Privacy Policy
This Privacy Policy explains how Eliora OS, Inc. (“Eliora OS,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the Eliora OS platform, our websites, and our products and services, including Eliora OS.M, our Marketing Operating System (collectively, the “Services”).
Eliora OS is an operating-system platform designed to centralize the systems businesses use to run their operations. Eliora OS.M is an AI-assisted operating system for marketing agencies that consolidates workflows such as client and project management, CRM and pipeline management, business records, contacts, proposals, contracts, invoices, payments and retainers, tasks and requests, calendars, files and digital assets, content and campaign operations, social and advertising workflows, analytics and reporting, SEO and business-listing information, client communication, client portals, and team access.
Contents
- Introduction
- Scope
- Information We Collect
- Information You Provide
- Information From Connected Services
- Google API Data
- How We Use Information
- AI-Assisted Features
- How Information Is Shared
- Service Providers
- Data Storage and Security
- Data Retention
- Connected Account Controls
- Data Deletion Requests
- Cookies and Similar Technologies
- Your Privacy Rights
- U.S. State Privacy Rights
- Children’s Privacy
- International Users
- Changes to This Privacy Policy
- Contact Us
1Introduction
We provide the Services primarily to businesses — including marketing and creative agencies and the organizations they work with. This Privacy Policy describes our practices for information we control. Where an organization uses the Services to manage information about its own clients, contacts, or team members, that organization is responsible for its own privacy practices, as described in Scope.
This Privacy Policy is provided for transparency and does not constitute legal advice.
2Scope
This Privacy Policy applies to information processed through the Services. It is important to understand the two roles in which we process information:
- Information we process as a controller. For our public websites, account registration, billing, support, and direct communications with you, Eliora OS determines how and why information is processed.
- Information we process on behalf of an organization. When an organization (for example, an agency) creates a workspace and uses the Services to manage projects, clients, contacts, campaigns, documents, and other business data, Eliora OS processes that information under the organization’s direction in order to provide the Services. The organization is responsible for ensuring it has the authority and any necessary permissions or notices to provide that information — including information about its clients and contacts — to Eliora OS, and for responding to privacy requests from the individuals whose information it manages.
3Information We Collect
Depending on how the Services are used and which features are enabled, we may process the following categories of information:
Account information
- Name, email address, and authentication and account credentials
- Organization or agency membership, role, and access permissions
- Profile details you choose to add
Business information
- Agency and client business profiles, contacts, products and services
- Goals, KPIs, discovery information, brand information, and market information
Workflow information
- Projects, tasks, requests, approvals, and internal operational records
- Calendar information and communications created or stored in the Services
Marketing information
- Campaigns, content, and publishing information
- Social account information, advertising-related information, SEO information, and analytics and performance information
Documents and files
- Uploaded files and digital assets
- Proposals, contracts, invoices, and other documents
Financial and business transaction information
The Services may be used to create and track business records related to invoices, payments, retainers, and payment status. Where payments are processed, they are handled by third-party payment processors under their own terms and privacy policies. We do not store complete payment card numbers on our systems; we may retain limited transaction records (such as amounts, status, and references) needed to operate billing and reporting features.
Integration data
Information obtained from third-party services that a user explicitly connects to the Services, limited to what the user authorizes and what the provider makes available. See Information From Connected Services and Google API Data.
Technical information
- Browser and device information
- IP address, where collected by our infrastructure and security systems
- Logs, timestamps, and authentication and security events
- Application usage information generated as you interact with the Services
4Information You Provide
We collect information you or your organization provide directly, including when you create an account, configure a workspace, upload files, enter business or client records, submit a form on our website, connect a third-party service, contact support, or otherwise use the Services. You are responsible for the accuracy of the information you provide and for having the necessary authority to provide information about other people.
5Information From Connected Services
Eliora OS is designed with a provider-neutral integration architecture. Depending on the features you choose to use, Eliora OS may allow you to connect third-party services so that the platform can display, organize, and act on information from those services on your behalf. These may include services such as Google services, Meta / Facebook / Instagram, LinkedIn, TikTok, Pinterest, X, YouTube, and analytics, email, accounting, and payment platforms.
We do not currently integrate with every provider listed above, and availability changes as the platform develops. When you connect a third-party account:
- You authorize Eliora OS to access specific information from that service.
- Eliora OS receives only the information permitted by that authorization and by the provider.
- Eliora OS uses that information to provide the platform functionality you have requested.
- You may disconnect the integration at any time where that option is available, and/or revoke access through the third-party provider.
- The third-party service continues to be governed by its own terms and privacy policy.
6Google API Data
Eliora OS is implementing Google OAuth so that users can authorize Eliora OS to access supported Google services on their behalf. The platform is designed to support connections to services such as Google Analytics / GA4, Google Search Console, Google Business Profile, and YouTube. Access depends entirely on which integrations and features you choose to connect and which permissions Google grants through its OAuth consent process.
What Google data may be accessed
Depending on the connected feature and the scopes you authorize, Eliora OS may access information associated with your connected Google services, such as:
- Google account identification needed to establish and maintain the connection
- Google Analytics properties and reporting data
- Search Console properties and search performance information for websites you manage
- Google Business Profile information
- YouTube channel and account information
- Other data you specifically authorize through Google’s OAuth consent screen
Eliora OS does not receive unrestricted access to your Google account. Access is limited to the specific permissions and scopes you explicitly authorize, and you can review those permissions before granting them.
How Google data is used
Information accessed from Google services is used only to provide and improve user-facing features of the Services, such as:
- Connecting the correct Google property or account to the relevant client workspace
- Displaying analytics and performance information
- Generating and maintaining reports
- Monitoring digital performance and supporting SEO insights
- Supporting business-listing information and YouTube / channel information
- Powering AI-assisted analysis or recommendations that you specifically request
Eliora OS does not claim ownership of your Google data. You and your organization remain responsible for that data and for your use of the connected Google services.
Authorization credentials
When you connect a Google service, authorization credentials or tokens issued through Google’s OAuth process may be stored securely so that Eliora OS can maintain the authorized connection without requiring you to reconnect every session. These credentials are used only to access the services you have authorized.
Sharing of Google data
Eliora OS does not sell Google user data. We do not use Google user data for advertising, and we do not transfer it to third parties except: (a) to third-party infrastructure and service providers that process it solely to operate the Services on our behalf and under confidentiality obligations; (b) as necessary for security purposes or to comply with applicable law; or (c) as part of a merger, acquisition, or sale of assets, with notice as required and consistent with Google’s requirements. Google-derived data is not used for advertising or any purpose unrelated to providing the Services you request.
Retention of Google data
We distinguish between:
- OAuth credentials / tokens — retained while the integration is connected and deleted or invalidated when you disconnect the integration or revoke access, subject to short operational and backup cycles.
- Synced or current integration data — retained to keep connected dashboards and features current while the integration is connected.
- Historical reports and snapshots legitimately created within Eliora OS (for example, a monthly performance report saved to a client workspace) — retained as part of your business records unless you request deletion or deletion is required by law.
Disconnecting a Google integration stops future authorized access. It does not automatically delete every historical business record or report already created within Eliora OS unless you request deletion as described in Data Deletion Requests.
Disconnecting Google services
You can disconnect connected Google services through Eliora OS where that option is available, and you can review or revoke Eliora OS’s access at any time through your Google Account permissions at myaccount.google.com/permissions.
Deletion of Google data
You may request deletion of data associated with your account or a specific integration, including data obtained from Google services, by contacting us at privacy@elioraos.com. See Data Deletion Requests for details.
Limited Use
Eliora OS’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we limit our use of data obtained from Google APIs to providing or improving user-facing features that are prominent in the Eliora OS user interface; we do not transfer or sell this data to third parties for advertising, retargeting, personalized or interest-based advertising, credit assessment, or lending purposes, or to data brokers or information resellers; and we do not allow humans to read this data except as permitted under that policy (for example, with your affirmative agreement, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized for operations).
7How We Use Information
We use information to:
- Provide, operate, maintain, and secure the Services
- Authenticate users and manage accounts, workspaces, roles, and permissions
- Deliver platform features you or your organization configure, including connected integrations
- Generate reports, dashboards, and analytics you request
- Provide AI-assisted features you request (see AI-Assisted Features)
- Process and track invoices, payments, and retainers where those features are used
- Respond to support requests and communicate with you about the Services
- Monitor performance, debug, prevent fraud and abuse, and protect the security and integrity of the Services
- Comply with legal obligations and enforce our agreements
- Improve the Services, consistent with this Privacy Policy and applicable law
8AI-Assisted Features
Eliora OS includes AI-assisted functionality that may be used for tasks such as business and marketing analysis, content assistance, recommendations, summaries, reporting, and workflow and campaign assistance.
When you use an AI-assisted feature, information you provide or authorize — which may include business data, connected-integration data, and content in your workspace — may be processed by AI systems to the extent necessary to perform the feature you requested. This processing may involve third-party AI providers that act as our service providers and process the information on our behalf to return a result. We do not use this information to train AI models for unrelated purposes, and we seek to work with providers that offer comparable commitments; specific provider terms may vary as the platform develops.
9How Information Is Shared
We do not sell personal information. We share information only as described here:
- Within your organization. Information in a workspace is accessible to authorized members of that organization according to the roles and permissions the organization configures.
- With service providers. We share information with vendors that process it on our behalf to operate the Services (see Service Providers).
- With connected services. When you connect a third-party service or direct the Services to send information to it, information is shared with that service according to your instructions.
- For legal reasons. We may disclose information to comply with applicable law, regulation, legal process, or governmental request, or to protect the rights, property, and safety of Eliora OS, our users, or the public.
- Business transfers. Information may be transferred in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards and, where required, notice or consent.
- With your direction or consent. We share information in other ways when you or your organization instruct us to.
10Service Providers
We rely on third-party providers to deliver the Services. These currently include infrastructure and hosting providers used for the platform. For example, we use Netlify for website and application hosting and Supabase for authentication, database, storage, and related back-end functionality. Depending on the features in use, we may also rely on providers for AI processing, email delivery, analytics, error monitoring, and payment processing. Service providers are permitted to process information only as needed to provide services to us and are bound by confidentiality and data-protection obligations.
11Data Storage and Security
Information is stored on infrastructure operated by our hosting and back-end providers. We use technical and organizational measures intended to protect information, including access controls, authentication, encryption in transit, and workspace-level permission controls that are designed to restrict access to information according to account and workspace roles.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for configuring workspace roles and permissions appropriately.
12Data Retention
We retain information for as long as needed to provide the Services and for legitimate business or legal purposes, including maintaining your account and workspace, preserving historical reporting and business records where appropriate, complying with legal obligations, resolving disputes, and maintaining the security and integrity of the Services. Retention periods vary by data type and context. When information is no longer needed, we take steps to delete or de-identify it. Backups are retained for a limited period and are cycled out on a rolling basis.
13Connected Account Controls
Where a feature supports it, you can view and manage your connected integrations from within Eliora OS, including disconnecting a service. Disconnecting a service stops future authorized access to that service. You can also manage or revoke Eliora OS’s access directly through the third-party provider — for Google, at myaccount.google.com/permissions. As described in Google API Data and Data Retention, disconnecting an integration does not by itself delete historical records or reports already created within Eliora OS.
14Data Deletion Requests
You may request deletion of data associated with your account or with a specific integration — including data obtained from connected Google services — by emailing privacy@elioraos.com from the email address associated with your account, or by using an in-product deletion option where available.
- We will verify your request and identify the data within our control.
- If your information is managed within an organization’s workspace, we may need to route your request to that organization, which controls that data.
- We will delete or de-identify the applicable data within a reasonable period, except where we are required or permitted to retain it (for example, for legal, security, dispute-resolution, or tax and accounting purposes).
- Residual copies may persist in backups for a limited time before being cycled out.
15Cookies and Similar Technologies
Our websites and application use cookies and similar browser storage technologies that are necessary to operate the Services — for example, to keep you signed in, maintain your session, remember preferences, and support security. We may use a limited amount of analytics or error-monitoring technology to understand usage and diagnose problems. We do not use advertising cookies or sell information collected through these technologies. You can control cookies through your browser settings, though disabling necessary cookies may affect functionality.
16Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, to object to or restrict certain processing, or to withdraw consent. To exercise a right, contact us at privacy@elioraos.com. We will respond consistent with applicable law. If your information is processed on behalf of an organization, we will direct your request to that organization. We will not discriminate against you for exercising your rights.
17U.S. State Privacy Rights
Residents of certain U.S. states may have additional rights regarding their personal information, including the right to confirm whether we process their personal information, to access or delete it, to correct inaccuracies, and to obtain a portable copy, as well as the right to opt out of “sales” of personal information or “targeted advertising.” Eliora OS does not sell personal information and does not use personal information for targeted advertising. To exercise a right, contact privacy@elioraos.com. You may appeal a decision by replying to our response. Where our processing is carried out on behalf of an organization, that organization is responsible for responding to these requests and we will assist as required.
18Children’s Privacy
The Services are intended for use by businesses and individuals who are at least 18 years old. The Services are not directed to children, and we do not knowingly collect personal information from children under 13 (or the applicable age in your jurisdiction). If you believe a child has provided us personal information, contact privacy@elioraos.com and we will take appropriate steps to delete it.
19International Users
Eliora OS is operated from the United States, and information we process may be stored and processed in the United States or other countries where we or our service providers operate. These countries may have data-protection laws that differ from those in your country. Where required, we take steps to ensure appropriate safeguards are in place for cross-border transfers.
20Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice through the Services or by email. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Privacy Policy.
21Contact Us
If you have questions about this Privacy Policy or our privacy practices, or to make a privacy or deletion request, contact us at:
Eliora OS, Inc.
Privacy: privacy@elioraos.com
General inquiries: elioraos.com/site/scheduler.html