Privacy Policy
Last updated 29 July 2026
1. Who we are
Envoy CRM ("Envoy," "we," "us") is a product of Hypericon. This policy covers the hosted version of Envoy at envoycrm.com and its subdomains. If you self-host Envoy instead — running your own copy against your own database — this policy doesn't apply to that instance at all: none of your data ever reaches us, and you're responsible for your own privacy practices for it.
2. What we collect
Account and organisation data: your name, email address, and organisation name when you sign up or are invited to join an organisation.
Content you put into Envoy: contacts, companies, deals, notes, tasks, media contacts, pitches, press kits, and anything else you or your team enter. This is your data — see §5.
Usage analytics: on this marketing site, via Plausible — a privacy-friendly analytics tool that doesn't use cookies or track you across other sites, and doesn't collect personally identifiable information. Inside the product itself, if you connect your own Plausible or Google Analytics account (an optional feature), that's your own analytics account, not data we collect.
AI features: Envoy's AI features are bring-your-own-key. If you use them, the relevant content (e.g. a pitch draft, a contact summary) is sent directly to the AI provider you've configured (OpenAI, Anthropic, etc.) using your own API key. We don't send this to our own servers for any purpose beyond relaying the request, and we don't use it to train anything.
3. How we use it
- To operate the service — storing and serving your organisation's data, running the features you use.
- To send transactional email — welcome emails, invites, password resets. Not marketing email unless you separately opt in somewhere.
- To maintain and improve the product, including diagnosing technical issues.
We do not sell your data, and we do not use your organisation's content to train any AI model.
4. Where it's stored, and who else touches it
Hosted Envoy runs on DigitalOcean infrastructure — managed Postgres for your data, and DigitalOcean Spaces for files (press kit assets, contact avatars). We use the following subprocessors:
- DigitalOcean — hosting, database, and file storage.
- Resend — sends transactional email on our behalf (welcome, invite, password reset).
- Plausible — privacy-friendly analytics for this marketing site.
- Your own AI provider — only if you enable AI features and configure your own key; see §2.
5. Your data is yours
Every organisation's data is isolated at the database level using row-level security — technically enforced, not just a policy promise. You can request an export or deletion of your organisation's data at any time by contacting us (§9). If you cancel, we retain your data for a reasonable period in case you want to reactivate, then delete it.
6. Security
Data is encrypted in transit (TLS) and secrets (like AI provider keys and SMTP credentials you configure) are encrypted at rest. Access to your organisation's data is scoped to your organisation by default — there's no cross-organisation visibility in normal operation.
7. Your rights
Wherever you're based, you can ask us to access, correct, export, or delete your personal data. If you're in the UK or EU, this reflects your rights under UK GDPR / GDPR specifically (access, rectification, erasure, portability, and objection). Contact us (§9) to exercise any of these.
8. Children
Envoy is a business tool and isn't directed at children. We don't knowingly collect data from anyone under 16.
9. Contact & changes
Questions, requests, or concerns about this policy:[email protected]. We'll update the "last updated" date above if this policy changes, and post material changes here.