Legal

Ody Privacy Policy

Effective Date: September 12, 2026  ·  Last Modified: September 12, 2026

This Privacy Policy describes how Origns Inc. ("Origns", "Ody", "we", "us", or "our"), with its notice address at 169 Madison Ave, Ste 2938, New York, NY 10016, United States, collects, uses, discloses, retains, and protects personal information when you use Ody: the Ody web application at app.ody.co, the Ody iOS application, the Ody developer API and MCP server at api.ody.co, the Ody help center at help.ody.co, and our marketing website at ody.co (together, the "Service"). It also explains the choices and rights you have with respect to that information.

Ody is a business phone system. It is designed to be used by businesses and their team members, and it necessarily processes information about the people who call, text, or are contacted by those businesses. Please read this Policy carefully. By creating an account, using the Service, or communicating with an Ody customer through the Service, you acknowledge the practices described here. Capitalized terms not defined in this Policy have the meaning given in the Ody Terms of Service at ody.co/terms.

1.Who This Policy Covers and Our Role

Ody processes information about four groups of people. Which parts of this Policy apply to you depends on which group you belong to, and several apply to more than one.

Customers and Account Holders. The business or individual that creates an Ody workspace, agrees to our Terms of Service, and is responsible for the workspace's billing and settings (the "Customer"). For Customers and their account holders, Ody acts as an independent controller (or "business" under U.S. state privacy law) of account, billing, identity-verification, and usage information.

Team Members. People a Customer invites into its workspace to make and receive calls and texts, manage contacts, and use shared inboxes. Team Members' account information is processed as described for Customers; their activity inside a workspace (calls placed, messages sent, notes written) is Customer Content controlled by the Customer.

End Users and Contacts. People who call, text, or leave voicemails for a Customer's Ody numbers, are called or texted by a Customer, or are stored in a Customer's contact list or imported from a Customer's connected CRM or CSV file ("End Users"). Ody processes End Users' information solely as a service provider and processor on behalf of, and under the instructions of, the Customer. The Customer, not Ody, decides why and how End Users' information is collected, whether calls are recorded, and how long it is kept. If you are an End User and want to access, correct, or delete information a Customer holds about you, please contact that business directly; we will support their response as their service provider.

Visitors. People who browse ody.co or help.ody.co, watch our demo video, open a support ticket, or chat with our support assistant without an account.

"Customer Content" means the content and metadata of communications handled through a workspace and the records a Customer keeps in it: call audio and recordings, voicemails and their transcripts, text messages and media attachments, contact records, notes, tasks, tags, AI summaries and suggested replies, Astra receptionist configuration and knowledge sources, and call-flow settings. Customer Content is owned and controlled by the Customer. We process it only to provide, secure, and improve the Service as described in this Policy and in our Terms of Service.

2.The Short Version

This section summarizes the Policy. The detailed sections that follow control if there is any inconsistency.

What we collect. Account details (name, email, password or single-sign-on identity, verified mobile number), business and billing details, identity-verification results, the phone numbers you provision, and the calls, texts, voicemails, recordings, transcripts, and contacts that flow through your workspace. Automatically: device and browser information, IP-derived country, usage events, crash and error data, and push-notification tokens.

Why. To run a phone system for you: route calls and texts, store your inbox, power Astra (the AI receptionist) and other AI features you turn on, bill you, verify that you are a real business, keep the platform secure and lawful, support you, and improve the product.

Who else touches it. Infrastructure providers we need to deliver the Service, each bound by contract and listed by name in Section 8: Google Cloud (hosting, database, storage, Vertex AI, Firebase authentication and push), Stripe (payments and identity verification), OpenAI models accessed through Vercel AI Gateway (call transcription and summaries), Customer.io (email), Apple and Google (sign-in and push delivery), Nango (integrations you connect), Cloudflare (network edge), PostHog (product analytics), Google Ads (marketing measurement on ody.co), and Trustpilot (review invitations).

What we do not do. We do not sell personal information. We do not use Customer Content to train general-purpose AI models, and we do not permit our AI providers to do so. We do not upload your device's address book. We do not use advertising identifiers or cross-app tracking in the iOS app. Call recording is off by default and is never turned on without a Customer's instruction.

Where. Our systems run in Google Cloud's us-central1 region in the United States. If you use Ody from outside the United States, your information is transferred to and processed in the United States.

Your choices. You can access and update your profile in Settings, export your analytics, opt out of marketing email, reply STOP to any Ody text message, turn off push notifications on your device, and request a copy or deletion of your data by emailing [email protected]. Section 12 explains every right in detail, including rights under U.S. state laws and the GDPR.

3.Information We Collect

We collect information in three ways: you provide it to us, we collect it automatically when you use the Service, and we receive it from third parties such as sign-in providers, telecom carriers, and the integrations you connect. The tables below list each category precisely.

3.1 Information you provide to us

3.2 Information we collect automatically

3.3 Information we receive from third parties

4.How We Use Information

We use the information described above for the following purposes. Where the GDPR or UK GDPR applies, the legal basis we rely on for each purpose is shown in the right-hand column. For Customer Content, we act on the Customer's documented instructions; the Customer is responsible for its own legal basis to collect and use End Users' information.

We may also de-identify or aggregate information so that it can no longer reasonably be linked to you or to a Customer (for example, average pickup time across all workspaces). We use and share such information for any purpose, and we commit to maintaining it in de-identified form and not attempting to re-identify it.

5.Calls, Texts, Voicemail, and Recordings

Because Ody is a phone system, communications content is at the heart of what we process. This section explains exactly what happens to it.

5.1 Calls

Calls are carried by Ody's telephony platform over the public telephone network and, for the web and iOS softphone, over encrypted WebRTC connections. For every call we store metadata (numbers, direction, timestamps, duration, outcome, and the path through your call flow). We do not store call audio unless recording is enabled for the number, or the caller leaves a voicemail.

5.2 Call recording

Recording is off by default on every number. It is enabled only at the Customer's request and applies per number. When enabled, both sides of the call are recorded from the moment it is answered; the recording is stored in Ody's private Google Cloud Storage bucket in the United States, where it remains available in the conversation until it is deleted or the account is closed. Ody does not currently play an automatic recording announcement. Many jurisdictions require notice to, or consent from, all parties before a call is recorded. The Customer is solely responsible for determining whether recording is lawful for its calls, for giving any required notices, and for obtaining any required consents. If you are an End User and believe you were recorded without appropriate notice, please contact the business you called.

5.3 Voicemail and transcription

When a caller leaves a voicemail, the audio is recorded by Ody, transcribed by Ody's speech-to-text service, and both the audio and the transcript are stored in the Customer's inbox. Recorded calls may additionally be transcribed and summarized by the AI features described in Section 6 when the Customer enables them.

5.4 Text messages

SMS and MMS content and attachments are delivered through Ody's messaging platform and stored in the Customer's inbox; media attachments are stored in our private storage. Text messages sent through Ody must comply with our Terms and carrier rules. Ody itself sends a small number of texts to account holders' verified mobile numbers: one-time verification codes, and, if a subscription payment fails, a short series of billing reminders. Reply STOP to any Ody text to stop receiving that category of message; reply HELP for help. Test-mode API keys never send real messages.

5.5 Who can see communications inside a workspace

Ody is a shared team inbox. Depending on the roles and number assignments the Customer configures, other Team Members and workspace administrators can see calls, messages, voicemails, recordings, transcripts, notes, and contacts associated with shared numbers. Administrators control who has access to what. If you are a Team Member and have questions about what your workspace's administrators can see, please ask them.

5.6 Customer Proprietary Network Information

Call detail records such as the numbers you call, when, and for how long are treated as Customer Proprietary Network Information (CPNI) consistent with U.S. Federal Communications Commission rules. We use CPNI only to provide, bill for, and protect the Service, to comply with law, and as you direct. We do not use CPNI for marketing unrelated services without your consent, and we authenticate you before disclosing call detail information over the phone or by email.

6.AI Features and Your Data

Ody includes several AI-powered features. Each one sends specific data to a specific model provider, listed below, for the sole purpose of returning the result to you. Our providers process this data as our service providers under terms that limit its use to delivering the service to us and that do not permit them to use your data to train or improve their general models. We do not use Customer Content to train general-purpose AI models ourselves.

AI output can be wrong. Summaries, transcripts, suggested replies, and Astra's answers are generated automatically and are not reviewed by Ody staff before you see them. You are responsible for reviewing AI output before relying on it or sending it to anyone. You are responsible for configuring Astra's greeting to disclose that callers are speaking with an automated assistant where the law requires it, and you must not configure Astra to deceive callers about its nature.

7.Push Notifications and Device Permissions

The Ody iOS app and the web app can notify you about activity in your workspace. Notifications for new messages include the sender's name or number and a preview of the message text (up to about 140 characters); notifications for missed calls and voicemails include the caller's name or number. These notifications are delivered through Apple Push Notification service and Google Firebase Cloud Messaging, which means Apple and Google carry that content in transit. You can turn notifications off, or hide previews, in your device settings at any time.

Incoming calls on iOS ring through Apple's VoIP push service and CallKit. The VoIP push carries the caller's number or name so the native call screen can display it. The iOS app requests the following permissions, each only when needed: Microphone, to speak on calls; Notifications, to alert you; and Background audio and VoIP modes, to keep calls alive and ring when the app is closed.

The iOS app does not access your device's address book, photos, camera, or location, does not use the Advertising Identifier (IDFA), and does not track you across other companies' apps or websites. It contains no third-party analytics or advertising SDKs. Contacts in the app are your workspace's business contacts, created from calls and texts, imported by your team, or synced from your CRM.

8.How We Share Information

We do not sell personal information, and we do not share it with third parties for their own marketing. We disclose personal information only in the circumstances described in this section.

8.1 Service providers and sub-processors

We rely on the following companies to operate the Service. Each processes personal information only on our instructions, under a written agreement that requires confidentiality and appropriate security, and only for the purpose listed.

We will update this table when we add or replace a sub-processor that processes Customer Content. Customers with a data processing agreement receive advance notice as provided in that agreement.

8.2 Within your workspace

Your name, avatar, presence, and activity are visible to other Team Members in your workspace as configured by its administrators. Customer Content is shared with the Customer's Team Members according to the roles and number assignments the Customer sets.

8.3 At your direction

When you connect an integration, place a call, send a text, forward a call to an outside number, connect an AI assistant through the developer API or MCP server, register a webhook, or export data, we disclose the information necessary to carry out that action to the recipient you chose. Those recipients, including telecom carriers and the operators of the tools and AI assistants you connect, handle the information under their own terms and privacy policies.

8.4 Legal, safety, and compliance

We may disclose information if we believe in good faith that doing so is required by law, subpoena, court order, or other legal process; to comply with telecom regulations and carrier requirements, including responding to law enforcement requests and traceback requests about unlawful robocalls or spam texts; to protect the rights, property, or safety of Ody, our users, or the public; to detect and prevent fraud, abuse, or security incidents; or to enforce our Terms of Service. Where permitted, we will notify the affected Customer of requests for its Customer Content.

8.5 Business transfers

If Origns Inc. is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will notify you by email or a prominent notice on the Service before your information becomes subject to a different privacy policy.

8.6 With your consent

We share information for any other purpose with your consent or at your direction.

9.Cookies and Similar Technologies

We use a small number of cookies and browser storage keys. None are used to build advertising profiles of you across other websites.

Your choices. You can block or delete cookies through your browser settings; blocking first-party cookies may prevent you from signing in. To opt out of Google's advertising cookies, use Google's Ads Settings at adssettings.google.com or install the Google Analytics opt-out browser add-on. To opt out of PostHog analytics and session replay in the Ody app, email [email protected] and we will disable it for your account. We honor the Global Privacy Control browser signal on ody.co: when your browser sends it, we do not load the Google Ads measurement tag.

10.How Long We Keep Information

We keep personal information only as long as needed for the purposes described in this Policy, to meet our legal, tax, and telecom obligations, to resolve disputes, and to enforce our agreements. The table below gives our standard periods; a Customer may shorten most of them by deleting content or closing its account.

11.How We Protect Information

We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, and alteration. Among other measures:

  • Encryption in transit (TLS 1.2 or higher for every connection to our services; encrypted WebRTC media for softphone calls) and encryption at rest for our database, object storage, and analytics warehouse.
  • Structural tenant isolation: every record belongs to a workspace, and database row-level security enforced by the database itself, not just the application, prevents one workspace's data from being read by another.
  • Authentication through Google Identity Platform with hashed passwords, and support for Google and Apple single sign-on. Sign-in sessions use short-lived tokens.
  • API keys are shown once and stored only as SHA-256 hashes; customer webhooks are signed so that you can verify they came from Ody; production secrets live in a managed secret store, never in code.
  • Least-privilege access for our staff, with administrative tools behind identity-aware proxies and access logged. Our staff access Customer Content only to provide support you request, to investigate abuse or incidents, or as required by law.
  • Independent vendors bound by data processing agreements, and infrastructure hosted on Google Cloud, which maintains SOC 2, ISO 27001, and other independent certifications.

No method of transmission or storage is completely secure. You are responsible for keeping your password and API keys confidential, for enabling the security features available to you, and for configuring who in your workspace can see what. If we learn of a security breach affecting your personal information, we will notify you and any regulator as required by applicable law.

12.Your Rights and Choices

Everyone, regardless of where they live, has the following choices with respect to information Ody holds about them.

Access and correction. Account holders and Team Members can view and update their profile, email preferences, and workspace settings at any time in Settings. You may also request a copy of the personal information we hold about you by emailing [email protected].

Export. Customers can export analytics from the app, download recordings and media from conversations, and, on request, receive an export of their workspace's contacts, messages, and call history in a machine-readable format.

Deletion. You can delete individual messages, recordings, contacts, and notes in the app. To delete your account or an entire workspace, email [email protected] from the email address on the account; we verify the request and complete deletion within 30 days, subject to the retention exceptions in Section 10 (for example, billing records we must keep by law). Workspace deletion releases its phone numbers. Where the iOS app offers an in-app account-deletion option, you may use it instead.

Marketing email. Click Unsubscribe in any marketing email or change your preferences in Settings. You will continue to receive transactional messages necessary to operate your account.

Text messages. Reply STOP to any text from Ody to stop receiving that category of message.

Push notifications and previews. Manage in your device's notification settings, or per workspace in the app.

Analytics and session replay. Email [email protected] to have PostHog analytics and session replay disabled for your account, and see Section 9 for cookie controls.

AI features. Astra, call recording, call intelligence, and suggested replies are each controlled by the Customer and can be turned off in Settings or by contacting support.

End Users. If a business that uses Ody holds information about you, please contact that business; it controls that information. If you tell us you no longer wish to be contacted by a specific Ody number, we will pass the request to the Customer, and you can always reply STOP to a text or ask the business to remove you.

To exercise any right, email [email protected] or write to the address in Section 17. We will verify your identity by confirming control of the email address on the account (and, where necessary, your verified mobile number) before acting. You may designate an authorized agent to make a request on your behalf if the agent provides proof of your written authorization and we can verify your identity. We will not discriminate against you for exercising your rights. If we decline a request, we will tell you why, and you may appeal by replying to our decision; if you remain unsatisfied you may contact your state attorney general or data protection authority.

13.Additional Disclosures for U.S. State Residents

This section supplements the rest of the Policy for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws. Depending on your state, you may have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, to obtain a portable copy, to opt out of the sale of personal information, of its sharing for cross-context behavioral advertising, of targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects, and to limit the use of sensitive personal information. Section 12 explains how to exercise these rights.

In the preceding 12 months we collected the categories of personal information listed in Section 3, from the sources listed there, for the purposes listed in Section 4, and disclosed them for business purposes to the service providers listed in Section 8.1. In California Consumer Privacy Act terms, those categories are: identifiers (name, email, phone numbers, account and device identifiers, IP address); customer records (billing name and address, payment reference, verified legal name and document address from identity verification); commercial information (plan, purchases, usage); internet and network activity (usage events, session replays, logs); audio and electronic information (call recordings, voicemails, transcripts, messages, when the Customer enables or receives them); geolocation (country-level only); professional information (business name, role, 10DLC registration details); and inferences limited to product-usage patterns and inbound spam or fraud scoring. Sensitive personal information we collect: account log-in credentials, and, through Stripe, the contents of a government ID and biometric comparison data, which Stripe processes for verification and does not return to us. We use sensitive personal information only to provide the Service, verify identity, prevent fraud, and as otherwise permitted without a right to limit.

Sale and sharing. We do not sell personal information and have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. The Google Ads conversion cookies on our marketing site ody.co may constitute "sharing" for cross-context behavioral advertising or "targeted advertising" under some state laws. You can opt out through the cookie controls in Section 9, by enabling the Global Privacy Control signal in your browser, or by emailing [email protected] with the subject "Do Not Share". We do not use those cookies on app.ody.co.

Service provider relationship. When we process End Users' information and other Customer Content on behalf of a Customer, we do so as a service provider or processor; the Customer is the business or controller. We do not retain, use, or disclose that information for any purpose other than the specific purpose of performing the Service for the Customer, as permitted by law.

Notice of financial incentive. We do not offer financial incentives in exchange for personal information. Retention. Our retention periods are set out in Section 10. Metrics. We will publish annual metrics on the privacy requests we receive when required by law.

14.Users Outside the United States

Ody is operated from the United States and is built primarily for businesses in the United States and Canada. Our servers and those of our sub-processors are located in the United States (see Section 8.1). If you access the Service from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and other countries where our providers operate, which may not offer the same level of data protection as your home jurisdiction.

14.1 European Economic Area, United Kingdom, and Switzerland

Where the GDPR, UK GDPR, or Swiss FADP applies, Origns Inc. is the controller of account, billing, and usage information and a processor of Customer Content. Our legal bases are shown in Section 4. Where we rely on consent you may withdraw it at any time without affecting prior processing. You have the rights to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority. For transfers out of the EEA, UK, and Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our sub-processors, or on other lawful transfer mechanisms. Customers in these regions may request our data processing agreement by emailing [email protected].

14.2 Canada

If you are in Canada, we process personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial laws. Your information may be processed in the United States and accessed by U.S. authorities under U.S. law. You may request access to or correction of your personal information, and withdraw consent subject to legal and contractual restrictions, by contacting us as described in Section 17. Our commercial electronic messages comply with Canada's Anti-Spam Legislation and include an unsubscribe mechanism.

14.3 Other regions

Account creation is not available in some regions. If local law grants you additional rights, we will honor them to the extent required.

15.Children

Ody is a business service. You must be at least 18 years old to create an account or be a Team Member, as set out in our Terms of Service. We do not knowingly collect personal information from anyone under 18 as an account holder, and we do not knowingly collect personal information from children under 13 (or the higher age required by your jurisdiction) from any source. If you believe a child has provided us with personal information, or that an account holder is under 18, please email [email protected] and we will delete the information promptly. As a phone system, Ody may incidentally process communications from a child who calls or texts a Customer; that information is Customer Content controlled by the Customer, which is responsible for handling it lawfully.

16.Third-Party Services, Links, and Changes to This Policy

16.1 Third-party services

The Service links to and interoperates with services we do not control, including the integrations directory, the tools and AI assistants you connect, telecom carriers, and Stripe's hosted payment and identity pages. Their privacy practices are governed by their own policies, which we encourage you to read. Stripe, Google, Apple, PostHog, Customer.io, Nango, Cloudflare, Vercel, OpenAI, and Trustpilot each publish privacy policies on their websites.

16.2 Changes to this Policy

We may update this Policy from time to time. When we do, we will change the Last Modified date at the top. If a change materially reduces your rights or expands how we use previously collected personal information, we will give you advance notice by email or a prominent notice in the Service, and, where required, obtain your consent. Prior versions are available on request from [email protected]. Your continued use of the Service after a change becomes effective means you accept the updated Policy.

17.How to Contact Us

Questions, requests, and complaints about this Policy or our handling of personal information can be directed to us at any of the addresses below. We aim to respond to privacy requests within 30 days (45 days where permitted, with notice).

Privacy and legal requests: [email protected]

Support, data access, export, and deletion requests: [email protected]

Mail: Origns Inc., Attn: Privacy, 169 Madison Ave, Ste 2938, New York, NY 10016, United States

Help center: help.ody.co

If you are in the EEA, UK, or Switzerland and believe we have not addressed your concern, you may contact your local data protection authority. If you are a California resident, you may contact the California Privacy Protection Agency or the California Attorney General.