Privacy policy

Elepha

Privacy Policy — v1.0 — 17 May 2026

Your privacy matters to us. This Privacy Policy explains what information we collect when you visit the Elepha website or use the Elepha browser extension, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR).

We collect only the minimum data needed to operate this website and respond to your messages. We do not maintain user accounts or user profiles, we do not sell or rent personal data, and we do not profile our visitors. Your Elepha extension data is stored locally in your browser by default and is not sent to us.

1. Data Controller

The party responsible for processing your personal data is:

Responsible: Daniel Arroyo

Email: contact@elepha.app

This Privacy Policy will be updated whenever the responsible party or processing activities change.

2. Information We Collect

Depending on how you use the website and the browser extension, the following data may be involved:

Contact form

When you send us a message, we process the name, email address, message content, optional source information, privacy acceptance, app locale, browser language and IP address associated with your submission. This information is delivered to our company email inbox via SMTP and stored in our database so that we can manage your request.

Browser extension data, cookies and analytics

Your Elepha extension profiles, memories, prompts and AI context are stored locally in your browser by default and are not sent to us. AI chats receive only the text you choose to insert or paste, and their processing is governed by their own terms and privacy policies. On the website, we use a small set of strictly necessary cookies to keep the site working. If web analytics is enabled, additional cookies are loaded only after you give consent. See section 8 for details.

Server logs

Our hosting provider may keep short-term technical logs (IP address, user agent, requested URL, timestamp) for security and abuse-prevention purposes. These logs are not used to identify visitors.

3. Purpose and Legal Basis

We process your data for the following purposes and on the following legal bases under GDPR Article 6:

  • Reply to your contact requests and manage related follow-up — legal basis: pre-contractual measures and our legitimate interest in answering inbound enquiries.
  • Keep the website secure, prevent spam and detect abuse — legal basis: our legitimate interest in protecting the service.
  • Measure aggregated website usage (only if analytics is enabled) — legal basis: your explicit consent, which you can withdraw at any time.

4. Data Retention

Contact form submissions and related emails are kept for as long as needed to handle your request and any related follow-up, and then archived or deleted. Local extension data remains in your browser until you delete it, reset the extension, or remove the extension data from your browser. Technical server logs are retained for a short period by our hosting provider and rotated automatically. Cookies expire as listed in section 8.

5. Recipients and Processors

We do not sell or share your personal data with third parties for marketing purposes. To operate the website and contact form we rely on the following processors:

  • Hosting — Laravel Cloud (servers located in Frankfurt, European Union).
  • Email delivery — our SMTP email provider, which transports the contact form messages to our inbox.
  • Analytics providers — only when explicitly enabled and accepted by you (see section 8).

6. International Transfers

Our hosting and primary data processing take place within the European Union. If any third-party processor (for example an analytics provider) transfers data outside the EU, such transfer is performed under the safeguards required by GDPR, including the European Commission Standard Contractual Clauses.

7. Third-party Links

This website may contain links to external sites. This Privacy Policy does not apply to those sites; please review their own privacy policies before sharing personal data with them.

8. Cookies

Cookies are small text files stored in your browser. We use only strictly necessary cookies by default. Any non-essential cookie is loaded only after you give consent through the cookie banner.

Cookie nameProviderExpiryPurpose
XSRF-TOKEN (Necessary)Elephamax. 10 hoursEncrypted cookie used to prevent cross-site request forgery (CSRF) attacks.
__Secure-p-e-s-wElephamax. 10 hoursEncrypted cookie used to maintain your session on the website.
cookies:consent (Necessary)Elepha90 daysStores your cookie consent choice so the banner is not shown again on every visit.

When web analytics or marketing pixels are enabled, additional cookies are set by the following providers. Please review their privacy policies:

9. Your Rights

Under GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, as well as the right to data portability and to withdraw any previously given consent. To exercise these rights, contact us at the email address listed in section 1.

You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD — www.aepd.es) or with the data protection authority of your EU country of residence.

10. Minimum Age

This website and the browser extension are not intended for users under the age of 16. If you are younger than 16, please do not submit any form or contact us without the consent of a parent or legal guardian.

11. Browser Extension and Chrome Web Store

Use and transfer of any information received through the Elepha browser extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

The extension does not collect, transmit, sell or share user data. Your profiles, memories, prompts and settings are stored locally in your browser. This data is never used or transferred for advertising or any unrelated purpose, and no human reads it. Text is sent to an AI chat only when you choose to insert or paste it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version is always available on this page. Material changes will be reflected in the version number and date shown at the top of this document.