Eliora

Privacy Policy

Version 2.6 — Effective 6 October 2026. Supersedes Version 2.5, effective 5 October 2026.

Who we are

Eliora is a personal life-organisation assistant that helps you keep the parts of your life — notes, plans, goals, reminders, and the areas you choose to track — in one calm place.

Eliora is operated by GreatLight Works Inc. (“GreatLight Works”, “we”, “us”), a corporation incorporated under the Canada Business Corporations Act, corporation number 1820555-8, registered extra-provincially in Ontario under Ontario corporation number 1001730320. GreatLight Works Inc. is the controller of the personal information described in this policy.

Our Privacy Officer can be reached at hello@myeliora.app.

What this policy covers

This policy explains what we collect, why, who we send it to, and what you can control. It is written for the service as it is today and is updated when that changes.

Eliora is operated from Canada and is designed to meet applicable Canadian privacy requirements, including PIPEDA and, where applicable, Quebec’s private-sector privacy law, and to follow recognised privacy-by-design principles.

Before we intentionally offer or direct the service in another jurisdiction, we assess material jurisdiction-specific privacy requirements and update our practices where required.

We do not claim that a single privacy policy establishes compliance with every privacy law worldwide.

The data we collect

Connected Google services (Google Calendar)

If you choose to connect Google Calendar, Eliora accesses only the Google Calendar information and permissions needed to provide the calendar features you enable. Eliora requests Google’s calendar.events.owned scope. Google’s permission allows Eliora to access events on Google calendars you own; it does not cover calendars other people have shared with you, and it does not allow changes to calendar-sharing or access-control settings. Eliora currently uses this permission only with your primary Google Calendar: to show relevant events, to check whether an Eliora item is already there so it is not added twice, and to add an event when you choose “Add to Google Calendar”. Eliora does not change or delete your existing Google Calendar events.

Depending on the feature and permissions you approve, this may include event titles and descriptions, dates and times, attendees, availability information and other event information available through the permissions you grant.

We use Google Calendar information only to provide or improve the user-facing connected features you request: to show your schedule inside Eliora, to include upcoming items in your daily brief, and to add an event to your Google Calendar when you ask. We request only the permissions reasonably necessary for those features.

Events retrieved from Google are held only for as long as needed to display them and to build your brief. We do not build a separate permanent copy of your Google Calendar, and any cached event data is deleted when you disconnect the integration or delete your account.

The access Google grants Eliora (its access tokens) is kept on Eliora’s servers only and is never sent to your browser or to the app. It is protected by encryption in transit and by our database provider’s encryption at rest, and only Eliora’s backend uses it, to make the Google Calendar requests described above.

We do not sell Google user data or use it for advertising. We disclose Google Calendar information to a service provider only where reasonably necessary to provide a feature you have requested, and subject to the privacy controls described in this Policy. Where a feature requires relevant Calendar information to be processed by one of Eliora’s AI providers, that transmission occurs only under Eliora’s applicable AI-processing controls and only for the user-facing feature you requested. We do not use Google Calendar information to train general-purpose AI models, and our AI providers receive it under API terms that do not allow them to use it to train their models.

You can disconnect Google Calendar at any time from the Google Calendar integration in Eliora, or revoke Eliora’s access from your Google Account permissions page. Disconnecting deletes the access tokens Eliora holds and asks Google to revoke Eliora’s access, so access stops straight away. Information that you separately chose to save into Eliora remains subject to Eliora’s normal retention and deletion controls.

Eliora’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sensitive information

Some hubs let you record health, financial, family or children’s, or faith information. We collect this only because you choose to enter it, and we process it to provide the features you asked for. The Vitality (health) hub and the Family hub each require a separate, explicit opt-in before you can use them, and you can withdraw that at any time. Eliora is an organisation tool, not a medical, legal or financial adviser, and does not diagnose.

Why we use your data

We use your personal information to:

We limit what we collect and use to what is needed for the function you have asked for.

Consent, and what it does and does not cover

Under Canadian privacy law we obtain meaningful consent where consent is required, and we decide what form that consent should take by looking at how sensitive the information is, what you would reasonably expect, and what the consequences of the processing are. When you sign up, your acceptance of the Terms, acknowledgement that this Privacy Policy has been made available to you, and confirmation that you are 18 or older are recorded. Privacy choices that require a separate affirmative decision are recorded separately.

Some processing simply has to happen for an account you asked us to create to exist and stay secure. We do not present that as a separate choice, and where another country’s law asks us to identify a specific legal ground for it, we record that ground rather than treating everything as consent. The section “Legal bases (UK/EU users)” below sets those out.

What we do treat as a distinct, explicit choice — never bundled into acceptance of the Terms, always withdrawable from Privacy & Data:

Each choice is recorded with the exact wording you were shown, and withdrawal is recorded the same way.

AI processing and providers

We use AI providers — currently OpenAI, Anthropic, Google and Groq — to classify, organise, transcribe and answer.

We do not send your personal content to an AI provider until you have said yes. That is a rule we chose, and it is stricter than the law requires:

Turning a recording into words is a separate permission. Before your first recording we ask once whether the audio may go to our speech-to-text provider (Groq, or OpenAI if Groq is unavailable); that one answer covers every place you can record — capture, your journal and your notes — and you can withdraw it in Settings at any time. If you would rather nothing you say leaves your device, type instead, or dictate with your phone keyboard’s own microphone, which never reaches us.

Saying yes to AI does not re-open anything you have switched off. A hub you have withdrawn consent from, a hub you have PIN-locked, and your journal all stay excluded regardless.

We send the minimum context needed for the specific request. Having an account does not mean everything in it is available to every AI request.

Under the commercial or API terms that apply to Eliora, our AI providers state that customer API content is not used to train their general-purpose models by default. Where a provider offers optional data-sharing or model-improvement controls, we configure those controls consistently with the privacy practices described in this Policy and periodically re-verify material provider settings.

Forwarding emails to Eliora

Where forwarding is available on your account, Eliora gives you a personal capture address. An email you send or forward to that address is received through our email-service provider and then handled by Eliora much like a capture you type.

If AI processing is enabled for your account, the email text needed to understand and file the capture may be sent to our AI providers under the same AI-processing choice described above. Before that AI processing, Eliora removes links and recognised forwarding-header information where supported by the feature.

Mail is accepted for filing only when it comes from your Eliora sign-in address or another email address that you have confirmed using a verification code sent to that address, and when the message passes Eliora’s applicable sender-authentication and anti-spoofing checks. Mail that does not meet those conditions is not filed into your Eliora account.

If AI processing is not enabled, Eliora does not send the forwarded email content to an AI provider. The app will handle the message according to the forwarding behaviour shown to you at that time rather than treating the absence of AI consent as permission.

Forwarded email may contain information about other people. You should forward personal or sensitive information about another person only where you have an appropriate reason and authority to do so, consistent with the section “Other people, and children”.

What Eliora files from a forwarded email is retained like other content you create and follows the same deletion controls. Confirmed forwarding addresses are deleted when your account is deleted.

The email-delivery provider may temporarily retain the original inbound message and related delivery information under its own processing and retention arrangements before that provider-side copy expires. Our current service providers and their processing locations are listed on the Sub-processors page.

You can generate a new personal capture address at any time in Settings. When you do, the previous address stops accepting captures for your account.

Your journal

Your journal is treated differently from everything else in Eliora. By default it stays out of AI entirely. AI touches your journal words only when you deliberately tap a feature that says so, and each of those features is described where you use it.

Other people, and children

You may record information about other people — a partner, a relative, a friend, a colleague, a child.

When you do, you confirm that you have the right, authority, permission or other lawful basis to provide and manage that information. Where the information is about a child, you confirm that you are that child’s parent or legal guardian, or are otherwise lawfully authorised to manage it. The Family hub asks you to confirm this again before you use it.

Please do not store another person’s sensitive information unless you have a good reason and the authority to do so.

We keep information about other people to a minimum. We never go and collect information about someone just because you mentioned them, and when Eliora spots a person in something you captured it proposes a record for you to confirm — it does not create one silently.

Eliora is for adults. You must be 18 or over. We do not knowingly provide accounts to children, and Eliora is not designed, marketed or distributed for children. A child whose details appear in an adult’s Family hub is not an Eliora user. We review from time to time whether the service is in fact being used directly by children, and would reassess our approach if it were.

When a person can see your content

We do not routinely read your content. There is no moderation queue, no review team, and we do not sample what you write to check quality.

Someone authorised may need to access content only where it is reasonably necessary — to investigate a security problem, to comply with the law, or to help you with support that you have asked for or authorised. Access is limited to the people who need it, those people are under confidentiality obligations, and privileged access is logged.

The Vault

Files you place in the Vault are encrypted on your device (AES-256) using a key derived from a passphrase that only you know. We store and transmit only the encrypted result, and we cannot read your Vault files or recover your passphrase. If you lose both your passphrase and your recovery key, nobody — including us — can recover the contents.

This protects the contents of your files. Some information needed to operate the Vault — that an item exists, its size, when it changed — remains visible to us. That is why we describe it as a client-side encrypted Vault rather than using stronger language that might suggest we know nothing about it at all.

The optional per-hub PIN is a privacy screen on your device, not encryption.

The Eliora app on your phone

The Eliora app for iPhone and Android is the same service as the website, signed in to the same account, with the same choices and the same controls. A few things are specific to the app:

Push notifications

If you enable notifications, Eliora uses Apple Push Notification Service on Apple devices, Firebase Cloud Messaging on Android devices, and your browser’s own push service on the web to deliver notifications you have requested or enabled. These services receive a device-specific push token and the limited notification information needed for delivery.

Push notifications are optional and can be disabled through your device or browser settings. Eliora is designed not to place sensitive personal or confidential information in a remote push-notification payload: before a reminder is sent, its wording is checked by the same rule that identifies sensitive content elsewhere in Eliora, and a reminder that touches health, legal, financial or similar matters is delivered as “You have a reminder” — the full text is retrieved from Eliora after you open the app. On Android the notification is kept off the lock screen; on iPhone your phone’s own preview setting decides.

Apple and Google may process technical information associated with notification delivery under their applicable service and privacy terms.

Where your data is stored, and international transfers

Eliora uses service providers in the United States and other jurisdictions, including providers that operate global infrastructure. The providers that process personal information on Eliora’s behalf are identified on our Sub-processors page: Supabase (database, authentication and file storage), Vercel (web hosting), Render (our backend), Resend (email), the AI providers named above, Sentry (crash and error reports, with personal-information sending disabled), OtaKit (updates to the mobile app’s screens: the phone’s IP address, the app version and update results, never your content or identity), Namecheap (domain and mailbox), Google and Apple (push-notification delivery to the mobile app), WeatherAPI (weather forecasts and city search, contacted by our backend on your behalf) and Google News RSS (the topic you follow, never your identity). A current, itemised list is published at /subprocessors and is updated before we add or change a provider. Before we send personal information to a provider outside Quebec we assess the sensitivity of the information, what it will be used for, the contractual and technical protections, and the legal environment of the destination — including government-access risk — and we only proceed where that assessment supports it. Those transfers are governed by written agreements with each provider.

Retention

We keep information for as long as it is needed for the purpose it was collected for, and no longer. Different kinds of information have different lifespans:

WhatHow long we keep it
Your account and sign-in informationWhile your account exists
The content you create — notes, entries, journal, goals, people, hub recordsUntil you delete it, or you delete your account
Files you uploadUntil you delete them
Temporary processing artefacts created while filing a captureUp to 90 days
Content you have deleted, before the purge runsUp to 30 days
Copies held by AI providersTheir retention window; see Sub-processors
Product analytics14 months
Service records (captures that failed)14 months
The date you last used ElioraWhile your account exists (a single date, replaced each time)
Anonymous usage counts14 months; they identify no one
How you found Eliora, kept with your account (only if you accept analytics)14 months, then deleted
Application and security logs14 months
Your audit logAbout 14 months
Records of privacy, email and consent choicesWhile needed to administer your choices and, where reasonably necessary after withdrawal or account closure, to demonstrate compliance with applicable law; retained in minimised form and then deleted or anonymised when no longer required
Records of privacy or security incidentsAt least 24 months, as the law requires

Accounts that are no longer used

If an account has not been used for 12 months, we may delete it. Before we do, we email the account address — after about 3 months and about 6 months without use, and a final time about 30 days before deletion — so you can come back or delete it yourself. Using Eliora at any time resets the clock. Deletion of an unused account follows the same process as “Deleting your account” below.

Deleting your account

You can delete your account at any time from Privacy & Data. We ask you to type a confirmation and to enter a six-digit code we email to your account address, so that nobody else can do it for you.

Deletion removes your personal content, uploaded files, sign-in record and other account data from Eliora’s active product systems.

We may retain limited records separately where reasonably necessary to demonstrate or comply with legal obligations — for example records of consent or withdrawal, unsubscribe actions, account deletion, security incidents or other compliance events. These records are minimised, are not used to continue providing the deleted account or for marketing, and are retained only for as long as reasonably necessary for the relevant purpose.

Encrypted copies of deleted information may also remain temporarily in routine provider backups until those backups expire or are overwritten under the provider’s normal backup cycle. Those copies are not used for ordinary product purposes. If a backup is restored after a disaster, applicable deletion controls are reapplied.

Your rights and controls

From Privacy & Data inside the app you can export a full copy of your data as a single structured file, and delete your account.

Separately, and regardless of what the app offers, you may contact our Privacy Officer at hello@myeliora.app to:

We may take reasonable steps to confirm your identity, and the authority of anyone making a request on your behalf, before we release or change personal information.

The tools in the app add to your legal rights; they do not limit them.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to the Commission d’accès à l’information du Québec if you are in Quebec.

Where UK or EEA data-protection law applies to Eliora’s processing of your information, you may also have the right to complain to the applicable data-protection authority.

Where California privacy law applies to Eliora and your information, you may have additional rights including rights concerning access, correction and deletion. Eliora does not sell personal information or use it for cross-context behavioural advertising.

Legal bases (UK/EU users)

Where UK or EU data-protection law applies, we process your personal data on these bases: performance of our contract with you, to provide the service you asked for; your consent, for optional features and for special-category data, which you can withdraw at any time; our legitimate interests, in keeping Eliora secure, reliable and improving it, and in understanding which of our announcements bring people to Eliora — which is the basis for the service records, the anonymous usage counts and the anonymous campaign totals described under “Service records and analytics”; you may object to them by contacting us; and compliance with legal obligations where applicable.

Canadian privacy law

Eliora is operated from Canada, so PIPEDA applies to how we handle your personal information, and Quebec’s Law 25 applies to residents of Quebec.

We have carried out a Privacy Impact Assessment covering this service and the transfer of personal information outside Quebec to the providers listed under Sub-processors. Our Privacy Officer is our accountable individual for privacy, and we will confirm the identity of that individual on request.

Security

We use technical and organisational safeguards appropriate to the nature and sensitivity of the information we handle. These include encryption in transit, provider-managed encryption at rest for standard stored data, client-side encryption for Vault file contents, account and database access controls, authentication safeguards and restricted administrative access.

Some additional account-security features, including two-factor authentication, may be available to you.

No method of transmission, storage or security is completely risk-free. We maintain safeguards designed to reduce those risks and procedures for responding to privacy and security incidents.

If a privacy or security incident occurs that creates a real risk of significant harm to you, we will notify you and the appropriate regulator as the law requires.

Service records and analytics

Eliora measures itself in three layers. None of them involves third-party analytics or advertising software, none is sold, and none is used to show you advertising.

1. Service records — kept for everyone, and kept narrow. To run Eliora reliably we record, against your account: when a capture fails, what kind it was (text, voice, photo or file), why it failed, and the platform and app version it failed on — never its content; and the date you last used Eliora — a single date, replaced each time, not a history. We use these records to find and fix problems and to administer unused accounts (see “Accounts that are no longer used”). Failed-capture records are kept for 14 months; the last-used date is kept while your account exists. 2. Anonymous usage counts — kept for everyone. We count how often parts of Eliora are used — for example how many times the Daily Brief was opened on a given day, on each platform. These counts are stored as totals with no account, name or device attached, so they cannot identify you. They are kept for 14 months. 3. Product analytics — only if you say yes. If you accept analytics, we also record how you, individually, use Eliora — for example which days you used it, which platform you first used it on, that you opened your Daily Brief or that you acted on a suggestion from Eliora — so we can see whether and how Eliora helps people. These events go to Eliora alone, are tied to your account and are kept for 14 months. Product analytics are opt-in: if you decline, you lose no functionality, and you can change your answer in Settings at any time.

How you found Eliora. At sign-up we may ask how you heard about Eliora; answering is optional. When you arrive through a link we have labelled for a particular announcement or campaign, we note that label. For everyone, your answer and the label are counted in anonymous totals that are not linked to you, which tell us which of our announcements bring people to Eliora. Only if you accept analytics do we also keep them with your account, for 14 months, after which they are deleted, so we can see how people who arrived from each announcement go on to use Eliora. They are never combined with information from other companies or shared with advertisers.

Cookies and local storage

We use what is needed to keep you signed in, to remember your preferences on your device, and to remember your analytics choice.

Changes to this policy

We will publish material changes to this Policy with an updated effective date and, where appropriate, provide notice in the app or by another reasonable means.

Where a change affects processing for which applicable law requires renewed consent, or processing that Eliora makes conditional on an affirmative privacy choice, we will obtain the required choice before that changed processing occurs.

Contact

Privacy Officer, GreatLight Works Inc. — hello@myeliora.app

GreatLight Works Inc., Ontario, Canada.

Sub-processors · Terms of Service · ← Back to home