PRIVACY POLICY

Last updated: April 23, 2026 · Effective: April 23, 2026

QUICK SUMMARY

  • We do not sell your personal information. Ever.
  • OAuth tokens you grant us are encrypted at rest and used only to perform the tasks you authorize.
  • We do not use your private content (emails, contacts, files, messages, calls) to train shared AI models.
  • Google Workspace data is handled in compliance with the Google API Services User Data Policy, including Limited Use requirements.
  • You can revoke any integration, export your data, or delete your account at any time.
  • We comply with GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and applicable global data protection laws.

This summary is provided for convenience only. The full policy below is the controlling document.

1. INTRODUCTION

eggsy.ai ("eggsy," "we," "us," or "our") operates the eggsy.ai platform (the "Platform"), which provides AI-powered virtual employees that perform tasks on behalf of you and your business, including social media management, email handling, lead generation, voice reception, blog writing, and document review.

This Privacy Policy describes how we collect, use, disclose, store, share, and safeguard information when you use the Platform, our website at eggsy.ai, our APIs, or any related services (collectively, the "Services").

By creating an account, connecting a third-party integration, or otherwise using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, you must not use the Services.

2. WHO WE ARE (DATA CONTROLLER)

eggsy.ai acts as a Data Controller for account, billing, and platform usage information, and as a Data Processor for content, contacts, and operational data you submit or that we access through your connected third-party accounts on your instruction.

  • Operator: eggsy.ai
  • Contact: privacy@eggsy.ai
  • Data Protection Officer (DPO): dpo@eggsy.ai
  • EU/UK Representative: Available upon request to qualifying users in the EEA/UK

3. INFORMATION WE COLLECT

3.1 Account & Profile Information

  • Name, email address, password (hashed using bcrypt or equivalent)
  • Company name, role, industry, team size
  • Profile photo, time zone, language preference
  • Authentication identifiers (Google/Microsoft/Apple SSO subject IDs where used)

3.2 Billing & Payment Information

  • Billing address, tax ID, VAT number where applicable
  • Subscription plan, invoices, payment history, refund records
  • Payment instrument tokens (we do not store full card numbers; payment data is processed and stored by Stripe, Inc.)

3.3 OAuth Tokens & Connected Account Data

When you connect a third-party account (Section 5), we collect and store:

  • OAuth access tokens, refresh tokens, and scope grants (encrypted at rest with AES-256)
  • Account identifiers (account ID, username, email, page IDs, channel IDs)
  • The minimum content and metadata required to perform the tasks you instruct (emails, calendar events, contacts, posts, comments, files, etc.)

3.4 Content You Submit or Generate

  • Chat messages and instructions you give to AI employees
  • Brand voice samples, knowledge base documents, FAQs, brand assets
  • Files you upload (PDFs, images, audio, contracts)
  • AI-generated drafts, posts, emails, blog articles, and reports
  • Approval/rejection history and edits

3.5 Voice & Phone Data (ALEX agent)

  • Inbound and outbound call audio (recorded via Twilio)
  • Call transcripts (generated via OpenAI Whisper or Deepgram)
  • Caller phone numbers, call duration, call outcomes
  • Voicemails and SMS message content

Recording disclosure: You are responsible for ensuring that callers in jurisdictions requiring two-party (all-party) consent (including California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, Washington, and others) are properly notified that the call is being recorded. ALEX includes a configurable opening disclosure for this purpose; disabling it is at your own legal risk.

3.6 Lead & Prospect Data (HUNTER agent)

  • Business contact information sourced from licensed data providers (Apollo.io, Hunter.io, ZoomInfo, etc.)
  • Email engagement data (opens, clicks, replies, bounces)
  • Outreach sequence performance metrics

You are responsible for the lawful basis for processing prospect data, including compliance with CAN-SPAM (US), CASL (Canada), GDPR (EEA/UK), and any other applicable anti-spam or data-protection laws. See our Terms of Service.

3.7 Usage & Technical Data

  • IP address, device type, operating system, browser type and version
  • Pages visited, features used, session duration, click events
  • API request logs (timestamp, endpoint, status code)
  • Error logs and crash reports
  • Approximate geolocation derived from IP

3.8 Cookies & Tracking Technologies

See Section 9 for our full cookie disclosure.

4. HOW WE USE YOUR INFORMATION

We process your data for the following purposes and on the following legal bases:

PurposeLegal Basis (GDPR)
Provide and operate the ServicesContract
Execute tasks via connected integrationsContract / Consent
Process payments and prevent fraudContract / Legal Obligation
Customer support and account communicationContract / Legitimate Interest
Product improvement and analytics (aggregated)Legitimate Interest
Security, abuse detection, and incident responseLegitimate Interest / Legal Obligation
Marketing emails about new features (opt-out anytime)Legitimate Interest / Consent
Legal compliance and dispute resolutionLegal Obligation

5. THIRD-PARTY INTEGRATIONS & OAUTH

The Platform integrates with third-party services so your AI employees can perform real work on your behalf. When you authorize an integration via OAuth or an equivalent authentication flow, you grant eggsy.ai permission to access your account on that service strictly within the scopes you approve.

5.1 Integrations We Support

ProviderPurposeTypical Scopes
Google (Gmail, Calendar, Drive, Docs, Sheets, Search Console)Email, calendar, file access, SEOgmail.modify, calendar, drive.file, webmasters.readonly
Microsoft 365 (Outlook, Calendar, OneDrive)Email, calendar, filesMail.ReadWrite, Calendars.ReadWrite, Files.ReadWrite
Meta (Facebook Pages, Instagram Business)Social posting, insights, commentspages_manage_posts, instagram_content_publish, pages_read_engagement
LinkedInProfile, page posting, outreachw_member_social, w_organization_social, r_liteprofile
X (Twitter)Posting, engagementtweet.read, tweet.write, users.read
TikTok for BusinessContent publishing, insightsvideo.publish, video.list, user.info.basic
YouTubeVideo upload, analyticsyoutube.upload, youtube.readonly
WordPress, Webflow, Shopify, WixBlog publishingposts.write, content.publish
HubSpot, Salesforce, PipedriveCRM sync, lead routingcontacts, deals, tickets (read/write)
Calendly, Cal.comMeeting bookingscheduling.read, scheduling.write
Slack, Microsoft Teams, DiscordNotifications, team chatchat:write, channels:read
TwilioVoice, SMS, phone numbersAPI key (PSTN access)
Zapier, MakeWorkflow automationWebhook + API key
StripeSubscription billingRead-only customer + payment data

5.2 Google API Services User Data Policy — Limited Use

eggsy.ai's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide or improve user-facing features that are prominent in the Platform's user interface.
  • We do not transfer Google user data to third parties except (a) as necessary to provide or improve the Services, (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data except (a) with your explicit consent for specific messages, (b) when necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
  • We do not use Google user data, or data derived from Google user data, to train, retrain, or fine-tune generalized or non-personalized AI/ML models.

5.3 Meta Platform Terms

When you connect Meta-owned accounts (Facebook Pages, Instagram Business), our use of that data complies with the Meta Platform Terms and Developer Policies. We do not sell, license, or purchase any data obtained from Meta, and we delete platform data within 30 days of your disconnection, except as legally required.

5.4 LinkedIn API Terms

Our use of LinkedIn data is subject to the LinkedIn API Terms of Use. We do not scrape LinkedIn outside its official APIs and do not store LinkedIn member data beyond what is necessary to provide the Services you request.

5.5 Revoking Access

You may disconnect any integration at any time from Settings > Integrations. Upon disconnection, we revoke our OAuth tokens, stop accessing your account on that provider, and delete cached content from that provider within 30 days, subject to legal retention obligations. You may also revoke access directly from the provider (e.g., Google Account permissions, Meta Business Suite, etc.).

6. AI PROCESSING & MODEL TRAINING

6.1 How AI Processes Your Data

Your instructions and the data your AI employees need to complete tasks are sent to large language model (LLM) and audio-model providers for inference. Current providers include:

  • OpenAI (GPT-4 family, Whisper, embeddings) under the OpenAI API Data Processing Addendum
  • Anthropic (Claude family) under Anthropic's Commercial Terms and DPA
  • ElevenLabs (text-to-speech) for voice generation
  • Deepgram (speech-to-text) for call transcription
  • Stability AI / Replicate (image generation) for social image creation

6.2 No Training on Your Private Data

We have contractual commitments with our model providers that customer data submitted via API is not used to train their general-purpose models. We do not use your private content (emails, calls, contacts, files, chats, generated outputs) to train any model that is shared with other customers.

We may use fully anonymized, aggregated metrics (e.g., “average tokens per task”) to improve the Platform.

6.3 Brand Voice Personalization

When you submit brand voice samples, knowledge base content, or feedback (approve/reject/edit), we store these in your isolated workspace and use them only to personalize your AI employees. They are never shared across workspaces.

6.4 Human Review

Eggsy personnel do not access the content of your messages, files, or AI conversations except: (a) when you explicitly request support and grant access, (b) to investigate suspected abuse or security incidents, (c) to comply with legal process, or (d) on aggregated/anonymized data. All such access is logged.

7. SUBPROCESSORS

We engage trusted subprocessors to operate the Services. Current subprocessors include:

SubprocessorFunctionRegion
Microsoft Azure / AWS / Google CloudHosting, storage, computeUS / EU
Stripe, Inc.Payment processingUS / EU
OpenAI, L.L.C.LLM inference, transcriptionUS
Anthropic, PBCLLM inferenceUS
Twilio, Inc.Voice, SMSUS / global
ElevenLabs / DeepgramVoice synthesis & transcriptionUS
SendGrid / Postmark / ResendTransactional emailUS / EU
CloudflareCDN, DDoS protection, WAFGlobal
Sentry / DatadogError monitoring & observabilityUS
Apollo.io / Hunter.ioB2B contact data (HUNTER agent)US

Each subprocessor is bound by a written agreement requiring confidentiality, security, and (where applicable) GDPR-compliant data processing terms. Material changes to this list will be announced at least 30 days in advance for paid customers via email or in-app notice.

8. SHARING & DISCLOSURE

We do not sell your personal information. We share data only as follows:

  • With your direction: Whenever your AI employees act on a connected integration (e.g., posting to LinkedIn), the relevant content is transmitted to that platform on your behalf.
  • Subprocessors: As listed in Section 7, strictly to operate the Services.
  • Within your workspace: With other team members or admins you invite.
  • Legal requirements: To comply with subpoenas, court orders, regulators, or to enforce our rights and protect against fraud or harm.
  • Corporate transactions: In connection with a merger, acquisition, or asset sale, with notice to affected users.
  • With explicit consent: Any other sharing requires your separate, opt-in consent.

9. COOKIES & TRACKING

We use the following categories of cookies and similar technologies:

  • Strictly necessary: Authentication tokens, CSRF tokens, session cookies. Cannot be disabled.
  • Functional: Remember your preferences (theme, language, sidebar state).
  • Analytics: Aggregated usage analytics via privacy-friendly providers (e.g., PostHog, Plausible, or Google Analytics 4 with IP anonymization).
  • Marketing (opt-in only): Conversion tracking on the marketing site (eggsy.ai) only after consent via our cookie banner.

EU/UK/EEA visitors are presented with a granular cookie consent banner. You can withdraw consent at any time via Cookie Settings in the footer.

10. DATA SECURITY

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption at rest for OAuth tokens, API keys, and sensitive content fields
  • Role-based access control (RBAC) and principle of least privilege for internal access
  • Mandatory MFA for all production system access
  • Workspace-level data isolation (multi-tenant with per-tenant encryption keys for paid tiers)
  • Continuous vulnerability scanning, dependency monitoring, and quarterly penetration testing
  • Audit logs of admin and system activity retained for at least 12 months
  • Working toward SOC 2 Type II certification

Despite our safeguards, no system is 100% secure. In the event of a personal data breach affecting you, we will notify you and applicable supervisory authorities without undue delay (and within 72 hours where required by GDPR).

11. DATA RETENTION

Data TypeRetention Period
Account & profile dataLife of account + 30 days after deletion
OAuth tokensUntil you disconnect or revoke; then deleted within 30 days
Chat & AI interaction historyUntil you delete it; auto-deletion configurable per workspace
Cached emails / calendar / files from integrationsUp to 30 days unless required for active workflow
Call recordings & transcripts90 days by default; configurable 7 days to 2 years
Billing & invoice records7 years (tax / accounting compliance)
Server & application logs90 days
BackupsUp to 35 days, then permanently overwritten

12. INTERNATIONAL DATA TRANSFERS

eggsy.ai is operated from the United States. If you access the Services from outside the US, your data will be transferred to and processed in the US (and other countries where our subprocessors operate).

For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and the EU–US Data Privacy Framework (where applicable to our subprocessors). Copies of SCCs are available on request.

13. YOUR PRIVACY RIGHTS

13.1 GDPR / UK GDPR (EEA, UK, Switzerland)

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability (machine-readable export)
  • Right to object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making and profiling
  • Right to withdraw consent at any time
  • Right to lodge a complaint with your local Supervisory Authority

13.2 California (CCPA / CPRA)

  • Right to know what personal information we collect, use, and disclose
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt out of “sale” or “sharing” (we do not sell or share personal information as those terms are defined under CPRA)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your rights
  • The right to designate an authorized agent to make requests on your behalf

13.3 Other Jurisdictions

If you are in Canada (PIPEDA), Brazil (LGPD), Australia (Privacy Act), or another jurisdiction with applicable data-protection laws, equivalent rights apply.

13.4 How to Exercise Your Rights

Email privacy@eggsy.ai from the email associated with your account. We respond within 30 days (or 45 days under CCPA). For most rights you can also self-serve from Settings > Privacy in your dashboard.

14. CHILDREN'S PRIVACY

The Services are not directed to or intended for individuals under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal data, contact us at privacy@eggsy.ai and we will delete it promptly.

15. AUTOMATED DECISIONS & AI OUTPUTS

The Services use AI to generate content, score leads, route messages, and recommend actions. These outputs are not solely automated decisions producing legal or similarly significant effects on you within the meaning of GDPR Article 22, because (a) they require your approval to take effect by default, and (b) you may always override or disable any AI behavior. You retain full control over what is published, sent, or executed in your name.

16. DO NOT TRACK

Our Platform does not currently respond to browser “Do Not Track” signals because no consistent industry standard has been adopted. We do honor Global Privacy Control (GPC) signals as an opt-out under CCPA/CPRA where applicable.

17. CHANGES TO THIS POLICY

We may update this Privacy Policy. Material changes will be communicated via email and/or an in-app notice at least 30 days before they take effect. The “Last updated” date at the top reflects the most recent revision. Your continued use of the Services after changes take effect constitutes acceptance.

18. CONTACT US