the customer.
- The dedicated US long-code we assign to that customer-sender relationship.
- Numbers that text a dedicated long-code even if they are not registered (unknown senders), so we can quarantine the message instead of silently dropping it.
- Carrier and routing metadata needed to send and receive SMS (for example timestamps, delivery attempts, and error codes from our SMS provider).
2.2 Message content
- The full body of inbound and outbound SMS on a dedicated long-code, including media if a message includes it.
- OTP messages we send to verify the customer number (we need the number and verification result; we do not keep the code longer than needed to complete verification).
- Keyword messages such as HELP and STOP, and our replies to them.
- Customer-approved outbound text, including any calmer wording the customer chooses after an AI suggestion.
Originals. Inbound and outbound messages on the relationship line are stored encrypted at rest, timestamped, and not edited. Summaries, logistics extractions, risk labels, and suggested wording are stored as separate records. They do not replace the original.
2.3 Account, device, and usage
- Account data: name or display name you provide, email address, password or authentication secrets (stored hashed or via our auth provider), timezone, and relationship labels you create.
- Device and technical data: IP address, browser or app type and version, device type and OS, language, referring URL, approximate location derived from IP (city/region level, not a precise GPS track unless you later grant that and we say so), crash logs, and timestamps of access.
- App/device identifiers and push-notification tokens, so we can notify you on that device.
- Customer actions in the product: which senders you registered, approvals and refusals of outbound drafts, notification preferences, quarantine reviews, and STOP/HELP events we tell you about.
2.4 Payment
Payments are processed by Stripe. We receive billing-related data such as subscription status, plan, charge amount and time, last four digits and brand of a card, and billing email or ZIP if Stripe provides them. We do not receive or store full card numbers or CVV. Stripe use of your payment data is also governed by Stripe privacy policy.
2.5 Support and legal
If you email us, we collect the content of that correspondence. If we receive a subpoena, court order, or similar legal process, we collect the request and our response.
2.6 What we do not collect as a product feature
We do not require the protected sender to create an account, install an app, or share contacts, photos, or location with us. We only see what they send to the dedicated long-code, plus standard telecom metadata. We do not sell a court-evidence package and we do not scrape the sender phone.
3. Why we collect it (purpose)
| Purpose | What we use |
|---|---|
| Provide the relay | Phone numbers, dedicated long-code assignment, message content, delivery metadata. So the protected sender can text a number that is not your personal phone, you can read the archive, and an approved reply can go back out. |
| First-message notice, HELP, and STOP | Sender number and message content. So we can disclose that the line is documented, honor opt-out of outbound texts, and answer HELP. |
| Safety classification and notification loudness | Message content and timestamps. AI may extract logistics (pickup times, addresses, medical notes you were sent) and may summarize. AI may change how loudly we notify you (for example, a routine schedule text vs. a threat). Emergency, medical, child-safety, threat, and deadline content is not suppressed. Classification mistakes can still happen; originals remain available. |
| Outbound drafting | Message content you are about to send. AI may suggest calmer wording. Nothing goes to the sender until you explicitly approve it. |
| Quarantine | Messages from unknown numbers, so you can see who texted the long-code without the Service auto-replying to that person. |
| Billing | Stripe payment data, account identity, subscription state. The Service is a paid subscription (currently about $24.99 per month). |
| Account security | OTP, login device data, IP, and auth logs. |
| Operate, debug, and secure the Service | Device, usage, and delivery logs. |
| Legal, safety, and abuse | Any of the above, as needed to comply with law, respond to lawful process, enforce our Terms, or protect a person from serious harm. |
We do not use message content to advertise third-party products to you or to a protected sender.
4. AI processing of message content
The Service is not a human inbox with a person reading every text. Automated systems, including a large-language-model (LLM) provider, process message content for the purposes in Section 3:
- Summarize inbound messages for the customer.
- Extract logistics (dates, times, locations, and similar facts that appeared in the text).
- Classify risk so we can reorder how loudly the customer is notified. High-risk categories we attempt to treat as loud and never suppress: emergency, medical, child safety, threats, and deadlines.
- Suggest calmer wording for a reply. Suggestion is optional. Send requires the customer explicit approval.
What AI does not do in this product:
- It does not edit, delete, or replace the stored original.
- It does not auto-send a reply to a protected sender.
- It does not auto-reply to unknown senders (other than required HELP/STOP keyword replies).
- It does not decide court outcomes, write affidavits, or certify a record as admissible evidence.
LLM processing happens on systems we do not physically own. See Subprocessors. We use that processing to run Indirect Number, not to sell your conversations.
5. SMS program disclosures
These statements are part of how we collect and use mobile numbers. They also belong on this page because US A2P 10DLC review looks for them.
- Program. Indirect Number provides a documented two-way SMS line between a verified customer and a registered protected sender, using a dedicated US long-code. Message frequency varies with how often the two parties text. It is not a fixed four-messages-per-month marketing club.
- Message and data rates may apply. Your carrier and the other party carrier bill their own SMS rates. Indirect Number subscription is separate.
- Customer consent. The customer verifies their own number with OTP and creates an account at https://indirectnumber.com. That is how we know the customer asked us to operate a line on their behalf.
- Notice to the protected sender. The protected sender does not install an app. On the first message we send to them on that long-code, we tell them this is a documented Indirect Number line set up by the customer, that messages are preserved, that they may be AI-summarized, that originals are kept, that message and data rates may apply, and that they can reply HELP or STOP.
- STOP. If a protected sender texts STOP, we stop outbound SMS from Indirect Number to that sender for that relationship. We notify the customer. We may still receive and archive messages that sender later texts to the long-code (that is inbound mail, not a message we send). STOP does not erase the existing archive.
- HELP. Reply HELP to the long-code, or email support@indirectnumber.com, or visit https://indirectnumber.com.
- No sale of SMS opt-in or mobile numbers. We do not sell mobile phone numbers, SMS opt-in records, or message content. We do not share mobile numbers with third parties or affiliates for their own marketing or promotional use. Carriers, our SMS provider, and other subprocessors see numbers only to deliver the Service.
US consent rules for calls and texts are not the same in every state. Some states require only one party to know a communication is being preserved; others expect notice to all parties. We send the first-message notice so the protected sender is told what the line is. That notice is a product feature, not a promise that every state recording or privacy statute is satisfied. Customers are responsible for using the Service lawfully.
6. Who we share with (subprocessors and no sale)
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not rent our message archive.
We share information with service providers who process it for us, under contracts, only to run Indirect Number:
| Category | Role | Examples of data | | --- | --- | | SMS / telecommunications provider | Provision US long-codes, send and receive SMS, delivery receipts. We expect to use Twilio (or a successor SMS provider). | Phone numbers, message bodies as they transit SMS, carrier metadata. | | Payment processor | Charge the subscription. Stripe. | Payment method tokens, charges, limited billing details. | | Hosting / cloud infrastructure | Store the encrypted archive, run the application, logs, backups. | Account data, encrypted message content, device and usage logs. | | LLM provider | Summaries, logistics extraction, risk classification, optional wording suggestions. | Message content and the minimum account context needed to return a result. | | Email and support tools | Support tickets and transactional email. | Name, email, the content of your support request. | | Authentication (if used) | Login and session security. | Email, hashed credentials or SSO identifiers, device/IP for fraud checks. |
We may also disclose information:
- To you, in your account, exports you request, and notices we send you (including that a sender texted STOP).
- If you ask us to, for example a file you download and then give to your attorney. Once it is on your device, our Privacy Policy no longer controls that copy.
- For legal process — a subpoena, court order, search warrant, or similar demand we believe in good faith we must honor. We may also share a limited amount if we believe it is necessary to prevent imminent serious harm.
- In a business transfer — if WINJEXA LLC is involved in a merger, acquisition, financing, or sale of assets, information may move with the business, still subject to this policy or a successor policy we will post.
- Aggregated or de-identified data that cannot reasonably identify you, for capacity planning. We do not sell anonymized full message transcripts.
We do not give protected senders a login to the customer archive. We do not market the archive to the other parent as a shared folder.
7. Storage, encryption, and security
- Where. We operate a US-focused service. Content is stored on cloud infrastructure we reasonably believe is located in the United States unless we later post a change.
- Encryption at rest. Original messages are stored encrypted at rest.
- In transit. We use HTTPS for the website and account. SMS as a channel is not end-to-end encrypted. Carriers and our SMS provider can see SMS bodies in transit the same way they can see any other text message. Do not treat SMS as a sealed envelope.
- Integrity. Originals are timestamped and are not modified. If we need to note a delivery failure or a STOP event, that is a separate record.
- Access. Employees and contractors get access only as needed to operate support, security, and the Service, and they are bound to confidentiality.
No method of transmission or storage is perfect. A dedicated long-code can still be mis-typed, a carrier can fail, a device can be stolen, or a password can leak. Protect your account credentials. Tell us at support@indirectnumber.com if you believe an account or long-code is compromised.
8. Retention
| Data | How long |
|---|---|
| Relationship SMS originals, timestamps, and related AI labels/summaries | For the life of the paying account, because the product is an archive. After you close the account, we delete or de-identify this content within 90 days, unless a legal hold, unresolved billing dispute, active safety investigation, or a preservation request we are required to honor applies. |
| Quarantined messages from unknown senders | Same as the relationship archive for that long-code, or shorter if you delete them from quarantine and no hold applies. |
| OTP codes | Minutes, until verification succeeds or the code expires. Verification success/failure logs: a limited security period (generally up to 12 months). |
| Account profile, registered sender numbers, STOP state | Life of the account, then up to 90 days after closure (STOP state may be kept longer if needed so we do not accidentally text someone who opted out). |
| Device tokens, session logs, IP logs | Generally up to 12 months unless needed longer for security. |
| Billing records | As long as tax, accounting, and anti-fraud rules require (often several years). Stripe keeps payment records under its own policy. |
| Support emails | Generally up to 3 years after the last message in the thread, unless a legal hold applies. |
| Backups | Rolling backups may lag deletion by a short period (typically weeks, not years). Deletion from backups occurs as those backups expire. |
If you ask us to delete message content while the account is open, understand that deleting the archive is at odds with why most customers buy this product. We will still honor a verified deletion request as described in Your rights, except where we must keep a copy (legal hold, STOP proof, billing, security). We cannot unsay an SMS that already reached a carrier or the other party phone.
9. Your rights
9.1 Customers (account holders)
Depending on the law that applies to you (including the California Consumer Privacy Act / CPRA and similar US state laws), you may have the right to:
- Access the personal information we hold about you, including message content on your relationships.
- Correct inaccurate account information (we will not "correct" an original SMS; the point of the archive is that the original stays as received or sent).
- Delete personal information, subject to the exceptions above.
- Export a copy of your archive and account data in a reasonable electronic format.
- Opt out of sale or sharing — we do not sell or share personal information as those terms are used in CPRA. You do not need to ask us to "stop selling"; we don't.
- Limit use of sensitive information where the law gives you that right. Message content and phone numbers are used to provide the Service you requested.
- Non-discrimination for exercising a privacy right.
To make a request, email support@indirectnumber.com from the email on the account, or write to us as described in Contact. We will verify that you control the account (for example, by OTP to the verified number or a login). An authorized agent may submit a request if the law requires us to accept agents and we can verify both you and the agent.
If we refuse a request, you may appeal by replying to our decision and writing "Privacy appeal" in the subject line. We will answer the appeal in writing.
9.2 Protected senders and unknown senders
You did not create the account. The customer did. You still have rights in information that is about you.
- Text STOP to the dedicated long-code to stop outbound Indirect Number texts to you on that relationship. That is the fastest control we offer you.
- Text HELP or email support@indirectnumber.com to ask what this number is, who the customer of record is (we will confirm it is an Indirect Number line and the first name the customer gave us), and to request access or deletion of your personal information as the law allows.
- We may not be able to delete a message that is also the customer archive of a conversation they were a party to, where another law lets us or requires us to keep it, or where deletion would break STOP/HELP compliance. We will explain what we can and cannot do.
We will not give a protected sender the customer full account, payment data, or other relationships.
9.3 Do Not Track
The website does not respond to Do Not Track signals because there is no consistent industry standard for them. We do not run a third-party advertising network on the product.
10. How we do not use this data
- We do not sell personal information, SMS opt-in lists, or message archives.
- We do not use the Service as a marketing list broker.
- We do not promise that a preserved message will be admitted in court, will satisfy a parenting-app order, or will produce any legal outcome.
- We do not use AI to quietly drop high-risk inbound content. We may still fail to classify it correctly, and carriers may still fail to deliver a notification.
11. Cookies and similar technology
The website and customer account may use:
- Strictly necessary cookies or local storage for login session, security, and load balancing.
- Preference cookies (for example, to remember that you are logged in on this browser).
We do not use third-party advertising cookies as part of this product. If that changes, we will update this policy.
12. US focus and other regions
Indirect Number is built for US numbers, US SMS (including 10DLC rules), and US customers. If you access the Service from outside the United States, you understand that your information is processed in the United States, where the law may differ from the law where you live.
We do not currently market the Service as a GDPR product. If that changes, we will post the additional disclosures the law requires.
13. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Anyone under 13 may not create an account.
Indirect Number is for adults who need a documented line with another adult — typically a co-parent, the other party in a parenting schedule, or a similar high-conflict adult contact — about children. Children names, schools, medical facts, and schedules will appear in message content because adults text about those things. That does not make the child a user of the Service.
If you believe we have collected personal information from a child under 13, email support@indirectnumber.com. We will delete it unless we are required to keep it.
You must be 18 or older to open a customer account (see our Terms).
14. Changes
We will post updates to this page and change the effective date. If we make a change that materially weakens the promises in this policy (for example, if we ever were to sell data — we have no plan to), we will give additional notice, such as email to the account or an in-product notice, before the change applies to stored message content.
The current policy lives at https://indirectnumber.com/privacy.
15. State privacy notice (California and similar states)
If you are a US resident covered by a state consumer privacy law, this section is a short index.
Categories collected (last 12 months, once we are operating): identifiers (name, email, phone numbers, IP, device IDs); customer records (account, billing status); commercial information (subscription); internet / electronic activity (app and site logs); approximate geolocation (from IP); and sensitive personal information in the form of message contents and the phone numbers those messages travel on, including messages that may discuss children, health, or conflict.
Sources: you; the people who text a dedicated long-code; your devices; Stripe; our SMS provider; and our hosting and LLM providers (return data only).
Business purposes: Section 3.
Disclosed to: Section 6 (service providers / contractors). Sold or shared for cross-context advertising: no. Sold for money: no.
Retention: Section 8.
Sensitive information: used to provide the Service you requested (the relay, classification, and billing). We do not use it to infer characteristics for advertising.
To exercise rights, use Section 9. We will not require you to create a new account solely to say "do not sell," because we do not sell.
16. Contact
WINJEXA LLC d/b/a Indirect Number
State of formation: Texas (formed September 5, 2023)
Email: support@indirectnumber.com
Web: https://indirectnumber.com
This policy: https://indirectnumber.com/privacy
Terms: https://indirectnumber.com/terms