Comms

Privacy Policy

Last updated July 17, 2026

Comms moves real conversations between businesses and their customers, so we treat the data in those conversations with care. This policy explains what we collect, why, who it is shared with, how long we keep it, and the rights you have over it — whether you run a workspace on Comms or received a message from a business that does.

1. Who this policy covers

This Privacy Policy explains how Osis AI LLC (“Osis,” “Comms,” “we”) collects, uses, shares, and protects information in connection with the Comms platform at comms.osis.co and osis.co, our messaging lines, APIs, and related services (the “Service”). It covers three groups of people:

  • Customers — the businesses and people who create Comms workspaces and run agents;
  • Recipients — the people our Customers message through the Service;
  • Visitors — people browsing our websites.

If you received a text from a business using Comms, that business controls why you were contacted and what data it holds about you. We process your messages on that business’s behalf. Reply STOP to any Comms thread to stop receiving messages on that number, and contact the business directly for requests about your data. We will help route requests we receive.

2. Information we collect

Account information. Your phone number (verified by one-time code), workspace name, team member details, and settings you configure.

Workspace content. Agent instructions and configuration, knowledge sources you upload or connect, audience lists and subscriber records you import, and templates you create.

Messages and conversations. The content and metadata of messages sent and received through the Service — including inbound replies from Recipients — so we can deliver them, show them in your inbox, run your agents, honor opt-outs, and keep audit records.

Billing information. Paid plans are processed by our payment partners. We receive plan, status, and transaction records; we do not receive or store full card numbers.

Usage and device data. Log data such as IP address, browser and device information, pages viewed, API calls, timestamps, and error and delivery events. We use strictly necessary cookies for authentication and session state.

Support and communications. Messages you send us — including support requests from the product — and our records of resolving them.

3. How we use information

  • Provide the Service: authenticate you, deliver messages, run agents, and show conversation history;
  • Operate AI features: message content is processed by machine-learning models to generate agent replies, apply compliance checks, and take configured actions;
  • Enforce compliance: process STOP and opt-out keywords, maintain suppression lists, keep consent and audit records;
  • Bill for paid plans and manage subscriptions;
  • Protect the Service: prevent spam, fraud, and abuse; enforce rate limits; secure accounts; debug and fix problems;
  • Improve the Service: understand aggregate usage and reliability. We do not use your workspace content or your Recipients’ messages to train generalized AI models;
  • Communicate with you about the Service, including transactional notices and, with your consent where required, product updates;
  • Comply with law and enforce our Terms of Service.

4. AI processing

Agent replies are generated by large language models. When a conversation runs through an agent, relevant message content and workspace configuration are sent to the model runtime — which may include third-party model providers acting as our subprocessors — to produce the reply and any tool actions. We apply platform safeguards around this processing, including secret-leak scanning and content validation on model output.

Our model providers are contractually restricted to processing this data to provide the service to us. We do not sell message content, and we do not use it to train generalized models.

5. How we share information

We share information only as needed to run the Service:

  • Subprocessors. Infrastructure vendors that host our systems and databases, deliver SMS/iMessage and email, provide AI model inference, process payments, and provide analytics for reliability. Each is bound by contract to protect the data and use it only to provide services to us.
  • Within your workspace. Teammates in your workspace can see workspace content and conversations according to their roles.
  • Carriers and platforms. Delivering a message necessarily shares its content and destination with telecom carriers and device platforms.
  • Legal. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, safety, or property of Osis, our customers, or the public.
  • Business transfers. If we are involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction with notice.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

6. Our customers' data (processor role)

For Recipient data — contact lists, subscriber records, and conversation content — the Customer is the data controller and we act as their processor or service provider. We process that data according to the Customer’s configuration and our Terms of Service, and we require Customers to have a lawful basis (such as consent) for the people they message. If you believe a business has messaged you through Comms without permission, report it to support@osis.co — network abuse is something we act on.

7. Data retention

We keep information for as long as needed to provide the Service and for legitimate business purposes:

  • Account and workspace data: for the life of the account;
  • Conversations and messages: while your workspace retains them, so your inbox and agent context keep working;
  • Opt-out and consent records, and audit logs: retained even after related content is deleted, because we are required to honor opt-outs durably and to keep compliance records;
  • Billing records: as required by tax and accounting law;
  • Log data: for a limited operational window, then deleted or aggregated.

When you delete your workspace, we delete or de-identify associated content within a reasonable period, except for the records above.

8. Security

We protect data with measures appropriate to its sensitivity: encryption in transit, scoped credentials and API keys, workspace isolation, audit logging, secret-leak scanning on AI output, and access controls limiting who at Osis can view customer data (support access happens when you ask for help or when required to keep the Service safe). No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as required by law.

9. Your rights and choices

  • Access and portability. You can request a copy or export of the data we hold about you.
  • Correction. You can update workspace information in the product or ask us to correct inaccurate data.
  • Deletion. You can delete your workspace or ask us to delete your data, subject to the retention rules above.
  • Opt out of messages. Recipients can reply STOP on any thread; marketing emails include unsubscribe links.

To exercise any of these rights, email privacy@osis.co from an address or number associated with your account. We respond within the timelines required by applicable law, and we do not discriminate against you for exercising your rights. Depending on where you live — for example California (CCPA/CPRA) or the European Economic Area and UK (GDPR) — you may have additional statutory rights, including the right to lodge a complaint with your local supervisory authority.

10. Children

The Service is for business use and is not directed to children under 13 (or the higher age of digital consent where you live). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@osis.co and we will delete it.

11. International transfers

We are based in the United States and process data on servers in the United States. If you use the Service from elsewhere, your information will be transferred to and processed in the United States and any other jurisdictions where our subprocessors operate, under appropriate safeguards where required by law.

12. Changes to this policy

We may update this policy as the Service evolves. If a change is material, we will give notice in the product or by message before it takes effect. The “Last updated” date at the top reflects the current version.

13. Contact

Privacy requests: privacy@osis.co · everything else: support@osis.co. Osis AI LLC, United States.