Legal

Privacy Policy

Last updated: 11 April 2026

This policy explains what personal data Envio collects, how it is used, and your rights in relation to it. Please read it carefully. By using Envio, you agree to the practices described here.

1. Who we are

Envio is an AI-powered email campaign planning tool for ecommerce stores. The service is currently operated by an individual (the "Operator"). A registered legal entity is forthcoming. For all privacy-related matters, contact us at support@envioapp.com.

2. What data we collect

We collect the following when you use Envio:

Account data: your name and email address when you sign up.

Store data: the website URL you provide, and the content we crawl from it — product descriptions, page copy, and brand signals.

Campaign data: the campaign plans, email copy, and push notification copy generated for your store.

Usage data: basic records of actions taken in the app, such as campaigns generated and emails marked as sent.

We do not collect payment card data directly — this is handled by Stripe, our payment processor.

3. How we use your data

We use your data solely to provide the Envio service: to crawl your website, generate campaign plans, and produce copy in your brand voice. We do not sell your data, share it with advertisers, or use it to train AI models. Your website content is used only to generate campaigns for your account and is not shared with other users.

4. Third parties we work with

To provide the service, your data passes through the following third-party processors. Each has been selected for their data protection standards:

Supabase — authentication and database hosting.

Anthropic — AI text generation. Campaign plans and copy are generated using Anthropic's Claude API.

Firecrawl — website crawling.

Vercel — application hosting.

Stripe — payment processing, when billing is enabled.

Each of these providers processes data on our behalf under their own data processing agreements. We encourage you to review their privacy policies.

5. Data retention

We retain your account and campaign data for as long as your account is active. If you delete your account, all associated data — including your business profile, campaign history, and crawled content — is permanently deleted within 30 days. You can delete your account at any time from the Settings page.

6. Your rights (GDPR)

If you are located in the European Economic Area, you have the following rights regarding your personal data: the right to access, correct, or delete your data; the right to restrict or object to processing; and the right to data portability. To exercise any of these rights, contact us at support@envioapp.com and we will respond within 30 days.

7. Cookies

Envio uses only essential cookies necessary to operate the service — specifically, authentication cookies set by Supabase to keep you logged in. We do not use advertising cookies, tracking cookies, or third-party analytics. No cookie consent banner is required as we only use strictly necessary cookies.

8. Security

We take reasonable technical measures to protect your data, including encrypted connections (HTTPS), secure authentication via Supabase, and access controls. No system is completely secure — if you have concerns about your account, contact us immediately at support@envioapp.com.

9. Children

Envio is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. If we make significant changes, we will notify you by email or by displaying a notice in the app. The date at the top of this page indicates when the policy was last updated. Continued use of Envio after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions or requests, contact us at support@envioapp.com. We aim to respond to all enquiries within 30 days.