Elio — Privacy Policy

Last updated: 4 September 2026

Elio (“the app”, “we”) is a fictional AI companion app for adults. This policy explains what data the app processes, why, and your choices. Elio is designed to keep your data on your device as much as possible.

1. Who this applies to

Elio is intended only for users aged 18 and older. We do not knowingly collect data from anyone under 18.

2. Data we process

3. What we do NOT do

3a. Usage statistics (optional, off by default)

You can turn on anonymous usage statistics in Settings → Usage Insights. It is off unless you switch it on, and switching it off stops all sending immediately.

When it is on we receive: which onboarding screens you reached, how long replies took, whether a reply failed, when a paywall was shown, and — when a session ends on a companion reply — the text of that reply. We collect that last one because a reply people stop reading after is the clearest signal that something needs fixing.

The same events go to our own server and to Mixpanel, an analytics provider that acts as a processor on our behalf. Mixpanel receives exactly what is listed above and nothing more: we do not enable its automatic event capture and we do not enable session recording, so your screen is never recorded and your conversations are never sent there. Turning the setting off opts you out of Mixpanel immediately and clears anything queued on your device.

Usage statistics do not include the text of your messages, only how many characters they were, and exclude conversations where our safety features detected a crisis. The usage data is grouped by an anonymous per-installation identifier that is regenerated if you delete your account, and it is not linked to any identity.

3b. Dialogue quality and safety diagnostics

When you use AI conversations, we automatically retain short-lived diagnostic copies of new dialogue turns so our team can diagnose response quality, prompt and safety problems. This includes your messages, AI replies, voice transcripts (not audio), failed turns, and the original reply when the app substitutes a safety response. Health, sexual and crisis topics may be included. This does not depend on the optional usage-statistics setting. Earlier conversation history is not uploaded.

On-device entity recognition and server-side filtering remove detected names, contact details, addresses and identifiers before storage. These filters cannot guarantee anonymity: context and undetected details can still identify someone. We therefore treat these logs as sensitive content with restricted operator access. They are stored on our own server, never sent to Mixpanel or Firebase. We retain the order of turns, response source, app and backend revisions, and a random daily dialogue identifier; we do not attach device IDs, account IDs, IP addresses or exact timestamps.

Logs expire within 7 days. Delete Account also requests deletion of retained logs; automatic expiry still applies if that request cannot reach the server. Replies you explicitly report for review use the same filtering and expiry.

3c. Operational server measurements

Whenever a request reaches our backend, we measure request counts, response status and duration, concurrency, and provider-reported token usage to understand capacity, reliability and operating costs. This does not depend on the optional in-app analytics setting. Health checks and admin-page reads are excluded from these counters. These measurements do not store message text, reply text, IP addresses, account details or the original installation identifier.

To count distinct installations, server sessions and return rates, we transform the existing technical installation identifier into a keyed HMAC retained only on our server. This is a pseudonymous identifier, not fully anonymous data. We store daily request and session counts and the last request time for session continuity under it. It is not joined to dialogue diagnostics or sent to analytics providers. The admin report exposes only aggregate counts. Requests without an installation identifier still contribute to load totals but cannot be counted as distinct devices. A new server session starts after 30 minutes without an application-function request; background analytics uploads and push registration do not start sessions.

Operational day records are retained for up to 180 days. The app's optional event analytics remain separate: disabling them stops those events, while content-free server measurements continue for requests needed to provide the service.

3d. Free period and subscription access

To apply the free-chat period consistently, our server keeps the first connection date under a keyed hash of the app installation identifier. The identifier is retained in the device Keychain across ordinary restarts and reinstalls. It is not an advertising identifier and is not joined to dialogue diagnostics.

For subscribers, the app sends an Apple-signed purchase proof to our server. We validate its signature, product and validity dates, and use signed Apple notifications to process renewals, expiry and refunds. Stored access records contain subscription status, validity dates and keyed hashes of transaction identifiers; we do not persist the original signed proof or receive payment card details. These records provide app functionality regardless of optional analytics consent.

Installation access records are retained to preserve the free-period counter until Delete Account successfully removes them from the server. Minimal hashed transaction records may remain to honor renewals and prevent replay of refunded purchases; these records contain no conversation content. General remote memory settings can pause use, extraction or consolidation of memories without giving the operator access to your local memory archive.

4. Third-party AI processors & your consent

To provide AI features we use: OpenAI (chat replies and image generation) and ElevenLabs (text-to-speech). When you use these features we send only what is needed to produce a reply, voice, or image — your recent messages, bounded active memory context, relevant recalled memories, the in-app display name and persona you configured, and (for voice) the reply text. We do not send your contact details or device identifiers to build a profile of you.

We ask for your explicit permission inside the app before any of this data is sent to a third-party AI service. During onboarding Elio shows a dedicated screen explaining what is shared, who receives it, and how it is used, and no data leaves your device until you agree. If you do not agree, no messages are sent to these services.

These providers act as data processors on our behalf and are contractually required to protect your data with the same or equivalent safeguards described in this policy, to use it only to perform the requested processing, and not to use your content to train their models. Their handling of data is also governed by their own privacy policies (OpenAI, ElevenLabs).

5. Storage & retention

To recover interrupted reply requests without starting duplicate generations, completed replies may be held in server memory for up to 10 minutes. Request status and opaque message fingerprints are retained on disk for approximately 24 hours; this status ledger contains no message or reply text and is separate from dialogue diagnostics.

Your conversations, memories, settings and generated media are stored on your device. Requests to our backend are processed transiently to generate a response, except subscription access records, dialogue diagnostic logs, operational measurements and explicitly reported replies described above, and are not used to build a profile of you. You can erase your local data at any time (see “Your choices”).

6. Security

Network requests use HTTPS/TLS. Generated media on your device is written with iOS file protection. You can enable an in-app passcode and biometric lock for your conversation history.

7. Your choices

8. Changes

We may update this policy; material changes will be reflected by the “Last updated” date above.

9. Contact

Questions about privacy: claudepro1t2a@outlook.com.