Privacy Policy

Last updated: February 20, 2026

This Privacy Policy describes how Envel ("we", "us", or "our") collects, uses, and shares information when you use our website at envel.co and our web application (collectively, the "Service"). Envel is an AI-powered code development platform that helps teams build software.

By using the Service, you agree to the collection and use of information as described in this policy.

1. Information We Collect

Information You Provide

  • Account information: When you create an account, we collect your email address and name. If you sign in with Google, we also receive your profile picture from your Google account.
  • Organization and workspace data: Names, descriptions, and slugs for organizations and workspaces you create.
  • Project data: Repository URLs, branch names, project titles, and other project configuration you provide.
  • Code and content: Source code files, chat messages, and other content you submit through the Service for AI-assisted code analysis and editing.
  • Communications: If you contact us directly, we may retain the content of those communications.

Information Collected Automatically

  • Session data: When you sign in, we record your IP address and browser user agent string alongside your session token.
  • Usage analytics: We use PostHog to collect product analytics, including pages visited, features used, and interactions with the Service. This data helps us understand how the Service is used and improve it.
  • Cookies: We use a session cookie to keep you authenticated. This cookie is set with secure and sameSite attributes for security. PostHog may also set cookies for analytics purposes.

Information from Third-Party Services

  • Google: If you authenticate with Google OAuth, we receive your name, email address, and profile picture (scopes: openid, email, profile).
  • GitHub: If you connect a GitHub account or install the Envel GitHub App, we receive access to your repositories, branches, and commit data as permitted by the scopes you authorize.
  • Slack: If you install the Envel Slack integration, we receive your Slack team name, bot user ID, and access to messages in channels where the bot is active (scopes: app_mentions:read, channels:history, chat:write, im:history, im:write, users:read).

2. How We Use Your Information

We use the information we collect to:

  • Provide and operate the Service: Authenticate your identity, manage your account, and deliver the core functionality of the platform.
  • AI-powered features: Process your code and project data through AI models to provide code analysis, editing, and generation capabilities.
  • Send transactional emails: Deliver one-time verification codes for sign-in, organization invitations, and other service-related notifications.
  • Improve the Service: Analyze usage patterns and product analytics to understand how the Service is used and identify areas for improvement.
  • Maintain security: Detect and prevent fraud, abuse, and security incidents.
  • Enforce our terms: Ensure compliance with our Terms of Service and applicable policies.

3. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

Service Providers

We use third-party service providers to operate and improve the Service. These providers process data on our behalf and are contractually bound to use it only for the purposes we specify:

  • Anthropic: Processes code and project content through Claude AI models for code analysis and editing.
  • OpenAI: Processes code and project content through GPT models for AI-assisted tasks such as branch creation and title generation.
  • PostHog: Receives usage analytics and event data for product analytics.
  • Google Cloud Storage: Stores project files, preview images, and other artifacts.
  • Render: Hosts our application infrastructure.
  • Vercel: Provides sandbox environments for code execution.
  • Modal: Executes serverless functions for background processing.
  • Doppler: Manages application secrets and configuration.
  • SMTP provider: Delivers transactional emails (verification codes, invitations).

Third-Party Integrations You Enable

When you connect third-party services (GitHub, Slack), data flows between Envel and those services as needed to provide the integration functionality. These integrations are opt-in and governed by each provider's own privacy policy.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process, such as a subpoena, court order, or government request.

Business Transfers

If Envel is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service.

  • Account data: Retained until you request deletion of your account.
  • Session data: Session records are retained in our database. Expired sessions are not automatically deleted.
  • Project and code data: Retained as long as the associated project exists. When a project is deleted, all related branches, sandboxes, chats, and files are permanently deleted (cascading hard delete).
  • Analytics data: Retained according to PostHog's data retention policies.

When data is deleted, it is permanently removed from our database. We use hard deletes: we do not use soft-delete or archival patterns, which means deleted data cannot be recovered.

5. Data Security

We implement reasonable technical and organizational measures to protect your information:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
  • Secure authentication: Passwords are hashed using industry-standard algorithms (via Better Auth). Session cookies are set with secure and sameSite attributes.
  • Access controls: Role-based access control within organizations and workspaces (Admin, Member roles).
  • Secrets management: Application secrets and API keys are managed through Doppler, not stored in code.

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate personal information.
  • Deletion: Request that we delete your personal information.
  • Portability: Request your data in a portable format.
  • Opt-out of analytics: You can opt out of PostHog analytics tracking through your browser settings or by using a browser extension that blocks tracking scripts.

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: You may request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request that we delete your personal information, subject to certain exceptions.
  • Right to opt-out: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, contact us at the email address listed below.

7. Children's Privacy

The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information promptly.

8. International Users

The Service is hosted in the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, through the Service interface or by email.

We encourage you to review this Privacy Policy periodically.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:

Email: privacy@envel.co