Legal · last updated 4 October 2026

Privacy Policy

This policy explains what Elpis collects, why, and who processes it. The short version: we collect what the product needs to work, we do not sell data, and we do not run tracking or advertising cookies.

1. What we collect

  • Account data: username or email, a password hash (we never store your plain password), and your role.
  • Incident data: incidents you create or inject, their evidence, timelines, approvals and remediation records.
  • Settings and keys: LLM endpoints and API keys you choose to save, and an optional GitHub token. Keys are encrypted at rest and never returned by the API after you save them.
  • Usage records: actions taken in the app, token usage and per-incident cost accounting, kept for budgets and audit trails.
  • Communications: anything you send us, including apply-form submissions (name, email, company, team size, stack, goal) and support email.
  • Technical logs: standard server logs used for security and debugging.

2. How we use it

  • To provide the service: authenticate you, isolate your data, run investigations, and show results to your account only.
  • To run AI analysis: with your own key, requests go to the provider you configured; without one, they go to our built-in model, then to a rules-based fallback.
  • To keep the service safe: prevent abuse, debug failures, and enforce budgets and limits.
  • To respond to you: support, apply-form conversations, and billing discussions for paid work.

Legal grounds: performing our contract with you (running the service) and our legitimate interest in keeping it secure and improving it.

3. Your keys are different

We treat saved keys as secrets: AES-256-GCM encrypted at rest with a server-side key, write-only through the API, masked in the interface. Keys are used only to call the provider endpoints you configure. When you connect a provider, incident content is transmitted to that provider under your relationship and your agreement with them, so their privacy terms apply to that transfer.

4. Who processes your data

We do not sell or rent personal data. We use subprocessors to run the service, and the current list with purposes is on our Subprocessors page. We may also disclose data if required by law.

5. Retention and deletion

We keep account and incident data while your account is active. You can request deletion at any time by email, and we will remove your account data from active systems; encrypted backups age out on their normal rotation. Support and apply emails are deleted once no longer needed. Audit and cost records tied to shared demo data may be retained to keep the demo consistent.

6. Security

We encrypt data in transit (HTTPS), encrypt keys at rest, hash passwords with pbkdf2-sha256 and per-user salts, isolate data per account, and gate remediation behind explicit human approval. Full detail is on our Security page. No system is perfectly secure, so please use strong unique passwords and revoke keys you believe are exposed.

7. International transfers

Our providers may process data in countries other than yours. Where a transfer requires a legal safeguard, we rely on standard contractual clauses or an equivalent mechanism.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, delete or object to the processing of your personal data. Email us and we will act on verified requests. You may also complain to your local data protection authority.

9. Children

Elpis is a product for businesses and is not directed at children under 18, and we do not knowingly collect data from them.

10. Cookies

We do not use tracking or advertising cookies. Sign-in state is stored in your browser's local storage, which is strictly necessary for the app to work. Details are in our Cookie Policy.

11. Contact

Privacy questions and data requests: notsekiro11@gmail.com.