1. Scope and roles
This policy applies to EchoCody-controlled websites and services. For client deployments, the client may control prospect data while EchoCody acts as a service provider or processor under the signed agreement. A client’s own privacy notice may also apply.
2. Information we may process
Depending on the interaction and enabled services, we may process contact details, business information, website activity, appointment data, CRM identifiers, campaign attribution, call metadata, recordings, transcripts, messages, consent and opt-out records, agent tool results, pipeline events, support communications, and billing or contract records.
Payment-card credentials are collected through an approved payment processor’s hosted checkout or secure billing surface, not through EchoCody application fields. EchoCody is designed to retain only limited billing metadata such as provider customer and payment-method references, card brand and last four digits when supplied by the processor, expiration, consent records, transaction status, invoices, refunds, disputes, and receipt identifiers. EchoCody does not intentionally store full card numbers, card verification values, PINs, track data, or card images.
3. AI voice, recording, and disclosure
Calls may involve an automated AI agent and an authorized synthetic or cloned version of the founder’s voice. The system is designed to identify the business and automated nature of the interaction where required. Calls or messages may be recorded or transcribed only when enabled and subject to applicable notice, consent, and recording laws. Do not use the service for an emergency.
4. How information is used
We use information to respond to inquiries, provide contracted services, qualify and route requests, schedule appointments, maintain CRM records, create evidence-bound notes and tasks, measure verified outcomes, secure the service, prevent misuse, support clients, improve approved workflows, and meet legal or contractual obligations. Provider-generated summaries are treated as synthesis and kept separate from source-authenticated facts and verbatim statements.
5. How information is shared
Information may be shared with the applicable client and contracted providers that support CRM, AI voice, telephony, hosting, security, analytics, scheduling, email, SMS, document delivery, and payments. Access is intended to be limited to the service purpose. We do not sell or rent personal information.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use-case categories exclude text-messaging originator opt-in data and consent; this information will not be shared with third parties.
6. SMS and communication choices
Where text messaging is enabled, message frequency varies and carrier message or data rates may apply. Reply STOP to opt out and HELP for help. Consent is not a condition of purchase unless expressly stated and lawful. Reasonable revocation requests are routed for suppression.
7. Retention and deletion
Information is retained only as reasonably needed for service, security, audit, dispute, and legal purposes or as required by a signed agreement. Retention varies by data type, client instruction, provider setting, and law. EchoCody is designed to redact identity from analytics where full identity is unnecessary and to keep client data tenant-scoped.
8. Security
We use measures intended to protect data, including restricted access, server-side secrets, authenticated webhooks, redacted ledgers, controlled deployment boundaries, and transport security. No method of storage or transmission is completely secure, and this policy does not promise absolute security.
9. Your requests
Subject to applicable law and the relevant client relationship, you may request access, correction, deletion, or information about processing by emailing us. We may need to verify identity and may direct a client-controlled request to the applicable client.
10. Sensitive and professional information
Never provide payment-card credentials to an EchoCody voice agent or through a call recording, voicemail, transcript, SMS, email, chat, CRM note, support ticket, or ordinary web form. Use only the approved processor-hosted checkout or billing portal. Do not submit emergency information, government identifiers, medical records, privileged legal material, or other sensitive information unless a signed deployment specifically authorizes and protects that use. EchoCody does not provide legal, medical, financial, or other professional advice.
11. Children, location, and changes
The services are for businesses and adults and are not directed to children under 18. Information may be processed in the United States and other locations used by contracted providers. We may update this policy and will post a revised effective date.
12. Contact
North Star Intelligence LLC, a Utah limited liability company organized in 2026 and operating EchoCody AI · Utah, United States · echocodyai@gmail.com · (801) 980-0308.