Effective Date: June 15, 2026
Last Updated: August 8, 2026
Envoy Technologies LLC (“Envoy,” “we,” “us,” or “our”), a South Carolina limited liability company, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS platform, website (hello-envoy.com), and AI project-scoping and marketplace services (collectively, the “Service”).
Please read this policy carefully. It describes our data practices and the choices available to you. During onboarding, you acknowledge that you have received and reviewed this Privacy Policy separately from your agreement to our Terms and Conditions.
1. INFORMATION WE COLLECT AND HOW WE COLLECT IT
We collect information that you voluntarily provide to us, data generated automatically, and information obtained via third-party integrations.
A. Information You Provide to Us
- Account Information: Full name, email address, company name, account credentials, and professional profile details.
- AI Input & Scoping Data: Project parameters, budgets, specifications, text prompts, and chat histories utilized by our AI scoping tool.
- Marketplace Interactions: Communications, project briefs, messages, and files you choose to attach to outreach or replies exchanged with contacts via our platform.
- Billing and Payment Data: Credit card or banking information processed via our third-party payment processor (Stripe). We do not directly store financial transaction credentials; we receive secure payment tokens and basic billing metadata.
B. Information Collected via Third-Party Integrations (Google & Microsoft OAuth)
If you utilize our Gmail or Microsoft Outlook integration features, we request access via Google OAuth or Microsoft Graph API permissions. This allows us to collect:
- Your connected email address (Gmail or Outlook).
- Secure authentication and access tokens.
- For new inbox changes, limited message and thread identifiers plus From, To, Subject, and Date headers. Envoy compares the From and To addresses to determine whether a message involves a contact you linked to an active Envoy project. Non-matching header summaries are discarded after this comparison and are not stored by Envoy.
- Message content, snippets, headers, and thread metadata for matching project-contact messages and for messages you send through Envoy. Envoy stores these messages in the related project's Outreach conversation.
- Normal file attachments on matching project-contact messages, including their filenames, content types, sizes, and file contents. Inline, blocked, unavailable, or oversized files may be represented by metadata only. Envoy does not fetch or store attachments from messages that do not match an active project contact.
C. Information Collected Automatically
- Usage, Device, and Telemetry Data: IP addresses, browser types, operating systems, referring URLs, specific platform pages viewed, dates/times of visits, and AI system performance logs.
- Cookies and Tracking: We utilize cookies, web beacons, and similar tracking technologies to handle secure session states, remember preferences, and optimize system functionality.
D. Product Feedback and Community Features
After you sign in and complete any required privacy acknowledgment, Envoy may make a self-hosted feedback widget available. Envoy also operates a public feedback portal where published feedback can be viewed without an Envoy account. When you use these features, we process:
- Your Envoy user identifier, current name, and current email address so the feedback system can recognize you without requiring a second account or sign-in.
- Feedback posts, feature requests, bug reports, votes, comments, and screenshots or other images you choose to attach.
- Limited operational context consisting of the Envoy environment, broad page area, and application version. Envoy does not automatically send project identifiers, full page URLs, connected-mailbox content, credentials, or payment data to the feedback system.
We use this information to operate and secure the feedback service, understand and prioritize requests, investigate bugs, communicate product decisions, and improve Envoy. Published feedback and the name attributed to it may be visible to anyone on the Internet, together with its status, vote count, published comments, roadmap placement, and changelog information. Submitting feedback, voting, and commenting require an authenticated Envoy user. Some submissions may be moderated before publication, and Envoy administrators can review unpublished feedback and moderation information.
Do not include passwords, access tokens, payment information, connected-email contents, sensitive personal information, or confidential third-party information in feedback, comments, or screenshots.
2. THIRD-PARTY EMAIL SERVICES & LIMITED USE COMPLIANCE (GOOGLE & MICROSOFT)
Envoy’s platform integrates with Google API services and Microsoft Graph API services to allow you to communicate seamlessly with project contacts.
- Google Limited Use Disclosure: Envoy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its strict Limited Use requirements.
- Microsoft Platform Compliance: Envoy’s use and transfer of information received from Microsoft APIs will adhere to the Microsoft Developer Terms and applicable commercial data safety policies, ensuring data is used strictly for core application functionality.
- Authorized Scopes & Access:
- Google/Gmail Scopes Requested: openid, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/auth/userinfo.profile, https://www.googleapis.com/auth/gmail.readonly, and https://www.googleapis.com/auth/gmail.send.
- Microsoft/Outlook Scopes Requested: openid, profile, email, offline_access, User.Read, Mail.Read, and Mail.Send.
- Project-Contact Matching and Synchronization: We use email read scopes (https://www.googleapis.com/auth/gmail.readonly and Mail.Read) to inspect limited headers for new inbox changes, match sender or recipient addresses to contacts linked to active projects, and retrieve full content and normal file attachments only for matching messages. Matching messages and available attachments are displayed in the related project's Outreach thread.
- User-Approved Sending: We use email send scopes (https://www.googleapis.com/auth/gmail.send and Mail.Send) to transmit project outreach or replies, including files you select, only after you review the recipient, subject, body, and attachments and explicitly choose a send action in Envoy.
- AI-Assisted Draft Processing: Relevant project context and matching project-contact message content may be securely transferred to Envoy's contracted AI API processor solely to prepare a user-visible reply draft. Attachment bytes, extracted attachment text, and file contents are not included in this processing. The draft remains in Envoy for your review and is never automatically sent.
- Capabilities We Do Not Use: Envoy is not a general email client. It does not use these permissions to modify labels, archive, delete, or permanently delete mailbox messages, and it does not create or manage Gmail Drafts.
- Your Control: You may disconnect an account in Account Settings, which stops future synchronization and sending. You may also revoke Envoy's access through your Google Account or Microsoft account settings.
- No Human Reading: Envoy personnel do not read your integrated email content unless you explicitly authorize it for troubleshooting purposes or as required for platform security or legal compliance.
- Strict Transfer Prohibitions: We do not sell, rent, or lease any data obtained through Google or Microsoft APIs to third parties under any circumstances. We do not transfer your email data to advertising platforms, data brokers, or speculative data miners.
- No Generalized Model Training: Information received from Google, Gmail, Google Workspace, Microsoft Graph, Outlook, or another connected mailbox provider is never used to create, train, fine-tune, or improve a generalized AI model. The optional Envoy model-training preference does not change this exclusion.
3. OPTIONAL FUTURE MODEL IMPROVEMENT
Envoy does not currently use user content for generalized model improvement or training. The optional control in Envoy records your interest in a possible future program; it does not trigger or authorize current training and does not affect access to normal Envoy features. Before any such program begins, Envoy will provide an updated notice and ask interested users to confirm their choice.
Potential future eligible Envoy-native data
If Envoy offers the program in the future, the potential categories are:
- Project descriptions, requirements, constraints, budgets, prompts, chat messages, and other project-scoping inputs entered directly into Envoy.
- Envoy-generated scopes, estimates, outlines, recommendations, and other outputs.
- Corrections, ratings, and explicit product or model feedback you submit.
- De-identified product-usage and model-performance signals that are not derived from a connected provider.
Data that is always excluded
- Connected-provider message bodies, attachments, headers, metadata, contacts, and data derived from Gmail, Google Workspace, Outlook, Microsoft Graph, or another mailbox.
- OAuth tokens, passwords, credentials, provider identifiers used only for authentication, and encryption material.
- Payment-card, bank-account, billing-credential, and payment-token data.
- Direct identifiers such as your name, email address, IP address, mailing address, and phone number unless separately de-identified under an approved process.
- Private communications authored by contacts or other third parties, and any data whose use is restricted by law, contract, provider policy, or a deletion requirement.
Changing your choice
You can change this preference at any time from the Data & Privacy section of Account Settings. No training use occurs based on this saved preference today. Envoy will require a fresh confirmation under an updated notice before using eligible content in a future program.
4. TWO-SIDED MARKETPLACE & DATA SHARING WITH VENDORS
To fulfill the core functionality of our marketplace, Envoy shares relevant user-generated project data with third-party vendors.
- Shared Data Profiles: When you request quotes or communicate with a vendor, Envoy transfers necessary information to that vendor, which may include your name, company name, email address, AI-generated project scopes, and designated budgets.
- Unverified Vendor Warning: Our marketplace features both verified and unverified third-party vendors. Unverified vendors are indexed from external platforms and have not undergone privacy or operational vetting by Envoy.
- Independent Data Controllers: Once your information is shared with or transferred to a vendor (verified or unverified), that vendor acts as an independent Data Controller of your data. Their handling of your data is governed strictly by their own privacy practices, which Envoy does not monitor, oversee, or control.
5. THIRD-PARTY SUB-PROCESSORS
To securely host our platform and process specialized data requests, Envoy transfers specific data categories to trusted third-party sub-processors. These sub-processors are legally bound by contract to protect your data and are prohibited from using it for any purpose other than providing contracted services:
| Sub-Processor Category | Purpose | Core Data Handled |
|---|---|---|
| Cloud Infrastructure Providers (e.g., AWS) | Core platform hosting, databases, private file storage, and backup infrastructure | All system data, account logs, User Content, and connected-message attachments |
| AI API Providers (e.g., OpenAI, Anthropic) | Processing and generation of project scopes and user-visible outreach or reply drafts | User prompts, project context, scoping parameters, and matching project-contact message content when draft generation is performed |
| Payment Processors (Stripe) | Secure subscription billing and financial compliance | Payment methods, billing addresses, and tax details |
| Product Analytics Platforms | Monitoring application uptime and error reporting | De-identified usage logs, browser type, and device telemetry |
Envoy operates its product-feedback system on AWS infrastructure using self-hosted Quackback software. Quackback Ltd. does not host or have access to data in Envoy's self-hosted deployment. Envoy has disabled Quackback telemetry and AI features for this deployment.
6. DATA RETENTION, MINIMIZATION, AND SECURITY
- Retention Parameters: We retain your personal data only as long as necessary to provide your active subscription, maintain your marketplace historical record, or fulfill legal obligations.
- Outreach Attachment Retention: Files attached to sent or received project messages are retained with the related project and conversation under the retention purposes above. Unsent attachments are automatically deleted after twenty-four (24) hours without a change to the attachment record. Removing an unsent attachment or canceling its draft also queues its stored file for deletion; temporary deletion failures are retried.
- Consent Records: We keep a current record of your Terms acknowledgment and model-training preference and an immutable event history containing the disclosure shown, versions, timestamps, request metadata, and actor. These records support legal and operational accountability. Account deletion may remove them in accordance with applicable retention, deletion, and legal obligations.
- Feedback Retention and Deletion: Active feedback remains available while it is useful for product planning, support, security, legal compliance, or the purposes described in this policy. Soft-deleted feedback posts are permanently removed after thirty (30) days. Feedback audit logs may be retained indefinitely for security and accountability. When a feedback user is deleted, their user record is permanently deleted, votes are removed, sessions are invalidated, and retained posts and comments are attributed to “Deleted User.” Feedback text and attachments may therefore remain in anonymized form to preserve discussion continuity unless we also delete the content in response to an applicable request. Backup copies age out under Envoy's backup-retention schedule and are not used for ordinary product access.
- Automated Minimization:
- Gmail Interaction Logs: Metadata logs regarding emails sent via the Gmail API are automatically deleted or fully anonymized after ninety (90) days.
- AI Cache & Context Logs: Raw API interaction logs submitted to external AI sub-processors are set to auto-expire or be deleted within thirty (30) days, subject to the sub-processor's standard data safety windows.
- Security Architecture: We implement robust administrative, technical, and physical security measures (including TLS encryption in transit and AES-256 encryption at rest) designed to shield your data from accidental loss or unauthorized breach. Outreach attachment files are stored in private, non-public object storage and are available through authenticated, project-owner-scoped access rather than public file links. However, no transmission medium over the internet is completely infallible.
7. YOUR DATA RIGHTS & GLOBAL COMPLIANCE (GDPR/CCPA)
Depending on your local jurisdiction (including the European Economic Area under GDPR and California under the CCPA/CPRA), you possess specific, enforceable rights regarding your personal data:
- Right to Access & Portability: You have the right to receive a copy of your personal data and AI history in a structured, machine-readable format.
- Right to Rectification: You can modify or correct inaccurate account information directly through your dashboard settings.
- Right to Erasure (“Right to be Forgotten”): You may request that we delete your personal data, past AI generation histories, stored outreach attachments, and platform credentials, subject to applicable legal and retention obligations.
- Right to Revoke Authorization: You may revoke Envoy's access to your Google/Gmail account at any time either through your Envoy profile configuration panel or directly via your Google Security Account Permissions dashboard.
To exercise any of these privacy rights, please submit a formal request to our privacy team at contact@hello-envoy.com. We will verify your identity and respond within the legally mandated timeframes. A request may include access to or export of your feedback, correction of the identity associated with it, deletion of your feedback-system user, or deletion of specific feedback content or attachments.
8. CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify or update this Privacy Policy at our discretion to match changing AI regulations or platform upgrades. We will notify you of material changes by updating the “Last Updated” date at the top of this document or by sending a direct notification to your registered system email address. When a change materially affects the practices for which acknowledgment is appropriate, we may ask you to acknowledge the revised policy in Envoy. A Privacy Policy acknowledgment does not reset or require you to repeat your acceptance of the Terms and Conditions.
9. CONTACT INFORMATION
For privacy-specific inquiries, data deletion requests, or questions regarding our Google API data handling policies, please reach out to us at: