Privacy
| Data | Why | How long | |
|---|---|---|---|
| Intake answers (the fourteen inputs) | They are the read. Without them there is no output. | For the life of the account. Anonymous intakes: 12 months, then deleted. | |
| Reads and decision-log entries | Your file: position, confidence, window, counter-case, and what you recorded happened. | For the life of the account. | |
| Terminal chat logs | To keep a conversation coherent across messages, and to show you the thread again later. | For the life of the account, or until you delete the thread. | |
| Date of birth — optional | Reduced to an age band before it reaches the model. Nothing is cast from it and the read is identical without it. | Until you clear it in your account, or delete the account. | |
| Email address | Sign-in codes, the renewal notice, and anything you asked to receive. | For the life of the account. | |
| Analytics events | Page views, step drop-off, device class, coarse country, first-touch campaign tags. First-party only — no third-party tracker, no advertising pixel, no cross-site profile. | 24 months, then aggregated and the raw rows dropped. | |
| Payment records | Plan, amount, renewal date and Stripe identifiers, so we can bill, renew and refund correctly. | As long as tax and accounting law requires. Card numbers never reach us. | |
| Technical logs | Errors, rate-limit counters, and hashed IP addresses for abuse prevention. Addresses are hashed, not stored in the clear. | 90 days. |
Cookies
Three, all first-party, none for advertising:
st_session— set when you sign in. Holds a signed token identifying your session. Removed when you sign out.st_anon— a random identifier with no name attached to it, set on your first visit so an anonymous intake and its read can find each other, and so page views can be counted without identifying you. Expires after a year.st_attr— first-touch campaign tags, if you arrived from a link that carried them. Expires after 90 days.
No analytics or advertising cookie is set by a third party, because no third-party analytics or advertising script is loaded.
Who your data is sent to
Four categories of processor, and no-one else:
- The model provider — your intake answers and chat messages are sent to the configured provider (Anthropic, OpenAI or Google, depending on the route set in the admin) to generate output. Your date of birth is not sent; only an age band is. We do not permit the use of your content for training.
- Hosting and database — the servers that run the application and store your rows.
- Stripe — payments. They handle card data; we never see it.
- The email provider — sign-in codes, renewal notices and dispatch emails if you enable them.
Your data is not sold, rented, or shared with data brokers or advertising networks. There is no such deal.
Why we are allowed to hold it
To perform the contract you entered into when you used the service (intake, reads, chat, billing); for our legitimate interest in keeping the product working and free of abuse (rate limits, error logs, first-party analytics); and for consent where you gave it (marketing email, dispatch email). Consent can be withdrawn at any time in your account without losing anything you paid for.
How to delete it
- Delete your account — account page, one confirmation. Removes intakes, reads, chat threads, the decision log and your profile. Billing records that tax law requires us to keep are retained in a form that no longer identifies your content.
- Delete one thing — individual reads, chat threads and the date of birth can be removed on their own.
- Export — a machine-readable copy of everything is available from the account page.
- By email — write to support@eldr.space from the address on the account. Requests are completed within 30 days, usually within two working days.
Anonymous intakes are keyed to the st_anon cookie. If you never made an account, clearing that cookie leaves the row unreachable, and it is deleted on the 12-month schedule regardless.
Your rights
Depending on where you live you have the right to access, correct, export, restrict or delete your personal data, to object to processing based on legitimate interest, and to complain to your data protection authority. We do not make automated decisions that produce legal effects about you — the output of this product is a second opinion, not a determination.
Security
Traffic is encrypted in transit. Sessions can be revoked server-side. Provider API keys are encrypted at rest. IP addresses are hashed before storage. Access to production data is limited to the people who operate the service. No system is perfect; if there is a breach affecting you, you will be told, and told what to do about it.
Children
The service is for adults, 18 and over. We do not knowingly collect data about children. If you believe a child has used the service, write to support@eldr.space and the data will be deleted.
Changes
If this notice changes materially, account holders are emailed at least seven days before it takes effect, and the effective date at the top of this page changes.
Contact
Data questions, export requests, deletion requests, complaints: support@eldr.space. One address, answered by a person.