LEGAL
Privacy Policy
Last updated: 29 July 2026
This policy explains what data Elyvo Assist (“Elyvo”, “the app”, “we”) collects, why, who it is shared with, and what rights you have. It is written to reflect what the software actually does.
1. Who is responsible for your data
Elyvo Assist is operated by IE Sergei Melnikov, an Individual Entrepreneur registered in Georgia under identification number 322749683, at Untsa, Adigeni Municipality, Georgia. For any privacy question or request, contact [email protected]. We act as the data controller for the data described below.
2. What Elyvo does — in plain terms
Elyvo is a desktop assistant that you summon over any window. To suggest a next move, it needs context about the moment you are in. Depending on the features you use, that context can include audio from your meetings, images of your screen, and entries from your calendar. This data is processed by us and by the third-party providers listed in section 5.
Please read this carefully. Elyvo is designed to be invisible in screen shares and recordings — other people in your call cannot see it. That is a feature about visibility to others. It does not mean your data stays on your device. Audio is sent to a speech-to-text provider, and screen content and prompts are sent to AI providers, in order to produce suggestions.
3. What we collect
Account data
- Email address, first and last name, username.
- A password hash (we never store your password in readable form), or a Google account identifier if you sign in with Google.
- Profile image, if you provide one.
- Your points balance, purchase history and the ledger of points you have spent.
Content you give the assistant
- Audio. When you use meeting or ambient features, audio from your microphone and/or system output is captured and streamed for transcription.
- Transcripts. The resulting text, including speaker labels and timings, is stored in your account so sessions are searchable and resumable.
- Screen content. When a suggestion requires visual context, a screenshot is captured and sent to an AI provider along with your prompt.
- Prompts, chats and session history, including any files or documents you add to a project.
- Calendar data, if you connect Google Calendar: event titles, descriptions, times, and organiser email addresses. We request read-only access.
Technical data
- IP address at registration and in security audit records.
- Device identifiers and names of the devices you sign in from.
- Login attempts (email and IP are stored in hashed form for abuse prevention).
- Usage records such as AI token counts, used to work out what each action costs in points.
4. Why we use it, and our legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the assistant, generate suggestions | Audio, transcripts, screen content, prompts, calendar | Performance of a contract |
| Create and secure your account | Account data, password hash, device data | Performance of a contract |
| Send sign-in codes and service email | Email address | Performance of a contract |
| Connect your calendar | Google account, calendar events | Consent (you may disconnect at any time) |
| Prevent abuse and keep audit records | IP, hashed login attempts, usage counters | Legitimate interests |
| Sell and credit points, and keep the ledger of what you spent | Purchase and points records | Performance of a contract; legal obligation |
5. Who your data is shared with
We do not sell your data and we do not use it for advertising. To operate the service, data is shared with the processors below, and with the provider that handles your payment:
| Provider | What it receives | Why |
|---|---|---|
| Deepgram (USA) | Meeting and microphone audio | Speech-to-text transcription |
| OpenAI (USA) | Prompts, screenshots, relevant transcript and calendar context | Generating suggestions and answers |
| Google (USA/EU) | Prompts, screenshots, relevant transcript and calendar context; calendar data if connected; account identifier if you sign in with Google | AI models, Google Calendar, Google Sign-In |
| Anthropic (USA) | Prompts, screenshots, relevant transcript and calendar context | Generating suggestions and answers, when enabled as the selected model provider |
| Brevo (EU) | Your email address | Delivering sign-in codes and service email |
| Cloudflare (USA/EU) | IP address and request metadata; email sent to our contact address | Website delivery, security, contact email forwarding |
| OVH (Germany) | All data stored by the service | Hosting of our servers and database |
Elyvo Assist is an independent product. We are not affiliated with, endorsed by or sponsored by any of the providers above. Their names and trademarks belong to their respective owners and are named here only to identify who processes your data.
Payment provider
We sell the points to you directly. The payment itself is processed by NOWPayments, which holds the transaction data as an independent controller under its own policy.
| Provider | What it receives | Role |
|---|---|---|
| NOWPayments | The amount, the currency and an order reference for the pack you bought. We do not send it your name or your email address. | Payment processor — independent controller (privacy policy) |
We receive back only the order reference and whether the payment was confirmed, which is what tells us to credit your points. We never receive or store your wallet credentials.
Where your data is stored
Our servers and database are hosted with OVH in Germany. Your account, sessions, transcripts and project files are stored there, inside the European Union.
Some of the providers above are located outside the European Economic Area, including in the United States — notably Deepgram, OpenAI and Anthropic. This means that when you use transcription or AI features, that content is transferred to the United States for processing. Where data is transferred internationally, we rely on the safeguards offered by those providers, such as standard contractual clauses. Each provider handles your data under its own terms, and we recommend reviewing them if this matters to you.
6. Google user data and Limited Use
If you connect Google Calendar, Elyvo reads your upcoming events using read-only access. Event data — titles, descriptions, times, and organiser email addresses — may be included as context in the prompts we send to the AI providers listed in section 5, so that suggestions reflect the meeting you are actually in.
Those prompts are processed by a model from one of the AI providers listed in section 5 — Google, OpenAI or Anthropic. Which provider and model handle a given request is a configuration we control; it is not a choice made inside the app, and the app does not expose provider or model names to you. We only use models operating under terms that prohibit the use of submitted data to train or improve those models. Google Workspace data is never used, by us or by our providers, to develop, improve, or train AI or machine-learning models, and it is never sold, transferred to data brokers or advertisers, or used for advertising, credit assessment, or any purpose other than providing the features described in this policy.
The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can withdraw Elyvo's access to your Google account at any time, either by disconnecting the calendar inside the app or at myaccount.google.com/permissions. When you disconnect the calendar in the app, and when you delete your account, we revoke our access token with Google and delete the cached events, the meeting overviews generated from them, and the stored connection record from our database.
7. How long we keep it
- Account data is kept while your account exists.
- Sessions, transcripts, chats and project files are kept until you delete them, or until you delete your account.
- Google Calendar data (cached events, meeting overviews, and the connection record) is kept while the calendar is connected, and is deleted as soon as you disconnect it or delete your account.
- Security and audit records (including IP addresses and hashed login attempts) are kept for a limited period for abuse prevention.
- Payment records may be kept longer where accounting or tax law requires it.
When you delete your account, we remove or irreversibly anonymise the personal data associated with it. Some records may survive in backups for a limited period before being overwritten.
8. Your rights
Regardless of where you live, we apply the following rights to everyone. You may:
- Ask what data we hold about you, and get a copy of it.
- Correct data that is wrong or incomplete.
- Delete your account and the data attached to it.
- Ask us to restrict or stop certain processing.
- Receive your data in a portable, machine-readable form.
- Withdraw consent — for example by disconnecting your calendar — at any time.
- Lodge a complaint with your data protection authority. In Georgia this is the Personal Data Protection Service; in the EU it is your national supervisory authority.
To exercise any of these, email [email protected]. We aim to respond within 30 days.
9. Security
- All traffic between the app and our servers is encrypted with TLS.
- Passwords are stored as salted hashes, never in readable form.
- Third-party access tokens, such as your Google Calendar tokens, are encrypted at rest.
- Access to production systems is restricted to the operator over a private network.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority where the law requires it.
10. Recording other people
If you use Elyvo to transcribe a meeting, you may be recording other participants. Laws on recording and consent differ by country, and in many places you must inform participants or obtain their consent. You are responsible for complying with those laws. Elyvo provides a tool; it does not obtain consent on your behalf.
11. Children
Elyvo is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will tell you in the app or by email.
13. Contact
Questions, requests, or complaints: [email protected].