Privacy Policy
Last updated: February 2025
1. Introduction
Elixion ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Elixion platform at elixion.ai (the "Service"). By using the Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Full name, email address, username, and avatar when you create an account.
- Profile Information: Work capacity settings and preferences you configure in your account.
- Payment Information: Billing details are collected and processed by Stripe. We do not store your credit card numbers on our servers.
- Content: Projects, issues, documents, comments, and other content you create within the platform.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, and timestamps.
- Device Information: Browser type, operating system, and device identifiers.
- Analytics Data: We use Google Analytics and Google Tag Manager to collect aggregated usage statistics.
- Cookies: Session cookies to maintain your authentication state, and analytics cookies for usage tracking.
3. How We Use Your Information
- Service Delivery: To provide, maintain, and improve the Elixion platform and its features.
- Billing: To process payments, manage subscriptions, and track credit usage.
- Analytics: To understand how users interact with our Service and to improve the user experience.
- Communication: To send transactional emails (account confirmations, billing receipts, service updates) and, with your consent, marketing communications.
- Security: To detect and prevent fraud, abuse, and unauthorized access.
4. Third-Party Services
We share information with the following third-party service providers:
- Stripe: Processes all payment transactions. Stripe receives your payment information directly and is PCI DSS compliant. See Stripe's Privacy Policy.
- Google Analytics / Google Tag Manager: Collects aggregated usage data to help us understand user behavior and improve the Service.
We do not sell your personal information to third parties.
5. Payment Data Handling
All credit card and payment information is transmitted directly to and processed by Stripe. We never store, log, or have access to your full credit card numbers. Stripe is certified as a PCI Level 1 Service Provider, the most stringent level of certification available in the payments industry. We only store a reference to your Stripe customer ID and subscription status.
6. Data Retention and Deletion
We retain your personal information for as long as your account is active or as needed to provide the Service. If you request deletion of your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes. Aggregated, anonymized data may be retained indefinitely for analytics purposes.
7. Your Rights
7.1 GDPR Rights (European Users)
If you are located in the European Economic Area, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data.
- Portability: Request a machine-readable copy of your data.
- Restriction: Request limitation of processing of your data.
- Objection: Object to processing of your personal data.
7.2 CCPA Rights (California Users)
If you are a California resident, you have the right to:
- Know: Request information about the personal data we collect and how it is used.
- Delete: Request deletion of your personal data.
- Opt-Out: Opt out of the sale of your personal data (we do not sell personal data).
- Non-Discrimination: Not be discriminated against for exercising your privacy rights.
8. Cookies and Tracking
We use the following types of cookies:
- Essential Cookies: Required for authentication and core Service functionality (session tokens).
- Analytics Cookies: Google Analytics cookies to measure site usage and performance.
You can control cookie preferences through your browser settings. Disabling essential cookies may affect your ability to use the Service.
9. Children's Privacy
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country. We take appropriate safeguards to ensure that your personal data remains protected in accordance with this Privacy Policy when transferred internationally.
11. AI Assistant Connectors (Claude)
Elixion offers an optional connector that lets an AI assistant (such as Claude) access your Elixion workspace on your behalf. The connector is off unless you explicitly connect it, and you can disconnect it at any time.
- What it can access. The connector acts strictly as you, with exactly the permissions your Elixion account already has. It cannot see a project you cannot see, and it cannot perform an action you could not perform yourself. At connection time you choose a default workspace and approve read-only or read-and-write access.
- What we receive. Only the requests the assistant makes to Elixion. We do not receive your conversation with the assistant — not its prompts, its replies, nor any other content from it.
- Credentials and storage. Connection tokens are stored as one-way hashes, never in plain text. Tokens, authorization codes and
Authorizationheaders are never written to our logs. - Third parties. Connecting the assistant means the requests it makes, and the Elixion data returned, pass through that assistant provider, under their privacy policy. Elixion shares nothing with them beyond what the connector returns in response to your requests.
- Retention and revocation. A connection lives until it expires or you revoke it — by removing the connector in the assistant, or by revoking it in Elixion. Revocation takes effect immediately: the next request is refused. Revoked and expired tokens are purged on the schedule described in “Data Retention and Deletion” above.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service. Your continued use of the Service after the changes take effect constitutes your acceptance of the revised policy.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at support@elixion.ai.