Privacy Policy
Last updated 11 August 2026
1. Who we are
Envoy CRM ("Envoy," "we," "us") is a product of Hypericon. This policy covers the hosted version of Envoy at envoycrm.com and its subdomains. If you self-host Envoy instead - running your own copy against your own database - this policy doesn't apply to that instance at all: none of your data ever reaches us, and you're responsible for your own privacy practices for it.
2. What we collect
Account and organisation data: your name, email address, and organisation name when you sign up or are invited to join an organisation.
Content you put into Envoy: contacts, companies, deals, notes, tasks, media contacts, pitches, press kits, and anything else you or your team enter. This is your data - see §5.
Email you forward to us: if you use Email Forwarding (Settings → Email), we receive and process whatever you forward or Bcc to your personal Envoy address - including content originally written by someone else, such as a contact or journalist - to match it against your contacts and log it in your organisation's history. Attachments are stored the same way. If an email can't be matched to a contact, we keep a record that the attempt happened but clear the captured text after 90 days unless you manually link it to a contact first (see §5).
Usage analytics: on this marketing site, via Plausible - a privacy-friendly analytics tool that doesn't use cookies or track you across other sites, and doesn't collect personally identifiable information. Inside the product itself, if you connect your own Plausible or Google Analytics account (an optional feature), that's your own analytics account, not data we collect.
AI features: by default, AI features run on a small monthly credit included with your plan - in that case, whatever content you're generating from (a pitch draft, a contact summary, a scanned business card photo) is sent to our AI subprocessor, OpenRouter, through our own account. If you switch to "Bring your own key" in Settings, that content goes directly to the provider you've configured (OpenAI, Anthropic, etc.) instead, using your own API key, and never passes through our infrastructure. Either way, we don't use your content to train any model. Self-hosted instances have no managed credit and always use your own key.
Billing information: if you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details directly - we never see or store your full card number ourselves. We hold the billing records Stripe gives us back (subscription status, invoice history) against your organisation.
Connected social accounts: if you use Envoy's social posting feature to connect a LinkedIn, Bluesky, or Mastodon account, we store an access credential for that account (encrypted, see §6) so Envoy can publish posts you create to it on your behalf. We only use it for the posting actions you take inside Envoy.
3. How we use it
- To operate the service - storing and serving your organisation's data, running the features you use.
- To send transactional email - welcome emails, invites, password resets. Not marketing email unless you separately opt in somewhere.
- To maintain and improve the product, including diagnosing technical issues.
We do not sell your data, and we do not use your organisation's content to train any AI model.
4. Where it's stored, and who else touches it
Hosted Envoy runs on DigitalOcean infrastructure - managed Postgres for your data, and DigitalOcean Spaces for files (press kit assets, contact avatars). We use the following subprocessors:
- DigitalOcean - hosting, database, and file storage.
- Resend - sends transactional email on our behalf (welcome, invite, password reset), and receives email you forward to your personal Envoy address if you use Email Forwarding; see §2.
- OpenRouter - routes AI requests made using Envoy's managed AI credits (the default, unless you switch to your own key); only sees content involved in a request you make while using managed credits. See §2.
- Plausible - privacy-friendly analytics for this marketing site.
- Stripe - processes payments and manages subscriptions for hosted paid plans. Only involved if your organisation subscribes to a paid plan.
- Your own AI provider - only if you switch to "Bring your own key" and configure it; see §2.
- Social platforms you connect (LinkedIn, Bluesky, Mastodon) - only if you use the social posting feature; publishes content you create through Envoy to the account you've authorised.
5. Your data is yours
Every organisation's data is isolated at the database level using row-level security - technically enforced, not just a policy promise. You can request an export or deletion of your organisation's data at any time by contacting us (§9). If you cancel, we retain your data for a reasonable period in case you want to reactivate, then delete it.
6. Security
Data is encrypted in transit (TLS) and secrets (like AI provider keys, SMTP credentials, and connected social account tokens) are encrypted at rest. Access to your organisation's data is scoped to your organisation by default - there's no cross-organisation visibility in normal operation.
7. Your rights
Wherever you're based, you can ask us to access, correct, export, or delete your personal data. If you're in the UK or EU, this reflects your rights under UK GDPR / GDPR specifically (access, rectification, erasure, portability, and objection). Contact us (§9) to exercise any of these.
8. Children
Envoy is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 16.
9. Contact & changes
Questions, requests, or concerns about this policy:[email protected]. We'll update the "last updated" date above if this policy changes, and post material changes here.