Elio — Privacy Policy
Last updated: 4 September 2026
Elio (“the app”, “we”) is a fictional AI companion app for adults. This policy explains what data the app processes, why, and your choices. Elio is designed to keep your data on your device as much as possible.
1. Who this applies to
Elio is intended only for users aged 18 and older. We do not knowingly collect data from anyone under 18.
2. Data we process
- Conversation content — the messages you write and the companion’s replies. Stored locally on your device. To generate AI replies, your recent messages and the persona you configured, along with a bounded active memory context and any archived memories recalled as relevant to the current conversation, are sent to our backend, which relays them to our AI processor (OpenAI) to produce a reply. Historical event logs and unrelated archived memories are not sent. This data is not used to identify you.
- Voice audio — during a voice call your speech is transcribed on-device by Apple’s speech recognition. To produce the companion’s spoken voice, reply text is sent to our voice processor (ElevenLabs). Generated audio is stored locally.
- Generated media — AI-generated images are stored locally on your device.
- Identifiers — an app-generated session identifier and, if you enable push notifications, your device push token, used only to deliver app functionality.
- Profile & settings — the name and preferences you enter, stored locally.
3. What we do NOT do
- We do not track you across other apps or websites, and we do not use advertising identifiers.
- Optional in-app event analytics are collected only when you turn them on and exclude crisis events. Content-free operational server measurements are described in section 3c.
- We do not sell your personal data.
- We do not require an account, email, or real-world identity to use the app.
3a. Usage statistics (optional, off by default)
You can turn on anonymous usage statistics in Settings → Usage Insights. It is off unless you switch it on, and switching it off stops all sending immediately.
When it is on we receive: which onboarding screens you reached, how long replies took, whether a reply failed, when a paywall was shown, and — when a session ends on a companion reply — the text of that reply. We collect that last one because a reply people stop reading after is the clearest signal that something needs fixing.
The same events go to our own server and to Mixpanel, an analytics provider that acts as a processor on our behalf. Mixpanel receives exactly what is listed above and nothing more: we do not enable its automatic event capture and we do not enable session recording, so your screen is never recorded and your conversations are never sent there. Turning the setting off opts you out of Mixpanel immediately and clears anything queued on your device.
Usage statistics do not include the text of your messages, only how many characters they were, and exclude conversations where our safety features detected a crisis. The usage data is grouped by an anonymous per-installation identifier that is regenerated if you delete your account, and it is not linked to any identity.
3b. Dialogue quality and safety diagnostics
When you use AI conversations, we automatically retain short-lived diagnostic copies of new dialogue turns so our team can diagnose response quality, prompt and safety problems. This includes your messages, AI replies, voice transcripts (not audio), failed turns, and the original reply when the app substitutes a safety response. Health, sexual and crisis topics may be included. This does not depend on the optional usage-statistics setting. Earlier conversation history is not uploaded.
On-device entity recognition and server-side filtering remove detected names, contact details, addresses and identifiers before storage. These filters cannot guarantee anonymity: context and undetected details can still identify someone. We therefore treat these logs as sensitive content with restricted operator access. They are stored on our own server, never sent to Mixpanel or Firebase. We retain the order of turns, response source, app and backend revisions, and a random daily dialogue identifier; we do not attach device IDs, account IDs, IP addresses or exact timestamps.
Logs expire within 7 days. Delete Account also requests deletion of retained logs; automatic expiry still applies if that request cannot reach the server. Replies you explicitly report for review use the same filtering and expiry.
3c. Operational server measurements
Whenever a request reaches our backend, we measure request counts, response status and duration, concurrency, and provider-reported token usage to understand capacity, reliability and operating costs. This does not depend on the optional in-app analytics setting. Health checks and admin-page reads are excluded from these counters. These measurements do not store message text, reply text, IP addresses, account details or the original installation identifier.
To count distinct installations, server sessions and return rates, we transform the existing technical installation identifier into a keyed HMAC retained only on our server. This is a pseudonymous identifier, not fully anonymous data. We store daily request and session counts and the last request time for session continuity under it. It is not joined to dialogue diagnostics or sent to analytics providers. The admin report exposes only aggregate counts. Requests without an installation identifier still contribute to load totals but cannot be counted as distinct devices. A new server session starts after 30 minutes without an application-function request; background analytics uploads and push registration do not start sessions.
Operational day records are retained for up to 180 days. The app's optional event analytics remain separate: disabling them stops those events, while content-free server measurements continue for requests needed to provide the service.
3d. Free period and subscription access
To apply the free-chat period consistently, our server keeps the first connection date under a keyed hash of the app installation identifier. The identifier is retained in the device Keychain across ordinary restarts and reinstalls. It is not an advertising identifier and is not joined to dialogue diagnostics.
For subscribers, the app sends an Apple-signed purchase proof to our server. We validate its signature, product and validity dates, and use signed Apple notifications to process renewals, expiry and refunds. Stored access records contain subscription status, validity dates and keyed hashes of transaction identifiers; we do not persist the original signed proof or receive payment card details. These records provide app functionality regardless of optional analytics consent.
Installation access records are retained to preserve the free-period counter until Delete Account successfully removes them from the server. Minimal hashed transaction records may remain to honor renewals and prevent replay of refunded purchases; these records contain no conversation content. General remote memory settings can pause use, extraction or consolidation of memories without giving the operator access to your local memory archive.
4. Third-party AI processors & your consent
To provide AI features we use: OpenAI (chat replies and image generation) and ElevenLabs (text-to-speech). When you use these features we send only what is needed to produce a reply, voice, or image — your recent messages, bounded active memory context, relevant recalled memories, the in-app display name and persona you configured, and (for voice) the reply text. We do not send your contact details or device identifiers to build a profile of you.
We ask for your explicit permission inside the app before any of this data is sent to a third-party AI service. During onboarding Elio shows a dedicated screen explaining what is shared, who receives it, and how it is used, and no data leaves your device until you agree. If you do not agree, no messages are sent to these services.
These providers act as data processors on our behalf and are contractually required to protect your data with the same or equivalent safeguards described in this policy, to use it only to perform the requested processing, and not to use your content to train their models. Their handling of data is also governed by their own privacy policies (OpenAI, ElevenLabs).
5. Storage & retention
To recover interrupted reply requests without starting duplicate generations, completed replies may be held in server memory for up to 10 minutes. Request status and opaque message fingerprints are retained on disk for approximately 24 hours; this status ledger contains no message or reply text and is separate from dialogue diagnostics.
Your conversations, memories, settings and generated media are stored on your device. Requests to our backend are processed transiently to generate a response, except subscription access records, dialogue diagnostic logs, operational measurements and explicitly reported replies described above, and are not used to build a profile of you. You can erase your local data at any time (see “Your choices”).
6. Security
Network requests use HTTPS/TLS. Generated media on your device is written with iOS file protection. You can enable an in-app passcode and biometric lock for your conversation history.
7. Your choices
- Delete everything — Settings → Delete Account permanently erases your local conversations, memories, generated media, passcode, and settings, and asks our backend to forget your session.
- Usage statistics — Settings → Usage Insights turns anonymous usage statistics on or off. It is off by default, and the same screen shows you exactly what has been recorded on your device.
- Notifications — you can disable notifications in iOS Settings at any time.
- Report content — touch and hold any message to report an objectionable AI reply.
8. Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
9. Contact
Questions about privacy: claudepro1t2a@outlook.com.