Privacy Policy

Last updated: December 15, 2025

This Privacy Policy describes how Elephantasm ("we", "us", or "our") collects, uses, and shares information about you when you use our website, platform, and services (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information You Provide

  • Account Information: When you create an account, we collect your email address, name, and authentication credentials.
  • User Content: Data you submit to the Service, including events, memories, knowledge entries, and agent configurations stored within your Animas.
  • Communications: Information you provide when you contact us for support, submit feedback, or participate in surveys.
  • Payment Information: If you purchase paid features, our payment processor (Stripe) collects billing details. We do not store full payment card numbers.

1.2 Information Collected Automatically

  • Device Information: Browser type, operating system, device identifiers, and hardware specifications.
  • Usage Data: Pages visited, features used, time spent on pages, click patterns, and navigation paths.
  • Log Data: IP address, access times, referring URLs, and error logs.
  • Cookies and Similar Technologies: We use cookies, local storage, and similar technologies as described in Section 8.

1.3 Information from Third Parties

  • Authentication Providers: If you sign in via third-party services (e.g., Google, GitHub), we receive basic profile information from those providers.
  • Analytics Partners: We may receive aggregated analytics data from service providers.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Operate, maintain, and deliver the features and functionality of the platform.
  • Process Your Content: Store, retrieve, and process your User Content to enable memory synthesis, knowledge extraction, and pack compilation.
  • Improve the Service: Analyze usage patterns to enhance performance, fix bugs, and develop new features.
  • Communicate with You: Send service-related announcements, security alerts, and support messages.
  • Process Payments: Facilitate transactions and manage billing for paid features.
  • Ensure Security: Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Comply with Law: Meet legal obligations, respond to lawful requests, and protect our rights.

3. AI Processing and Training

AI-Powered Features. The Service uses artificial intelligence to synthesize memories, extract knowledge, and generate insights from your User Content. This processing is performed to deliver core functionality, not for model training purposes.

No Training Without Consent. We do not use your User Content to train, fine-tune, or improve machine learning models or AI systems without your explicit consent. Your data remains yours.

Third-Party AI Providers. We use third-party AI services (such as OpenAI and Anthropic) to process certain requests. When your content is sent to these providers, it is subject to their respective privacy policies and data handling practices. We select providers that offer appropriate data protection commitments.

Embeddings and Vectors. We generate vector embeddings from your content for semantic search functionality. These embeddings are mathematical representations stored within your account and are not shared externally.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: We share information with vendors who help us operate the Service, including cloud hosting (e.g., Supabase, Fly.io), payment processing (Stripe), analytics providers, and AI service providers. These providers are bound by confidentiality obligations.
  • Legal Requirements: We may disclose information if required by law, court order, or government request, or to protect the rights, property, or safety of Elephantasm, our users, or others.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
  • With Your Consent: We may share information for other purposes with your explicit consent.

No Advertising. We do not share your User Content with third parties for advertising or marketing purposes.

5. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy. Specifically:

  • Account Data: Retained while your account is active and for a reasonable period thereafter to comply with legal obligations.
  • User Content: Retained until you delete it or close your account. Upon account deletion, we will delete or anonymize your content within 30 days, unless retention is required by law.
  • Usage Data: Typically retained for up to 24 months for analytics purposes, then aggregated or deleted.
  • Legal Holds: We may retain information longer if required for legal proceedings, investigations, or compliance.

6. Your Rights and Choices

6.1 All Users

  • Access and Update: You can access and update your account information through your account settings.
  • Delete Content: You can delete your User Content (events, memories, knowledge) at any time through the platform.
  • Close Account: You can request account deletion by contacting us. We will process your request within 30 days.
  • Email Preferences: You can opt out of marketing emails using the unsubscribe link. Service-related communications cannot be opted out of while you maintain an account.

6.2 European Economic Area, UK, and Switzerland

If you are in the EEA, UK, or Switzerland, you have additional rights under GDPR:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure: Request deletion of your personal data in certain circumstances.
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To exercise these rights, contact us at support@elephantasm.com. You also have the right to lodge a complaint with your local data protection authority.

6.3 California Residents

Under the California Consumer Privacy Act (CCPA), California residents have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of personal information
  • Opt out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising privacy rights

7. Legal Basis for Processing

For users in the EEA and UK, we process personal data under the following legal bases:

  • Contract: Processing necessary to provide the Service you requested.
  • Legitimate Interests: Processing for our legitimate business interests, such as improving the Service, ensuring security, and communicating with you, where these interests are not overridden by your rights.
  • Consent: Processing based on your consent, which you may withdraw at any time.
  • Legal Obligation: Processing necessary to comply with applicable laws.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Service, remember your preferences, and analyze usage. The types of cookies we use include:

Essential Cookies

Required for the Service to function. These include authentication tokens, session identifiers, and security cookies. You cannot opt out of essential cookies.

Functional Cookies

Remember your preferences and settings to enhance your experience.

Analytics Cookies

Help us understand how users interact with the Service. We may use services like Google Analytics or PostHog to collect aggregated usage data.

Managing Cookies

You can control cookies through your browser settings. Note that disabling certain cookies may affect Service functionality. Most browsers allow you to:

  • View and delete cookies
  • Block third-party cookies
  • Block all cookies
  • Clear cookies when you close your browser

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our servers and service providers are located.

When we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we use appropriate safeguards such as:

  • Standard Contractual Clauses approved by the European Commission
  • The EU-U.S. Data Privacy Framework and UK Extension, where applicable
  • Other legally recognized transfer mechanisms

10. Security

We implement commercially reasonable technical, administrative, and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication mechanisms
  • Access controls and audit logging
  • Regular security assessments
  • Row-level security for multi-tenant data isolation

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.

11. Children's Privacy

The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible.

If you believe we have inadvertently collected information from a child, please contact us at support@elephantasm.com.

12. Third-Party Links

The Service may contain links to third-party websites or services that are not owned or controlled by Elephantasm. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also provide notice via email or through the Service.

Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Elephantasm

Privacy Inquiries: support@elephantasm.com

General Contact: support@elephantasm.com

Website: elephantasm.com

By using Elephantasm, you acknowledge that you have read and understood this Privacy Policy.