Privacy Policy
Effective September 4, 2026 · Last updated September 6, 2026
This Privacy Policy explains what information EnvoyAgent collects — including account data, lead data, call recordings, and consent records — and how we use and share it. For a customer's own leads, the customer controls that data and EnvoyAgent processes it on their behalf. We don't sell personal information, and we describe exactly which service providers (like Stripe, Twilio, and Google) we share data with and why. This is a summary — read the full policy for the details, including how to delete your data.
Who is EnvoyAgent, and what does this policy cover?
EnvoyAgent LLC ("EnvoyAgent," "we," "us") is based in Portage, Michigan. This Privacy Policy explains how we collect, use, and share information through envoyagent.app, the /try and /consent pages, the EnvoyAgent dashboard, and the calls, texts, and emails our AI agents send on behalf of our customers.
If you're an EnvoyAgent customer, this policy covers your own account and billing information. If you were contacted by a business using EnvoyAgent — a call, text, or email from one of our AI agents — this policy also explains what we do with information collected about you during that contact, and how to ask us to stop.
Whose information is this — yours, or a customer's lead?
EnvoyAgent plays two different roles, depending on whose data is involved.
When a customer uploads their own leads' names, phone numbers, or other contact information and asks our AI agents to call, text, or email them, the customer is the data controller for that information and EnvoyAgent acts as their data processor (or "service provider"), following the customer's instructions and this policy's safeguards.
When it comes to a customer's own account information — name, business details, billing information, and how they use the platform — EnvoyAgent is the data controller.
What information do we collect?
We collect the following categories of information:
- Account and billing information: your name, email, business name, and subscription details. Stripe processes and stores your card number directly — we never see or store full card numbers ourselves.
- Lead data: names, phone numbers, email addresses, and other contact or opportunity information you upload or connect to EnvoyAgent.
- Call recordings and transcripts: audio recordings and text transcripts of calls placed by our AI voice agents.
- SMS and email content: the text messages and emails our agents send and receive on your behalf, and the ones you exchange with our support team.
- Consent records: for every call or text we place, we keep a record of the consent given — including the IP address, timestamp, and the exact disclosure text that was agreed to.
- Connected-account tokens: if you connect a calendar, mailbox, or social media account, we store the access credentials needed to operate that connection.
- Usage data: how you and your team use the dashboard, so we can operate, support, and improve the service.
Are you talking to a person, or to an AI?
Outbound calls placed through EnvoyAgent use AI-generated voice technology. These calls are recorded, and our AI agents disclose — near the start of the call — that the caller is an AI assistant, not a human being. Every completed call also includes a verbal opt-out: if you tell the agent you'd rather not be contacted again, that request is honored.
If you'd like to stop receiving calls or texts from an EnvoyAgent customer, you can tell the AI agent to stop during a call, reply STOP to a text message, or email support@envoyagent.app.
What happens when you text us, or we text you?
EnvoyAgent does not share, sell, or rent SMS opt-in data or phone numbers to third parties.
Reply STOP to any text message from an EnvoyAgent customer to opt out of future texts. Reply HELP for support information. Message and data rates may apply, and message frequency varies depending on the conversation.
Consent to receive calls or texts is never a condition of purchasing any goods or services.
What do we do with your Google Calendar?
If you connect Google Calendar, we request access to view your calendar list, check your free/busy time, read your calendar events, and create or cancel calendar events. We read your events — including titles, times, and attendees — for the window currently shown on your dashboard (7 days by default, up to 31 days) to display your schedule and check availability, and we create or cancel events that you or our AI agents book on your behalf. We do not keep a permanent copy of your calendar or its events — we read them live from Google each time they're needed, and store only the encrypted access tokens needed to keep the connection. Those tokens are encrypted at rest.
You can disconnect Google Calendar at any time from Settings → Integrations. Disconnecting immediately deletes the stored access tokens.
EnvoyAgent's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. See https://developers.google.com/terms/api-services-user-data-policy for details.
What do we do with your Facebook, Instagram, or Messenger connection?
If you connect a Facebook Page or Instagram account, we request the following permissions:
- pages_show_list — to list the Facebook Pages and linked Instagram accounts available to connect.
- pages_read_engagement — to read comments on your posts, so our automations can detect and act on them.
- pages_manage_posts and instagram_content_publish — to publish posts and videos you've reviewed and approved.
- instagram_basic — basic account information needed to operate the connection.
Do we publish to Facebook or Instagram automatically?
We only publish a post or video after you've reviewed and approved it — with one exception: if you set up an automated comment-reply rule (for example, replying to a specific keyword left in the comments on a post), that reply sends automatically once you turn the rule on, because you approved the rule itself in advance.
EnvoyAgent's use of information received through Meta's platforms follows Meta's Platform Terms and Developer Policies.
You can disconnect a Facebook, Instagram, or Messenger connection at any time from Content Studio → Publishing accounts → Disconnect. Disconnecting immediately deletes the stored connection and its access token from our systems, and disconnecting Facebook also pauses any comment-reply automations you'd set up — they're kept, paused, so reconnecting doesn't silently resume them. You can also revoke EnvoyAgent's access from Facebook's Business Integrations settings. See our Data Deletion page at /data-deletion for details.
What happens when you connect an email inbox?
If you connect a mailbox (Gmail or another provider over IMAP), the credential you provide — an app password, or an OAuth grant — is encrypted at rest. We cache message headers and a limited preview so our AI agents can triage messages and prepare replies for you to send, but that cache is automatically deleted after 24 hours, and we never store full message bodies.
Disconnecting a mailbox from Settings → Integrations immediately deletes the stored credential and purges the cached messages for that mailbox.
What about TikTok, YouTube, your own API keys, or your bank account?
TikTok and YouTube: if you connect these accounts to publish content, we store the access tokens needed to post on your behalf. You can disconnect either one at any time from Content Studio → Publishing accounts → Disconnect, which immediately deletes the stored connection and its access token from our systems. You can also revoke access separately from TikTok's or Google's own account settings.
Bring-your-own-key (BYOK): on plans that support it, you can provide your own Twilio, ElevenLabs, or OpenRouter API credentials so that usage is billed to your own accounts. Those credentials are encrypted at rest and used only to operate your account.
Bank connections: if you choose to connect a bank account for the optional Financial Command feature, we use Plaid to establish that connection, and the resulting access token is encrypted at rest and tied to your account only. We do not use Plaid to access your leads' or customers' financial information — only your own connected business bank account, and only if you choose to connect one.
HeyGen (avatar video): if you use an AI video presenter, video generation is handled by HeyGen using an EnvoyAgent-operated account, not a personal connection of yours. Avatar presenters go through HeyGen's own on-camera consent verification before they can be used to generate video.
How long do we keep your information?
Consent records and call records are retained for 5 years, matching the window in which a TCPA claim can be brought, so we can demonstrate that a call or text was properly authorized.
Cached mailbox messages are deleted after 24 hours. Billing records are retained as long as required by applicable tax and accounting law.
Other account and lead information is retained for as long as your account is active, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements.
How do we protect your information?
We encrypt sensitive credentials at rest — including calendar and mailbox connection tokens, bring-your-own-key API credentials, and bank connection tokens — and we use row-level security so that each customer's data is isolated from every other customer's. All traffic to and from EnvoyAgent is encrypted in transit (TLS).
No system is perfectly secure, and we can't guarantee absolute security. If you believe your information has been exposed, contact support@envoyagent.app.
What rights do you have over your information?
You can ask us to access, correct, delete, or export the personal information we hold about you. Because EnvoyAgent doesn't currently offer a self-serve deletion or export button, the way to exercise these rights today is to email support@envoyagent.app — see our Data Deletion page at /data-deletion for the full process and timeline.
If you were contacted by an EnvoyAgent customer rather than being a customer yourself, the Data Deletion page also explains how to opt out and ask what information we hold about you.
Is EnvoyAgent for children?
EnvoyAgent is a business tool and is not directed at, or intended for use by, anyone under 18. We don't knowingly collect personal information from children.
How will you know if this policy changes?
We'll update the "Last updated" date at the top of this page when we make changes, and for material changes, we'll make a reasonable effort to notify active customers by email.
These terms may be updated following legal review; we'll update the date at the top of this page when they are. Questions can be sent to support@envoyagent.app.
Questions? support@envoyagent.app