SMS Terms & Opt-In

How we collect SMS consent — and what messages we'll send.

HarvestEngine sends only transactional SMS to authenticated users. Requested one-time codes, including two-factor verification codes, are not part of the optional recurring text program and are sent because you requested them. The optional recurring text program has four categories: trade-approval links, account-security alerts, post-execution trade summaries, and replies when you text us. We never send marketing or promotional SMS. This page documents the opt-in flow, the consent language users see, how to opt out, and the operational details of our messaging program.

How users opt in

HarvestEngine.ai is in limited preview. Nobody can reach an opt-in page by browsing to it: a prospective user first requests access at /preview-access, and an administrator approves that request before the account can sign in at all. Every phone number in the program therefore belongs to a person we admitted deliberately — there is no open self-serve signup, and no way to enroll a number without first clearing that gate.

SMS is never required to create or use a HarvestEngine account or sign in. Accounts are created and accessed with email and password or with Google, Microsoft, or Apple sign-in — no phone number is involved. Consent to recurring text messages is entirely optional and is never a condition of creating an account, signing in, subscribing, or enrolling a number. One-time two-factor verification codes are a separate security message category.

For users who choose to add a mobile number, it is collected after sign-in. The SMS opt-in is optional:

  1. Phone enrollment after sign-in at https://app.harvestengine.ai/onboarding/phone. After a user has already created their account (with email + password or SSO), they are offered the chance to add a mobile number. This step carries a prominent “Not now — I'll add a number later” skip: the user can decline and continue into the full product without a phone. If they do add a number, the consent to recurring texts is a separate checkbox, unchecked by default, that they may leave unchecked and still finish adding the number for sign-in security only.

Messaging consent is a distinct, unchecked, clearly optional control — separate from any required agreement — and declining it never blocks the user from creating an account, signing in, or using the service. You must be 18 or older to enroll a mobile number.

Passwordless sign-in by text is disabled. The sign-in page does not offer it, and /auth/sms/start is unavailable. It may be re-enabled only after this page, the applicable 10DLC campaign, and the toll-free verification records have been reviewed and updated for that restored message category.

Screenshots of the sign-in and opt-in pages

These pages show the current disabled sign-in state and the post-sign-in enrollment page where consent language appears:

Sign-in page with no passwordless text sign-in option
Step 1 — /login. Passwordless sign-in by text is disabled: the page offers no text-sign-in control or SMS consent collection.
Verify your mobile number — phone entry, visible optional recurring-text disclosure, and collapsed More details expander
Step 2 — /onboarding/phone (post-SSO phone enrollment). Offered after the account already exists; carries a “Not now” skip so the user can decline and use the full product without a phone. The recurring-texts consent box is unchecked by default. Required carrier disclosures stay visible beside it; “+ More details” contains elaboration only.

These screenshots are illustrative and are not the consent record. For every enrollment, HarvestEngine separately writes a timestamped record of the disclosure version shown, the number it was shown for, and the affirmative action taken — see Consent records below. Carriers and aggregators conducting campaign vetting should treat the live opt-in URLs above as authoritative rather than these images.

Consent language presented at opt-in

This is the current label on the optional, unchecked-by-default consent checkbox, quoted from the live templates (disclosure version 2026-09-20). It applies to post-sign-in enrollment and the Settings phone card. Leaving it unchecked does not stop the user from enrolling a number or using the product:

Optional: Yes, send me recurring account texts from HarvestEngine.ai (Aubrey Holdings, LLC): trade-approval links, trade summaries, and account-security alerts.

The following required disclosures remain visible beside the checkbox: Msg frequency varies. Msg & data rates may apply. Reply STOP to opt out, HELP for help. The page also names END, CANCEL, QUIT, UNSUBSCRIBE, REVOKE, and OPTOUT; links to SMS Terms, Terms, and Privacy; and says that consent is not required to add or verify a number. The native “+ More details” expander holds only elaboration: the Settings → Notifications preference path and the limited SMS-provider sharing needed to deliver messages.

Passwordless text sign-in is disabled today. Its dormant template carries the same 2026-09-20 disclosure so a future re-enable cannot restore stale copy; it is not a public opt-in route while the sign-in method is off. Re-enabling it still requires the documented campaign and toll-free record review.

/onboarding/phone and the Settings phone card are the live sources of this quoted disclosure. Both name Settings → Notifications as where the preference can change. /onboarding/phone also carries a prominent “Not now — I'll add a number later” link that lets the user decline entirely and continue into the product without a phone.

Users who enrolled before this version retain the disclosure version recorded against their number. The checked-in Consent Version Archive preserves prior verbatim wording; matching consent records are available on request at privacy@harvestengine.ai.

What we send

Requested one-time codes. Two-factor verification codes confirm a phone number or identity, including phone enrollment, Settings, offboarding, and SMS MFA after SSO or password sign-in. They are not part of the optional recurring text program and are sent because you requested them.

The optional recurring text program has four categories:

We do not send marketing SMS, promotional offers, cross-sell, advertising, surveys, or third-party content. Your mobile information — your phone number, your SMS opt-in, and your consent to receive texts — is never shared, sold, rented, or leased to any third party or affiliate for their marketing or promotional purposes. Your number is shared only with our messaging provider (Twilio) for the sole purpose of delivering the messages described here; that is a service-provider relationship, and Twilio may not use it for any other purpose. SMS opt-in and consent data is excluded from every information-sharing category described in our Privacy Policy.

Sample messages

These are the actual shapes of the bodies our system sends, with the account-specific values replaced by illustrative ones. The first is the two-factor verification-code body.

Only the two-factor verification-code messages carry a “Reply STOP” footer today; the transactional alerts above do not append one per message. You can opt out at any time by the methods in How to opt out below, and we are evaluating adding a periodic STOP reminder to recurring alerts.

Message bodies never contain offers, pricing, upgrade prompts, cross-sell, advertising, surveys, third-party content, or any other promotional material. Some messages do include dollar amounts drawn from your own account — the size of a proposed or executed order, or the size of a loss just harvested — because those amounts are what the message is about. They are facts about your own account, not an offer. Text messages do not carry estimated tax savings or any other derived benefit figure: those appear only in email and in the authenticated application, where the assumptions behind them fit alongside the number.

Message frequency

These are recurring messages, and message frequency varies. How many you get is driven entirely by your own activity — how often you sign in, how many proposals you approve, and how much your portfolio does in a given week. An account being actively traded gets messages most days; a dormant account gets none. We do not send scheduled broadcasts, we have no minimum send volume, and we never text you to fill a quota.

Keeping your number current

Mobile numbers get reassigned. Every number in this program is tied to an authenticated account that signs in regularly, and each enrollment is confirmed by a code we send to the handset, so a number that has changed hands stops being exercised as soon as the account stops using it. If you change your mobile number, update it in Settings → Sign-in & security — which re-runs the same verification — or email support@harvestengine.ai. If you change your mobile number, please update your preferences in Settings. Opt-outs are recorded against the number itself, so they survive any later change to the account.

When we send

Two-factor verification codes are sent the moment you request them, at any hour, because you asked for them. Replies to messages you send us go out when you text us. Everything else is driven by market activity: trade-approval links, trade summaries, and trading-related alerts are generated by processes that run on the US market calendar, so in normal operation they land during US market hours and the surrounding business day. Account-security alerts — a broker connection that has expired, or automated trading paused by a guardrail — are sent when the condition occurs, because holding them back would defeat their purpose.

How users opt out (revocation of consent)

You may withdraw your consent to receive HarvestEngine text messages at any time, by any reasonable method. We will honor your request regardless of how you make it.

By reply text. Reply to any HarvestEngine message with any of:

By any other reasonable method. You may also opt out by:

How fast we act. We process opt-outs automatically and typically within seconds. In every case we will honor a revocation request within 10 business days of receipt, as required by 47 C.F.R. § 64.1200(a)(10).

Confirmation. Opting out is confirmed immediately, and you receive a single confirmation either way — but it comes from one of two places, depending on how you ask.

When you text one of the keywords listed above, your mobile carrier intercepts it at the network level and replies with its own notice that texts from this sender are now blocked. That message comes from your carrier, not from us, and its wording is set by the carrier.

When you make the request some other way — a free-text revocation such as “stop texting me”, which the carrier does not intercept — we send the confirmation ourselves. It contains no promotional content and no attempt to talk you out of it; it tells you how to resume if you opted out by mistake, and nothing else. We send nothing further to that number unless you affirmatively opt back in. Our confirmation reads:

You've been unsubscribed from HarvestEngine Assistant. No further messages will be sent. Reply START to resubscribe.

What opting out affects. Opting out stops all HarvestEngine text messages, including two-factor codes, trade-approval links, security alerts, and trade summaries. SMS two-factor authentication will stop working; you can continue to sign in with Google, Microsoft, Apple, email and password, or an email magic link. SMS is currently the only second factor we support — we do not yet offer an authenticator app or a passkey — so if two-factor authentication is switched on for your account, stopping your texts means you will need to turn two-factor authentication off in Settings → Sign-in & security in order to keep signing in. We will show you this in the app if you opt out while SMS is your only sign-in or second-factor method.

Help & support

Reply HELP to any HarvestEngine message and you will receive:

HarvestEngine Assistant: For questions about your portfolio or account, just text this number and our AI chat assistant will reply. Msg & data rates may apply. Reply STOP to cancel. For support, email support@harvestengine.ai

You can also email support@harvestengine.ai directly, or reach our privacy team at privacy@harvestengine.ai.

Program identity, numbers, and carrier disclosures

Every time a mobile number is enrolled, HarvestEngine writes a consent record to its append-only audit log containing: the number in E.164 format; the account it belongs to; the version of the disclosure that was displayed; which page it was displayed on; the date and time in UTC; and the IP address and browser user agent of the request. The record is written only when the consent box is checked, and the enrollment is separately confirmed by the user returning the verification code we send to that number. Consent is optional and is never a condition of enrolling a number: a submission with the box unchecked proceeds normally and the number is verified, no consent record is written, and the absence of a record is itself the evidence that consent was not given. We write the same kind of record for opt-outs and re-subscriptions.

These records are append-only, are not deleted when an account is closed, and carry the number and disclosure version inline so they remain readable and attributable after the account itself is gone. You may request a copy of your own consent record at privacy@harvestengine.ai.

Data handling

Phone numbers are stored in HarvestEngine's Postgres database with row-level security scoped to the owning user account. They are used solely for the transactional messages described above and are subject to the same retention and deletion rules as the rest of your account data — see our Privacy Policy for the full operational summary. Consent and opt-out records are the one exception: we keep those for the period described above even after an account is closed, because we are required to be able to prove when and how consent was given and withdrawn.

This page is the operational summary of HarvestEngine's SMS messaging program for purposes of carrier, CTIA, and A2P 10DLC compliance review. The formal Terms of Service govern in case of conflict. Last updated: 2026-09-20.