24 Sept 2026
This document describes how SalesMessage, Inc. ("Salesmsg") handles data when you connect your Salesmsg account to an AI assistant (the "Host") using the Salesmsg MCP connector. Our general Privacy Policy covers the rest of the Salesmsg platform.
The connector lets the Host call tools that read from and act on your existing Salesmsg account through the Salesmsg Public API. It runs only when a tool is invoked. When you instruct it, it can send and schedule messages, manage broadcasts, create, edit, tag, and delete contacts, and assign conversations.
It gives no access beyond what your Salesmsg role already permits, and it performs no background syncing.
The connector requests no personal information beyond what you provided when you registered your Salesmsg account, and it does not request your Host conversation or chat history. Tool inputs are limited to what each action needs: identifiers, search terms, filters, date ranges, and the content you ask it to send or save.
When a tool runs, the following data from your Salesmsg account may be returned to the Host:
The connector does not return payment card or bank details, credentials, call recordings, or debug data. Contact records belong to your organization, which is responsible for having a lawful basis to share them with the Host.
The connector is not intended for protected health information (PHI). Customers subject to HIPAA should not use it with conversations that contain PHI.
Only to perform the tool calls you initiate and to secure the connection. We do not sell connector data, use it for marketing, or use it to train machine learning models.
The Host you connected, whose own privacy policy governs what it does with returned data; Amazon Web Services, which hosts Salesmsg infrastructure in the United States; and authorities where required by law. The connector sends data to no other third party.
When you connect, Salesmsg shows the permissions below, and no access is granted until you approve them:
You can disconnect at any time from the Host's connected apps settings. After that, the Host can no longer call the connector, and any issued token expires within 24 hours. To request access to or deletion of your data, email support@salesmessage.com.
Connections use OAuth 2.0 over TLS; the Host never receives your Salesmsg password. Data is encrypted at rest. No system is completely secure.
Changes to this document will be posted here with an updated date. Contact: support@salesmessage.com, SalesMessage, Inc., 1045 E Atlantic Ave #202, Delray Beach, FL 33483.
Last Updated: September 24, 2026