Privacy Policy
How we handle your information, process connected product data, and support your privacy choices.
Last updated September 17, 2026
1. Who We Are and When This Policy Applies
ELU Labs, Inc. ("ELU," "we," "us," or "our") provides product intelligence tools that help teams understand product usage, investigate problems, and develop improvements. This Privacy Policy describes how we handle information across our website, application, analytics tools, browser extension, APIs, SDKs, MCP service, and related services (the "Services").
Our role depends on why we process information. We act as a controller for information we use to manage our business, such as account administration, billing, support, and website marketing. When we process data from a customer's product on its instructions, we act as a processor or service provider under the applicable customer agreement. A customer may itself be acting on behalf of another organization.
If your information was collected through a product that uses ELU, contact the organization operating that product first. It controls collection settings and handles requests about its data. We assist customers with those requests as required by our agreements and applicable law.
This Policy describes our practices; it does not replace a consent request where consent is required. Our Terms of Service govern use of ELU. A signed customer agreement or data processing agreement may provide additional protections.
2. Information We Collect
Account, billing, and communications
- Account information: names, work email addresses, profile information, authentication identifiers, organization membership, roles, and preferences.
- Billing information: subscription, transaction, invoice, company, and payment-method metadata. Our payment provider, Stripe, processes payment details.
- Communications: information you provide in support requests, demo bookings, surveys, feedback, and other communications.
- Connection information: integration settings, API keys, OAuth tokens, and other credentials needed to access services you choose to connect.
Connected product data and workspace content
The information we receive depends on the features you enable, your configuration, and the permissions you grant. It may include:
- Analytics: events, page URLs, timestamps, device and browser details, user or device identifiers, user properties, and product activity from ELU Analytics or connected providers such as PostHog and Amplitude.
- Session recordings: page structure, visible text and images, interactions, navigation, scrolling, and, depending on settings, input, canvas, console, or network information. We may reconstruct recordings and derive visual frames, summaries, and other analysis artifacts.
- Connected sources: database schemas and query results, repository files and changes, issue and ticket information, and messages made available through enabled integrations.
- Workspace content: business context, instructions, journeys, agent schedules, investigation questions, chat messages, tool results, findings, recommendations, generated fixes, feedback, and sharing preferences.
Masking and capture controls depend on the integration and configuration. Masking typed inputs does not necessarily remove sensitive information displayed elsewhere on a page, in a URL, or in an image. Customers should configure and test capture settings and avoid sending sensitive information unnecessary for their use of ELU.
Website, device, and service activity
We and our providers may collect IP addresses, browser and device information, approximate location, referring pages, visits, feature usage, diagnostic events, and security logs. Cookies, local storage, and advertising technologies are described in Section 7. The browser extension has additional disclosures in Section 15.
3. How We Use Information
We use information for these purposes, subject to applicable agreements and law:
- Provide, configure, authenticate, and administer the Services and integrations.
- Analyze product activity and recordings, answer investigation questions, generate findings and suggested fixes, and run customer-configured agents and monitoring.
- Deliver reports, notifications, tickets, pull requests, and other outputs through destinations the customer selects.
- Process subscriptions and payments, provide support, and communicate service updates.
- Monitor reliability, investigate errors, prevent misuse, and protect accounts and systems.
- Evaluate and improve service quality, including reviewing model outputs and feedback. Model development and training, including your opt-out, are described in Section 16.
- Communicate about ELU, measure marketing effectiveness, and advertise our Services, subject to applicable choices and requirements.
- Meet legal obligations, enforce agreements, and establish or defend legal claims.
AI features may process relevant recording frames, event data, messages, code, and connected context. Workspace access and conversation visibility depend on permissions and sharing settings. Information sent to an external destination is also subject to that destination's access controls and practices.
4. Legal Bases for Processing
Where the GDPR, UK GDPR, or similar laws require a legal basis for processing that we control, we rely on the basis appropriate to the purpose:
- Contract: to provide Services you request and take steps at your request before entering into a contract.
- Legitimate interests: to administer business relationships, support customers, secure and improve our Services, and communicate about our business, where those interests are not overridden by your rights and interests.
- Legal obligations: to comply with applicable accounting, tax, legal, and regulatory requirements.
- Consent: where required for particular activities, such as certain tracking, marketing, or additional uses of personal information.
You may withdraw consent where processing relies on it, without affecting the lawfulness of earlier processing. You may also have a right to object to processing based on legitimate interests. Without information needed to provide a requested service, we may be unable to provide that service.
For customer-controlled data, the customer determines its legal basis and provides required notices and choices. An account-level training opt-out does not replace consent or another legal basis where one is required.
5. How We Disclose Information
We may disclose information to:
- Service providers: infrastructure, AI, payment, monitoring, communication, scheduling, and other providers that help deliver and operate ELU.
- Authorized recipients: organization members and connected services according to permissions, sharing settings, and the actions you authorize.
- Advertising and measurement partners: providers receiving website and conversion information through the technologies described in Section 7.
- Legal and professional recipients: advisers, authorities, or others when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or resolve disputes.
- Business transaction participants: parties involved in a proposed or completed financing, merger, acquisition, reorganization, or sale of assets, subject to applicable protections.
- Other recipients at your direction or with your consent.
We do not sell customer workspace content for money. Website advertising disclosures may be treated as a "sale," "sharing," or targeted advertising under some privacy laws even when no money changes hands. See Sections 7 and 11 for choices and rights.
We may use or disclose aggregated or de-identified information where it no longer identifies a person and applicable requirements for that treatment are met. Removing a name alone does not necessarily make information anonymous.
6. Providers and Connected Services
Providers used to operate the Services include Google Cloud and Firebase for infrastructure and authentication, AI providers such as Anthropic and OpenAI, and Stripe for payments. We also use providers for operational monitoring, communications, and scheduling. The providers involved depend on the feature, deployment, and configuration.
ELU Analytics may use ELU-managed analytics infrastructure. If you connect your own analytics, database, repository, messaging, or project-management account, its provider continues to handle information under its own terms and your agreement with it. Selecting a provider region does not determine where every other ELU processing activity takes place.
Third-party AI clients that connect through MCP or our APIs may receive the results you request. Their processing is governed by your relationship with those clients.
Contact support@elu.dev for information about subprocessors relevant to your deployment and applicable data processing terms. Additional obligations in your customer agreement, including agreed subprocessor notices, continue to apply.
8. Retention and Deletion
Retention depends on the type of information, its purpose, the customer's configuration and agreement, and applicable legal requirements. We consider the period needed to provide the Services, resolve support and security matters, maintain required records, and establish or defend legal claims.
Account records, analytics events, recordings, derived findings, conversations, model-quality records, security logs, and backups may follow different retention schedules. A retention period in an applicable customer agreement continues to govern the data it covers.
Subscription cancellation, disconnection of an integration, and data deletion are separate actions. To request account closure or deletion, contact support@elu.dev. We may need to verify your authority, coordinate with your organization, and retain records where required or permitted by law. Backup copies may remain until the applicable backup cycle expires.
Deleting information from ELU does not automatically delete copies held in your connected accounts or already sent to other destinations. Requests about data we process for a customer are handled in coordination with that customer.
9. Security
We use technical and organizational safeguards designed to protect information, including encrypted connections, authentication, organization-level access controls, protected credential storage, and security logging. Safeguards depend on the service and deployment.
Integration credentials may need to remain retrievable so ELU can access connected services; those credentials are stored in a secrets-management service. Some ELU-issued authentication keys use stored verification hashes instead. These are different forms of credential storage.
No system is completely secure. Customers should limit integration permissions, protect credentials, review sharing settings, and test recording controls. Privacy settings reduce collection but do not guarantee that all sensitive content is removed.
Report suspected security issues to support@elu.dev. If an incident creates a notification obligation, we will provide notice as required by applicable law and our agreements.
10. International Processing
ELU is based in the United States. Information may be processed in the United States and other countries where ELU or its providers operate. Privacy laws in those countries may differ from the laws where you live.
Where a transfer is subject to restrictions under applicable data protection law, an appropriate transfer mechanism is required. Depending on the transfer, this may involve an adequacy decision, contractual safeguards such as standard contractual clauses and a UK addendum, or another legally permitted mechanism. Customer agreements may specify additional transfer requirements.
Contact support@elu.dev for information about processing locations and the safeguards applicable to your use of the Services. A regional setting for one connected service does not guarantee that all ELU support, AI processing, or other operations occur in that region.
11. Your Rights and Choices
Depending on where you live and the processing involved, you may have rights to:
- Learn about and obtain access to your personal information.
- Correct inaccurate information or request deletion.
- Receive a portable copy of certain information.
- Object to processing or request that it be restricted.
- Withdraw consent where processing relies on consent.
- Opt out of sale, sharing, targeted advertising, or certain profiling, and limit certain uses of sensitive information, where the relevant law provides those rights.
- Use an authorized agent or appeal a decision on a request where applicable law allows.
- Complain to a competent privacy regulator.
How to make a request
Email support@elu.dev and describe your request and the account or product involved. You do not need to create an ELU account to submit a request. We may request information needed to verify identity or authority as permitted by law, and will respond within the applicable legal timeframe. Some rights have exceptions. We will not unlawfully discriminate against you for exercising them.
For data collected through a customer's product, contact that customer. We may forward your request or help it respond under the applicable agreement. Customers remain responsible for decisions they make using ELU findings.
Marketing and model training
You can unsubscribe from marketing emails using the link in the message or contact us. You may object to direct marketing at any time. Essential account, security, billing, and service messages may still be sent. Section 16 explains how to opt out of model training.
Regional information
For California residents, Sections 2 through 8 describe the categories and sources of information, purposes, recipients, and retention criteria relevant to our practices. Advertising disclosures may qualify as sale or sharing under California law. You may request an opt-out through the contact method above; applicable statutory rights remain available regardless of the choices described elsewhere in this Policy.
If you are in the EEA, United Kingdom, or Switzerland, you may contact your local data protection authority. In the United Kingdom, this is the Information Commissioner's Office. We welcome the opportunity to address your concern directly as well.
12. Children
ELU accounts are intended for adults using a business service. Our Services are not directed to children under 16, and we do not knowingly collect personal information directly from children under 16 for their own ELU accounts.
Customers are responsible for complying with laws that apply to children using their own products. If you believe a child's information has been provided to ELU improperly, contact support@elu.dev so we can investigate and take appropriate action.
13. Third-Party Websites and Services
Our Services may link to, embed, or connect with third-party websites, products, and AI clients. This Policy does not govern those parties' independent processing. Review their notices and your agreements before connecting accounts or sharing information.
14. Customer-Controlled Data
When acting as a processor or service provider, we process customer-controlled personal information under the customer's instructions and the applicable agreement. Customers determine which sources to connect, what permissions to grant, and how to configure collection, access, and sharing.
Customers are responsible for providing notices, establishing a lawful basis, obtaining required permissions, and responding to their users' requests. Contact support@elu.dev for applicable data processing terms and assistance. Nothing in this Policy overrides a stricter restriction in an applicable customer agreement.
15. Browser Extension
The ELU browser extension lets you deliberately record product journeys and send them to a workspace. A recording may include page URLs and titles, interaction steps, action descriptions, and information identifying the elements you interact with.
The recorder omits typed values from recorded input descriptions and includes special handling for password fields. This does not guarantee removal of sensitive information from URLs, page titles, labels, or other captured context. Review what you record and upload, and use the extension only on sites where you are authorized to do so.
You control when to start and stop recording. Uninstalling the extension does not remove information already uploaded to ELU; contact your workspace administrator or support@elu.dev for a deletion request.
16. AI Processing and Model Training
Providing AI features
ELU uses third-party AI services and models operated by ELU to analyze information and produce outputs. Relevant inputs may include product events, recording frames, prompts, conversation context, repository content, tool results, and feedback. Processing an input to generate a response is distinct from using it to train a model.
Information sent to an AI provider is subject to the applicable service terms, data protections, and retention arrangements. These may differ by provider and feature. We do not represent that every provider has the same retention period or configuration.
Model improvement and your opt-out
Where permitted by our customer agreements and applicable law, we may use customer data to develop, evaluate, train, and improve ELU models, including through model distillation. This may involve examples of inputs and outputs, such as recording frames, prompts, contextual information, model responses, and feedback. Providers assisting us with this work may process the relevant information for that purpose.
Customers can opt out of having their data used for model training or distillation by emailing support@elu.dev. Include your workspace name and the email associated with your account so we can verify your authority and apply the request to the correct organization. Contact us about how a request applies to data already processed or existing models.
An opt-out from training does not prevent processing needed to deliver the AI features you request. Restrictions in existing customer agreements and commitments made when data was collected continue to apply. Updating this Policy does not, by itself, authorize a new training use of data previously collected under a no-training commitment. We obtain any additional permission required by law or the applicable agreement before that use.
Reviewing AI outputs
AI outputs can be inaccurate or incomplete. Review outputs before acting on or sharing them, particularly when they contain information about an identifiable person. Customer-configured agents and notifications may run automatically according to their settings.
17. Changes to This Policy
We may update this Policy to reflect changes to the Services, our practices, or legal requirements. The date above identifies the latest revision. We will provide additional notice and obtain consent where required by law or our agreements.
A revised notice does not eliminate existing contractual restrictions or replace consent needed for a new use of information. Contact us with questions about a change.
18. Contact Us
For privacy questions, rights requests, training opt-outs, or information about data processing terms, contact:
ELU Labs, Inc.
United States
support@elu.dev
Please identify the account, workspace, or customer product involved. Avoid including passwords, integration secrets, or unnecessary sensitive information in your request.