Privacy
How Envy handles account, search, usage, and reference data.
Last updated: 14 September 2026
Account data
Envy uses Better Auth for sign-in and OAuth authorization. We store account and session records, including your name, email address, workspace, and sign-in state, in Neon. Google processes Google sign-in when you choose it. Cloudflare delivers one-time sign-in links and account messages.
Search and usage data
Envy processes the search arguments needed to answer each request and sends search text to an embedding provider to create a vector for that request. We do not store search arguments, email copy, OAuth access tokens, or raw API-key values in usage events.
Usage records contain the workspace, principal type, tool name, result state, timing, and successful monthly call count. Hosting and security providers may process request metadata such as time, status, and network address to operate and protect the service.
Analytics choices
With your permission, PostHog measures page visits, referral sources, library interactions and setup steps. It uses a browser identifier stored on your device. When you sign in, we connect those events to a pseudonymous Envy account ID to understand whether people can set up and use the service. Browser and device information, country and page performance help us find problems.
You can decline analytics and continue using Envy. We honor Do Not Track and Global Privacy Control signals. lets you change your browser choice; withdrawing stops future browser collection and clears its stored analytics identifier.
Separately, we use pseudonymous account and workspace IDs, account creation and key-management actions, and MCP tool outcomes and timings to operate and improve the service. These server measurements do not depend on browser consent. Contact us to object to this processing or request deletion of your analytics data.
Analytics excludes prompts, raw search text, email content, names, email addresses, API keys and authentication tokens. We do not enable session recording or automatic form and click capture. URLs are stripped of query strings and fragments, except selected campaign attribution labels recorded separately.
PostHog processes this analytics data in its US region. Data remains subject to the project's retention settings and account deletion requests. We review the data we retain as the service develops.
Payments
Envy does not collect payment details or subscription payments at launch. If paid plans become available, this policy will identify the payment provider and the billing records Envy retains before the first payment is accepted.
The reference library
Envy stores screenshots and extracted content from marketing emails as attributed design references. Public and agent-facing surfaces identify the source brand. We do not offer the library as a bulk download.
Removal requests
Brands and rights holders may request removal or exclusion by emailing support@envy.email. Removed references stop appearing in Envy's serving surfaces.
Service providers
Neon hosts Envy's Postgres data. Cloudflare provides DNS, email routing, transactional email, and R2 object storage. Fly.io runs the serving, authentication, and ingestion applications. PostHog provides analytics. These providers process data needed for their part of the service.
Your account
To ask about account information or request deletion, email support@envy.email. Some records may need to be retained for security, legal, or dispute handling.
Contact
Questions about privacy can be sent to support@envy.email.