Envelope

Privacy Policy

Last updated: 26 June 2026

1. Who we are

Envelope ("we", "our", "us") operates the Envelope platform at openenvelope.org. We are the data controller for personal data collected through the Service. You can reach us at [email protected].

If you have privacy questions or concerns, please contact us at the email address above.

2. Data we collect

We collect the following categories of data when you use the Service:

  • Account data — email address, name, and avatar when you sign in via GitHub, Google, or magic link
  • Design workspace data — agent configurations, roles, prompts, access policies, and other team design content you create and store in Envelope
  • Credentials — API keys and secrets you store in the credentials vault, encrypted at rest with AES-256
  • Billing data — payment method details (handled by Stripe — we never see full card numbers), subscription status, and invoice history
  • Usage data — IP addresses, browser type, and page views collected via our server logs

We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.

3. Design workspace data

Content you create in Envelope — agent roles, prompts, tool configurations, and exported spec files — is stored on our infrastructure and used solely to provide the Service. We apply a minimal-data principle: we do not inspect or use your design content for any purpose other than rendering and storing it for you.

Envelope does not use your workspace content to train AI models.

4. How we use your data

We use your data to:

  • Provide, operate, and improve the Service
  • Process payments and send invoices
  • Send transactional emails (magic link sign-in, trial reminders, billing receipts)
  • Respond to support enquiries
  • Monitor for abuse and enforce our Terms of Service
  • Generate aggregated, anonymised analytics about platform usage

We do not sell your personal data to third parties.

If you are located in the EEA or UK, we process your personal data on the following legal bases under the GDPR / UK GDPR:

  • Contract performance — processing your account data, workspace data, and billing data is necessary to provide the Service you signed up for.
  • Legitimate interests — we process usage data and server logs to operate the platform securely, detect abuse, and improve performance. Our legitimate interest in doing so does not override your privacy rights.
  • Legal obligation — we retain billing records for 7 years to comply with tax and accounting obligations.
  • Consent — where we send optional marketing communications (if any), we will obtain your explicit consent first and you may withdraw it at any time.

6. Third-party processors

We share data with the following processors to operate the Service:

  • Stripe — payment processing (USA)
  • Resend — transactional email delivery (USA)
  • GitHub — OAuth sign-in (only if you choose GitHub login) (USA)
  • Google — OAuth sign-in (only if you choose Google login) (USA)
  • Neon — PostgreSQL database hosting (USA)

Each processor is engaged under a data processing agreement. Where processors are located in the USA or other countries outside the EEA/UK, we rely on Standard Contractual Clauses or adequacy decisions to ensure your data is protected to an equivalent standard.

7. International data transfers

Our infrastructure and most of our third-party processors are based in the United States. If you are located in the EEA or UK, your personal data will be transferred to and processed in the USA. We ensure such transfers are covered by appropriate safeguards — primarily the Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Agreement — so your data receives the same level of protection regardless of where it is processed.

8. Secrets and credentials

Secrets stored in the credentials vault are encrypted at rest using AES-256 before being written to our database. They are decrypted only when needed to run agents or services you have configured. Envelope staff cannot view your secret values in plain text. You can rotate or delete secrets at any time from the credentials settings in your account.

9. Data retention

We retain your data for as long as your account is active. After account deletion, personal data (account details, workspace content, and credentials) is purged within 30 days. Billing records are retained for 7 years for tax compliance, as required by law.

10. Your rights

Depending on your location, you may have rights in relation to your personal data. If you are in the EEA or UK, these rights under the GDPR / UK GDPR include:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your personal data where there is no overriding legal basis for us to keep it
  • Restriction — ask us to pause processing of your data in certain circumstances
  • Portability — receive your personal data in a structured, machine-readable format
  • Objection — object to processing based on our legitimate interests
  • Withdraw consent — where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or your local supervisory authority in the EEA.

We do not carry out solely automated decision-making that produces legal or similarly significant effects on you.

11. Cookies

We use a single session cookie to maintain your authenticated session. This cookie is strictly necessary for the Service to function and does not require your consent under applicable cookie laws. We do not use advertising or tracking cookies. No third-party analytics scripts are embedded in the Service.

12. Security

We apply industry-standard security practices including TLS in transit, AES-256 encryption at rest for sensitive values, and access controls limiting who can reach production systems. If you discover a security vulnerability, please disclose it responsibly to [email protected] before public disclosure.

13. Changes to this policy

We will notify you of material changes to this Privacy Policy by email or in-product notice at least 14 days before the changes take effect.

14. Contact

For privacy enquiries, email [email protected].