Ellydee Privacy Policy
1. Introduction
At Ellydee, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our mobile application, or interact with our services (collectively, the "Services"). Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by all the terms outlined in this Privacy Policy. If you do not agree to these terms, please discontinue use of our Services immediately.
This Privacy Policy applies to all information collected through our Services, as well as any related services, sales, marketing, or events.
2. What We Collect (And What We Absolutely Do Not)
At Ellydee, we believe your thoughts belong to you—and only you. We are engineered on the principle of cognitive liberty: your prompts, conversations, and queries are never logged, stored, trained on, or shared. Ever.
That said, to provide you with a functional account and comply with legal and security necessities, we collect only the minimum essential data—and nothing more. Below is a full, transparent accounting of what that is.
2.1 Account & Authentication Data (Required for Service)
To let you log in, manage your account, and contact support, we collect only what's necessary:
- Email address (used solely for login and critical account communications)
- Account password (securely hashed—never readable by us)
- Basic profile preferences (e.g., display name, theme choice)
Note: We do not require your real name, phone number, physical address, or government ID. If you choose to provide payment details (for premium features), those are handled by PCI-compliant third parties—we never store your credit card number.
2.2 Technical & Diagnostic Data (Never Linked to Your Prompts)
To keep our service running smoothly and securely, we collect anonymous, non-identifying technical logs. This data is never associated with your conversation history or prompt content:
- Basic usage metrics: Feature access timestamps, session duration (aggregated, not tied to identity)
- Device & browser type: OS, browser version, screen size (for compatibility)
- IP address: Temporarily logged for security (e.g., detecting brute-force attacks) and deleted within 24 hours
- Crash/error reports: Anonymous diagnostics to fix bugs—never includes your input text
2.3 What We Do Not Collect
We want to be unequivocal:
- No prompt content is ever stored, logged, or transmitted beyond real-time processing outside the boundaries defined by your own preferences or actions (such as deleting a conversation).
- No conversation history is retained on our servers after you delete it or if it deletes itself after your set period of time
- No behavioral profiling or interest tracking occurs
- No third-party analytics (e.g., Google Analytics, Meta Pixel) are used
- No advertising IDs or cross-site tracking cookies
2.4 Cookies & Local Storage
We use only essential, first-party cookies to maintain your session and preferences. These are strictly necessary for functionality and expire when you log out or close your browser. We do not use tracking or advertising cookies.
2.5 Third-Party Data
We do not buy, sell, or receive your personal data from data brokers, social media platforms, or public records. If you choose to sign in via a third-party provider (e.g., Google), we only request your email and profile name—and you can revoke this at any time.
3. How We Use Your Data
We use the minimal data we collect for one purpose: to operate a secure, private, and functional service. Nothing more.
3.1 Service Operation
- Authenticate your account and maintain session security
- Process payments (via secure third parties, if applicable)
- Respond to support requests
- Prevent abuse, fraud, and system attacks (e.g., rate limiting, IP-based threat detection)
3.2 Legal Compliance
- Fulfill legal obligations (e.g., tax records for paid plans, court orders where legally required)
- Protect the safety of our users and infrastructure in rare, extreme cases (e.g., credible threats of violence)
We do not:
- Use your data to train AI models
- Personalize content based on your behavior
- Send marketing emails without explicit opt-in
- Share your data with advertisers, partners, or affiliates
4. Your Right to Be Forgotten
You own your data—and your right to delete it is absolute.
At any time, you can:
- Delete your account instantly via your account settings
- Permanently erase all associated data (including email, preferences, and logs)
- Request a data export of what little we hold
Upon deletion, all data is purged from our systems within 24 hours, including backups. No exceptions.
This applies globally—not just in the EU. We don’t treat privacy as a regional privilege. Privacy is a universal right.
5. Specific Security & AI Commitments
In addition to the general practices outlined above, Ellydee adheres to the following strict operational and legal covenants regarding your content.
5.1 Zero-Access Human Review Policy
Human Access to Content
Ellydee maintains a strict "Zero-Access" policy regarding User Content. No employee, contractor, agent, or affiliate of the Company shall access, view, read, or review the substance of any user inputs or outputs generated during your use of the Service. While the Company employs automated systems for security and operational integrity (e.g., to filter malicious code or prohibited content), these systems are purely algorithmic. There are no human safety reviewers, no "human-in-the-loop" oversight, and no manual review processes. The Company explicitly covenants that no human being will view your data for any purpose, including safety, training, or quality assurance.
5.2 Non-Training of Models
Use of Data for Artificial Intelligence
Ellydee does not and will not use any User Content to train, fine-tune, retrain, or otherwise improve its artificial intelligence models, algorithms, or underlying software infrastructure. Your inputs and the resulting outputs are not utilized for machine learning purposes, product development, or derivative data generation. We do not bake your data into our models. User Content is processed solely to generate the immediate response requested by the user and is not aggregated or analyzed for model advancement.
5.3 Data Minimization, Encryption, and Deletion
Data Retention and Security
We adhere to a principle of strict data minimization. All User Content is encrypted at rest using industry-standard AES-256 encryption (or stronger). User Content is retained in our systems solely for the duration of the active session or for a defined short period necessary for the transmission of the output to the user, not to exceed 24 hours. Upon the conclusion of this retention period, all User Content is permanently and irrecoverably deleted from our servers. We do not maintain backups, archives, or logs of User Content once the deletion process is complete. We do not retain data "just in case" or for indefinite storage.
5.4 Resistance to Legal Process
Government Requests and Legal Process
Ellydee will not voluntarily disclose User Content to any third party, including government authorities, absent your express consent. In the event we receive a subpoena, court order, search warrant, or other compulsory legal process seeking User Content, we commit to the following: (a) we will notify the affected user promptly via secure electronic means prior to disclosure, unless prohibited by a gag order or specific statute; and (b) we will assert all available legal objections and defenses on the user's behalf, including but not limited to motions to quash, claims of lack of jurisdiction, and objections based on attorney-client privilege and work product protection. We will act as a steadfast custodian of your data, challenging legal requests to the fullest extent of the law before complying.
5.5 Affirmative Statement of Confidentiality
Confidentiality Covenant
Ellydee acknowledges that users may input highly confidential, privileged, trade secret, or legally sensitive information into the Service. The Company agrees to treat all User Content as strictly confidential. The Company will not disclose, access, distribute, or commercialize such information except as strictly necessary to provide the technical functionality of the Service (e.g., generating the text response). This Agreement creates a binding contractual duty of confidentiality, requiring the Company to protect User Content with the same degree of care it uses to protect its own proprietary information, but in no event with less than a reasonable degree of care.
5.6 Preservation of Privilege and Agency Status
Attorney-Client Context and Agency
Ellydee acknowledges that the Service may be used by attorneys, law firms, and their clients in connection with the provision of legal services. For the avoidance of doubt, the Company agrees that when the Service is used at the direction of an attorney for the purpose of legal representation, the Company functions solely as a tool or agent of the attorney (or the client acting under the attorney's direction). The Company claims no independent interest in the User Content and agrees that its role is purely ministerial. This section is intended to ensure that the transmission of information to the Company does not constitute a waiver of attorney-client privilege or work product protection under applicable law.
6. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Ellydee Email: hello@ellydee.ai