Privacy Policy

Last Updated: 17-08-2026

This Privacy Policy explains how Elyx GmbH ("Elyx", "we", "us") collects, uses, and protects your personal data when you use our platform. We are committed to fully complying with the General Data Protection Regulation (GDPR).

1. Data Controller

The Data Controller responsible for your personal data is: Elyx GmbH in formation, Berlin, Germany Email: privacy@elyx.tech

2. What Data We Collect

We collect the absolute minimum amount of data required to operate the Service:

  • Account Information: Your name, last name, email address, and profile picture.

  • Billing Information: Managed entirely through our payment processor (Stripe). We only keep a reference to your Stripe Customer ID.

  • Project Data: The logic, structures, and data you input into the Elyx canvas to build your applications.

3. How We Use Your Data

  • To provide, maintain, and bill for the Service.

  • To authenticate you into your account securely.

  • We do not use your personal data, project data, or code to train AI models.

  • We do not sell your data to advertisers or data brokers.

4. Data Security and Protection Mechanisms

Your privacy and data security are paramount. To protect your sensitive data and Google user data from unauthorized access, alteration, disclosure, or destruction, we implement the following security mechanisms:

  • Encryption in Transit: All data transferred between your browser, our servers, and third-party APIs (including Google) is encrypted using modern TLS/HTTPS protocols.

  • Encryption at Rest: All personal data, OAuth tokens, and project data stored in our AWS databases are encrypted at rest using industry-standard AES-256 encryption.

  • Strict Access Controls: Elyx staff cannot and will not access your project data, secure credentials, or personal configurations unless you explicitly request us to do so via a verified support ticket.

5. Cookies and Tracking (No Tracking Cookies)

  • No Tracking: We do not use third-party tracking cookies, marketing cookies, or analytics trackers on our core platform.

  • Local Storage: We use local storage in your browser strictly for functional purposes (e.g., remembering your canvas scroll location or UI preferences). This data is linked to a Project ID, contains no personally identifiable information (PII), and never leaves your browser.

6. Third-Party Data Processors

To run Elyx, we rely on trusted infrastructure partners who process data on our behalf. We have Data Processing Agreements (DPAs) in place with them:

  • Amazon Web Services (AWS): All Elyx backend infrastructure, databases, and servers are hosted securely in AWS data centers located in Frankfurt, Germany (eu-central-1).

  • Stripe: Used for secure payment processing and subscription management.

Google User Data Disclosures:

  • Transfers to Third Parties: We do not transfer, share, or disclose raw or aggregated Google user data to third parties, except as strictly necessary to provide or maintain platform functionality (such as cloud hosting on AWS) or as required by law.

  • No Sale of Data: We never sell, rent, or trade Google user data to third parties, advertisers, or data brokers.

  • Use of Data: Google user data accessed through Google Workspace APIs is used exclusively to provide and improve user-facing features on the Elyx platform. It is not used for serving advertisements or for training generalized AI/ML models.

A note on External Integrations: While Elyx allows you to connect to hundreds of third-party tools, we route these connections through our own self-hosted infrastructure. We do not use third-party bridging services that would process your integration data. Data only flows to a third party when you explicitly configure your project to send it there.

7. Google Workspace API Limited Use Disclosure

Elyx's use and transfer to any other app of information received from Google APIs (including Google Sheets, Google Drive, and Gmail APIs) will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

In compliance with the Limited Use policy:

  • No AI Model Training: Google Workspace user data (raw, aggregated, or derived) is NEVER used, transferred, or sold to train, fine-tune, or improve generalized or foundational artificial intelligence (AI) or machine learning (ML) models.

  • Data Processing Isolation: Google user data is processed solely to execute user-directed workflow operations (such as reading, editing, or appending rows to Google Sheets).

  • Commercial API Protection: When users optionally route data through AI integration nodes (e.g., Google Gemini, OpenAI, or Anthropic), data is transmitted strictly via commercial API endpoints governed by zero-data-retention and non-training terms.

8. Your GDPR Rights (Right to Erasure)

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.

  • Rectify inaccurate or incomplete data.

  • Request Erasure ("Right to be Forgotten"): You can request the complete deletion of your user account, personal data, and all associated project data at any time.

  • Export your data in a portable format.

To exercise any of these rights, please contact us at privacy@elyx.tech.