This Privacy Policy describes how Origns Inc. ("Origns", "Ody", "we", "us", or "our"), with its notice address at 169 Madison Ave, Ste 2938, New York, NY 10016, United States, collects, uses, discloses, retains, and protects personal information when you use Ody: the Ody web application at app.ody.co, the Ody iOS application, the Ody developer API and MCP server at api.ody.co, the Ody help center at help.ody.co, and our marketing website at ody.co (together, the "Service"). It also explains the choices and rights you have with respect to that information.
Ody is a business phone system. It is designed to be used by businesses and their team members, and it necessarily processes information about the people who call, text, or are contacted by those businesses. Please read this Policy carefully. By creating an account, using the Service, or communicating with an Ody customer through the Service, you acknowledge the practices described here. Capitalized terms not defined in this Policy have the meaning given in the Ody Terms of Service at ody.co/terms.
1.Who This Policy Covers and Our Role
Ody processes information about four groups of people. Which parts of this Policy apply to you depends on which group you belong to, and several apply to more than one.
Customers and Account Holders. The business or individual that creates an Ody workspace, agrees to our Terms of Service, and is responsible for the workspace's billing and settings (the "Customer"). For Customers and their account holders, Ody acts as an independent controller (or "business" under U.S. state privacy law) of account, billing, identity-verification, and usage information.
Team Members. People a Customer invites into its workspace to make and receive calls and texts, manage contacts, and use shared inboxes. Team Members' account information is processed as described for Customers; their activity inside a workspace (calls placed, messages sent, notes written) is Customer Content controlled by the Customer.
End Users and Contacts. People who call, text, or leave voicemails for a Customer's Ody numbers, are called or texted by a Customer, or are stored in a Customer's contact list or imported from a Customer's connected CRM or CSV file ("End Users"). Ody processes End Users' information solely as a service provider and processor on behalf of, and under the instructions of, the Customer. The Customer, not Ody, decides why and how End Users' information is collected, whether calls are recorded, and how long it is kept. If you are an End User and want to access, correct, or delete information a Customer holds about you, please contact that business directly; we will support their response as their service provider.
Visitors. People who browse ody.co or help.ody.co, watch our demo video, open a support ticket, or chat with our support assistant without an account.
"Customer Content" means the content and metadata of communications handled through a workspace and the records a Customer keeps in it: call audio and recordings, voicemails and their transcripts, text messages and media attachments, contact records, notes, tasks, tags, AI summaries and suggested replies, Astra receptionist configuration and knowledge sources, and call-flow settings. Customer Content is owned and controlled by the Customer. We process it only to provide, secure, and improve the Service as described in this Policy and in our Terms of Service.
2.The Short Version
This section summarizes the Policy. The detailed sections that follow control if there is any inconsistency.
What we collect. Account details (name, email, password or single-sign-on identity, verified mobile number), business and billing details, identity-verification results, the phone numbers you provision, and the calls, texts, voicemails, recordings, transcripts, and contacts that flow through your workspace. Automatically: device and browser information, IP-derived country, usage events, crash and error data, and push-notification tokens.
Why. To run a phone system for you: route calls and texts, store your inbox, power Astra (the AI receptionist) and other AI features you turn on, bill you, verify that you are a real business, keep the platform secure and lawful, support you, and improve the product.
Who else touches it. Infrastructure providers we need to deliver the Service, each bound by contract and listed by name in Section 8: Google Cloud (hosting, database, storage, Vertex AI, Firebase authentication and push), Stripe (payments and identity verification), OpenAI models accessed through Vercel AI Gateway (call transcription and summaries), Customer.io (email), Apple and Google (sign-in and push delivery), Nango (integrations you connect), Cloudflare (network edge), PostHog (product analytics), Google Ads (marketing measurement on ody.co), and Trustpilot (review invitations).
What we do not do. We do not sell personal information. We do not use Customer Content to train general-purpose AI models, and we do not permit our AI providers to do so. We do not upload your device's address book. We do not use advertising identifiers or cross-app tracking in the iOS app. Call recording is off by default and is never turned on without a Customer's instruction.
Where. Our systems run in Google Cloud's us-central1 region in the United States. If you use Ody from outside the United States, your information is transferred to and processed in the United States.
Your choices. You can access and update your profile in Settings, export your analytics, opt out of marketing email, reply STOP to any Ody text message, turn off push notifications on your device, and request a copy or deletion of your data by emailing [email protected]. Section 12 explains every right in detail, including rights under U.S. state laws and the GDPR.
3.Information We Collect
We collect information in three ways: you provide it to us, we collect it automatically when you use the Service, and we receive it from third parties such as sign-in providers, telecom carriers, and the integrations you connect. The tables below list each category precisely.
3.1 Information you provide to us
| Category | What it includes | When we collect it |
|---|---|---|
| Account and profile | Email address, password (stored only as a one-way hash by our authentication provider), or your Google or Apple sign-in identity; display name; optional avatar image; interface language; time zone; the country you signed up from. | When you create an account, accept an invitation, or edit your profile. |
| Verified mobile number | A personal mobile number you confirm with a one-time code during onboarding. Used to secure your account, to send service and billing texts you have agreed to receive, and as part of our fraud checks. | During onboarding and when you update it in Settings. |
| Workspace and business details | Workspace name and logo, account type, the plan you choose, the area code or numbers you pick, team member invitations (invitee email and role), business hours, and routing preferences. | During onboarding and whenever you change workspace settings. |
| Identity verification | Before a workspace can provision a phone number, the account holder verifies their identity with our provider Stripe. Stripe captures an image of a government-issued ID, a selfie, and a live capture, and compares them. Ody receives only the verification status, the verified first and last name, and the address printed on the document. Ody never receives or stores the ID images, the selfie, your date of birth, or your ID number. | Once per workspace during onboarding, and again only if verification fails or expires. |
| Messaging registration (10DLC) | To send text messages from a U.S. number, carriers require business registration: legal business name, EIN or tax ID, business address, website, a contact name and phone, and a description of your messaging use case and sample messages. | When you enable texting on a number or file a registration through the API. |
| Billing | Billing name and email, billing address, and subscription and invoice history. Card numbers are entered directly into Stripe's secure fields and are never transmitted to or stored on Ody's servers; we hold a Stripe customer reference and the card brand and last four digits Stripe returns. | When you start a trial, add a card, change plans, or buy an add-on. |
| Contacts | First and last name, company, phone numbers, email addresses, notes, tags, custom properties, and the source of the record (created manually, created automatically from an inbound call or text, imported from a CSV file, or synced from a CRM you connected). | When you add or edit contacts, upload a CSV, or connect an integration. |
| Communications content | The audio of calls you choose to record, voicemail audio and transcripts, the text and media of SMS and MMS messages you send and receive, internal notes and thread comments, tasks, and the AI summaries, tags, and suggested replies generated from those communications. | Continuously, as calls and messages flow through your numbers. |
| Astra configuration and knowledge | The instructions, greeting, voice, and transfer rules you give the AI receptionist, and the knowledge sources you add (website URLs and typed text) so it can answer questions about your business. | When you set up or edit Astra. |
| Developer platform | API key names and scopes (we store only a SHA-256 hash of each key), webhook endpoint URLs and signing secrets, and the requests made with your keys. | When you create keys or webhooks in Settings, or call api.ody.co. |
| Support | Your email address, the page you contacted us from, your messages, and the transcript of any conversation with our AI support assistant. If you are signed in, your account and workspace identifiers are attached so we can help faster. | When you open a ticket or chat on help.ody.co or in the app. |
| Marketing preferences and feedback | Your marketing email opt-in status, survey answers, and any review you choose to leave when we invite you. | When you sign up, change preferences, or respond to an invitation. |
3.2 Information we collect automatically
| Category | What it includes | Why |
|---|---|---|
| Device and connection | IP address, browser and operating-system type and version, device model, screen size, language settings, and the two-letter country code our network edge (Cloudflare) derives from your IP address. | To deliver the Service, secure your account, apply our signup eligibility rules, and understand where our users are. |
| Usage events | Pages and screens viewed, features used, buttons clicked, sign-up funnel progress, and timestamps, collected through our product-analytics provider PostHog. On app.ody.co, PostHog may also record a replay of your session (mouse movement, scrolling, and interface interactions) and capture front-end errors and console logs so we can reproduce bugs. | To understand how the product is used, find and fix problems, and improve onboarding. |
| Call and message metadata | The phone numbers involved, direction, start and end times, duration, ring and answer outcomes, carrier delivery status, and the route a call took through your call flow or Astra. | To route and bill communications, show your call and message history, and produce analytics for your workspace. |
| Server logs | Requests to our services with timestamps, IP address, request identifiers, response codes, and error details, stored in Google Cloud Logging. | To operate, debug, and secure the Service and to investigate abuse. |
| Push notification tokens | The device token issued by Apple or Google that lets us deliver notifications to your phone, and a separate VoIP push token used to ring incoming calls on iOS. | To alert you to new messages, missed calls, voicemails, and incoming calls. |
| Cookies and similar technologies | Described in detail in Section 9. | To keep you signed in, remember your language and country, and measure usage. |
3.3 Information we receive from third parties
| Source | What we receive |
|---|---|
| Sign-in providers (Google, Apple) | Your name, email address, and a unique account identifier when you choose to sign in with Google or Apple. Apple may provide a private relay email address if you choose to hide your email. |
| Telecom carriers that interconnect with Ody's network | Caller ID and caller-name (CNAM) information for inbound calls, message delivery receipts, number-porting records you authorize, and spam or fraud signals attached to inbound traffic. |
| Stripe | Payment outcomes, dispute and refund events, and identity-verification results as described in Section 3.1. |
| Integrations you connect | Contact records (name, email, phone, company, and last-updated time) synced from the CRM, help desk, e-commerce, or marketing tools you connect through our integrations directory, and the results of actions you trigger in those tools. Your login credentials for those tools are held by our integration provider Nango and are never visible to Ody staff. |
| AI assistants you connect | If you connect ChatGPT, Claude, or another agent to Ody's MCP server with your API key, we receive the requests that agent makes on your behalf. |
4.How We Use Information
We use the information described above for the following purposes. Where the GDPR or UK GDPR applies, the legal basis we rely on for each purpose is shown in the right-hand column. For Customer Content, we act on the Customer's documented instructions; the Customer is responsible for its own legal basis to collect and use End Users' information.
| Purpose | What this involves | Legal basis |
|---|---|---|
| Providing the Service | Creating and securing your account; provisioning phone numbers; connecting, routing, and recording (when enabled) calls; sending and receiving texts; storing and displaying your inbox, contacts, and history; running call flows and Astra; syncing with the integrations you connect; and delivering notifications. | Performance of our contract with you (Terms of Service). |
| AI features | Transcribing voicemails and recorded calls, generating call summaries and tags, suggesting replies, answering callers through Astra, and answering support questions. See Section 6. | Performance of our contract; your instructions when you enable each feature. |
| Billing and account management | Processing payments, running the trial and card-verification checks described in the Terms, calculating usage such as international calling, sending invoices and receipts, and recovering failed payments (including the billing reminder emails and texts described in Section 5.4). | Performance of our contract; compliance with legal obligations (tax, accounting). |
| Identity, fraud, and eligibility | Verifying that account holders are real people operating real businesses before they can obtain phone numbers, screening for fraud and telecom abuse, enforcing our signup eligibility rules, and complying with carrier registration requirements such as 10DLC. | Legitimate interests (preventing fraud and network abuse); compliance with legal and carrier obligations. |
| Communicating with you | Sending transactional email and texts about your account, security, billing, missed calls and voicemails, digests you have turned on, and product changes; responding to support requests; and, with your consent where required, sending marketing communications and review invitations. | Performance of our contract; legitimate interests; consent for marketing. |
| Security and integrity | Monitoring for unauthorized access, rate-limiting, investigating incidents, and enforcing our Terms and acceptable-use rules. | Legitimate interests (protecting the Service and our users); legal obligations. |
| Analytics and product improvement | Understanding how features are used, diagnosing errors, and improving design, reliability, and onboarding. | Legitimate interests (improving the Service); consent where required for cookies. |
| Marketing measurement | Measuring the effectiveness of our advertising on ody.co, for example whether a visitor who clicked an ad later started a trial. | Consent where required; otherwise legitimate interests. |
| Legal compliance | Responding to lawful requests, meeting telecom, tax, and consumer-protection obligations, and establishing or defending legal claims. | Compliance with legal obligations; legitimate interests. |
We may also de-identify or aggregate information so that it can no longer reasonably be linked to you or to a Customer (for example, average pickup time across all workspaces). We use and share such information for any purpose, and we commit to maintaining it in de-identified form and not attempting to re-identify it.
5.Calls, Texts, Voicemail, and Recordings
Because Ody is a phone system, communications content is at the heart of what we process. This section explains exactly what happens to it.
5.1 Calls
Calls are carried by Ody's telephony platform over the public telephone network and, for the web and iOS softphone, over encrypted WebRTC connections. For every call we store metadata (numbers, direction, timestamps, duration, outcome, and the path through your call flow). We do not store call audio unless recording is enabled for the number, or the caller leaves a voicemail.
5.2 Call recording
Recording is off by default on every number. It is enabled only at the Customer's request and applies per number. When enabled, both sides of the call are recorded from the moment it is answered; the recording is stored in Ody's private Google Cloud Storage bucket in the United States, where it remains available in the conversation until it is deleted or the account is closed. Ody does not currently play an automatic recording announcement. Many jurisdictions require notice to, or consent from, all parties before a call is recorded. The Customer is solely responsible for determining whether recording is lawful for its calls, for giving any required notices, and for obtaining any required consents. If you are an End User and believe you were recorded without appropriate notice, please contact the business you called.
5.3 Voicemail and transcription
When a caller leaves a voicemail, the audio is recorded by Ody, transcribed by Ody's speech-to-text service, and both the audio and the transcript are stored in the Customer's inbox. Recorded calls may additionally be transcribed and summarized by the AI features described in Section 6 when the Customer enables them.
5.4 Text messages
SMS and MMS content and attachments are delivered through Ody's messaging platform and stored in the Customer's inbox; media attachments are stored in our private storage. Text messages sent through Ody must comply with our Terms and carrier rules. Ody itself sends a small number of texts to account holders' verified mobile numbers: one-time verification codes, and, if a subscription payment fails, a short series of billing reminders. Reply STOP to any Ody text to stop receiving that category of message; reply HELP for help. Test-mode API keys never send real messages.
5.5 Who can see communications inside a workspace
Ody is a shared team inbox. Depending on the roles and number assignments the Customer configures, other Team Members and workspace administrators can see calls, messages, voicemails, recordings, transcripts, notes, and contacts associated with shared numbers. Administrators control who has access to what. If you are a Team Member and have questions about what your workspace's administrators can see, please ask them.
5.6 Customer Proprietary Network Information
Call detail records such as the numbers you call, when, and for how long are treated as Customer Proprietary Network Information (CPNI) consistent with U.S. Federal Communications Commission rules. We use CPNI only to provide, bill for, and protect the Service, to comply with law, and as you direct. We do not use CPNI for marketing unrelated services without your consent, and we authenticate you before disclosing call detail information over the phone or by email.
6.AI Features and Your Data
Ody includes several AI-powered features. Each one sends specific data to a specific model provider, listed below, for the sole purpose of returning the result to you. Our providers process this data as our service providers under terms that limit its use to delivering the service to us and that do not permit them to use your data to train or improve their general models. We do not use Customer Content to train general-purpose AI models ourselves.
| Feature | What is processed | Provider |
|---|---|---|
| Astra, the AI receptionist | Live audio of calls answered by Astra, the instructions and greeting you configure, the knowledge sources you add (website content and typed text), and the transfer and hang-up actions it takes. | Ody's voice AI platform (speech recognition, language model, and voice synthesis) |
| Voicemail transcription | Voicemail audio. | Ody's speech-to-text service |
| Call transcription | Audio of recorded calls, when the Customer enables call intelligence. | OpenAI Whisper model, accessed through Vercel AI Gateway |
| Call summaries and tags | The transcript of a recorded call or voicemail. | OpenAI GPT models, accessed through Vercel AI Gateway |
| Suggested replies | The recent messages in a text conversation, examples of how your team has replied before, and your Astra knowledge text. | Google Gemini on Google Cloud Vertex AI |
| Support assistant | Your support question, the conversation so far, and, if you are signed in, limited account context needed to answer it. | Google Gemini on Google Cloud Vertex AI |
| Threat assessment | Signals about inbound callers and senders used to flag likely spam or fraud in your inbox. | Processed within Ody's own systems |
AI output can be wrong. Summaries, transcripts, suggested replies, and Astra's answers are generated automatically and are not reviewed by Ody staff before you see them. You are responsible for reviewing AI output before relying on it or sending it to anyone. You are responsible for configuring Astra's greeting to disclose that callers are speaking with an automated assistant where the law requires it, and you must not configure Astra to deceive callers about its nature.
7.Push Notifications and Device Permissions
The Ody iOS app and the web app can notify you about activity in your workspace. Notifications for new messages include the sender's name or number and a preview of the message text (up to about 140 characters); notifications for missed calls and voicemails include the caller's name or number. These notifications are delivered through Apple Push Notification service and Google Firebase Cloud Messaging, which means Apple and Google carry that content in transit. You can turn notifications off, or hide previews, in your device settings at any time.
Incoming calls on iOS ring through Apple's VoIP push service and CallKit. The VoIP push carries the caller's number or name so the native call screen can display it. The iOS app requests the following permissions, each only when needed: Microphone, to speak on calls; Notifications, to alert you; and Background audio and VoIP modes, to keep calls alive and ring when the app is closed.
The iOS app does not access your device's address book, photos, camera, or location, does not use the Advertising Identifier (IDFA), and does not track you across other companies' apps or websites. It contains no third-party analytics or advertising SDKs. Contacts in the app are your workspace's business contacts, created from calls and texts, imported by your team, or synced from your CRM.
8.How We Share Information
We do not sell personal information, and we do not share it with third parties for their own marketing. We disclose personal information only in the circumstances described in this section.
8.1 Service providers and sub-processors
We rely on the following companies to operate the Service. Each processes personal information only on our instructions, under a written agreement that requires confidentiality and appropriate security, and only for the purpose listed.
| Provider | Purpose | Information processed | Location |
|---|---|---|---|
| Google Cloud (Google LLC) | Hosting and infrastructure: Cloud Run compute, AlloyDB database, Cloud Storage for recordings, voicemails, and media, Pub/Sub and BigQuery for events and analytics, Memorystore for rate limits, Secret Manager, Cloud Logging, and Vertex AI (Gemini models and text embeddings). | All Service data, including Customer Content, encrypted at rest and in transit. | United States (us-central1) |
| Firebase / Google Identity Platform (Google LLC) | Account authentication: email and password, Google sign-in, Apple sign-in; issuing the session tokens used by the web and iOS apps. Firebase Cloud Messaging relays push notifications to Apple and Android devices. | Email, hashed password, sign-in provider identity, user ID; push tokens and notification content. | United States |
| Stripe, Inc. | Payment processing, subscription billing, invoices, and identity verification (Stripe Identity). | Billing name, email, and address; payment card details (entered directly with Stripe); subscription events; government ID images, selfie, and biometric comparison data for identity verification, which Stripe processes under its own privacy policy and does not return to Ody. | United States |
| Vercel, Inc. (AI Gateway) and OpenAI, L.L.C. | Routing call-transcription and summarization requests to OpenAI's Whisper and GPT models. | Audio of recorded calls and the resulting transcripts, when call intelligence is enabled. | United States |
| Customer.io, Inc. | Sending transactional and lifecycle email (welcome, invitations, billing, missed-call and voicemail alerts, digests) and managing marketing email preferences. | Email, name, account and workspace identifiers, plan and lifecycle status, verified mobile number (for billing reminder routing), and the notification details included in each email, which may include a caller's number or a message preview. | United States |
| Apple Inc. | Sign in with Apple; Apple Push Notification service, including VoIP push for incoming calls; App Store distribution and, where used, in-app purchases. | Apple account identity; device tokens; notification and incoming-call content in transit; purchase records when billing is through Apple. | United States |
| Nango (Nango Inc.) | Secure storage of OAuth tokens and API keys for the third-party tools you connect, running contact syncs, and proxying the actions you trigger in those tools. | Your credentials for connected tools; contact records flowing between those tools and Ody. | United States |
| Cloudflare, Inc. | Network edge for ody.co and app.ody.co: DNS, TLS, DDoS protection, web application firewall, country detection, and hosting of the demo video (Cloudflare Stream). | IP address, request metadata, derived country code. | Global edge network; United States |
| PostHog, Inc. | Product analytics, error tracking, and session replay for app.ody.co and ody.co. | Usage events, device and browser information, IP-derived location, a pseudonymous identifier (linked to your user ID once you sign in), and session recordings of the interface. | United States |
| Google Ads (Google LLC) | Measuring conversions from our advertising on the ody.co marketing site. | Cookie identifiers, page views, and conversion events on ody.co. | United States |
| Trustpilot A/S | Inviting customers to leave a review after they have used Ody. | Name, email, and an order reference, transmitted in encrypted form only when we send an invitation. | Denmark / European Union |
We will update this table when we add or replace a sub-processor that processes Customer Content. Customers with a data processing agreement receive advance notice as provided in that agreement.
8.2 Within your workspace
Your name, avatar, presence, and activity are visible to other Team Members in your workspace as configured by its administrators. Customer Content is shared with the Customer's Team Members according to the roles and number assignments the Customer sets.
8.3 At your direction
When you connect an integration, place a call, send a text, forward a call to an outside number, connect an AI assistant through the developer API or MCP server, register a webhook, or export data, we disclose the information necessary to carry out that action to the recipient you chose. Those recipients, including telecom carriers and the operators of the tools and AI assistants you connect, handle the information under their own terms and privacy policies.
8.4 Legal, safety, and compliance
We may disclose information if we believe in good faith that doing so is required by law, subpoena, court order, or other legal process; to comply with telecom regulations and carrier requirements, including responding to law enforcement requests and traceback requests about unlawful robocalls or spam texts; to protect the rights, property, or safety of Ody, our users, or the public; to detect and prevent fraud, abuse, or security incidents; or to enforce our Terms of Service. Where permitted, we will notify the affected Customer of requests for its Customer Content.
8.5 Business transfers
If Origns Inc. is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will notify you by email or a prominent notice on the Service before your information becomes subject to a different privacy policy.
8.6 With your consent
We share information for any other purpose with your consent or at your direction.
9.Cookies and Similar Technologies
We use a small number of cookies and browser storage keys. None are used to build advertising profiles of you across other websites.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| ody_geo | ody.co and app.ody.co (first party) | Stores the two-letter country code derived from your IP address by Cloudflare so that signup eligibility can be checked. Contains only a country code, never your IP address. | 30 days |
| ody_locale | ody.co and app.ody.co (first party) | Remembers the language you chose in the footer language switcher or that we negotiated from your browser settings. | 1 year |
| Firebase Authentication storage | app.ody.co (first party, browser storage) | Keeps you signed in between visits. | Until you sign out |
| ph_* (PostHog) | ody.co and app.ody.co, shared across the ody.co domain | Assigns a pseudonymous identifier so that page views, product usage, errors, and session replays can be linked into a single journey, including from the marketing site into the app. | 1 year |
| _gcl_* and related (Google Ads) | ody.co | Attributes a trial signup to the advertisement that brought you to ody.co, for conversion measurement. | Up to 90 days |
| Cloudflare Stream | cloudflarestream.com (third party) | Set only if you play the demo video, to deliver and buffer the video. | Session |
Your choices. You can block or delete cookies through your browser settings; blocking first-party cookies may prevent you from signing in. To opt out of Google's advertising cookies, use Google's Ads Settings at adssettings.google.com or install the Google Analytics opt-out browser add-on. To opt out of PostHog analytics and session replay in the Ody app, email [email protected] and we will disable it for your account. We honor the Global Privacy Control browser signal on ody.co: when your browser sends it, we do not load the Google Ads measurement tag.
10.How Long We Keep Information
We keep personal information only as long as needed for the purposes described in this Policy, to meet our legal, tax, and telecom obligations, to resolve disputes, and to enforce our agreements. The table below gives our standard periods; a Customer may shorten most of them by deleting content or closing its account.
| Information | Retention |
|---|---|
| Account and workspace records | For the life of the account, then deleted or de-identified within 90 days of account closure, except as needed for the purposes below. |
| Customer Content (messages, contacts, notes, tasks, summaries) | Until the Customer deletes it or closes the workspace; then deleted with the account records. |
| Call recordings and voicemail audio | Until the Customer deletes them or closes the workspace. Stored in our private storage bucket in the United States with object versioning for accidental-deletion protection. |
| Call and message metadata (CDRs) | For the life of the account and for as long afterwards as required for billing disputes, tax, and telecom compliance, typically not more than 24 months after account closure. Event copies in our analytics warehouse expire after 13 months. |
| Identity verification | Status, verified name, and document address for the life of the account and as required for fraud prevention afterwards. Stripe retains the underlying images under its own retention policy. |
| Billing records | As required by tax and accounting law, generally 7 years. |
| Released phone numbers | Held in a 60-day quarantine after release before they can be reassigned, so a former Customer can recover a number released by mistake. |
| Support tickets and chat transcripts | Up to 3 years after the ticket is closed. |
| Server logs | Typically 30 days; security-relevant logs up to 1 year. |
| Product analytics and session replays | Session replays up to 30 days; aggregated usage events up to 12 months. |
| API idempotency records and data exports | 24 hours and 3 days respectively. |
| Backups | Encrypted database backups are rotated on a rolling schedule and expire within 35 days; deleted data may persist in backups until they expire. |
11.How We Protect Information
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, and alteration. Among other measures:
- Encryption in transit (TLS 1.2 or higher for every connection to our services; encrypted WebRTC media for softphone calls) and encryption at rest for our database, object storage, and analytics warehouse.
- Structural tenant isolation: every record belongs to a workspace, and database row-level security enforced by the database itself, not just the application, prevents one workspace's data from being read by another.
- Authentication through Google Identity Platform with hashed passwords, and support for Google and Apple single sign-on. Sign-in sessions use short-lived tokens.
- API keys are shown once and stored only as SHA-256 hashes; customer webhooks are signed so that you can verify they came from Ody; production secrets live in a managed secret store, never in code.
- Least-privilege access for our staff, with administrative tools behind identity-aware proxies and access logged. Our staff access Customer Content only to provide support you request, to investigate abuse or incidents, or as required by law.
- Independent vendors bound by data processing agreements, and infrastructure hosted on Google Cloud, which maintains SOC 2, ISO 27001, and other independent certifications.
No method of transmission or storage is completely secure. You are responsible for keeping your password and API keys confidential, for enabling the security features available to you, and for configuring who in your workspace can see what. If we learn of a security breach affecting your personal information, we will notify you and any regulator as required by applicable law.
12.Your Rights and Choices
Everyone, regardless of where they live, has the following choices with respect to information Ody holds about them.
Access and correction. Account holders and Team Members can view and update their profile, email preferences, and workspace settings at any time in Settings. You may also request a copy of the personal information we hold about you by emailing [email protected].
Export. Customers can export analytics from the app, download recordings and media from conversations, and, on request, receive an export of their workspace's contacts, messages, and call history in a machine-readable format.
Deletion. You can delete individual messages, recordings, contacts, and notes in the app. To delete your account or an entire workspace, email [email protected] from the email address on the account; we verify the request and complete deletion within 30 days, subject to the retention exceptions in Section 10 (for example, billing records we must keep by law). Workspace deletion releases its phone numbers. Where the iOS app offers an in-app account-deletion option, you may use it instead.
Marketing email. Click Unsubscribe in any marketing email or change your preferences in Settings. You will continue to receive transactional messages necessary to operate your account.
Text messages. Reply STOP to any text from Ody to stop receiving that category of message.
Push notifications and previews. Manage in your device's notification settings, or per workspace in the app.
Analytics and session replay. Email [email protected] to have PostHog analytics and session replay disabled for your account, and see Section 9 for cookie controls.
AI features. Astra, call recording, call intelligence, and suggested replies are each controlled by the Customer and can be turned off in Settings or by contacting support.
End Users. If a business that uses Ody holds information about you, please contact that business; it controls that information. If you tell us you no longer wish to be contacted by a specific Ody number, we will pass the request to the Customer, and you can always reply STOP to a text or ask the business to remove you.
To exercise any right, email [email protected] or write to the address in Section 17. We will verify your identity by confirming control of the email address on the account (and, where necessary, your verified mobile number) before acting. You may designate an authorized agent to make a request on your behalf if the agent provides proof of your written authorization and we can verify your identity. We will not discriminate against you for exercising your rights. If we decline a request, we will tell you why, and you may appeal by replying to our decision; if you remain unsatisfied you may contact your state attorney general or data protection authority.
13.Additional Disclosures for U.S. State Residents
This section supplements the rest of the Policy for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws. Depending on your state, you may have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, to obtain a portable copy, to opt out of the sale of personal information, of its sharing for cross-context behavioral advertising, of targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects, and to limit the use of sensitive personal information. Section 12 explains how to exercise these rights.
In the preceding 12 months we collected the categories of personal information listed in Section 3, from the sources listed there, for the purposes listed in Section 4, and disclosed them for business purposes to the service providers listed in Section 8.1. In California Consumer Privacy Act terms, those categories are: identifiers (name, email, phone numbers, account and device identifiers, IP address); customer records (billing name and address, payment reference, verified legal name and document address from identity verification); commercial information (plan, purchases, usage); internet and network activity (usage events, session replays, logs); audio and electronic information (call recordings, voicemails, transcripts, messages, when the Customer enables or receives them); geolocation (country-level only); professional information (business name, role, 10DLC registration details); and inferences limited to product-usage patterns and inbound spam or fraud scoring. Sensitive personal information we collect: account log-in credentials, and, through Stripe, the contents of a government ID and biometric comparison data, which Stripe processes for verification and does not return to us. We use sensitive personal information only to provide the Service, verify identity, prevent fraud, and as otherwise permitted without a right to limit.
Sale and sharing. We do not sell personal information and have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. The Google Ads conversion cookies on our marketing site ody.co may constitute "sharing" for cross-context behavioral advertising or "targeted advertising" under some state laws. You can opt out through the cookie controls in Section 9, by enabling the Global Privacy Control signal in your browser, or by emailing [email protected] with the subject "Do Not Share". We do not use those cookies on app.ody.co.
Service provider relationship. When we process End Users' information and other Customer Content on behalf of a Customer, we do so as a service provider or processor; the Customer is the business or controller. We do not retain, use, or disclose that information for any purpose other than the specific purpose of performing the Service for the Customer, as permitted by law.
Notice of financial incentive. We do not offer financial incentives in exchange for personal information. Retention. Our retention periods are set out in Section 10. Metrics. We will publish annual metrics on the privacy requests we receive when required by law.
14.Users Outside the United States
Ody is operated from the United States and is built primarily for businesses in the United States and Canada. Our servers and those of our sub-processors are located in the United States (see Section 8.1). If you access the Service from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and other countries where our providers operate, which may not offer the same level of data protection as your home jurisdiction.
14.1 European Economic Area, United Kingdom, and Switzerland
Where the GDPR, UK GDPR, or Swiss FADP applies, Origns Inc. is the controller of account, billing, and usage information and a processor of Customer Content. Our legal bases are shown in Section 4. Where we rely on consent you may withdraw it at any time without affecting prior processing. You have the rights to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority. For transfers out of the EEA, UK, and Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our sub-processors, or on other lawful transfer mechanisms. Customers in these regions may request our data processing agreement by emailing [email protected].
14.2 Canada
If you are in Canada, we process personal information in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial laws. Your information may be processed in the United States and accessed by U.S. authorities under U.S. law. You may request access to or correction of your personal information, and withdraw consent subject to legal and contractual restrictions, by contacting us as described in Section 17. Our commercial electronic messages comply with Canada's Anti-Spam Legislation and include an unsubscribe mechanism.
14.3 Other regions
Account creation is not available in some regions. If local law grants you additional rights, we will honor them to the extent required.
15.Children
Ody is a business service. You must be at least 18 years old to create an account or be a Team Member, as set out in our Terms of Service. We do not knowingly collect personal information from anyone under 18 as an account holder, and we do not knowingly collect personal information from children under 13 (or the higher age required by your jurisdiction) from any source. If you believe a child has provided us with personal information, or that an account holder is under 18, please email [email protected] and we will delete the information promptly. As a phone system, Ody may incidentally process communications from a child who calls or texts a Customer; that information is Customer Content controlled by the Customer, which is responsible for handling it lawfully.
16.Third-Party Services, Links, and Changes to This Policy
16.1 Third-party services
The Service links to and interoperates with services we do not control, including the integrations directory, the tools and AI assistants you connect, telecom carriers, and Stripe's hosted payment and identity pages. Their privacy practices are governed by their own policies, which we encourage you to read. Stripe, Google, Apple, PostHog, Customer.io, Nango, Cloudflare, Vercel, OpenAI, and Trustpilot each publish privacy policies on their websites.
16.2 Changes to this Policy
We may update this Policy from time to time. When we do, we will change the Last Modified date at the top. If a change materially reduces your rights or expands how we use previously collected personal information, we will give you advance notice by email or a prominent notice in the Service, and, where required, obtain your consent. Prior versions are available on request from [email protected]. Your continued use of the Service after a change becomes effective means you accept the updated Policy.
17.How to Contact Us
Questions, requests, and complaints about this Policy or our handling of personal information can be directed to us at any of the addresses below. We aim to respond to privacy requests within 30 days (45 days where permitted, with notice).
Privacy and legal requests: [email protected]
Support, data access, export, and deletion requests: [email protected]
Mail: Origns Inc., Attn: Privacy, 169 Madison Ave, Ste 2938, New York, NY 10016, United States
Help center: help.ody.co
If you are in the EEA, UK, or Switzerland and believe we have not addressed your concern, you may contact your local data protection authority. If you are a California resident, you may contact the California Privacy Protection Agency or the California Attorney General.