← elavite.co
Legal

Privacy Policy

Last updated: July 20, 2026

Elavite ("we", "us") provides managed customer support that connects to authorized business systems, builds policy-backed workflows, operates customer conversations, and uses Elavite personnel to handle exceptions within an agreed scope. This policy explains what we collect, how we use it, and the choices you have. Questions: team@elavite.co.

Information we collect

How we use Gmail data

Google API Limited Use disclosure. Elavite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide the support-automation features you request. We do not use Gmail data for advertising, do not sell it, do not use it to train generalized AI or machine-learning models, and do not transfer it to third parties except as necessary to provide the service, comply with law, or as part of a merger or acquisition with prior notice.

Elavite team access

Authorized Elavite personnel may access support conversations and related business context only as needed to operate the service, handle exceptions, investigate incidents, maintain workflows, and support your account. Access is limited by role and subject to confidentiality obligations. Elavite does not use this access to advertise to your customers or to sell their information.

Where your data lives

Synced email and the knowledge base derived from it are stored in an isolated, per-customer workspace on infrastructure we control. OAuth refresh tokens are encrypted at rest. Each customer's data is segregated; no customer can access another's data.

Sharing

We do not sell personal information. We share data only with subprocessors strictly necessary to operate the service (for example, hosting and network providers), under confidentiality obligations, or where required by law.

Retention and deletion

We retain synced data while your account is active. You may disconnect your Google account at any time from your Google Account permissions page, which revokes our access immediately. On request to team@elavite.co, we will delete your synced data and derived knowledge base within 30 days.

Security

We use TLS for all data in transit, encrypt OAuth credentials at rest, restrict access to production systems, and keep an append-only audit log of every action taken in a connected mailbox.

Changes

We will post any changes to this policy on this page and update the date above. Material changes will be announced to affected customers by email.