← Back to ELOSTATE

Privacy Policy

Version 0.1 · last updated

The core promise (the structural one)

Whatever ELOSTATE records about you, you can see. There is no backstage read by the System that you don't have access to. Admins in your company can see aggregate views of their team — and YOU can see the underlying per-person data those aggregates are built from, including the data attributed to you, at the same level of detail. This isn't a feature we added; it's a structural rule the product is built to.

What we collect from you directly

  • Account info: email, name, role (CEO / COO / Lead / Member), company assignment.
  • Content you author in-product: chat messages, task descriptions, decision dialogues, feedback, smoke-test notes.
  • Behavior on the platform: which buttons you press, which messages you pin, which tasks you complete steps on. The record is append-only so we can reason over patterns, not just snapshots.

Recorded conversations (Sales Coach)

This is the most sensitive thing the product does, so it gets its own section rather than a line in a list.

A sales representative using Sales Coach can record a sales conversation so it can be transcribed and coached afterwards.
  • It only records when a person starts it. There is no ambient or automatic listening. Recording begins when the representative presses record, is visible on screen while it runs, and ends when they stop it.
  • The other person's voice is in the recording. A sales conversation has two sides, and the prospect is audible in the audio and named in nothing. Representatives are responsible for recording lawfully where they work — in some places that means telling the other party, and in some it means asking them.
  • Who can hear it:the representative who recorded it, and managers at their own company. Peers cannot hear each other's recordings, and neither can anyone at another company. This is enforced by database policy, not by screen design.
  • What we derive from it: a transcript, a per-conversation score across a fixed set of skills, and coaching notes. Those are what the product is for; the audio itself is kept so a representative can listen back.
  • How long we keep the audio:we keep each representative's twenty most recent recordings. A job runs every night and deletes the audio of anything older than that. The transcript, the score and the coaching notes are kept — we drop the recording, not the coaching.
  • Recordings that are kept longer: a representative or a manager can press Save on a recording. A saved recording is exempt from the nightly deletion and is kept until it is removed.
  • Deleting one: a manager or an administrator at your company can have a specific recording removed from our servers. A representative cannot remove their own — a recording is a record of how a call was handled, and the person it is about is not the person who decides whether it is kept. Deleting a recording removes the audio; the transcript and the scores stay.
  • The copy on the phone: a representative can delete a recording from their own device before it is uploaded, and once it has uploaded that copy on the phone is removed automatically.
  • If you are the person who was recorded:you will not have an account here, so use the contact route in “Retention and deletion” below and we will act on it.

What the System derives about you

  • Engagement signals (last meaningful action on a task, participation in topics, response patterns).
  • Communication grades — when the Coach is on, every sent message gets a grade (productive / neutral / needs-guidance / withheld). This is the encouragement system; you see your own grades, and your leader sees aggregate patterns framed as "Requesting Collaboration", never as a verdict on you.
  • Cross-conversation memory — the Coach reads patterns of what it's already coached you on so it doesn't repeat the same lesson. The memory window is 30 days.

What we do NOT do

  • We do not infer your emotional state from typing patterns, late-night activity, or absence. The System reads what you show it. It does not read what it guesses about you.
  • We do not sell your data. Ever. We don't share with advertising platforms or data brokers. If we did, we wouldn't be ELOSTATE.
  • We do not surface a verdict labeled as your performance. The labels we ship to leaders are deliberately framed as invitations to help, never as ratings on the person.

Who can see what

  • You can see everything attributed to you, including the same data that appears in admin digests about you.
  • Other members of your companycan see shared content in topics they participate in and on tasks they're part of. Row-level security at the database layer prevents cross-topic / cross-company reads.
  • Your company admins (CEO / COO / admin role) can see all topics and tasks within the company, plus the readout. They see the same underlying per-person data you see about yourself; nothing extra.
  • We (ELOSTATE)can technically see everything via service-role access for support purposes. We don't routinely. In a future build we'll add audit-logged admin-access events so even our access is on the record.
  • Nobody else sees your data. No third parties, no analytics platforms.

Third-party services we use

  • Supabase— primary database and auth. Hosted in Supabase's data centers under their security posture.
  • Vercel — application hosting and edge delivery.
  • ElevenLabs — speech-to-text. A recorded sales conversation is sent to ElevenLabs to be turned into a transcript, which means the audio of both speakers leaves our systems and reaches theirs. They process it on our instruction and do not own it.
  • Anthropic Claude— the LLM behind the Coach. Your draft text passes through Anthropic's API to generate Coach analysis. Anthropic does not train on API content per their commercial terms.
    For Sales Coach, the transcript of a recorded conversation also passes through it. That transcript contains what the other party said, which is not something you authored in the product — we say so here rather than let the sentence above imply otherwise.
  • Postmark — transactional and weekly digest email. The weekly summaries carry names, points and deal counts to the address of the manager or representative receiving them, so Postmark handles that content in the course of delivering it.
  • Sentry — error monitoring, and only when it is switched on. Where it is enabled it receives crash and error reports. Tokens, signed links and anything that looks like a credential are stripped before a report leaves, and diagnostic attachments are dropped entirely.
  • Web Push / VAPID for notifications — browser-native, no third party in the message path.

Retention and deletion

The §3.1 chain (events / signals / problems / resolutions) is structurally append-only. We don't mutate or delete history; we append corrections.

What this means for personal data deletion requests:
  • We can REDACT your personal identifiers (email, name, user id) from past records. The structural events remain so the System's reasoning over time stays intact, but they no longer trace back to you personally.
  • Aggregate counts that include your contributions stay as aggregates — they're not personally identifiable.
  • For deletion that requires removing structural events (rare; usually a compliance obligation), contact us and we'll discuss what's legally required vs. what the system supports.

Cookies and local storage

We use local browser storage to:
  • Keep you signed in (Supabase auth session — a standard JWT).
  • Preserve unsent drafts of Decision Dialogues so a browser refresh doesn't lose your work.
  • Remember UI choices (theme, dismissed cards).
We do not use third-party advertising cookies. We do not track you across other sites.

Security

Production data sits in Supabase with row-level security policies enforcing company isolation. Authentication is standard email + password with a future second-factor path via the same Supabase auth layer. We do not have SOC2 attestation at pilot scale — that's on the roadmap before paid enterprise launch.

Your rights

You can:
  • See everything attributed to you, in-product.
  • Export your own data — currently via product surfaces (My Feedback, task lists); a structured export endpoint is roadmapped.
  • Request redaction of personal identifiers from historical records (see Retention section).
  • Withdraw consent — close your account and request data redaction by emailing us.

Children

ELOSTATE is for working professionals. It's not designed for and shouldn't be used by people under 18. We don't knowingly collect data about minors. If we discover we have, we delete it.

Changes to this policy

When we change this policy, we'll surface it in- product. Material changes get an explicit acknowledgment surface; small edits are version-stamped here. The full history of versions is visible.

Contact

Privacy questions go to johnsyramos@gmail.com. We answer real questions, especially uncomfortable ones.

v0.1 · 2026-06-15 · pilot-ready, not yet attorney-reviewed for GDPR / CCPA / regulated commercial use