This Privacy Policy explains how SEA & SEA LLC, a Texas limited liability company based in San Antonio, Texas, United States, collects, uses, discloses, and retains information when you visit our site or use Concierge. Concierge is designed to leave semantic conversation history with the native orchestrator rather than building a competing transcript database.
1. Information we collect
Account and purchase information
We may receive your name, email, billing address, subscription status, Stripe customer and subscription identifiers, invoices, and limited payment metadata. Stripe processes full payment-card details; Concierge does not need to store them.
Telephone and service information
We process assigned and contacted phone numbers, call direction, timestamps, duration, routing and thread references, carrier identifiers, provisioning state, usage, permissions, spend limits, setup-verification state, and fraud or abuse signals.
Contacts and bounded workflow information
When you ask Concierge to remember or use a contact, we may store owner-managed contact information such as a name, organization, relationship or category, and limited notes you provide. To preserve authorized workflow continuity, Concierge may also retain a bounded structured result from supported call-related work, such as a concise outcome or summary, decisions or facts obtained, an unresolved blocker or status, and safe references needed to continue the trusted workflow.
Work Awareness preview
Work Awareness is an unreleased, optional feature. If you enable it in a supported future version, trusted native Codex work may maintain up to 24 short current updates for your owner-only phone briefing. Each update contains a topic, summary, optional next step, source references, revision, and expiry. An update may also include a known GitHub repository owner, name, and branch so your native assistant can try reading pushed work when a computer is unavailable. The reference expires with the update; Concierge does not store GitHub credentials or copy repository contents for this feature. Updates expire after four hours by default, with a maximum lifetime of 24 hours, and expiry schedules removal of their content. Turning the feature off clears the stored updates. This does not erase information already delivered into your native Codex conversation history. Work Awareness does not retain an update history or record calls.
Content and media
Live call audio must transit Concierge and relevant providers to deliver the Service. Our architecture does not treat realtime transcript or audio notifications as Concierge’s canonical semantic conversation history, and Concierge does not record calls by default unless a feature clearly says otherwise and the required consent has been obtained. Codex owns the current beta phone conversation history under the terms and controls applicable to your OpenAI account.
Technical information
We may collect IP address, browser and device information, approximate region, request and security logs, referral data, cookie or session identifiers, and diagnostic information. We seek to minimize model-visible logs and exclude ordinary secrets.
2. How we use information
- Provide, route, provision, bill, and support calls, numbers, setup verification, plugins, and MCP tools.
- Execute authorized communications and preserve bounded continuity, including returning structured call-related results to the trusted workflow.
- Authenticate requests, enforce ownership and permissions, prevent replay and fraud, and protect service integrity.
- Apply your communication preferences, quiet hours, limits, and authorized routing context.
- Reconcile uncertain carrier or payment outcomes and prevent duplicate external actions.
- Comply with legal, tax, carrier, and regulatory requirements.
- Understand aggregate reliability and improve the Service.
3. How we share information
We share information only as needed with service providers and call recipients. These may include telecommunications carriers such as Telnyx, payment processors such as Stripe, infrastructure and security vendors, and OpenAI for the supported native orchestration path. A call necessarily exposes relevant audio and contact information to its recipient and network providers; setup verification may expose the destination number and delivery metadata to the verification provider.
We may disclose information to comply with law, protect people or the Service, investigate abuse, complete a corporate transaction, or with your direction. We do not sell personal information or share it for cross-context behavioral advertising.
4. OpenAI and the current Codex phone target
Codex/native orchestration is the current public-beta Concierge phone target. Concierge uses the existing OpenAI host surface and its account authorization, while the website does not ask for or store your ChatGPT password or OpenAI access token. OpenAI processes the Codex thread and host-owned conversation history under the terms and controls applicable to your account. Concierge does not build a separate canonical transcript or general personal-memory database. Concierge may retain limited operational and user-directed structured data needed to operate the communications service, including owner-managed contact information and notes, bounded call-related workflow results, routing and continuity metadata, and opaque thread references. ChatGPT Work and Workspace Agents are not currently selectable Concierge Voice phone targets.
5. Retention
Concierge keeps core account and identity records, subscription and billing references, telephone-number ownership and provisioning records, call and service metadata, owner-managed contact metadata and limited notes, bounded structured call-related workflow results, authorization and security records, routing and thread references, and provider webhook, idempotency, and reconciliation records for as long as reasonably necessary to provide and secure the Service, maintain billing and resource history, preserve authorized continuity, reconcile external actions, comply with legal, tax, carrier, and regulatory obligations, resolve disputes, and prevent fraud or abuse. The current implementation does not impose one fixed deletion period across all of those durable record types.
Support requests remain while they are open. After a request is closed, the current beta implementation schedules deletion of the closed support request after 180 days. Security and diagnostic logs or telemetry are kept for bounded operational and security needs under the retention configured for the relevant system or provider rather than a single repository-wide deadline.
Live call audio is streamed for the call and is not recorded by default. Where Concierge creates temporary media for a supported feature, that media is subject to feature-specific expiry and cleanup rather than being kept as canonical conversation history. Codex-owned conversation history follows your OpenAI account settings and OpenAI’s policies.
6. Security
We use technical and organizational safeguards designed for the sensitivity of the Service, including verified webhook boundaries, request-scoped authorization, least-privilege secret handling, encrypted transport, idempotency controls, and fail-closed live media behavior. No system is perfectly secure. Do not send passwords, API keys, full card numbers, or similarly sensitive secrets through ordinary conversations.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to appeal a decision. You may update billing through Stripe, communication policy through the Concierge plugin, and Codex history through OpenAI’s controls. We may need to verify your identity before fulfilling a request, and some records may need to be retained where required for legal, security, fraud-prevention, carrier, billing, or dispute purposes.
8. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal information.
9. United States beta and international processing
The initial public beta is offered in the United States. Our providers and telecommunications networks may process information in other locations as necessary to provide, secure, support, or comply with requirements applicable to the Service. This Policy does not make a certification about international-transfer mechanisms for jurisdictions in which Concierge is not currently offered.
10. Changes
We may update this Policy as the Service evolves. We will post the updated date and provide additional notice when changes are material.
Contact
Questions about this document may be sent through Support.