LEGAL

Privacy Policy

Effective: 30 August 2026 · Last updated: 1 September 2026

1. Who we are

Elvz is an AI social media and marketing platform operated by Elvz AI Private Limited, incorporated in India, registered office 254, Lane 20, Vijay Park, Delhi, India. “Elvz”, “we”, “us”, and “our” mean that company. “You” means the person using the service.

For data you upload, or that we retrieve from an account you connect, we act as a processor on your behalf. For your own account, billing, and product usage data, we act as a controller.

This policy covers the Elvz web application at app.elvz.ai, the marketing site at elvz.ai, and every platform and integration listed below.

2. The short version

  • We collect what you give us, what you connect, and what the product generates for you.
  • We do not train AI models on your content, and our AI providers are contractually barred from doing so.
  • We do not sell your data, and we do not use it for advertising.
  • Every connection is opt-in, per workspace, and revocable in one click.
  • Nothing is published to your accounts without your approval.
  • You can delete everything at any time — see our Data Deletion Instructions.

3. Data we collect

Data you give us

CategoryExamples
AccountName, email, password hash or Google sign-in identifier, profile photo
WorkspaceBrand name, website URL, industry, brand voice and positioning you enter
ContentPost drafts, prompts, briefs, uploaded images and video, product photos
ConversationsYour chat history with Fable and our other AI agents
SupportEmails and messages you send us

Data we generate

  • Content produced for you — captions, images, video, campaign plans, drafted replies.
  • Brand knowledge documents derived from your website, connected accounts, and imported files: service description, market analysis, brand voice, values, competitor positioning.
  • Credit balances, usage counts, and plan status.

Data we collect automatically

  • IP address, browser and device type, approximate location derived from IP.
  • Log data: pages viewed, features used, timestamps, error reports.
  • Essential cookies for authentication and session security. We do not use advertising cookies and we do not run third-party ad trackers.

Payment data

We never see or store your card details. Payments are processed by Dodo Payments, which acts as merchant of record and seller of record for your subscription. We receive only your subscription status, plan, transaction identifiers, and billing email.

4. Connected social platforms

When you connect a social account you grant Elvz permission through that platform’s own official login flow. Connections are made per workspace, are always optional, and can be revoked at any time. We request only what the feature you are using needs.

Access tokens are stored encrypted and used only server-side. They are never sent to your browser, never shown in chat, and never shared with another customer.

InstagramLIVE

Elvz supports two Instagram connection methods. Which one you use depends on how your account is set up; the app tells you at connect time. We request only the permissions listed for the method you choose.

Instagram Login (business or creator account, no Facebook Page required)

PermissionWhat we do with it
instagram_business_basicRead your profile, follower count, and media so we can show your account and learn your brand voice
instagram_business_manage_commentsRead comments and reply, including comment-to-DM automations
instagram_business_manage_messagesRead and send direct messages for story-reply, keyword, and mention automations
instagram_business_content_publishPublish posts you have approved

Facebook Login (Instagram account linked to a Facebook Page)

PermissionWhat we do with it
pages_show_listList the Facebook Pages you manage so you can pick one to connect
pages_read_engagementRead recent posts and engagement to learn your brand voice and report performance
instagram_basicRead the linked Instagram account profile and media
pages_messagingSend and receive Page messages for automations
instagram_manage_messagesRead and send Instagram direct messages for automations
instagram_manage_commentsReceive comment notifications and send replies
instagram_manage_insightsList active stories so an automation can target a specific one, and read performance metrics
pages_manage_metadataSubscribe your Page to our webhooks so automations receive events
pages_manage_postsPublish Page posts you have approved
instagram_content_publishPublish Instagram posts you have approved

What we store: Profile metadata, your most recent posts and their engagement metrics, and the comment and message threads involved in automations you have switched on.

Facebook PagesLIVE

Facebook uses the same Meta permission grant as the Instagram Facebook Login method above. Connecting one may connect both, and the consent screen shows you exactly what is granted.

What we store: Page profile details, your most recent Page posts and engagement metrics, and message threads involved in automations.

LinkedInLIVE

LinkedIn access is layered. Sign-in requests identity only. Publishing and analytics permissions are requested separately, and only once LinkedIn has approved us for them and you have opted in.

Always requested

PermissionWhat we do with it
openid, profile, emailSign you in and read your name, profile identifier, and email address

Requested only where enabled and approved

PermissionWhat we do with it
w_member_socialPublish posts to your personal LinkedIn feed on your approval
w_organization_socialPublish posts to a company Page you administer
r_organization_admin / rw_organization_adminConfirm which company Pages you administer and read their post performance
r_member_postAnalyticsRead performance metrics for your own posts

What we store: Your name, LinkedIn identifier, and email. Where publishing and analytics are enabled, the posts we published for you and their metrics. We never read your LinkedIn messages or your connections list.

ThreadsLIVE

Threads is a Meta product with its own permission set, granted separately from Instagram and Facebook.

Permissions requested

PermissionWhat we do with it
threads_basicRead your Threads profile and posts
threads_content_publishPublish threads you have approved
threads_read_repliesRead replies to your threads
threads_manage_repliesReply on your behalf where you have set up an automation
threads_manage_mentionsSee threads that mention you so an automation can respond
threads_manage_insightsRead performance metrics for your threads

What we store: Profile metadata, your recent threads and their metrics, and reply and mention threads involved in automations.

TikTokLIVE

Elvz reads your public creator profile and publishes videos you have approved. We do not read your TikTok direct messages.

Permissions requested

PermissionWhat we do with it
user.info.basicRead your TikTok display name, avatar, and open identifier
user.info.statsRead your follower, following, and video counts to report performance
video.listList your published videos and their public metrics
video.publishUpload and publish videos you have approved, using the settings you choose

What we store: Profile metadata, your recent videos and their public metrics, and the publish status of videos we posted for you.

YouTubeLIVE

YouTube access uses Google OAuth. See the Google user data section below, which governs everything we do with data received from Google APIs.

Permissions requested

PermissionWhat we do with it
youtube.readonlyRead your channel details, video list, and public metrics
youtube.uploadUpload videos you have approved
youtube.force-sslRead and post comments, and manage videos we published for you
yt-analytics.readonlyRead channel and video analytics to report performance

What we store: Channel metadata, your recent videos, analytics metrics, and comment threads involved in automations.

PinterestLIVE

Permissions requested

PermissionWhat we do with it
user_accounts:readRead your Pinterest account profile
boards:readList your boards so you can choose where a Pin goes
boards:writeCreate a board where you have asked us to
pins:readRead your Pins and their metrics to report performance
pins:writePublish Pins you have approved

What we store: Account metadata, your boards, and your recent Pins with their metrics.

Google Business ProfileLIVE

Google Business Profile access uses Google OAuth. See the Google user data section below.

Permissions requested

PermissionWhat we do with it
business.manageList the business locations you manage, read reviews and posts, and publish updates you have approved

What we store: Location metadata, your recent Business Profile posts, and review content where you have enabled review-reply automations.

X (Twitter)NOT YET AVAILABLE

Not yet available. When X connections launch we will publish the exact permissions we request in this policy before the feature goes live.

Your websiteLIVE

When you add a website to a workspace we crawl its publicly accessible pages to build your brand knowledge. We read only public content and respect standard crawler directives. We do not attempt to access pages behind a login.

What we store: Page text and images from the public pages we crawled, and the brand knowledge documents we derive from them.

Across every connected platform we hold at most your 50 most recent posts per account, refreshed periodically, plus the metrics attached to them. Older synced posts are discarded as new ones arrive.

5. Connected integrations

Integrations bring your own business material into a workspace so agents work from facts instead of guesses. Every integration is opt-in per workspace, read-only unless stated otherwise, and disconnectable at any time. Connections for these integrations are established and held by Composio, our integration provider, which brokers our read requests to each provider. Disconnecting revokes the credential upstream and deletes the connection.

Some integrations below are in our product catalogue but not yet available. They are listed for transparency about where the product is going. We collect nothing from them, and we will document them here before each one launches.

Access is described by data category rather than by raw permission string. These connections are brokered by Composio, whose authorisation settings sit outside our application code, so a transcribed permission list would drift out of date without anyone noticing. The categories below state what Elvz can actually read. Your social publishing platforms are not brokered this way, and their exact permissions are listed in Section 4.

Cloud storage

IntegrationAccess requestedWhat we do with it
Google Drivedrive.file, openid, emailRead only the specific files and folders you pick yourself in Google’s own picker. Elvz has no visibility into the rest of your Drive
DropboxFiles you select, and your account nameRead the documents you choose so agents can ground their work in your own material
OneDriveFiles you selectRead the documents you choose
BoxFiles you selectRead the documents you choose

Docs and notes

IntegrationAccess requestedWhat we do with it
NotionPages and databases you select during Notion’s own connect flowRead the pages you share with Elvz
Google DocsDocuments you selectRead the documents you choose
Google SlidesPresentations you selectRead the decks you choose, for brand and messaging context
Google SheetsCovered by the Google Drive connection — no separate grantRead the spreadsheets you choose
ConfluenceSpaces and pages you selectRead internal documentation you point us at
CodaDocs you selectRead the docs you choose

Calendar

IntegrationAccess requestedWhat we do with it
Google CalendarCalendar list and event details, read-onlyRead your calendars and events so content planning respects launches, holidays, and campaigns
Outlook CalendarBasic event times, read-onlyRead basic event times so content planning respects your schedule

E-commerce

IntegrationAccess requestedWhat we do with it
Shopifyread_products, read_inventoryRead your product catalogue and stock levels so agents write accurate product content. We do not request access to your orders or your customers

Web analytics

IntegrationAccess requestedWhat we do with it
Google Analytics 4Aggregated reports, read-onlyRead traffic and conversion reports to measure what your content achieved
Google Search ConsoleSearch performance data for your verified sites, read-onlyRead queries, impressions, and click data
AmplitudeAggregated product analytics, read-onlyRead event and funnel reports to measure content impact

SEO

IntegrationAccess requestedWhat we do with it
SemrushKeyword, ranking, and competitor reports for your domainsRead search visibility data to inform content strategy
AhrefsBacklink, keyword, and ranking reports for your domainsRead search visibility data to inform content strategy

Advertising

IntegrationAccess requestedWhat we do with it
Meta AdsCampaign, ad set, and creative performance, read-onlyRead ad performance so agents learn which messaging works. We do not create, edit, or spend on campaigns
Google AdsCampaign and keyword performance, read-onlyRead ad performance to inform content and messaging
LinkedIn AdsCampaign performance, read-onlyRead ad performance to inform content and messaging
TikTok AdsNOT YET AVAILABLENot yet availableNothing is collected

Design

IntegrationAccess requestedWhat we do with it
CanvaDesigns and brand assets you selectRead your designs and brand assets so generated visuals match your identity
FigmaFiles and projects you selectRead design files for brand colours, type, and component styling
Adobe ExpressNOT YET AVAILABLENot yet availableNothing is collected

Email marketing

IntegrationAccess requestedWhat we do with it
MailchimpCampaigns, templates, and audience listsRead past campaigns and performance so agents match your email voice. Audience data includes subscriber records — see “Data about other people” below
KlaviyoCampaigns, flows, and audience listsRead campaign performance and segments. Audience data includes subscriber records
BrevoCampaigns and contact listsRead campaign performance and segments. Contact data includes subscriber records

CRM

IntegrationAccess requestedWhat we do with it
HubSpotContact, company, and deal recordsRead customer records so agents understand who you sell to. These records describe identifiable people — see “Data about other people” below

Customer support

IntegrationAccess requestedWhat we do with it
IntercomConversations and contact recordsRead support conversations so agents learn the questions customers actually ask. These contain identifiable people — see “Data about other people” below
ZendeskTickets and requester detailsRead support tickets so agents learn common issues and your tone. These contain identifiable people

Community

IntegrationAccess requestedWhat we do with it
SlackChannels and messages you grant access toRead the channels you select for product context and internal announcements. Messages are written by your colleagues — see “Data about other people” below
RedditPublic posts and commentsRead public community discussion for audience research. We do not post on your behalf

CMS

IntegrationAccess requestedWhat we do with it
ContentfulEntries and assets in the spaces you selectRead published content so agents stay consistent with your site
WebflowSite content and CMS collectionsRead published content so agents stay consistent with your site
WixSite contentRead published content so agents stay consistent with your site

Project management

IntegrationAccess requestedWhat we do with it
AsanaProjects and tasks you selectRead your plans so content scheduling reflects real launch dates
ClickUpSpaces and tasks you selectRead your plans so content scheduling reflects real launch dates
AirtableBases and tables you selectRead structured business data you point us at

What happens to imported data when you disconnect

This differs by source, deliberately:

  • Deleted immediately — Google Calendar, Outlook Calendar, Mailchimp, Klaviyo, Brevo, Intercom, Zendesk, and HubSpot. Every one of these carries personal data about people who never signed up for Elvz, so revoking access removes everything derived from them.
  • Retained until you delete it — every other integration: cloud storage, docs and notes, e-commerce, analytics, SEO, advertising, design, community, CMS, and project management. These hold your own documents and business facts, and silently discarding an imported corpus because you reconnected a provider would be its own kind of data loss. You can delete this material at any time from the workspace.

In both cases the access token is revoked and erased the moment you disconnect.

6. Google user data and Limited Use

Several Elvz features use Google APIs: Google sign-in, Google Drive, Google Docs, Google Slides, Google Calendar, Google Analytics 4, Google Search Console, Google Ads, YouTube, and Google Business Profile.

Elvz’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means:

  • We use Google user data only to provide or improve the user-facing features you connected it for. Nothing else.
  • We do not transfer Google user data to third parties except as necessary to provide those features, for security, or to comply with law.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not use Google user data to train, retrain, or fine-tune any generalised or foundation AI model. Where Google user data is sent to an AI provider to produce output for you, that provider processes it under enterprise terms that prohibit training on it.
  • No human at Elvz reads your Google user data, except with your explicit permission, for a documented security investigation, to comply with law, or where the data is aggregated and anonymised.

Scopes we request

Elvz requests no restricted Google scopes. Google Drive access uses drive.file, which limits us to the individual files and folders you select in Google’s own picker. Our remaining Google permissions are read-only analytics, calendar, search, and channel scopes, each listed against its feature in the tables above. We request the narrowest scope that makes each feature work, and every Google connection is optional — you can use Elvz fully without connecting any Google account.

7. Meta Platform Data

Data we receive from the Instagram, Facebook, and Threads APIs is Platform Data under the Meta Platform Terms. Our use of it follows those terms and the Meta Developer Policies.

  • We do not sell, licence, or transfer Meta Platform Data, and we do not use it for advertising or to build advertising profiles.
  • We do not use Meta Platform Data to train, retrain, or fine-tune any AI model.
  • Where Meta Platform Data is sent to an AI provider so that it can produce content or a reply for you, that provider acts strictly as our service provider under written terms that forbid training on the data, forbid any independent use of it, and require deletion on our instruction.
  • We delete Meta Platform Data without undue delay when you disconnect the account, when it is no longer needed for the feature you enabled, when you delete your account, or when Meta or the law requires it.
  • Incoming Meta webhooks are cryptographically signature-verified before we process them.

8. TikTok data

Our access to and use of data from the TikTok API is governed by the TikTok Developer Terms of Service and the TikTok Developer Data Sharing Agreement, including the Developer Controller-to-Controller Data Terms that apply to United States personal data from 22 January 2026.

  • We collect only your creator profile, your public video list and its public metrics, and the publish status of videos we posted for you.
  • We do not read your TikTok direct messages, and we do not request that permission.
  • We do not sell TikTok data, do not use it for advertising, and do not use it to train AI models.
  • We honour the privacy, comment, duet, and stitch settings your TikTok account returns, and we surface them to you before a video is published.
  • TikTok data is deleted when you disconnect the account or delete your Elvz account.

9. Data about other people

Some features necessarily process data about third parties — people who comment on your posts, message your accounts, email you, or appear in your calendar. For all of it you are the controller and we are your processor. We handle it narrowly:

Commenters and people who message you

  • Where an automation has run, we store the commenter’s platform identifier and handle so the same person is not replied to twice and so a conversation can continue. We do not build profiles of these people, we do not enrich or cross-reference them against any other source, and we do not use their data for any other purpose.
  • Where an automation must actually converse — a comment-to-DM flow, a story reply, a mention response — we necessarily store the message and comment thread itself, including the platform handle, for as long as the conversation is live. That is the minimum a reply feature can run on.
  • Where we derive audience insight from comments, we store only paraphrased patterns, never verbatim text, and identifiers are stripped first.
  • If someone deletes their comment or message at source, we delete our record and re-derive any affected insight.
  • Inbound engagement we observed but never acted on is deleted after 400 days. Threads an automation actually replied to are kept while the workspace exists, and are removed when you delete the workspace or your account, or sooner on request.

Calendars, support desks, CRM, and marketing lists

Eight integrations carry personal data about people who never signed up for Elvz. Because of that, they are handled more strictly than the rest:

IntegrationWhose data
Google Calendar, Outlook CalendarMeeting attendees — names, email addresses, and what the meeting is about
Intercom, ZendeskPeople who contacted your support desk — names, email addresses, and the contents of their conversations
HubSpotYour CRM contacts — names, employers, deal history
Mailchimp, Klaviyo, BrevoYour marketing subscribers — email addresses and list membership
  • All eight are read-only. Elvz cannot send, reply, delete, or alter anything in your calendar, support desk, CRM, or mailing list.
  • Everything derived from these sources is deleted immediately when you disconnect the provider — this is enforced in code, not by policy alone.
  • We do not use this data to contact anyone, and we never add these people to any list of our own.
  • Before connecting a shared or company account, please make sure you are entitled to do so under your own organisation’s policies and applicable law.

Workplace messages

If you connect Slack, we read the channels you grant access to. Those messages are written by your colleagues. We read them for product and announcement context only, we do not post to Slack, and we do not build profiles of the people in a channel. Connect only channels you are entitled to share.

Public community content

The Reddit integration reads public posts and comments for audience research. We do not post, vote, or message on your behalf, and we store only paraphrased themes rather than individual users’ verbatim text.

Shopify catalogue data

We request read_products and read_inventory only. We do not request access to your orders, your customers, or their personal data, and we cannot read them.

If someone asks us to delete data about them, we will route the request to the customer who controls it and assist in fulfilling it. See Data Deletion Instructions.

10. Why we use your data

PurposeLegal basis (GDPR)
Provide the service you signed up forPerformance of a contract
Process payments and prevent fraudContract; legal obligation
Access connected platforms and integrationsConsent, given through each provider’s login flow
Keep the service secure and prevent abuseLegitimate interests
Improve the product and fix bugsLegitimate interests
Send service and security noticesContract; legal obligation
Send product marketing emailsConsent — opt out at any time

If you are in India, we process personal data on the basis of your consent or the legitimate uses permitted under the Digital Personal Data Protection Act, 2023.

11. AI processing and model training

Elvz is built on third-party AI models, currently Google’s Gemini family for text and reasoning and Google’s image and video generation models. To produce content for you, we send relevant parts of your brand knowledge, your prompt, and connected-account context to these models.

Our commitments:

  • We do not train AI models on your content. Not our own models, and we use enterprise API terms that prevent our providers from training on your data or using it independently.
  • Workspaces are isolated. Nothing from one workspace is ever used to inform another. This is enforced in code, not by policy alone.
  • Nothing publishes without your approval. Generated posts and drafted replies are queued for review.
  • Your brand knowledge is readable and correctable. You can view every document we hold about your brand, edit it, and delete it.

AI output can be wrong. You are responsible for reviewing content before publishing — see our Terms of Service.

12. Who we share data with

We do not sell your data. We share it only with the providers we need to run Elvz:

ProviderPurposeLocation
Google Cloud & FirebaseHosting, database, file storage, authenticationUS / EU
Google (Gemini & generative media APIs)AI text, image, and video generationUS
Dodo PaymentsPayment processing, merchant of record, tax complianceGlobal
ResendTransactional email deliveryUS
ComposioOAuth connection brokering and API access for knowledge and data integrations (cloud storage, notes, calendar, e-commerce, analytics). Holds the connection credential for these integrations and proxies our read requests to the providerUS
Connected platforms and integrationsOnly the data needed to publish, read, or automate on the account you connectedGlobal

We may also disclose data where legally required, or to protect our rights, users, or the public. If Elvz is acquired or merged, data may transfer to the acquirer under this same policy; we will notify you first.

13. International transfers

We are based in India and our providers operate globally, so your data is transferred and stored outside your country. For transfers out of the EEA or UK we rely on the European Commission’s Standard Contractual Clauses and equivalent safeguards.

14. How long we keep data

DataRetention
Account and workspace dataUntil you delete your account
Synced social posts, profile data, and metricsUntil you disconnect the account or delete the workspace; at most the 50 most recent posts per account
Inbound engagement we observed but did not act on400 days, or sooner if deleted at source
Comment and message threads involved in an automationKept while the workspace exists; deleted when you delete the workspace or your account, or sooner if deleted at source
Calendar, support desk, CRM, and marketing list dataDeleted immediately on disconnect
Imported documents and business dataUntil you delete them or delete your account
Generated and uploaded mediaUntil you delete it or delete your account
Access tokensDeleted immediately on disconnect or revocation
Invoices and financial records8 years, as required by Indian law
Security and access logs12 months

After account deletion, backups containing your data are overwritten within 30 days.

15. Your rights

Depending on where you live, you have the right to:

  • Access the personal data we hold about you.
  • Correct it — most of it you can edit directly in the app.
  • Delete it. See our Data Deletion Instructions.
  • Export it in a portable format.
  • Withdraw consent at any time, including by disconnecting any platform or integration.
  • Object to or restrict processing based on legitimate interests.
  • Nominate someone to exercise your rights if you die or become incapacitated (India, DPDP Act).
  • Complain to your data protection authority, or in India to the Data Protection Board.

Email contact@elvz.ai. We respond within 30 days and never charge for a first request.

16. Security

  • All traffic is encrypted in transit (TLS); data is encrypted at rest.
  • Access tokens and secrets are held server-side only and never exposed to the browser.
  • Every request is authenticated and scoped to your account — workspace separation is enforced at the data layer.
  • Incoming platform webhooks are cryptographically signature-verified before processing.
  • Internal access is limited to staff who need it, and is logged.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by law. Report a vulnerability to contact@elvz.ai.

17. Children

Elvz is a business product and is not intended for anyone under 18. We do not knowingly collect data from children. If we learn that we have, we will delete it. Parents or guardians can contact contact@elvz.ai.

18. Changes to this policy

We will update this page when our practices change and revise the date at the top. Every new platform or integration is documented here before it becomes available to connect. For material changes we will email you or show a notice in the app at least 14 days before they take effect.

19. Contact and grievance officer

TopicEmail
Privacy questions and data requestscontact@elvz.ai
Security reportscontact@elvz.ai
General supportcontact@elvz.ai

Grievance Officer. As required by Indian law, our Grievance Officer is:

Aleem Alam, Grievance Officer
Elvz AI Private Limited
254, Lane 20, Vijay Park, Delhi, India
Email: contact@elvz.ai

Complaints are acknowledged within 24 hours and resolved within 15 days.