ELARIS
← Return to Elaris

Privacy notice

Last updated 23 August 2026.

Account information

Elaris uses Clerk to provide account creation, authentication, password recovery, and session security. Clerk processes the identity details you submit, such as your email address and enabled sign-in method, under Clerk's own privacy terms.

Elaris preferences

Your display name, preferred starting mode, time zone, and onboarding status are stored as account metadata so your workspace can open consistently across sessions.

Your private Elaris vault

Each signed-in account has separate row-level-secured storage for its settings, memories, conversations, messages, agents, tasks, and non-secret income profile. Private file objects are additionally confined to that verified account's prefix in a non-public Storage bucket. New accounts begin with zero memories, an empty file vault, and only their own CEO, Research Agent, and Operations Agent. An owner transfer is attached only to the account that explicitly uploads it.

Subscription billing

If you choose Elaris Basic, Elaris sends Stripe the account email and name plus non-secret Elaris account and plan identifiers needed to create and reconcile the subscription. Payment-card details are entered on Stripe's hosted Checkout or customer portal and are not stored by Elaris. Elaris stores Stripe Customer, Subscription, Price, status, renewal, and webhook-event identifiers in Clerk private account metadata so paid access can be enforced for the correct tenant. Stripe processes billing data under its own privacy terms.

What remains excluded

The hosted workspace never receives the encrypted local database itself, Windows credentials, backups, device-control authority, provider API keys, passwords, access tokens, refresh tokens, private device keys, raw Brain data, conversations, or local files. If the owner explicitly pairs a trusted Windows Elaris installation, that installation publishes a bounded set of signed, read-only monitoring snapshots over outbound HTTPS. The snapshots are encrypted before database storage, are served only to the paired Clerk account, expire quickly when the local app stops publishing, and cannot authorize a local mutation.

Security

Authentication secrets are not embedded in the browser bundle. Personalized responses are private and non-cacheable, browser preferences and drafts are separated by account, and hosted consequential execution remains disabled. Ordinary hosted chat sends the current message, a bounded recent conversation window, and a bounded set of relevant private memories from the signed-in account to Elaris's configured cloud AI gateway; those inputs are never made available to another Elaris account. Never put provider credentials into memories, chats, or transfer metadata.