Eliza

Legal

Privacy Notice

How Eliza handles personal data on eliza.tools and related APIs.

1. Who is responsible

Eliza is responsible for personal data processed through the website, account system, licensing API, and optional cloud sync features. If you use Eliza solely as a local client without creating an account, little or no personal data may reach our servers.

2. Data we process

Depending on how you use the Service, we may process:

  • Account data — email address, password hash (Argon2id), optional display name, and MFA secrets stored encrypted;
  • License and device data — plan type, license key metadata, expiry, and a device binding identifier used to enforce seat limits;
  • Support correspondence — messages you send to our contact addresses;
  • Payment references — limited billing metadata from payment providers (we do not store full card numbers on Eliza servers);
  • Technical logs — IP address, timestamps, user-agent, request paths, and error diagnostics needed to operate and secure the API;
  • Synced profile payloads — see section 4.

We do not require government ID to open a standard account. We do not sell personal data.

3. Why we process it

We process personal data to:

  • create and authenticate accounts and perform the contract for paid licenses;
  • enforce plan limits and device binding;
  • provide sync, restore, and support;
  • protect the Service against abuse, fraud, and attacks (legitimate interests / security);
  • meet legal record-keeping obligations where they apply;
  • send service messages (security alerts, billing, material product changes).

Marketing emails, if offered, are sent only with a separate opt-in. You can withdraw consent via the unsubscribe link or by emailing us. Withdrawal does not affect earlier lawful processing or essential service mail.

4. Encrypted profile payloads

If you enable cloud sync, fingerprint configuration, proxy credentials, and related profile fields are encrypted with AES-256-GCM before they are written to our database. Encryption exists to reduce exposure if storage is compromised; it is not a substitute for your own operational security (strong account password, MFA, careful device hygiene).

We process these payloads to deliver sync and restore. We do not use the contents of your browsing profiles for advertising.

5. Product telemetry

The client or website may send limited, product-oriented events such as feature usage counters, crash signatures, version strings, and OS type. We use this to prioritize fixes and understand reliability. We do not build advertising profiles from this telemetry, and we do not sell it.

Where feasible, we prefer aggregated or pseudonymous forms. You can ask us what categories are currently collected for your account type.

6. Processors and transfers

We rely on infrastructure and edge providers to host the website, API, and databases (for example, cloud VPS hosts and CDN / tunnel providers such as Cloudflare). Those parties process data on our instructions as processors or as independent controllers for their own security logs, depending on the service.

Data may be processed in the country where our primary servers are located and in regions where edge providers operate. If you are in the EEA/UK and a transfer tool is required, we will rely on appropriate safeguards (such as standard contractual clauses) offered by those providers.

7. Retention

Account and license records are kept while the account is active and for a reasonable period afterward as needed for disputes, security, and legal obligations. Security logs are rotated on a shorter cycle unless an investigation requires holding them longer.

If an account shows no successful authentication and no license activity for 24 consecutive months, we may treat it as abandoned and delete or anonymize associated personal data and synced payloads, after which recovery may be impossible.

You may request earlier deletion; we will honor it unless we must retain specific records (for example, completed invoices) under mandatory law.

8. Your rights and choices

Subject to applicable law (including GDPR where it applies), you may request access, correction, deletion, restriction, portability, or an objection to certain processing. You may also lodge a complaint with your local supervisory authority.

To exercise rights, email [email protected] from the address on the account. We may ask for information reasonably needed to verify the request.

9. Security

We use TLS in transit, hashed passwords, encrypted sensitive fields, network hardening on origin servers, and access controls on production systems. No method of transmission or storage is perfectly secure. You should protect your devices and credentials; we are not responsible for losses caused by compromised endpoints outside our control.

10. Children

Eliza is directed at adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor registered, contact us and we will delete the account.

11. Updates

We may revise this notice as the product or legal requirements change. Where appropriate, we will provide an in-product or email notice for material updates.

12. Contact

Privacy requests: [email protected]
General: [email protected]