Privacy Policy
Elyan is an intelligence-powered agent system that separates a local-first architecture from a hosted control plane. This policy explains what data we process, why we process it, how permissions work, and how to request account or data deletion. Effective date: June 22, 2026.
1. Scope and contact
This policy applies to the Elyan website, Elyan Mobile, Elyan Desktop, and Elyan control-plane services.
For privacy, account, access, correction, export, or deletion requests, contact us at support@elyan.dev.
2. Data categories we process
Account data: email address, user ID, session details, authentication method, and records required for secure account management.
Device and pairing data: paired device identifiers, device type, connection state, runtime readiness, last heartbeat, and technical metadata required for safe task routing.
Task and conversation data: prompts, task states, responses, artifact metadata, errors, and limited context required for conversation continuity.
Support data: contact details, messages, and additional information you send when requesting help.
Subscription data: subscription status, plan information, and store-provided transaction metadata required for verification. Elyan does not store full payment card details.
3. Permissions, world signals, and sensitive context
Elyan requests permissions only for features you enable. Calendar, time, device state, notifications, health or activity signals, and similar device context are not used without permission.
When supported, these signals are processed as limited and summarized context packages to improve task quality rather than as a raw daily data dump. Examples may include high-level sleep, energy, activity, or workload signals.
Health and wellbeing signals are not used for medical diagnosis, treatment, emergency assessment, or creation of a permanent health profile. Elyan is not a medical or emergency service.
4. Local-first architecture and file processing
Elyan Desktop keeps a local-first boundary for private files, local tools, and on-device context. The local runtime performs private computer actions on your device.
When you attach a file, image, PDF, spreadsheet, or document, Elyan processes it only to complete the task. If a file must be sent to a server, that transfer is limited to the explicit task context; where possible, summaries, metadata, or processed packages are used instead.
Your private files are not used for advertising, profiling, or external marketing.
5. Elyan intelligence layer and secure infrastructure
Elyan manages response generation, task routing, authentication, database, notification, and security processes through its intelligence layer and secure operating infrastructure.
Data use is limited to what is necessary to provide the service. Personal data is not sold for advertising or external marketing.
Elyan is developed as one product identity. User content is not used for model development outside explicit consent or the task context required to provide the service.
6. Retention, account deletion, and data rights
Account data is retained while your account is active or for as long as required by legal, security, or billing obligations. Temporary task logs and technical error records are kept only for operational needs.
You can delete your account from the in-app Settings or Account area, or request deletion by emailing support@elyan.dev. The deletion process is also described at /en/data-deletion.
After account deletion, identity data, conversation history, paired device connections, and user-linked task records are deleted or anonymized within a reasonable technical period. Payment, security, and dispute records that must be retained by law may remain for the required period.
You may request access, correction, export, restriction, or deletion of your data by emailing support@elyan.dev.
7. Security
Elyan uses authentication, authorization, secure device pairing, session controls, and access boundaries to protect your data.
No internet service can guarantee absolute security. Report suspected access, security vulnerabilities, or unusual account activity to support@elyan.dev.
8. Children’s privacy
Elyan is not directed to children under 13. If we learn that personal data belonging to a child under 13 has been processed, we will take steps to delete it after verification.
9. International transfers and policy updates
Elyan services may use secure infrastructure components operating in different regions. In that case, data is processed with safeguards necessary to provide and secure the service.
We may update this policy as the product, law, or store requirements change. We may announce material changes through the website, in-app notices, or email.