Privacy Policy

SentX Technologies — Privacy Policy

Effective Date: July 29, 2026 Last Updated: July 29, 2026

1. Introduction

This Privacy Policy explains how SentX Technologies ("SentX," "we," "us," or "our") handles information in connection with the SentX AI autonomous sales agent and CRM software (the "Software"). This Policy should be read together with our Terms of Service.

This Policy applies to Customers who purchase and operate the Software. It does not directly govern how Customer's own End-Users' data is used by Customer — see Section 4 (Controller/Processor Roles) below.

2. Scope and Roles: Data Controller vs. Data Processor

2.1 Customer as Data Controller

SentX acts strictly as a software provider. With respect to any personal data of Customer's End-Users (e.g., WhatsApp/Instagram contacts, leads, email correspondents) that passes through or is generated by the AI Agent, Customer is the sole Data Controller (or "Business," under CCPA/CPRA terminology) responsible for determining the purposes and means of processing that data, and for ensuring it has an appropriate legal basis (e.g., consent, legitimate interest, contract) to process it under GDPR, CCPA/CPRA, or other applicable data protection law.

2.2 SentX's Limited Role

Because the Software runs as a Local Instance on Customer's own hardware and credentials are never uploaded to SentX (see Section 5), SentX does not act as, and does not have the technical ability to act as, a Data Processor or "Service Provider" for End-User conversation content. SentX's processing role is limited to the limited account/license/telemetry data described in Section 3.

Customer remains responsible for providing its own End-Users with appropriate privacy notices and for honoring End-User data subject rights requests.

3. Information We Collect

3.1 License and Account Information

To create Customer's account, issue a License Key, and provide support, SentX collects:

  • Customer's email address;
  • Customer's name;
  • Customer's date of birth (used solely to confirm Customer meets the minimum age requirement in Section 8 of the Terms of Service);
  • Customer's organization name;
  • the License Key identifier; and
  • a one-way hardware fingerprint hash (derived from CPU/MAC/OS identifiers) used solely to bind the License Key and local encryption vault to Customer's authorized device. This is a derived hash, not the raw hardware identifiers themselves, and is not used to track Customer across other services.

This is the complete set of personal data SentX itself collects and stores about Customer. SentX does not collect or store payment card details, bank details, or billing addresses — these are collected and processed directly by Gumroad, SentX's payment provider and Merchant of Record (see Sections 7 and 14).

3.2 Telemetry and Diagnostic Data

The Software may transmit limited, non-identifying technical telemetry to SentX, such as: crash/error logs, application version, feature-usage counters, and performance statistics. This telemetry is designed to exclude message content, contact details, or other End-User personal data.

3.3 Information We Do NOT Collect

SentX does not collect, transmit, or store:

  • Customer's Groq API keys;
  • Customer's Meta/WhatsApp or Instagram access tokens or credentials; or
  • the plaintext content of any message sent or received through the AI Agent.

These credentials are encrypted locally under AES-256 encryption and are cryptographically bound to Customer's local hardware fingerprint (see Section 5). SentX has no server-side copy, backup, or recovery mechanism for this vault.

4. How We Use Information

We use the information described in Section 3.1–3.2 solely to: (a) issue, validate, and manage License Keys; (b) provide customer support; (c) diagnose and fix technical issues; (d) send Customer transactional or policy-update communications; and (e) comply with legal obligations (e.g., tax and payment-processing records).

We do not sell the information described above, and we do not use it to build advertising profiles.

5. The Local Vault: Your API Keys and Credentials

Customer's Third-Party Platform credentials (Groq API keys, Meta/WhatsApp access tokens) are:

  • encrypted client-side using AES-256 encryption before ever being written to disk;
  • bound to a hardware fingerprint unique to Customer's licensed device; and
  • never transmitted to, or stored on, any SentX server, database, or backup system.

Because of this architecture, SentX cannot access, view, or recover these credentials, and cannot honor requests to "delete" or "export" credential data on Customer's behalf, since SentX never possesses it. Customer is solely responsible for securing its own local device and for backing up its own credentials directly with the issuing Third-Party Platform.

6. Data Handled via Webhook Tunnels (e.g., ngrok)

6.1 Customer-Hosted Infrastructure

To receive inbound webhook events (e.g., WhatsApp or Instagram message notifications) from Third-Party Platforms, Customer is solely responsible for establishing a local webhook relay tunnel (such as ngrok). SentX does not operate, host, or manage this relay tunnel, and webhook payloads do not pass through SentX servers. Because SentX is not in the data path, SentX does not collect, read, analyze, or retain any message content or End-User contact details.

6.2 Where Conversation Content Actually Goes: Groq

Once an inbound message reaches Customer's Local Instance, generating the AI Agent's reply requires sending the relevant message/conversation content to Groq's API for language-model processing. This exchange happens directly between Customer's Local Instance and Groq's own servers, using Customer's own Groq API key — it does not pass through, and is never visible to, SentX. Groq processes this content as an independent third party under its own privacy policy and terms (see Section 14), and Customer — not SentX — is the party actually sending End-User conversation data to Groq. Customer should review Groq's data-handling practices and ensure it has an appropriate legal basis to share End-User data with Groq before enabling the AI Agent.

7. Data Sharing and Disclosure

We do not sell personal information. We may share the limited information described in Section 3 with:

  • Gumroad (our payment provider and Merchant of Record), which independently collects Customer's payment details (card/billing information) directly at checkout and processes the transaction, invoicing, and applicable taxes on its own behalf — see Section 14 for Gumroad's own privacy policy;
  • Infrastructure/hosting providers, solely to operate license-validation systems;
  • Law enforcement or regulators, where required by valid legal process; and
  • A successor entity, in connection with a merger, acquisition, or asset sale, subject to this Policy (or a materially similar one) continuing to apply.

We do not share End-User conversation content with anyone because, as described above, we do not retain it. As explained in Section 6.4, End-User conversation content is instead sent by Customer's own Local Instance directly to Groq, using Customer's own credentials — SentX is not an intermediary in, and does not "share," that exchange.

8. Data Retention

  • License/account data: retained for as long as the License Key or Customer account is active, and thereafter as needed to comply with tax, accounting, and legal obligations.
  • Telemetry/crash logs: retained for a limited period 90 days sufficient for diagnostic purposes, then deleted or anonymized.
  • Webhook payloads: Not retained by SentX at all, as SentX does not operate the relay tunnel (see Section 6.1).

9. Your Rights Under the GDPR (EU/UK Users)

If you are located in the European Economic Area or the United Kingdom, you have rights under the GDPR/UK GDPR with respect to the limited personal data SentX holds about you as a Customer (e.g., your purchase email), including the right to: access, rectify, or erase that data; restrict or object to its processing; request portability; and lodge a complaint with your local supervisory authority. To exercise these rights, contact sentxsupport@gmail.com. Note that SentX cannot act on requests concerning End-User conversation data or local vault credentials, for the reasons described in Sections 2 and 5 — such requests should be directed to the Customer operating the Software (as the Data Controller).

10. Your Rights Under the CCPA/CPRA (California Residents)

If you are a California resident, you may have the right to: know what personal information is collected about you; request deletion of your personal information; correct inaccurate personal information; opt out of the sale or sharing of personal information (SentX does not sell or share personal information); and not be discriminated against for exercising these rights. Requests can be submitted to sentxsupport@gmail.com.

11. International Data Transfers

License/account and telemetry data described in Section 3 may be processed in countries other than Customer's own. Where required, SentX will rely on appropriate safeguards (such as Standard Contractual Clauses) for any such transfer.

12. Children's Privacy

The Software is a B2B business tool and is not directed at, nor knowingly used by, individuals under 18 years of age. SentX does not knowingly collect personal information from children.

13. Security Measures

SentX employs reasonable technical and organizational measures appropriate to the limited data it holds, including access controls for license-validation systems. No method of transmission or storage is 100% secure, and SentX cannot guarantee absolute security.

14. Third-Party Services

The Software is designed to interoperate with Groq, Meta (WhatsApp and Instagram), and other Third-Party Platforms selected by Customer. Those platforms' own privacy policies and terms govern their handling of any data Customer submits to them directly using Customer's own credentials:

  • Meta Privacy Policy: https://www.facebook.com/privacy/policy/
  • WhatsApp Privacy Policy: https://www.whatsapp.com/legal/privacy-policy
  • Groq Privacy Policy: https://groq.com/privacy-policy
  • Groq Services Agreement (Terms of Service for Groq's API/Cloud Services): https://console.groq.com/docs/legal/services-agreement

Additionally, because Gumroad acts as our payment provider and Merchant of Record for License Key purchases, Gumroad independently collects and processes Customer's payment and billing data under its own terms:

  • Gumroad Privacy Notice: https://gumroad.com/privacy
  • Gumroad Buyer Terms: https://gumroad.com/terms

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be indicated by a new "Last Updated" date and, where appropriate, communicated via the Software dashboard or the email on file.

16. Contact Us

Questions about this Privacy Policy, or requests regarding the limited data described in Section 3, may be directed to: sentxsupport@gmail.com.