Elula deploys apps to your Google Cloud project. This policy explains what we collect about you, what we can and cannot access in your project, who we share data with, and the rights you have. See also our Terms of Service.
1. Who we are
Elula is a deployment platform. It takes code from a Git repository, the Elula CLI, or an HTML file, builds it, and runs it in a Google Cloud project. Elula is operated by Envisioning LLC-FZ, a Free Zone limited liability company registered in the Emirate of Dubai, United Arab Emirates (“Elula”, “we”, “us”).
This policy covers the Elula website, web app, CLI, and API (the “Service”). It is written to meet the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), and the UAE Personal Data Protection Law.
2. Our role: controller and processor
We play two different roles, depending on whose data it is.
- Controller for data about the people who use Elula: your account, organization membership, billing contact, and how you use the Service. This policy describes how we handle that data.
- Processor for data inside the apps you deploy (your code, your app’s databases, your app’s users and their data, your logs). Your organization is the controller of that data and decides what goes into it. We handle it only to provide the Service, on your instructions. If you are a visitor to an app deployed with Elula, contact the organization that runs that app about your data.
3. What we can and cannot access
Elula is built so your apps run in your Google Cloud project, not ours. We want to be precise about what that means, because “your cloud” does not mean we have no access.
How access works
When you connect a Google Cloud project, our setup script creates a service account named elula-deployer in your project and lets Elula’s backend act as it. That service account holds these roles in your project: Cloud Run Admin, Cloud Build Editor, Artifact Registry Admin, Cloud SQL Admin, Secret Manager Admin, Security Admin (IAM), Cloud Scheduler Admin, Logs Viewer, Storage Admin, Certificate Manager Owner, and Compute Load Balancer Admin. The script also creates an elula-runtime service account that your apps run as. You can see and remove all of these grants in the Google Cloud console at any time.
Some organizations choose to run on Elula-managed Google Cloud projects instead of their own. For those organizations, the apps, databases, and logs below live in a project we own and operate.
What we access, and when
| Data | What Elula does with it |
|---|---|
| Your source code | Read from the GitHub repositories you grant the Elula GitHub App access to, or uploaded by the CLI, in order to build it. Also read when you use an AI feature (see section 6). |
| Environment variables | Plain variables are stored in Elula's database. Variables you mark as secret are stored in Secret Manager in your project; we store only their names. At deploy time our backend reads secret values and sets them on your Cloud Run service. |
| App databases (Cloud SQL) | We create the database, user, and password, and keep an encrypted copy of the connection details. Data is read only when a member of your organization uses the SQL console or database views in Elula. |
| Build logs, runtime logs, metrics | Read from your project when someone in your organization views them in Elula. We may keep copies of logs to show history beyond what Cloud Logging returns quickly. |
| Pages (HTML files) | Stored in a Cloud Storage bucket in your project, or in an Elula bucket if your organization has not set one up, and served to viewers you allow. |
| Your apps' end users | We do not collect data about people who visit your apps. Access checks for private apps are handled by Google's Identity-Aware Proxy using Google sign-in. |
What we do not have
- Card numbers. Payments are handled by Stripe. We store only Stripe customer and subscription IDs and plan status; card brand and last four digits are fetched from Stripe when you view billing.
- Your Google or GitHub password. Sign-in uses Google OAuth; GitHub uses OAuth and the GitHub App.
- Repositories you did not grant. The GitHub App can only see repositories you or your GitHub admin selected.
- Send contents. Items shared with Elula Send are encrypted in your browser. The key stays in the part of the link after
#, which browsers do not send to our servers. We store only the encrypted data. - Your Google Cloud bill. You pay Google directly for the resources your apps use.
Who at Elula can see your data
A small number of Elula staff have administrative access to the Service. They can view organizations, users, and projects, and act on projects, when needed to operate the Service, provide support you request, investigate abuse or security issues, or meet legal obligations. We do not look at your code, databases, or logs for any other reason.
Ending access
You can disconnect your Google Cloud project in Elula, and you can delete the Elula service accounts or their roles in the Google Cloud console. Disconnecting in Elula removes the connection from our database but does not remove the grants in your project; delete the service accounts to fully cut off our access. Your apps and data keep running in your project either way.
4. Information we collect
| Category | Examples and source |
|---|---|
| Account | Name, email address, profile photo, and Google account ID, from Google sign-in. Your GitHub username, GitHub access tokens, and GitHub App installation ID, if you connect GitHub. |
| Organization | Organization name, members, roles, invites (including invitee email), verified domains, access policies, and Google Cloud project details. |
| Projects and deployments | Project settings, repository and branch, environment variables, deployment history, build status, custom domains, access approvals, and job runs. |
| Audit log | Who did what in your organization, when, and from which IP address (for example deploys, access changes, and public-access approvals). |
| Billing | Plan, billing interval, Stripe customer and subscription IDs, and subscription status. Card details are held by Stripe. |
| Content you give AI features | Prompts, selected files, and logs sent when you use AI features (section 6). |
| Technical | IP address, browser and device information, and request logs created when you use the Service, kept for security and troubleshooting. |
| Communications | Messages you send us and support conversations. |
We do not use advertising cookies, third-party analytics, or cross-site tracking on the Service.
5. How we use information and our legal bases
- To provide the Service (performance of a contract): sign you in, build and deploy your apps, manage databases and secrets, show logs and metrics, send invites and notifications.
- To bill you (contract and legal obligation): manage subscriptions through Stripe and keep records required by tax and accounting law.
- To keep the Service secure (legitimate interests): detect abuse, enforce our Terms, keep audit logs, and investigate incidents.
- To support and improve the Service (legitimate interests): answer requests, fix bugs, and understand which features are used, using our own data rather than third-party trackers.
- To communicate with you (contract and legitimate interests): service and security notices, invites, and billing messages.
- To comply with law (legal obligation): respond to valid legal requests and keep required records.
We do not sell your personal information, share it for cross-context behavioral advertising, or use it to make automated decisions that have legal or similarly significant effects on you.
6. AI features
Some features use Google’s Gemini models through the Google Cloud API: suggesting project settings from your repository, explaining failed builds and deploys, proposing fixes for dependency vulnerabilities, and generating Pages from a prompt. When you use one, we send Google the content needed for that task, such as selected repository files, build or deploy logs, dependency lists, or your prompt.
These features run only when you or a member of your organization trigger them. We do not use your code, logs, or prompts to train AI models.
To check dependencies for known vulnerabilities, we send package names and versions (not your code) to the public OSV.dev database operated by Google.
8. International transfers
Elula and its providers process data in the United States and other countries where they operate, which may differ from where you live. Where the law requires it, we rely on the European Commission’s Standard Contractual Clauses or other approved safeguards for these transfers. You can ask for a copy at privacy@elula.com.
Your apps, app databases, and secrets run in the Google Cloud region you choose for your project.
9. Retention and deletion
- Account and organization data is kept while your account or organization is active. After you ask us to delete it, we delete or anonymize it within 30 days, except where we must keep it longer by law.
- Billing records are kept as long as tax and accounting law requires.
- Audit logs and deployment history are kept while your organization is active so you have a record of changes and approvals.
- Deleting a project in Elula removes its Cloud Run service, its Elula-created database and database secret, and its record in Elula. Secrets you created yourself in Secret Manager stay in your project until you delete them.
- Send items are deleted when they expire or reach their view limit.
- Data in your Google Cloud project is yours. It stays there when you stop using Elula, and you control how long it is kept.
To delete your account or organization, email privacy@elula.com from the email address on the account.
10. Security
We use TLS for all traffic, Google Cloud encryption at rest, HttpOnly secure session cookies, hashed invite tokens, encryption of the database credentials Elula creates, browser-side encryption for Send, private-by-default access through Google’s Identity-Aware Proxy, and role-based access within organizations. No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
You are responsible for the security of your own Google Cloud project, the code you deploy, and who you give access to. To report a security issue, email legal@elula.com.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong;
- delete your data;
- object to or restrict processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent where we rely on it;
- opt out of the sale or sharing of personal information (we do neither) and not be discriminated against for using your rights (California);
- complain to your data protection authority (EU/EEA: your local supervisory authority; UK: the ICO; UAE: the UAE Data Office; California: the Attorney General).
Email privacy@elula.com with your name and the email you sign in with. We may need to verify your identity. We respond within 30 days, or sooner if the law requires. If your request is about data inside an app your organization deployed, we will pass it to that organization, since it controls that data.
13. Children
Elula is a tool for businesses and professionals and is not meant for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
14. Changes to this policy
We will post changes on this page and update the date at the top. If a change is material, we will tell account owners by email or in the app before it takes effect, where the law requires.
15. Contact
Envisioning LLC-FZ, Dubai, United Arab Emirates. Privacy questions and requests: privacy@elula.com. Everything else: legal@elula.com.