Draft - pending legal review. This policy was drafted internally to have substantive content in place before launch, not written or reviewed by a solicitor. Do not treat it as final; review it properly before relying on it at launch.

Privacy Policy

Last updated 11 August 2026

1. Who we are

Envoy CRM ("Envoy," "we," "us") is a product of Hypericon. This policy covers the hosted version of Envoy at envoycrm.com and its subdomains. If you self-host Envoy instead - running your own copy against your own database - this policy doesn't apply to that instance at all: none of your data ever reaches us, and you're responsible for your own privacy practices for it.

2. What we collect

Account and organisation data: your name, email address, and organisation name when you sign up or are invited to join an organisation.

Content you put into Envoy: contacts, companies, deals, notes, tasks, media contacts, pitches, press kits, and anything else you or your team enter. This is your data - see §5.

Email you forward to us: if you use Email Forwarding (Settings → Email), we receive and process whatever you forward or Bcc to your personal Envoy address - including content originally written by someone else, such as a contact or journalist - to match it against your contacts and log it in your organisation's history. Attachments are stored the same way. If an email can't be matched to a contact, we keep a record that the attempt happened but clear the captured text after 90 days unless you manually link it to a contact first (see §5).

Usage analytics: on this marketing site, via Plausible - a privacy-friendly analytics tool that doesn't use cookies or track you across other sites, and doesn't collect personally identifiable information. Inside the product itself, if you connect your own Plausible or Google Analytics account (an optional feature), that's your own analytics account, not data we collect.

AI features: by default, AI features run on a small monthly credit included with your plan - in that case, whatever content you're generating from (a pitch draft, a contact summary, a scanned business card photo) is sent to our AI subprocessor, OpenRouter, through our own account. If you switch to "Bring your own key" in Settings, that content goes directly to the provider you've configured (OpenAI, Anthropic, etc.) instead, using your own API key, and never passes through our infrastructure. Either way, we don't use your content to train any model. Self-hosted instances have no managed credit and always use your own key.

Billing information: if you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details directly - we never see or store your full card number ourselves. We hold the billing records Stripe gives us back (subscription status, invoice history) against your organisation.

Connected social accounts: if you use Envoy's social posting feature to connect a LinkedIn, Bluesky, or Mastodon account, we store an access credential for that account (encrypted, see §6) so Envoy can publish posts you create to it on your behalf. We only use it for the posting actions you take inside Envoy.

3. How we use it

We do not sell your data, and we do not use your organisation's content to train any AI model.

4. Where it's stored, and who else touches it

Hosted Envoy runs on DigitalOcean infrastructure - managed Postgres for your data, and DigitalOcean Spaces for files (press kit assets, contact avatars). We use the following subprocessors:

5. Your data is yours

Every organisation's data is isolated at the database level using row-level security - technically enforced, not just a policy promise. You can request an export or deletion of your organisation's data at any time by contacting us (§9). If you cancel, we retain your data for a reasonable period in case you want to reactivate, then delete it.

6. Security

Data is encrypted in transit (TLS) and secrets (like AI provider keys, SMTP credentials, and connected social account tokens) are encrypted at rest. Access to your organisation's data is scoped to your organisation by default - there's no cross-organisation visibility in normal operation.

7. Your rights

Wherever you're based, you can ask us to access, correct, export, or delete your personal data. If you're in the UK or EU, this reflects your rights under UK GDPR / GDPR specifically (access, rectification, erasure, portability, and objection). Contact us (§9) to exercise any of these.

8. Children

Envoy is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 16.

9. Contact & changes

Questions, requests, or concerns about this policy:[email protected]. We'll update the "last updated" date above if this policy changes, and post material changes here.