Skip to content

Legal

Privacy Policy

Last updated:

This policy is under review by counsel. If you have a question about it, write to privacy@elysium-labs.ai.

In short

  • This website sets no cookies for analytics, advertising or tracking, and it loads nothing from other companies' servers. It counts visits without cookies, in daily totals that hold no IP address. A count passes our load balancer, whose log keeps your IP address for 30 days.
  • Anthropic's Claude writes Ask Elysium's answers. We keep no copy of a conversation unless you are signed in, and then for 180 days.
  • We use your early-access email address only for early access, and you can remove it at any time.
  • The hosted Elysium app keeps your household's data with us in Zürich and uses Anthropic's models to answer, or OpenAI's if you choose one.
  • An Elysium hub ships in Sovereign mode, in which The Butler runs on the hub and uses no cloud AI service, and only services your household turns on, such as web search, receive your requests or your household's data from it.
  • To get a copy of your data or have it deleted, write to privacy@elysium-labs.ai.

Who is responsible

Elysium is offered by Pieter Meyer under the name Elysium Labs, which is not a registered company. Pieter Meyer is responsible for the processing of personal data described in this policy: the controller under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).

Controller
Pieter Meyer, trading as Elysium Labs
Based in
Zürich, Switzerland
Postal address
To be published on this page. Until then, please use privacy@elysium-labs.ai.
Email
privacy@elysium-labs.ai

What this policy covers

This policy covers this website (elysium-labs.ai and its development copy at dev.elysium-labs.ai), Ask Elysium, the early-access list, Elysium accounts, the hosted Elysium app, Elysium hubs and email you send us. Each of the following sections describes one of them.

Visiting this website

You can read this site without telling us who you are. It sets no cookies for analytics, advertising or tracking, and it loads no scripts, fonts or images from other companies' servers.

Your requests to elysium-labs.ai and www.elysium-labs.ai can first reach Amazon CloudFront, the content delivery network of Amazon Web Services, at an edge location near you, which may be outside Switzerland. It sends a page from its own copy when it has one, and otherwise passes the request on to our servers in Zürich. It keeps copies only of pages and files that are the same for every visitor. We have not turned on its access logs, so it keeps no log of your requests for us.

Our load balancer logs each request it passes on: the IP address it came from, the address requested, the time, the user agent and the result. For a request that came through Amazon CloudFront, that IP address is CloudFront's. Our API, which this site and the app call for sign-in, Ask Elysium and early access, also logs each request it receives (the visit counts described below are the exception), and some of its entries identify an account or contain an email address, for example when an account is created or when The Butler sends an email for you. We use these logs to deliver the service, keep it secure and find faults, and we keep them for 30 days. Records of network connections (IP addresses and ports, without content) are kept for 14 days.

To prevent abuse, the API counts requests from each IP address, or from each account, to sign-in, early access and other features, for up to 1 hour (Ask Elysium's counters are described below). So that a request sent twice is carried out once, the API keeps a one-way fingerprint of each request the site or the app marks for this, made with a key only our servers hold, with a copy of its reply, for 10 minutes. It never does this for a request that carries a password, a code, a PIN or a sign-in token, or whose reply does.

How we count visits

So that we can tell which pages people read and where they come from, each page of this site, apart from your Account page and the welcome steps after you sign up, sends our API one count once it has loaded. The count holds four things: which page it is (its path, such as /faq, without the language part of the address or anything after a question mark), the page's language, the host name of the website whose link brought you here (such as news.example.org, without the rest of its address; nothing if you came directly; this site's own name when you moved from one of its pages to another), and whether your window is the width of a phone, a tablet or a computer. Our API adds one to that day's total for those four values.

  • The totals hold no IP address, no details of your browser or device (its user agent), no cookie and no identifier of you or your browser. A link from an IP address in place of a host name is recorded as no link.
  • Your browser sends the count without cookies, keeps no cookie from our answer and stores nothing for it. Our API's log holds no IP address or other identifier for a count. The count passes our load balancer, whose log (described above) keeps your IP address, your browser's user agent, the time and the address the count was sent to for 30 days, but not the four things the count holds.
  • To stop one address from inflating the totals, the API keeps a tally of the counts from each IP address for up to 1 hour, under a scrambled form of the address made with a key only our servers hold.
  • If your browser sends Do Not Track or Global Privacy Control, your visits are not counted: our pages send no count when your browser tells them about either signal, and our API discards any count that carries one without keeping a tally of it. Your questions to Ask Elysium are then left out of its totals, and an early-access request records no referring site or campaign and is left out of the totals too.
  • We keep the daily totals for 13 months. Our team reads them in a report that withholds every total from 1 to 4, because on a site with few visitors a small number can point to one person.

Ask Elysium

Ask Elysium is the AI assistant on this website. It answers questions about Elysium and, when you are signed in, helps with your account. It cannot see or control any home.

What happens when you ask a question

  • We send your question, the earlier questions and answers of the conversation (at most the last 4), your language and the address of the page you are on to Anthropic. Its Claude model first checks that the question is about Elysium, and then writes the answer from excerpts of this website's pages.
  • We send your question to OpenAI, which turns it into a search vector so we can find the pages of this site that answer it. For a short follow-up question, we send your previous question with it.
  • If you are signed in, we also send your display name and your type of membership. When a question needs them, the assistant can look up your email address, time zone and bio, and whether a deletion of your account is pending; what it looks up goes to Anthropic with your question. When you ask, it can change your display name, bio or time zone, or cancel a pending deletion of your account. It cannot delete your account: it shows you a button, and only your click sends you an email with a link to confirm the deletion.

What we keep

  • If you are not signed in, we keep no copy of the conversation. Your browser keeps it in the open tab until you close the tab or start a new chat.
  • If you are signed in, we keep each question you ask, and each answer, with your account for 180 days, to check the quality of answers and to prevent abuse. Deleting your account, or erasing your data in the app's Settings, deletes them sooner.
  • If you rate an answer, we keep the rating for 180 days. It is linked to your account if you are signed in, and to nothing about you if you are not. Deleting your account does not delete your ratings: until they expire, they keep only an internal number of the deleted account.
  • To prevent abuse and limit cost, we count requests from each IP address in counters that expire after at most 24 hours. If a chat keeps asking about things unrelated to Elysium, we pause it for 1 hour, and for longer each time it happens again, up to 24 hours. We remember a pause for up to 7 days after the last one. The counters hold your IP address; the records of pauses hold your IP address and a random identifier of the chat in your browser tab, or your account if you are signed in. None of them holds anything you typed.
  • For each question Ask Elysium checks, we add one to a daily total for the page you asked it on and your language, split by whether it was about Elysium; for each answer, one to the daily total of each page it cites. These totals hold nothing you typed and nothing that identifies you, and we keep them for 13 months (see How we count visits).

Ask Elysium also has a Request early access button. The address you enter there is handled as described under The early-access list, and is not sent to Anthropic or OpenAI.

Anthropic and OpenAI process this text for us under their API terms. They do not use it to train their models, and they may keep it for a limited time to detect misuse.

The early-access list

When you ask for early access on this site or in Ask Elysium, we store your email address, the page and form you used, the language of the page, when you asked and which version of our notice you saw. We also store how your visit began, when there is something to store: the host name of the website whose link brought you to this site, and the campaign tags in the address of the first page you opened on this visit (utm_source, utm_medium and utm_campaign). Your browser holds these in memory until you send the form, and we store none of them if your browser sends Do Not Track or Global Privacy Control. If you are signed in, we link the request to your account.

  • We email you a link to confirm your address. If you ask again, we may send another, at most one a day. If your address is already confirmed, we send a short note instead, and if our email cannot be sent, our team may write to you from hello@elysium-labs.ai. Your request counts only after you confirm it, and we record when you did.
  • For each email we try to send you about it, we keep its type, when we sent it or why sending failed, our email provider's reference for it, and the code in its link in scrambled form.
  • When you make a new request, we email our team your address, the page and form you used, your language and whether our email to you went out. We email our team again when you confirm.
  • We use your address only to contact you about early access.
  • To stop one inbox from receiving too many emails, we also store a scrambled form of your address (a hash), and delete it with your request.
  • When our team has written to you about your request, we record when.
  • We add your request, its confirmation and our team's first reply to daily totals for the page and the language of the form. The totals hold no address and nothing else about you, so they stay when you remove your request, until they expire after 13 months.

If you do not confirm, we delete the request within 7 days of the last time you asked. A confirmed request stays on the list until you remove it, delete your account or we close the early-access list.

You can remove your address at any time: open the link in any early-access email we send automatically and press the button, or write to privacy@elysium-labs.ai. Removing it deletes the request, and our records of the emails we sent you about it, at once. The emails our team received about your request are not deleted automatically: write to privacy@elysium-labs.ai and we will delete them too. Deleting your Elysium account also deletes the requests you made while signed in and any request for your account's email address.

Your Elysium account

Early access is by invitation. Only we create Elysium accounts, for the people we invite. An admin of a household can then invite an account into that household.

  • Sign-in. Amazon Cognito, run by AWS in Zürich, stores your email address, your name and your password. The password is stored in protected form. Our servers pass it to Cognito when you sign in or change it, and do not store it, not even as a fingerprint. If you turn on two-step verification, Cognito also stores the key for your authenticator app.
  • Sign in with Google. If you use it, Google shares your name, your email address, whether Google has verified it, a link to your profile picture and your Google account ID with Cognito, which stores them with your sign-in. Google's own privacy policy covers what Google does.
  • Profile. Your email address, your display name, your time zone, a short bio if you add one, a profile picture if you upload one, and your role in your household. We also record who invited you to the household, which its residents can see, and your wall-panel PIN in scrambled form if you set one. A profile picture can only be one you upload to us, so the browsers that show it load it only from our servers and our storage at AWS, never from another site.
  • Invitations. When we invite you, we enter your name and email address at Amazon Cognito, which emails you a temporary password that works for 7 days. If an admin of a household invites you, we store your email address, the role, who invited you, and when the invitation expires and is used.
  • Emails. Your invitation, password reset codes and other verification codes come from Amazon Cognito's own sender, no-reply@verificationemail.com. Other account emails, such as the link that confirms the deletion of your account, come from noreply@elysium-labs.ai through Amazon SES in Zürich. Household invitations are not sent by email.

We keep your account data for as long as your account exists. An invitation is kept, with the email address and role it was for, until the account of the person who sent it is deleted, even after it is used or expires.

The hosted Elysium app

Households in early access use the hosted Elysium app. It runs The Butler in our cloud account (Cloud mode): your household's data is stored with us in Zürich, and The Butler's reasoning runs on cloud AI models.

What the app stores

Your conversations with The Butler and the images you attach to them; the memories The Butler keeps about you and your household; your preferences and the standing preferences you set; the house instructions your household gives it and your home's settings, such as its location; your home's rooms and devices, their states and a history of their changes, including motion and presence; scenes, automations, reminders and scheduled tasks; the calendar feed you connect and the email account your household connects, with the email password encrypted; and an activity log of what The Butler did, at whose request and with which AI model.

The Butler remembers what you tell it, such as your preferences, names and routines, so it can help you better. It saves these memories from your conversations by itself. You can see them, change them or ask for them to be forgotten in Settings. Forgetting a memory erases its words, and those of any earlier version it replaced. A record remains that a memory was forgotten: when it was added and forgotten, who added it, its category and whether it was personal or shared with the household. A household memory can be changed or forgotten by the person who added it or by an admin (by any adult resident if no one is recorded as adding it), and never by a child. Forgetting a memory does not change the conversation it came from, which you can delete separately.

Standing preferences, such as how warm a room should be in the evening, apply to the whole household. Residents can see them in Settings, with who set each one, and remove them. A child cannot remove one, and only an admin can remove an admin's. A removed preference stops applying; it stays in the room's history, with who set it and who removed it, until the person who set it erases their data or deletes their account.

What is sent to the AI model

For each request, the app sends your message and the recent messages of that conversation, memories chosen for the request, your rooms and devices with their current state, the house instructions your household has set and the open goals The Butler is working on, your display name and preferred reply style, the short bio in your profile if you wrote one, the time and your home's time zone, and what The Butler's tools send and return. These go to Anthropic, whose Claude models write the answer, or to OpenAI if you choose an OpenAI model in Settings. Even then, Anthropic checks each reply that changed something in your home against what The Butler did, and answers the request if OpenAI cannot. Web research, which comes with web search, sends the research question and excerpts of the pages read for it to the same model as your requests, or to Anthropic if the app cannot read which model you chose.

A scheduled task uses the same AI model as the requests of the person who created it: Anthropic's, or OpenAI's if that person chose an OpenAI model. Each time the task runs, the app sends that model the task's instructions, that person's display name and preferred reply style, the open goals The Butler is working on, the time and your home's time zone, and what The Butler's tools send and return. If the app cannot read that person's choice when the task runs, the task goes to Anthropic.

In the background, the app also sends to Anthropic: conversation text to write each conversation's title and summary; conversation text with your saved memories, to pick out facts worth remembering; and, if your household turns it on, the night's device changes, alerts and reminders for the morning summary.

Who in your household sees what

Devices, rooms, scenes, automations and household memories are shared with your household. Other members cannot open your conversations or your personal memories in the app, with two exceptions: an admin can download a backup of the household, which includes the words of every resident's personal memories without saying whose they are; and what you say at a shared wall panel becomes part of that panel's conversation, which members can read. Members other than children can see the activity log, which shows who asked The Butler to do what and which actions it took.

If an admin removes someone from the household, their account stays but can no longer use the home. By default their personal memories are deleted and the standing preferences they set stop applying; the admin can choose to keep either. Their scheduled tasks are deleted, and their conversations stay with their account until they delete it.

Guests

An admin of your household can let a guest use The Butler with a PIN, for between one hour and 30 days, and only with the kinds of devices the admin allows, such as lights. Guests cannot see the household's memories, conversations or activity log, but they can ask about the home's devices, scenes and automations. For a guest pass we store the name the admin gives the guest, the PIN in scrambled form, the kinds of devices it allows, when it ends and which admin created it. The admin sees the PIN once, when the pass is created. We keep it after it ends, until that admin deletes their account. A guest's messages go to the AI model like any other request; we do not store them, but we record which tools The Butler used and which devices it changed for the guest. The guest's browser keeps the conversation until the tab is closed or the guest leaves.

Services The Butler contacts for you

  • To tell the weather and your home's local time, The Butler sends the place you set for your home, or its coordinates, to Open-Meteo.
  • Some capabilities stay off until someone in your household turns them on. With web search on, The Butler sends your search query to DuckDuckGo; for a research question it may send several related queries and open a few of the pages it finds, from our servers. With an email account connected, it reads that inbox and sends email from it only after the person who asked approves each message; we store the account's password encrypted. With a calendar feed connected, it reads the feed from the address you give. With a computer connected, it runs a command only after an administrator of your household approves it. Other tool servers your household connects receive what each request needs.
  • If you use the microphone button in the app, your browser turns your speech into text. Depending on your browser, this can happen on the browser maker's servers (for example Apple's, in Safari). We receive only the text.

An Elysium hub in your home

An Elysium hub runs The Butler on a device in your home. A hub does not send your household's data to us in either of its modes.

Sovereign mode

A hub ships in Sovereign mode. The Butler, your sign-in on the hub and your conversations stay on the hub, and it uses no cloud AI service. Only services your household turns on receive your requests or your household's data from it: with web search on, your search queries go to the search service; a tool server your household connects receives what each request needs; if the owner allows internet lookups, the hub fetches the weather and calendar feeds; and if the owner turns on remote access, the network service that connects your devices to the hub can see when the hub is online and its internet address.

Hybrid mode

Hybrid mode is on only if the owner sets the hub up with a cloud AI provider (Anthropic or OpenAI) and turns it on, in Settings or in the hub's configuration. Each resident's requests then go to the cloud model that resident picks in Settings; a resident who keeps the hub's own model keeps their requests on the hub. Requests spoken to the hub are the exception: they all go to the model of one resident, whoever speaks (see below). A request sent to the cloud carries what the provider needs to answer: your message or the transcript of what you said, the recent messages of that conversation, memories chosen for the request, the rooms and devices with their current state, the house instructions your household has set and the open goals The Butler is working on, what The Butler's tools send and return, your display name and preferred reply style, the short bio in your profile if you wrote one, and the time and the home's time zone. If the hub also has an Anthropic key and a resident's OpenAI model fails before it starts to answer a typed or spoken request, because OpenAI is out of quota, refuses the key or cannot be reached, the hub sends that request, with all of the above, to Anthropic's Claude Sonnet 4.6, which answers it instead. A scheduled task uses the same model as the requests of the resident who created it, so it runs on the hub if that resident keeps the hub's own model. When it goes to the cloud, it carries its instructions, that resident's display name and preferred reply style, the open goals The Butler is working on, the time and the home's time zone, and what The Butler's tools send and return. If the hub cannot read that resident's choice when the task runs, the task runs on the hub. Web research, which any adult resident can turn on with web search, sends the research question and excerpts of the pages read for it to the model of the resident who asks for it, so it runs on the hub if that resident keeps the hub's own model or the hub cannot read their choice. If the hub has an Anthropic key, it also sends to Anthropic, for every resident: conversation text to write titles and summaries, and each reply that changed something in the home, with what The Butler's tools did, to check it.

A few further items are sent only while they are also turned on: the audio of requests spoken to The Butler (cloud speech recognition), the text The Butler speaks aloud (cloud speech synthesis), for a few seconds after a spoken reply the text of what the hub hears, with your last request and the reply (follow-up detection), each exchange with your saved memories for picking out facts worth remembering, memory and request text for finding memories by meaning, spoken requests first handled by a fast cloud model, and the night's device changes, alerts and reminders for the morning summary. Cloud speech recognition, cloud speech synthesis and finding memories by meaning use OpenAI. Picking out facts worth remembering and the fast spoken model use Anthropic. Follow-up detection uses the provider of the model the owner names for it. The morning summary is written by Anthropic if the hub has an Anthropic key, and otherwise on the hub. The owner can turn these on only by changing how the hub is deployed: the hub's configuration has no setting for them. The exception is the morning summary, which any adult resident can turn on. Settings shows this list before an admin turns Hybrid mode on there, and the hub keeps it on its own disclosure page.

In both modes, camera video, the wake-word check, room audio until the hub recognises a request and your hub password stay on the hub, and the hub itself carries out device commands. On a hub, the microphone button in the app listens only through the hub's own microphone, never through your browser's speech recognition, and writes what you said into the message box, for you to send as your own request. The owner can return the hub to Sovereign mode at any time, and it then stops sending from the next request.

On the hub, a spoken request is kept in a conversation like a typed message, until it is deleted. Until the hub can tell voices apart, it treats every request spoken to it as a request of one resident, chosen when the hub is set up: it files the request in that resident's conversation and answers it with that resident's model, memories and profile, whoever is speaking. So in Hybrid mode, if that resident picked a cloud model, every request spoken to the hub goes to that model's provider, also from residents who keep the hub's own model. The hub also keeps a timing record of each spoken request. Only that resident can read the words in that record, and by default the record keeps them for at most 14 days. If the owner turns on automatic backups, the hub deletes each one after 14 days by default; backups the owner makes by hand stay until the owner deletes them. The owner can change the backup period in the hub's configuration, and the record's only by changing how the hub is deployed.

Writing to us

Email you send to any @elysium-labs.ai address is forwarded by ImprovMX to our mailbox at Google (Gmail). We use it to answer you, and we keep it as long as we need it for your matter and any follow-up. If you apply for a job, we delete your application within 6 months of our decision on the role, unless you agree that we keep it longer.

If an email we send you cannot be delivered or is marked as spam, a notice with your address and the email's subject reaches the same mailbox, and Amazon SES keeps your address on a list so that we stop sending to it.

Cookies and browser storage

We use only the cookies and browser storage needed for what you ask this site or the app to do, so we do not ask for cookie consent. There are no analytics, advertising or tracking cookies, and none of these items is shared with other companies. Counting visits uses no cookie and no browser storage.

Cookies

  • elysium_session, elysium_access

    Cookie

    Keep you signed in.

    Set by: Our API, for every elysium-labs.ai address. Lasts: 1 hour.

  • elysium_refresh

    Cookie

    Renew your sign-in without asking for your password again.

    Set by: Our API, for every elysium-labs.ai address. Lasts: Until you close the browser, or 14 days if you tick "Remember this device" or sign in with Google.

  • elysium_oauth_state

    Cookie

    Protect signing in with Google, and connecting Google, against forged requests.

    Set by: Our API, while you sign in with Google or connect Google to your account. Lasts: 10 minutes.

  • elysium_oauth_link

    Cookie

    Make sure Google is connected to the account you are signed in to.

    Set by: Our API, while you connect Google to your account on your Account page. Lasts: 10 minutes.

  • AWSALB, AWSALBCORS

    Cookie

    Send your requests to the same server.

    Set by: The load balancer in front of our API, when your browser uses the API, for example to sign in or in Ask Elysium. Lasts: 7 days.

While you sign in with Google or connect Google to your account, your browser passes through Amazon Cognito's sign-in address, where Cognito sets its own short-lived cookies, and Google sets its own cookies on its sign-in page.

Browser storage

  • els-lang

    Local storage

    Remember the language you chose.

    Set by: This website. Lasts: Until you clear your browser's site data.

  • els-orb-sound

    Local storage

    Remember whether Ask Elysium plays sounds, once you press its sound button.

    Set by: This website. Lasts: Until you clear your browser's site data.

  • els-ask-thread-v1:…

    Session storage

    Keep your Ask Elysium conversation while the tab is open, separately for each account that signs in: your questions, the answers with the seal our server puts on each one so it can be sent back as context, the pages each answer cites with the passages it quotes from them, the links the chat offered you, your ratings, and the notices the chat showed you.

    Set by: This website. Lasts: Until you close the tab or start a new chat; signing in with your email address, or signing out, on this site clears it sooner.

  • els-ask-chat-id

    Session storage

    A random identifier of Ask Elysium in this tab, sent with each question. If you are not signed in, an automatic pause applies to it rather than to everyone at your IP address.

    Set by: This website. Lasts: Until you close the tab.

  • elysium:sidebar-collapsed, elysium:device-positions, elysium:performance-mode

    Local storage

    Remember how you arranged and set up the app's screens.

    Set by: The Elysium app. Lasts: Until you clear your browser's site data.

  • surface_token, surface_name

    Local storage

    Keep the panel paired with your home, under the name an admin gave it.

    Set by: A wall panel paired with your home. Lasts: The pairing until the panel is unpaired; the panel's name until the browser's site data is cleared.

  • guest_token, guest_name, guest_devices, guest_transcript

    Session storage

    Run the guest session and keep its conversation while the tab is open.

    Set by: A guest session started with a PIN. Lasts: Until the guest leaves or closes the tab.

Who receives data

We do not sell personal data and do not use it for advertising. We share it only with the providers below, for the purposes described, and with authorities when the law requires it.

  • Amazon Web Services (AWS)

    Location
    Switzerland (AWS Zürich Region); a request to this website can also pass through an Amazon CloudFront edge location near the visitor, which may be in another country
    What it does
    Hosts this website and its content delivery network (Amazon CloudFront), the Elysium app and its database, stores uploaded images, runs sign-in (Amazon Cognito), sends our emails (Amazon SES and Amazon Cognito) and keeps our logs.
    Safeguard
    Your data is stored in Switzerland. Where AWS gives support from abroad, or a CloudFront edge location outside Switzerland handles a request to this website, its data processing addendum applies, with the EU standard contractual clauses. Amazon Cognito sends its emails with its own email service, from a Region that AWS chooses.
  • Anthropic

    Location
    Ireland and the United States
    What it does
    Its Claude models write Ask Elysium's answers and, in the hosted Elysium app, The Butler's answers, conversation titles and summaries, and the memories The Butler saves. They also check replies that changed something in a home, write the morning summary if a household turns it on, and answer a request when a chosen OpenAI model fails. They carry out the scheduled tasks and the web research of people who use a Claude model, and either one when the app cannot read which model that person chose.
    Safeguard
    Our contract is with Anthropic Ireland, Limited, in the EU. The models run in the United States. Anthropic's data processing addendum, which forms part of its commercial terms, includes the EU standard contractual clauses with a Swiss addendum.
  • OpenAI

    Location
    Ireland and the United States
    What it does
    Turns each Ask Elysium question into a search vector, so we can find the pages of this site that answer it. In the hosted Elysium app it writes The Butler's answers, and carries out the scheduled tasks you create and the web research you ask for, only if you choose an OpenAI model in Settings.
    Safeguard
    Our contract is with OpenAI Ireland Ltd, in the EU. Under OpenAI's data processing addendum, which we are concluding with OpenAI, OpenAI Ireland passes data to OpenAI companies in the United States under the EU standard contractual clauses.
  • Google

    Location
    Ireland and the United States
    What it does
    Hosts the mailbox (Gmail) where email sent to our addresses arrives, together with notices about our emails that could not be delivered. If you sign in with Google, Google also confirms who you are to our sign-in service.
    Safeguard
    Google Ireland Limited provides Gmail to us. Google LLC, which processes data in the United States, is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework.
  • ImprovMX Incorporated

    Location
    United States, with mail servers in France and the United States
    What it does
    Receives email sent to our @elysium-labs.ai addresses and forwards it to our mailbox.
    Safeguard
    EU standard contractual clauses in ImprovMX's data processing agreement, which we are concluding with ImprovMX.
  • OpenMeteo GmbH (Open-Meteo)

    Location
    Switzerland (the company), with servers in Europe and North America
    What it does
    Provides the weather and your home's local time in the Elysium app. It receives the place you set for your home, or its coordinates, and nothing about who you are.
    Safeguard
    We send it only a place name or coordinates, from our servers, with nothing that identifies you or your household.
  • DuckDuckGo, Inc.

    Location
    United States
    What it does
    Answers web searches in the Elysium app, only if your household turns web search on. It receives the search queries, sent from our servers without your name or IP address. For a research question, our servers also open a few of the pages it finds.
    Safeguard
    We send a query only when you ask The Butler to search, to carry out that request (Art. 17(1)(b) FADP, Art. 49(1)(b) GDPR).

Services your household connects to the hosted app, such as an email account, a calendar feed, a computer or another tool server, receive what each request needs and act under their own terms.

Switzerland and the EU recognise each other's data protection as adequate. In the United States, only companies certified under the Data Privacy Framework offer adequate protection on that basis; for the other providers there we use the safeguards listed above.

How long we keep data

  • Server and load-balancer logs: 30 days.
  • Records of network connections: 14 days.
  • Database backups: 7 days, so deleted data can remain in a backup for up to 7 days.
  • Counters of requests: up to 1 hour, and for Ask Elysium up to 24 hours. Fingerprints of requests and copies of their replies: 10 minutes.
  • Ask Elysium conversations: none when you are not signed in; 180 days when you are.
  • Ratings of Ask Elysium answers: 180 days, also after you delete your account.
  • Records of Ask Elysium pauses: up to 7 days after the last pause.
  • Unconfirmed early-access requests: up to 7 days after your last request.
  • Confirmed early-access requests: until you remove them, delete your account or we close the early-access list.
  • Daily totals of page views, early-access requests and Ask Elysium questions: 13 months.
  • Your account and what the hosted app stores for you: as long as your account exists (see Deleting your account).
  • The activity log and the history of your home's device changes: no time limit is set yet.
  • Invitations: until the account of the person who sent them is deleted, even after they are used or expire.
  • Guest passes: until the account of the admin who created them is deleted, even after they end.
  • Profile pictures, earlier profile pictures and images attached to chats: until you ask us to delete them.
  • Email to us: as long as your matter needs it; job applications up to 6 months after our decision.

Deleting your account

You can delete your account on your Account page, or by asking Ask Elysium while you are signed in, which shows you the same button. Anyone with an account can do this, a child included; a guest pass or a shared wall panel cannot. We send a link to your email address to confirm. It works for 24 hours, and a new request replaces it. When you confirm, we delete your profile and your sign-in at Amazon Cognito, your conversations and messages, what you said at a shared wall panel after identifying yourself, the words of your spoken requests, your memories (including household memories you added), your reminders, your preferences and standing preferences, the scheduled tasks, guest passes and invitations you created, your calendar connection, your signed-in Ask Elysium conversations and the early-access requests linked to your account.

What you set up for the whole household stays with the home without your name: scenes, automations, skills, wall panels, connected services and the activity log. Messages you left for other residents stay with them without your name, and The Butler's replies to you at a shared wall panel stay in that panel's conversation. Our record of which devices were changed at your request keeps an internal number for your account, but not your name or email address, and so do your ratings of Ask Elysium answers until they are deleted after 180 days.

Deleting your account does not delete your home: its rooms, devices and settings stay, and other residents keep their access. If you are its only admin, no one can manage the household until we make another resident an admin.

Copies in our database backups are deleted within 7 days. Profile pictures, earlier profile pictures and images you attached to chats are not deleted with your account: we delete them, with every stored copy, when you ask us at privacy@elysium-labs.ai.

If the confirmation email does not reach you, write to privacy@elysium-labs.ai from your account's email address, and we will delete the account for you.

Your rights

You have the right to:

  • get a copy of the personal data we hold about you, and information about how we use it;
  • have incorrect data corrected;
  • have your data deleted;
  • restrict or object to our use of it, in particular where we rely on our legitimate interest;
  • receive the data you gave us in a portable format;
  • withdraw your consent at any time, without affecting what we did before.

You can change your profile and delete your account on your Account page. If you are a resident of a home, you can also erase what the home knows about you in the app's Settings and keep your account: this deletes your personal memories, your conversations with The Butler, what you said in other people's conversations (for example at a shared wall panel), the words of your spoken requests, the standing preferences you set and your signed-in Ask Elysium conversations. Your account, settings, reminders, scheduled tasks and calendar connection stay, and so do your profile picture and chat images, your ratings of Ask Elysium answers, the activity log and what belongs to the household, such as household memories you added.

For anything else, write to privacy@elysium-labs.ai, from your account's email address if your request concerns an account. We reply within 30 days and may first ask you to confirm your identity. Requests are free of charge.

You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, if you live in the EU or the EEA, to the data protection authority where you live.

Children

Elysium accounts are for adults (18 or older), with one exception: an adult who manages a household can invite other residents, including children, and give a child a child account. A child account can do less than an adult account: for example, The Butler does not set the heating, change the household's settings or create, change or delete automations for a child, although a child can start a saved scene, which can include a heating setting. A child cannot add to or change the household's memories.

For a child, the app stores what it stores for any resident, such as their name, email address and role, their conversations, their reminders and their personal memories. The adult who manages the household decides whether a child joins, and can change the child's role or remove the child at any time. Removing a child from the household deletes their personal memories but not their account. To delete the account and its data, the child can do so on their Account page, or the adult can ask us at privacy@elysium-labs.ai to delete the child's account and data.

This website and Ask Elysium are meant for adults. If you believe a child has given us personal data without an adult's involvement, write to privacy@elysium-labs.ai and we will delete it.

Security

Connections to this site and the app are encrypted (HTTPS). Our database, cache and file storage are encrypted at rest with keys managed by AWS. Sign-in runs on Amazon Cognito, with optional two-step verification. Only the people who run Elysium, and the automated deployment tools they control, can access the production systems. To report a security problem, see our security policy.

Changes to this policy

We update this policy when our processing changes, and change the date at the top. If a change affects how we use data you have already given us, we tell account holders by email before it takes effect.

Contact

Questions and requests about your data: privacy@elysium-labs.ai.

Controller
Pieter Meyer, trading as Elysium Labs
Based in
Zürich, Switzerland
Postal address
To be published on this page. Until then, please use privacy@elysium-labs.ai.
Email
privacy@elysium-labs.ai