Privacy Policy
Effective: 30 August 2026 · Last updated: 1 September 2026
1. Who we are
Elvz is an AI social media and marketing platform operated by Elvz AI Private Limited, incorporated in India, registered office 254, Lane 20, Vijay Park, Delhi, India. “Elvz”, “we”, “us”, and “our” mean that company. “You” means the person using the service.
For data you upload, or that we retrieve from an account you connect, we act as a processor on your behalf. For your own account, billing, and product usage data, we act as a controller.
This policy covers the Elvz web application at app.elvz.ai, the marketing site at elvz.ai, and every platform and integration listed below.
2. The short version
- We collect what you give us, what you connect, and what the product generates for you.
- We do not train AI models on your content, and our AI providers are contractually barred from doing so.
- We do not sell your data, and we do not use it for advertising.
- Every connection is opt-in, per workspace, and revocable in one click.
- Nothing is published to your accounts without your approval.
- You can delete everything at any time — see our Data Deletion Instructions.
3. Data we collect
Data you give us
| Category | Examples |
|---|---|
| Account | Name, email, password hash or Google sign-in identifier, profile photo |
| Workspace | Brand name, website URL, industry, brand voice and positioning you enter |
| Content | Post drafts, prompts, briefs, uploaded images and video, product photos |
| Conversations | Your chat history with Fable and our other AI agents |
| Support | Emails and messages you send us |
Data we generate
- Content produced for you — captions, images, video, campaign plans, drafted replies.
- Brand knowledge documents derived from your website, connected accounts, and imported files: service description, market analysis, brand voice, values, competitor positioning.
- Credit balances, usage counts, and plan status.
Data we collect automatically
- IP address, browser and device type, approximate location derived from IP.
- Log data: pages viewed, features used, timestamps, error reports.
- Essential cookies for authentication and session security. We do not use advertising cookies and we do not run third-party ad trackers.
Payment data
We never see or store your card details. Payments are processed by Dodo Payments, which acts as merchant of record and seller of record for your subscription. We receive only your subscription status, plan, transaction identifiers, and billing email.
4. Connected social platforms
When you connect a social account you grant Elvz permission through that platform’s own official login flow. Connections are made per workspace, are always optional, and can be revoked at any time. We request only what the feature you are using needs.
Access tokens are stored encrypted and used only server-side. They are never sent to your browser, never shown in chat, and never shared with another customer.
InstagramLIVE
Elvz supports two Instagram connection methods. Which one you use depends on how your account is set up; the app tells you at connect time. We request only the permissions listed for the method you choose.
Instagram Login (business or creator account, no Facebook Page required)
| Permission | What we do with it |
|---|---|
instagram_business_basic | Read your profile, follower count, and media so we can show your account and learn your brand voice |
instagram_business_manage_comments | Read comments and reply, including comment-to-DM automations |
instagram_business_manage_messages | Read and send direct messages for story-reply, keyword, and mention automations |
instagram_business_content_publish | Publish posts you have approved |
Facebook Login (Instagram account linked to a Facebook Page)
| Permission | What we do with it |
|---|---|
pages_show_list | List the Facebook Pages you manage so you can pick one to connect |
pages_read_engagement | Read recent posts and engagement to learn your brand voice and report performance |
instagram_basic | Read the linked Instagram account profile and media |
pages_messaging | Send and receive Page messages for automations |
instagram_manage_messages | Read and send Instagram direct messages for automations |
instagram_manage_comments | Receive comment notifications and send replies |
instagram_manage_insights | List active stories so an automation can target a specific one, and read performance metrics |
pages_manage_metadata | Subscribe your Page to our webhooks so automations receive events |
pages_manage_posts | Publish Page posts you have approved |
instagram_content_publish | Publish Instagram posts you have approved |
What we store: Profile metadata, your most recent posts and their engagement metrics, and the comment and message threads involved in automations you have switched on.
Facebook PagesLIVE
Facebook uses the same Meta permission grant as the Instagram Facebook Login method above. Connecting one may connect both, and the consent screen shows you exactly what is granted.
What we store: Page profile details, your most recent Page posts and engagement metrics, and message threads involved in automations.
LinkedInLIVE
LinkedIn access is layered. Sign-in requests identity only. Publishing and analytics permissions are requested separately, and only once LinkedIn has approved us for them and you have opted in.
Always requested
| Permission | What we do with it |
|---|---|
openid, profile, email | Sign you in and read your name, profile identifier, and email address |
Requested only where enabled and approved
| Permission | What we do with it |
|---|---|
w_member_social | Publish posts to your personal LinkedIn feed on your approval |
w_organization_social | Publish posts to a company Page you administer |
r_organization_admin / rw_organization_admin | Confirm which company Pages you administer and read their post performance |
r_member_postAnalytics | Read performance metrics for your own posts |
What we store: Your name, LinkedIn identifier, and email. Where publishing and analytics are enabled, the posts we published for you and their metrics. We never read your LinkedIn messages or your connections list.
ThreadsLIVE
Threads is a Meta product with its own permission set, granted separately from Instagram and Facebook.
Permissions requested
| Permission | What we do with it |
|---|---|
threads_basic | Read your Threads profile and posts |
threads_content_publish | Publish threads you have approved |
threads_read_replies | Read replies to your threads |
threads_manage_replies | Reply on your behalf where you have set up an automation |
threads_manage_mentions | See threads that mention you so an automation can respond |
threads_manage_insights | Read performance metrics for your threads |
What we store: Profile metadata, your recent threads and their metrics, and reply and mention threads involved in automations.
TikTokLIVE
Elvz reads your public creator profile and publishes videos you have approved. We do not read your TikTok direct messages.
Permissions requested
| Permission | What we do with it |
|---|---|
user.info.basic | Read your TikTok display name, avatar, and open identifier |
user.info.stats | Read your follower, following, and video counts to report performance |
video.list | List your published videos and their public metrics |
video.publish | Upload and publish videos you have approved, using the settings you choose |
What we store: Profile metadata, your recent videos and their public metrics, and the publish status of videos we posted for you.
YouTubeLIVE
YouTube access uses Google OAuth. See the Google user data section below, which governs everything we do with data received from Google APIs.
Permissions requested
| Permission | What we do with it |
|---|---|
youtube.readonly | Read your channel details, video list, and public metrics |
youtube.upload | Upload videos you have approved |
youtube.force-ssl | Read and post comments, and manage videos we published for you |
yt-analytics.readonly | Read channel and video analytics to report performance |
What we store: Channel metadata, your recent videos, analytics metrics, and comment threads involved in automations.
PinterestLIVE
Permissions requested
| Permission | What we do with it |
|---|---|
user_accounts:read | Read your Pinterest account profile |
boards:read | List your boards so you can choose where a Pin goes |
boards:write | Create a board where you have asked us to |
pins:read | Read your Pins and their metrics to report performance |
pins:write | Publish Pins you have approved |
What we store: Account metadata, your boards, and your recent Pins with their metrics.
Google Business ProfileLIVE
Google Business Profile access uses Google OAuth. See the Google user data section below.
Permissions requested
| Permission | What we do with it |
|---|---|
business.manage | List the business locations you manage, read reviews and posts, and publish updates you have approved |
What we store: Location metadata, your recent Business Profile posts, and review content where you have enabled review-reply automations.
X (Twitter)NOT YET AVAILABLE
Not yet available. When X connections launch we will publish the exact permissions we request in this policy before the feature goes live.
Your websiteLIVE
When you add a website to a workspace we crawl its publicly accessible pages to build your brand knowledge. We read only public content and respect standard crawler directives. We do not attempt to access pages behind a login.
What we store: Page text and images from the public pages we crawled, and the brand knowledge documents we derive from them.
Across every connected platform we hold at most your 50 most recent posts per account, refreshed periodically, plus the metrics attached to them. Older synced posts are discarded as new ones arrive.
5. Connected integrations
Integrations bring your own business material into a workspace so agents work from facts instead of guesses. Every integration is opt-in per workspace, read-only unless stated otherwise, and disconnectable at any time. Connections for these integrations are established and held by Composio, our integration provider, which brokers our read requests to each provider. Disconnecting revokes the credential upstream and deletes the connection.
Some integrations below are in our product catalogue but not yet available. They are listed for transparency about where the product is going. We collect nothing from them, and we will document them here before each one launches.
Access is described by data category rather than by raw permission string. These connections are brokered by Composio, whose authorisation settings sit outside our application code, so a transcribed permission list would drift out of date without anyone noticing. The categories below state what Elvz can actually read. Your social publishing platforms are not brokered this way, and their exact permissions are listed in Section 4.
Cloud storage
| Integration | Access requested | What we do with it |
|---|---|---|
| Google Drive | drive.file, openid, email | Read only the specific files and folders you pick yourself in Google’s own picker. Elvz has no visibility into the rest of your Drive |
| Dropbox | Files you select, and your account name | Read the documents you choose so agents can ground their work in your own material |
| OneDrive | Files you select | Read the documents you choose |
| Box | Files you select | Read the documents you choose |
Docs and notes
| Integration | Access requested | What we do with it |
|---|---|---|
| Notion | Pages and databases you select during Notion’s own connect flow | Read the pages you share with Elvz |
| Google Docs | Documents you select | Read the documents you choose |
| Google Slides | Presentations you select | Read the decks you choose, for brand and messaging context |
| Google Sheets | Covered by the Google Drive connection — no separate grant | Read the spreadsheets you choose |
| Confluence | Spaces and pages you select | Read internal documentation you point us at |
| Coda | Docs you select | Read the docs you choose |
Calendar
| Integration | Access requested | What we do with it |
|---|---|---|
| Google Calendar | Calendar list and event details, read-only | Read your calendars and events so content planning respects launches, holidays, and campaigns |
| Outlook Calendar | Basic event times, read-only | Read basic event times so content planning respects your schedule |
E-commerce
| Integration | Access requested | What we do with it |
|---|---|---|
| Shopify | read_products, read_inventory | Read your product catalogue and stock levels so agents write accurate product content. We do not request access to your orders or your customers |
Web analytics
| Integration | Access requested | What we do with it |
|---|---|---|
| Google Analytics 4 | Aggregated reports, read-only | Read traffic and conversion reports to measure what your content achieved |
| Google Search Console | Search performance data for your verified sites, read-only | Read queries, impressions, and click data |
| Amplitude | Aggregated product analytics, read-only | Read event and funnel reports to measure content impact |
SEO
| Integration | Access requested | What we do with it |
|---|---|---|
| Semrush | Keyword, ranking, and competitor reports for your domains | Read search visibility data to inform content strategy |
| Ahrefs | Backlink, keyword, and ranking reports for your domains | Read search visibility data to inform content strategy |
Advertising
| Integration | Access requested | What we do with it |
|---|---|---|
| Meta Ads | Campaign, ad set, and creative performance, read-only | Read ad performance so agents learn which messaging works. We do not create, edit, or spend on campaigns |
| Google Ads | Campaign and keyword performance, read-only | Read ad performance to inform content and messaging |
| LinkedIn Ads | Campaign performance, read-only | Read ad performance to inform content and messaging |
| TikTok AdsNOT YET AVAILABLE | Not yet available | Nothing is collected |
Design
| Integration | Access requested | What we do with it |
|---|---|---|
| Canva | Designs and brand assets you select | Read your designs and brand assets so generated visuals match your identity |
| Figma | Files and projects you select | Read design files for brand colours, type, and component styling |
| Adobe ExpressNOT YET AVAILABLE | Not yet available | Nothing is collected |
Email marketing
| Integration | Access requested | What we do with it |
|---|---|---|
| Mailchimp | Campaigns, templates, and audience lists | Read past campaigns and performance so agents match your email voice. Audience data includes subscriber records — see “Data about other people” below |
| Klaviyo | Campaigns, flows, and audience lists | Read campaign performance and segments. Audience data includes subscriber records |
| Brevo | Campaigns and contact lists | Read campaign performance and segments. Contact data includes subscriber records |
CRM
| Integration | Access requested | What we do with it |
|---|---|---|
| HubSpot | Contact, company, and deal records | Read customer records so agents understand who you sell to. These records describe identifiable people — see “Data about other people” below |
Customer support
| Integration | Access requested | What we do with it |
|---|---|---|
| Intercom | Conversations and contact records | Read support conversations so agents learn the questions customers actually ask. These contain identifiable people — see “Data about other people” below |
| Zendesk | Tickets and requester details | Read support tickets so agents learn common issues and your tone. These contain identifiable people |
Community
| Integration | Access requested | What we do with it |
|---|---|---|
| Slack | Channels and messages you grant access to | Read the channels you select for product context and internal announcements. Messages are written by your colleagues — see “Data about other people” below |
| Public posts and comments | Read public community discussion for audience research. We do not post on your behalf |
CMS
| Integration | Access requested | What we do with it |
|---|---|---|
| Contentful | Entries and assets in the spaces you select | Read published content so agents stay consistent with your site |
| Webflow | Site content and CMS collections | Read published content so agents stay consistent with your site |
| Wix | Site content | Read published content so agents stay consistent with your site |
Project management
| Integration | Access requested | What we do with it |
|---|---|---|
| Asana | Projects and tasks you select | Read your plans so content scheduling reflects real launch dates |
| ClickUp | Spaces and tasks you select | Read your plans so content scheduling reflects real launch dates |
| Airtable | Bases and tables you select | Read structured business data you point us at |
What happens to imported data when you disconnect
This differs by source, deliberately:
- Deleted immediately — Google Calendar, Outlook Calendar, Mailchimp, Klaviyo, Brevo, Intercom, Zendesk, and HubSpot. Every one of these carries personal data about people who never signed up for Elvz, so revoking access removes everything derived from them.
- Retained until you delete it — every other integration: cloud storage, docs and notes, e-commerce, analytics, SEO, advertising, design, community, CMS, and project management. These hold your own documents and business facts, and silently discarding an imported corpus because you reconnected a provider would be its own kind of data loss. You can delete this material at any time from the workspace.
In both cases the access token is revoked and erased the moment you disconnect.
6. Google user data and Limited Use
Several Elvz features use Google APIs: Google sign-in, Google Drive, Google Docs, Google Slides, Google Calendar, Google Analytics 4, Google Search Console, Google Ads, YouTube, and Google Business Profile.
Elvz’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means:
- We use Google user data only to provide or improve the user-facing features you connected it for. Nothing else.
- We do not transfer Google user data to third parties except as necessary to provide those features, for security, or to comply with law.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to train, retrain, or fine-tune any generalised or foundation AI model. Where Google user data is sent to an AI provider to produce output for you, that provider processes it under enterprise terms that prohibit training on it.
- No human at Elvz reads your Google user data, except with your explicit permission, for a documented security investigation, to comply with law, or where the data is aggregated and anonymised.
Scopes we request
Elvz requests no restricted Google scopes. Google Drive access uses drive.file, which limits us to the individual files and folders you select in Google’s own picker. Our remaining Google permissions are read-only analytics, calendar, search, and channel scopes, each listed against its feature in the tables above. We request the narrowest scope that makes each feature work, and every Google connection is optional — you can use Elvz fully without connecting any Google account.
7. Meta Platform Data
Data we receive from the Instagram, Facebook, and Threads APIs is Platform Data under the Meta Platform Terms. Our use of it follows those terms and the Meta Developer Policies.
- We do not sell, licence, or transfer Meta Platform Data, and we do not use it for advertising or to build advertising profiles.
- We do not use Meta Platform Data to train, retrain, or fine-tune any AI model.
- Where Meta Platform Data is sent to an AI provider so that it can produce content or a reply for you, that provider acts strictly as our service provider under written terms that forbid training on the data, forbid any independent use of it, and require deletion on our instruction.
- We delete Meta Platform Data without undue delay when you disconnect the account, when it is no longer needed for the feature you enabled, when you delete your account, or when Meta or the law requires it.
- Incoming Meta webhooks are cryptographically signature-verified before we process them.
8. TikTok data
Our access to and use of data from the TikTok API is governed by the TikTok Developer Terms of Service and the TikTok Developer Data Sharing Agreement, including the Developer Controller-to-Controller Data Terms that apply to United States personal data from 22 January 2026.
- We collect only your creator profile, your public video list and its public metrics, and the publish status of videos we posted for you.
- We do not read your TikTok direct messages, and we do not request that permission.
- We do not sell TikTok data, do not use it for advertising, and do not use it to train AI models.
- We honour the privacy, comment, duet, and stitch settings your TikTok account returns, and we surface them to you before a video is published.
- TikTok data is deleted when you disconnect the account or delete your Elvz account.
9. Data about other people
Some features necessarily process data about third parties — people who comment on your posts, message your accounts, email you, or appear in your calendar. For all of it you are the controller and we are your processor. We handle it narrowly:
Commenters and people who message you
- Where an automation has run, we store the commenter’s platform identifier and handle so the same person is not replied to twice and so a conversation can continue. We do not build profiles of these people, we do not enrich or cross-reference them against any other source, and we do not use their data for any other purpose.
- Where an automation must actually converse — a comment-to-DM flow, a story reply, a mention response — we necessarily store the message and comment thread itself, including the platform handle, for as long as the conversation is live. That is the minimum a reply feature can run on.
- Where we derive audience insight from comments, we store only paraphrased patterns, never verbatim text, and identifiers are stripped first.
- If someone deletes their comment or message at source, we delete our record and re-derive any affected insight.
- Inbound engagement we observed but never acted on is deleted after 400 days. Threads an automation actually replied to are kept while the workspace exists, and are removed when you delete the workspace or your account, or sooner on request.
Calendars, support desks, CRM, and marketing lists
Eight integrations carry personal data about people who never signed up for Elvz. Because of that, they are handled more strictly than the rest:
| Integration | Whose data |
|---|---|
| Google Calendar, Outlook Calendar | Meeting attendees — names, email addresses, and what the meeting is about |
| Intercom, Zendesk | People who contacted your support desk — names, email addresses, and the contents of their conversations |
| HubSpot | Your CRM contacts — names, employers, deal history |
| Mailchimp, Klaviyo, Brevo | Your marketing subscribers — email addresses and list membership |
- All eight are read-only. Elvz cannot send, reply, delete, or alter anything in your calendar, support desk, CRM, or mailing list.
- Everything derived from these sources is deleted immediately when you disconnect the provider — this is enforced in code, not by policy alone.
- We do not use this data to contact anyone, and we never add these people to any list of our own.
- Before connecting a shared or company account, please make sure you are entitled to do so under your own organisation’s policies and applicable law.
Workplace messages
If you connect Slack, we read the channels you grant access to. Those messages are written by your colleagues. We read them for product and announcement context only, we do not post to Slack, and we do not build profiles of the people in a channel. Connect only channels you are entitled to share.
Public community content
The Reddit integration reads public posts and comments for audience research. We do not post, vote, or message on your behalf, and we store only paraphrased themes rather than individual users’ verbatim text.
Shopify catalogue data
We request read_products and read_inventory only. We do not request access to your orders, your customers, or their personal data, and we cannot read them.
If someone asks us to delete data about them, we will route the request to the customer who controls it and assist in fulfilling it. See Data Deletion Instructions.
10. Why we use your data
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the service you signed up for | Performance of a contract |
| Process payments and prevent fraud | Contract; legal obligation |
| Access connected platforms and integrations | Consent, given through each provider’s login flow |
| Keep the service secure and prevent abuse | Legitimate interests |
| Improve the product and fix bugs | Legitimate interests |
| Send service and security notices | Contract; legal obligation |
| Send product marketing emails | Consent — opt out at any time |
If you are in India, we process personal data on the basis of your consent or the legitimate uses permitted under the Digital Personal Data Protection Act, 2023.
11. AI processing and model training
Elvz is built on third-party AI models, currently Google’s Gemini family for text and reasoning and Google’s image and video generation models. To produce content for you, we send relevant parts of your brand knowledge, your prompt, and connected-account context to these models.
Our commitments:
- We do not train AI models on your content. Not our own models, and we use enterprise API terms that prevent our providers from training on your data or using it independently.
- Workspaces are isolated. Nothing from one workspace is ever used to inform another. This is enforced in code, not by policy alone.
- Nothing publishes without your approval. Generated posts and drafted replies are queued for review.
- Your brand knowledge is readable and correctable. You can view every document we hold about your brand, edit it, and delete it.
AI output can be wrong. You are responsible for reviewing content before publishing — see our Terms of Service.
12. Who we share data with
We do not sell your data. We share it only with the providers we need to run Elvz:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud & Firebase | Hosting, database, file storage, authentication | US / EU |
| Google (Gemini & generative media APIs) | AI text, image, and video generation | US |
| Dodo Payments | Payment processing, merchant of record, tax compliance | Global |
| Resend | Transactional email delivery | US |
| Composio | OAuth connection brokering and API access for knowledge and data integrations (cloud storage, notes, calendar, e-commerce, analytics). Holds the connection credential for these integrations and proxies our read requests to the provider | US |
| Connected platforms and integrations | Only the data needed to publish, read, or automate on the account you connected | Global |
We may also disclose data where legally required, or to protect our rights, users, or the public. If Elvz is acquired or merged, data may transfer to the acquirer under this same policy; we will notify you first.
13. International transfers
We are based in India and our providers operate globally, so your data is transferred and stored outside your country. For transfers out of the EEA or UK we rely on the European Commission’s Standard Contractual Clauses and equivalent safeguards.
14. How long we keep data
| Data | Retention |
|---|---|
| Account and workspace data | Until you delete your account |
| Synced social posts, profile data, and metrics | Until you disconnect the account or delete the workspace; at most the 50 most recent posts per account |
| Inbound engagement we observed but did not act on | 400 days, or sooner if deleted at source |
| Comment and message threads involved in an automation | Kept while the workspace exists; deleted when you delete the workspace or your account, or sooner if deleted at source |
| Calendar, support desk, CRM, and marketing list data | Deleted immediately on disconnect |
| Imported documents and business data | Until you delete them or delete your account |
| Generated and uploaded media | Until you delete it or delete your account |
| Access tokens | Deleted immediately on disconnect or revocation |
| Invoices and financial records | 8 years, as required by Indian law |
| Security and access logs | 12 months |
After account deletion, backups containing your data are overwritten within 30 days.
15. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you.
- Correct it — most of it you can edit directly in the app.
- Delete it. See our Data Deletion Instructions.
- Export it in a portable format.
- Withdraw consent at any time, including by disconnecting any platform or integration.
- Object to or restrict processing based on legitimate interests.
- Nominate someone to exercise your rights if you die or become incapacitated (India, DPDP Act).
- Complain to your data protection authority, or in India to the Data Protection Board.
Email contact@elvz.ai. We respond within 30 days and never charge for a first request.
16. Security
- All traffic is encrypted in transit (TLS); data is encrypted at rest.
- Access tokens and secrets are held server-side only and never exposed to the browser.
- Every request is authenticated and scoped to your account — workspace separation is enforced at the data layer.
- Incoming platform webhooks are cryptographically signature-verified before processing.
- Internal access is limited to staff who need it, and is logged.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by law. Report a vulnerability to contact@elvz.ai.
17. Children
Elvz is a business product and is not intended for anyone under 18. We do not knowingly collect data from children. If we learn that we have, we will delete it. Parents or guardians can contact contact@elvz.ai.
18. Changes to this policy
We will update this page when our practices change and revise the date at the top. Every new platform or integration is documented here before it becomes available to connect. For material changes we will email you or show a notice in the app at least 14 days before they take effect.
19. Contact and grievance officer
| Topic | |
|---|---|
| Privacy questions and data requests | contact@elvz.ai |
| Security reports | contact@elvz.ai |
| General support | contact@elvz.ai |
Grievance Officer. As required by Indian law, our Grievance Officer is:
Aleem Alam, Grievance Officer
Elvz AI Private Limited
254, Lane 20, Vijay Park, Delhi, India
Email: contact@elvz.ai
Complaints are acknowledged within 24 hours and resolved within 15 days.