← Elmer

Privacy Policy

This policy explains what [COMPANY LEGAL NAME — e.g. Elmer LLC] (“Elmer,” “we,” “us”) collects when you use the Elmer application and website (the “Service”), how we use it, and the choices you have. It is written to describe what the product actually does — no more, no less.

We collect what you type in and the minimum needed to sign you in. No advertising, no analytics trackers, no selling data, no reading your emails. Your CRM data is processed only to run the product for you.

1. What we collect

Information you provide

Information collected automatically — deliberately minimal

Email sync — only if you connect it, and headers only

If you choose to connect Gmail, we request read-only access and fetch message metadata only: sender, recipient, and date. We do not read, fetch, or store message bodies or subject lines. We use this metadata for one purpose: keeping your “last touched” dates honest and suggesting contacts you emailed who aren’t in your CRM yet (which you review before anything is added). Your Google tokens are encrypted at rest with AES-256-GCM. You can disconnect at any time in Settings → Email sync, which stops all collection.

Elmer’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Payments

Payments are processed by Stripe. Your card number goes directly to Stripe and never touches our servers. We store only what Stripe returns to run your subscription: customer and subscription identifiers, plan, and billing period dates. When you consent to automatic renewal we keep a permanent record of that consent — timestamp, the exact disclosure text you saw, price, IP address, and browser string — because subscription law requires us to be able to prove it.

2. What we never do

3. How we use information

We send operational emails (sign-in links, invitations, your daily digest if enabled, billing notices). We do not send third-party marketing.

4. The AI assistant

When you talk to Elmer, ask for a meeting review, or use photo/paste import, relevant parts of your workspace (and, for imports, the content you submit) are sent to Anthropic, our AI provider, to generate the response. Under Anthropic’s commercial API terms, data sent through the API is not used to train Anthropic’s models. Elmer’s changes to your board are shown to you with an undo option.

5. Who can see your data inside your own team

Your boss (the account owner) can see the work stuff; your private tasks stay private.

In a company account, the account owner can view the organization’s CRM data, including each rep’s customers, and can reassign leads. Reps see only their own book of business. Personal tasks a rep marks private are excluded from the owner’s board, reports, and exports. Company owners can export the organization’s data; reps cannot export.

6. Service providers we share data with

We share data only with the processors below, only so they can perform services for us, under their own contractual confidentiality obligations:

ProviderPurposeWhat they process
NeonDatabase hostingAll Service data
Vercel (or equivalent host)Application hostingData in transit through the app
StripePaymentsBilling details, card data (directly)
AnthropicAI assistantWorkspace excerpts sent for each Elmer request
ResendTransactional emailEmail address, message content we send you
TwilioText reminders (if enabled)Your mobile number, reminder text
GoogleSign-in and Gmail sync (if you connect them)OAuth identity; message metadata as described above

Beyond service providers, we disclose information only: to comply with law or valid legal process; to protect the rights, safety, or property of Elmer or others; or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to your data until changed with notice).

7. Security

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you as required by law.

8. Retention

9. Your rights and choices

Depending on where you live, you may have additional rights (such as access, portability, deletion, and non-discrimination under U.S. state privacy laws). We honor these rights on request at priv8development@gmail.com, and we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of on that front. If you are a contact stored in one of our customers’ CRMs, that customer is responsible for your data; contact them directly, and we will assist them as their processor.

10. Children

The Service is a business tool for adults. It is not directed to children under 18, and we do not knowingly collect information from them.

11. Where data is processed

We are a U.S. company and process data in the United States through the providers listed above. If you use the Service from outside the U.S., you consent to processing in the U.S.

12. Changes to this policy

If we change this policy materially, we will notify you by email or in-app notice before the change takes effect, and update the date at the top. We will never quietly weaken what section 2 promises.

Contact

[COMPANY LEGAL NAME] · Miami, Florida · priv8development@gmail.com