Skip to content
Elula / Privacy Policy

Privacy Policy

Last updated October 4, 2026

1. Who we are

Elula is a deployment platform. It takes code from a Git repository, the Elula CLI, or an HTML file, builds it, and runs it in a Google Cloud project. Elula is operated by Envisioning LLC-FZ, a Free Zone limited liability company registered in the Emirate of Dubai, United Arab Emirates (“Elula”, “we”, “us”).

This policy covers the Elula website, web app, CLI, and API (the “Service”). It is written to meet the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), and the UAE Personal Data Protection Law.

2. Our role: controller and processor

We play two different roles, depending on whose data it is.

  • Controller for data about the people who use Elula: your account, organization membership, billing contact, and how you use the Service. This policy describes how we handle that data.
  • Processor for data inside the apps you deploy (your code, your app’s databases, your app’s users and their data, your logs). Your organization is the controller of that data and decides what goes into it. We handle it only to provide the Service, on your instructions. If you are a visitor to an app deployed with Elula, contact the organization that runs that app about your data.

3. What we can and cannot access

Elula is built so your apps run in your Google Cloud project, not ours. We want to be precise about what that means, because “your cloud” does not mean we have no access.

How access works

When you connect a Google Cloud project, our setup script creates a service account named elula-deployer in your project and lets Elula’s backend act as it. That service account holds these roles in your project: Cloud Run Admin, Cloud Build Editor, Artifact Registry Admin, Cloud SQL Admin, Secret Manager Admin, Security Admin (IAM), Cloud Scheduler Admin, Logs Viewer, Storage Admin, Certificate Manager Owner, and Compute Load Balancer Admin. The script also creates an elula-runtime service account that your apps run as. You can see and remove all of these grants in the Google Cloud console at any time.

Some organizations choose to run on Elula-managed Google Cloud projects instead of their own. For those organizations, the apps, databases, and logs below live in a project we own and operate.

What we access, and when

What we do not have

  • Card numbers. Payments are handled by Stripe. We store only Stripe customer and subscription IDs and plan status; card brand and last four digits are fetched from Stripe when you view billing.
  • Your Google or GitHub password. Sign-in uses Google OAuth; GitHub uses OAuth and the GitHub App.
  • Repositories you did not grant. The GitHub App can only see repositories you or your GitHub admin selected.
  • Send contents. Items shared with Elula Send are encrypted in your browser. The key stays in the part of the link after #, which browsers do not send to our servers. We store only the encrypted data.
  • Your Google Cloud bill. You pay Google directly for the resources your apps use.

Who at Elula can see your data

A small number of Elula staff have administrative access to the Service. They can view organizations, users, and projects, and act on projects, when needed to operate the Service, provide support you request, investigate abuse or security issues, or meet legal obligations. We do not look at your code, databases, or logs for any other reason.

Ending access

You can disconnect your Google Cloud project in Elula, and you can delete the Elula service accounts or their roles in the Google Cloud console. Disconnecting in Elula removes the connection from our database but does not remove the grants in your project; delete the service accounts to fully cut off our access. Your apps and data keep running in your project either way.

4. Information we collect

We do not use advertising cookies, third-party analytics, or cross-site tracking on the Service.

5. How we use information and our legal bases

  • To provide the Service (performance of a contract): sign you in, build and deploy your apps, manage databases and secrets, show logs and metrics, send invites and notifications.
  • To bill you (contract and legal obligation): manage subscriptions through Stripe and keep records required by tax and accounting law.
  • To keep the Service secure (legitimate interests): detect abuse, enforce our Terms, keep audit logs, and investigate incidents.
  • To support and improve the Service (legitimate interests): answer requests, fix bugs, and understand which features are used, using our own data rather than third-party trackers.
  • To communicate with you (contract and legitimate interests): service and security notices, invites, and billing messages.
  • To comply with law (legal obligation): respond to valid legal requests and keep required records.

We do not sell your personal information, share it for cross-context behavioral advertising, or use it to make automated decisions that have legal or similarly significant effects on you.

6. AI features

Some features use Google’s Gemini models through the Google Cloud API: suggesting project settings from your repository, explaining failed builds and deploys, proposing fixes for dependency vulnerabilities, and generating Pages from a prompt. When you use one, we send Google the content needed for that task, such as selected repository files, build or deploy logs, dependency lists, or your prompt.

These features run only when you or a member of your organization trigger them. We do not use your code, logs, or prompts to train AI models.

To check dependencies for known vulnerabilities, we send package names and versions (not your code) to the public OSV.dev database operated by Google.

7. Who we share information with

We use these service providers to run Elula. They process data on our behalf under contracts that limit their use of it.

Within your organization

Members of your organization can see your name, email, role, and the actions recorded in the audit log. Organization owners and admins can manage members, apps, secrets, and billing.

When you share something yourself

If you make an app or Page public, anyone with the link can see it. Public access may require approval from an organization owner, and that approval is recorded. Elula Send links can be limited by password, allowed emails, number of views, and expiry.

Legal and business transfers

We may disclose information when required by law or to protect the rights, safety, or property of our users, the public, or Elula. If Elula is involved in a merger, acquisition, or sale of assets, information may transfer as part of that deal, and this policy will continue to apply to it.

8. International transfers

Elula and its providers process data in the United States and other countries where they operate, which may differ from where you live. Where the law requires it, we rely on the European Commission’s Standard Contractual Clauses or other approved safeguards for these transfers. You can ask for a copy at privacy@elula.com.

Your apps, app databases, and secrets run in the Google Cloud region you choose for your project.

9. Retention and deletion

  • Account and organization data is kept while your account or organization is active. After you ask us to delete it, we delete or anonymize it within 30 days, except where we must keep it longer by law.
  • Billing records are kept as long as tax and accounting law requires.
  • Audit logs and deployment history are kept while your organization is active so you have a record of changes and approvals.
  • Deleting a project in Elula removes its Cloud Run service, its Elula-created database and database secret, and its record in Elula. Secrets you created yourself in Secret Manager stay in your project until you delete them.
  • Send items are deleted when they expire or reach their view limit.
  • Data in your Google Cloud project is yours. It stays there when you stop using Elula, and you control how long it is kept.

To delete your account or organization, email privacy@elula.com from the email address on the account.

10. Security

We use TLS for all traffic, Google Cloud encryption at rest, HttpOnly secure session cookies, hashed invite tokens, encryption of the database credentials Elula creates, browser-side encryption for Send, private-by-default access through Google’s Identity-Aware Proxy, and role-based access within organizations. No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.

You are responsible for the security of your own Google Cloud project, the code you deploy, and who you give access to. To report a security issue, email legal@elula.com.

11. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy;
  • correct data that is wrong;
  • delete your data;
  • object to or restrict processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent where we rely on it;
  • opt out of the sale or sharing of personal information (we do neither) and not be discriminated against for using your rights (California);
  • complain to your data protection authority (EU/EEA: your local supervisory authority; UK: the ICO; UAE: the UAE Data Office; California: the Attorney General).

Email privacy@elula.com with your name and the email you sign in with. We may need to verify your identity. We respond within 30 days, or sooner if the law requires. If your request is about data inside an app your organization deployed, we will pass it to that organization, since it controls that data.

12. Cookies and browser storage

We only use what is needed for the Service to work:

  • elula_session: keeps you signed in. HttpOnly and secure; lasts 7 days.
  • Sign-in session cookie: protects the Google sign-in flow while it is in progress.
  • Local and session storage: remembers small things like your GitHub connection state, where to return after sign-in, and alerts you dismissed.

We do not use analytics or advertising cookies. Because these are strictly necessary, we do not show a cookie banner. The CLI stores your access token in a config file in your home directory (~/.elula).

We do not track you across other sites, so browser “Do Not Track” signals do not change how the Service behaves. Where the law requires it, we honor Global Privacy Control signals.

13. Children

Elula is a tool for businesses and professionals and is not meant for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

14. Changes to this policy

We will post changes on this page and update the date at the top. If a change is material, we will tell account owners by email or in the app before it takes effect, where the law requires.

15. Contact

Envisioning LLC-FZ, Dubai, United Arab Emirates. Privacy questions and requests: privacy@elula.com. Everything else: legal@elula.com.