This Privacy Policy explains how Concierge collects, uses, discloses, and retains information when you visit our site or use our communications service. Concierge is designed to leave semantic conversation history with the native orchestrator rather than building a competing transcript database.
1. Information we collect
Account and purchase information
We may receive your name, email, billing address, subscription status, Stripe customer and subscription identifiers, invoices, and limited payment metadata. Stripe processes full payment-card details; Concierge does not need to store them.
Telephone and service information
We process assigned and contacted phone numbers, call and message direction, timestamps, duration, delivery state, routing and thread references, carrier identifiers, provisioning state, usage, permissions, spend limits, and fraud or abuse signals.
Content and media
Live audio and message content must transit Concierge and relevant providers to deliver the Service. Our architecture does not treat realtime transcript or audio notifications as Concierge’s canonical semantic conversation history. Codex or another supported native host owns its conversation history under its own terms. We do not record calls by default unless a feature clearly says otherwise and the required consent has been obtained.
Technical information
We may collect IP address, browser and device information, approximate region, request and security logs, referral data, cookie or session identifiers, and diagnostic information. We seek to minimize model-visible logs and exclude ordinary secrets.
2. How we use information
- Provide, route, provision, bill, and support calls, messages, numbers, plugins, and MCP tools.
- Authenticate requests, enforce ownership and permissions, prevent replay and fraud, and protect service integrity.
- Apply your communication preferences, quiet hours, limits, and authorized routing context.
- Reconcile uncertain carrier or payment outcomes and prevent duplicate external actions.
- Comply with legal, tax, carrier, and regulatory requirements.
- Understand aggregate reliability and improve the Service.
3. How we share information
We share information only as needed with service providers and recipients. These may include telecommunications carriers such as Telnyx, payment processors such as Stripe, infrastructure and security vendors, and OpenAI or another native orchestration host you direct us to use. A call or message necessarily exposes relevant content and contact information to its recipient and network providers.
We may disclose information to comply with law, protect people or the Service, investigate abuse, complete a corporate transaction, or with your direction. We do not sell personal information or share it for cross-context behavioral advertising.
4. OpenAI and native Codex
For the Codex live integration, Concierge uses your existing Codex environment and ChatGPT-managed Codex authentication. The website does not ask for or store your ChatGPT password or OpenAI access token. OpenAI processes the native orchestration conversation under the terms and controls applicable to your account. Concierge stores the associated Codex thread reference only when needed for continuity and routing.
5. Retention
We retain account, billing, number ownership, authorization, operation, webhook, policy, and routing records for as long as necessary to provide the Service, meet legal obligations, resolve disputes, and prevent fraud. Security and diagnostic logs are retained for a limited operational period. Retention periods should be finalized and published before public launch. Codex-owned conversation history follows your OpenAI account settings and OpenAI’s policies.
6. Security
We use technical and organizational safeguards designed for the sensitivity of the Service, including verified webhook boundaries, request-scoped authorization, least-privilege secret handling, encrypted transport, idempotency controls, and fail-closed live media behavior. No system is perfectly secure. Do not send passwords, API keys, full card numbers, or similarly sensitive secrets through ordinary conversations.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to appeal a decision. You may update billing through Stripe, communication policy through the Concierge plugin, and Codex history through OpenAI’s controls. We may need to verify your identity before fulfilling a request.
8. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal information.
9. International processing
Our providers and telecommunications networks may process information in countries other than yours. Cross-border transfer mechanisms and supported launch regions must be finalized before service is offered in those jurisdictions.
10. Changes
We may update this Policy as the Service evolves. We will post the updated date and provide additional notice when changes are material.
Contact
Questions about this document may be sent through Contact the project.