PRIVACY POLICY

Effective Date: June 15, 2026

Last Updated: July 15, 2026

Envoy Technologies LLC (“Envoy,” “we,” “us,” or “our”), a South Carolina limited liability company, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS platform, website (hello-envoy.com), and AI project-scoping and marketplace services (collectively, the “Service”).

Please read this policy carefully. It describes our data practices and the choices available to you. During onboarding, you acknowledge that you have received and reviewed this Privacy Policy separately from your agreement to our Terms and Conditions.

1. INFORMATION WE COLLECT AND HOW WE COLLECT IT

We collect information that you voluntarily provide to us, data generated automatically, and information obtained via third-party integrations.

A. Information You Provide to Us

  • Account Information: Full name, email address, company name, account credentials, and professional profile details.
  • AI Input & Scoping Data: Project parameters, budgets, specifications, text prompts, and chat histories utilized by our AI scoping tool.
  • Marketplace Interactions: Communications, project briefs, and messages exchanged with contacts via our platform.
  • Billing and Payment Data: Credit card or banking information processed via our third-party payment processor (Stripe). We do not directly store financial transaction credentials; we receive secure payment tokens and basic billing metadata.

B. Information Collected via Third-Party Integrations (Google & Microsoft OAuth)

If you utilize our Gmail or Microsoft Outlook integration features, we request access via Google OAuth or Microsoft Graph API permissions. This allows us to collect:

  • Your connected email address (Gmail or Outlook).
  • Secure authentication and access tokens.
  • Inbound and outbound message content and metadata for emails handled through Envoy to sync conversation threads, track delivery status, and maintain communication histories with marketplace contacts.

C. Information Collected Automatically

  • Usage, Device, and Telemetry Data: IP addresses, browser types, operating systems, referring URLs, specific platform pages viewed, dates/times of visits, and AI system performance logs.
  • Cookies and Tracking: We utilize cookies, web beacons, and similar tracking technologies to handle secure session states, remember preferences, and optimize system functionality.

2. THIRD-PARTY EMAIL SERVICES & LIMITED USE COMPLIANCE (GOOGLE & MICROSOFT)

Envoy’s platform integrates with Google API services and Microsoft Graph API services to allow you to communicate seamlessly with project contacts.

  • Google Limited Use Disclosure: Envoy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its strict Limited Use requirements.
  • Microsoft Platform Compliance: Envoy’s use and transfer of information received from Microsoft APIs will adhere to the Microsoft Developer Terms and applicable commercial data safety policies, ensuring data is used strictly for core application functionality.
  • Authorized Scopes & Access:
  • How We Use Email Access: We utilize email read and send scopes (https://www.googleapis.com/auth/gmail.send, https://www.googleapis.com/auth/gmail.readonly, Mail.Send, and Mail.Read) solely to transmit project briefs, RFPs, or updates to contacts directly on your behalf, and to securely ingest incoming replies back into your platform timeline.
  • No Human Reading: Envoy personnel do not read your integrated email content unless you explicitly authorize it for troubleshooting purposes or as required for platform security or legal compliance.
  • Strict Transfer Prohibitions: We do not sell, rent, or lease any data obtained through Google or Microsoft APIs to third parties under any circumstances. We do not transfer your email data to advertising platforms, data brokers, or speculative data miners.
  • No Generalized Model Training: Information received from Google, Gmail, Google Workspace, Microsoft Graph, Outlook, or another connected mailbox provider is never used to create, train, fine-tune, or improve a generalized AI model. The optional Envoy model-training preference does not change this exclusion.

3. OPTIONAL MODEL IMPROVEMENT AND TRAINING

Envoy does not use your content for generalized model improvement or training unless you separately opt in. A missing preference or an unchecked control is treated as an opt-out. Participation is optional and does not affect your access to normal Envoy features.

Eligible Envoy-native data

When you opt in, the eligible categories are:

  • Project descriptions, requirements, constraints, budgets, goals, prompts, chat messages, and other project-scoping inputs entered directly into Envoy.
  • Envoy-generated scopes, estimates, outlines, recommendations, and other outputs.
  • Corrections, ratings, and explicit product or model feedback you submit.
  • De-identified product-usage and model-performance signals that are not derived from a connected provider.

Opting in makes all eligible historical and future data in these categories available. Eligibility is based on your current saved preference rather than the date on which each record was created.

Data that is always excluded

  • Connected-provider message bodies, attachments, headers, metadata, contacts, and data derived from Gmail, Google Workspace, Outlook, Microsoft Graph, or another mailbox.
  • OAuth tokens, passwords, credentials, provider identifiers used only for authentication, and encryption material.
  • Payment-card, bank-account, billing-credential, and payment-token data.
  • Direct identifiers such as your name, email address, IP address, mailing address, and phone number unless separately de-identified under an approved process.
  • Private communications authored by contacts or other third parties, and any data whose use is restricted by law, contract, provider policy, or a deletion requirement.

Changing your choice

You can change this preference at any time from the Data & Privacy section of Account Settings. Turning it off stops your data from being included in new training-data extractions and, when practical, removes it from queued datasets that have not yet been used. Opting out does not necessarily remove the influence of data from training that has already completed and does not require Envoy to retrain or modify an existing model. If you later opt in again, all eligible historical and future data becomes eligible again.

4. TWO-SIDED MARKETPLACE & DATA SHARING WITH VENDORS

To fulfill the core functionality of our marketplace, Envoy shares relevant user-generated project data with third-party vendors.

  • Shared Data Profiles: When you request quotes or communicate with a vendor, Envoy transfers necessary information to that vendor, which may include your name, company name, email address, AI-generated project scopes, and designated budgets.
  • Unverified Vendor Warning: Our marketplace features both verified and unverified third-party vendors. Unverified vendors are indexed from external platforms and have not undergone privacy or operational vetting by Envoy.
  • Independent Data Controllers: Once your information is shared with or transferred to a vendor (verified or unverified), that vendor acts as an independent Data Controller of your data. Their handling of your data is governed strictly by their own privacy practices, which Envoy does not monitor, oversee, or control.

5. THIRD-PARTY SUB-PROCESSORS

To securely host our platform and process specialized data requests, Envoy transfers specific data categories to trusted third-party sub-processors. These sub-processors are legally bound by contract to protect your data and are prohibited from using it for any purpose other than providing contracted services:

Sub-Processor CategoryPurposeCore Data Handled
Cloud Infrastructure Providers (e.g., AWS)Core platform hosting, databases, and backup infrastructureAll system data, account logs, and User Content
AI API Providers (e.g., OpenAI, Anthropic)Processing and generation of project scopesUser prompts, text inputs, and scoping parameters
Payment Processors (Stripe)Secure subscription billing and financial compliancePayment methods, billing addresses, and tax details
Product Analytics PlatformsMonitoring application uptime and error reportingDe-identified usage logs, browser type, and device telemetry

6. DATA RETENTION, MINIMIZATION, AND SECURITY

  • Retention Parameters: We retain your personal data only as long as necessary to provide your active subscription, maintain your marketplace historical record, or fulfill legal obligations.
  • Consent Records: We keep a current record of your Terms acknowledgment and model-training preference and an immutable event history containing the disclosure shown, versions, timestamps, request metadata, and actor. These records support legal and operational accountability. Account deletion may remove them in accordance with applicable retention, deletion, and legal obligations.
  • Automated Minimization:
    • Gmail Interaction Logs: Metadata logs regarding emails sent via the Gmail API are automatically deleted or fully anonymized after ninety (90) days.
    • AI Cache & Context Logs: Raw API interaction logs submitted to external AI sub-processors are set to auto-expire or be deleted within thirty (30) days, subject to the sub-processor's standard data safety windows.
  • Security Architecture: We implement robust administrative, technical, and physical security measures (including TLS encryption in transit and AES-256 encryption at rest) designed to shield your data from accidental loss or unauthorized breach. However, no transmission medium over the internet is completely infallible.

7. YOUR DATA RIGHTS & GLOBAL COMPLIANCE (GDPR/CCPA)

Depending on your local jurisdiction (including the European Economic Area under GDPR and California under the CCPA/CPRA), you possess specific, enforceable rights regarding your personal data:

  • Right to Access & Portability: You have the right to receive a copy of your personal data and AI history in a structured, machine-readable format.
  • Right to Rectification: You can modify or correct inaccurate account information directly through your dashboard settings.
  • Right to Erasure (“Right to be Forgotten”): You may request that we completely delete your personal data, past AI generation histories, and platform credentials.
  • Right to Revoke Authorization: You may revoke Envoy's access to your Google/Gmail account at any time either through your Envoy profile configuration panel or directly via your Google Security Account Permissions dashboard.

To exercise any of these privacy rights, please submit a formal request to our privacy team at contact@hello-envoy.com. We will verify your identity and respond within the legally mandated timeframes.

8. CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify or update this Privacy Policy at our discretion to match changing AI regulations or platform upgrades. We will notify you of material changes by updating the “Last Updated” date at the top of this document or by sending a direct notification to your registered system email address. When a change materially affects the practices for which acknowledgment is appropriate, we may ask you to acknowledge the revised policy in Envoy. A Privacy Policy acknowledgment does not reset or require you to repeat your acceptance of the Terms and Conditions.

9. CONTACT INFORMATION

For privacy-specific inquiries, data deletion requests, or questions regarding our Google API data handling policies, please reach out to us at:

Envoy Technologies LLC

Email: contact@hello-envoy.com

Web: hello-envoy.com

Back to Home