We collect only the information needed to operate the Service, respond to inquiries, and manage accounts and billing. We do not sell personal information. Free sample analyses use public data only. Do not send protected, confidential, proprietary, or personal data with a free demonstration request. Proprietary or protected data is accepted only through a separately governed engagement.
Information we collect
- Business inquiries and sample analysis requests. If you email us, we receive your work email address, company information, question, geography or market, decision context, and any other information you choose to include.
- Account information. Your email address and authentication details when you sign in, handled through Google Firebase Authentication.
- Billing information. Subscription plan and payment status. Stripe processes card payments; we do not receive or store full card numbers.
- Usage and metering. Scan counts, plan limits, and basic product event and log data needed to operate, secure, and troubleshoot the Service.
- Device, website, and analytics data. Google Analytics and our hosting infrastructure may collect page views, referring pages, approximate location, browser and device details, IP address, interaction data, and request timestamps to help us understand and improve website use.
Market insight and sample analysis services
The free sample analysis offer begins with public data, including CMS and other authoritative market sources. The page opens an email in your own email application; the page itself does not upload your question or attachments to Elephruit. Your email provider and ours process the message when you send it.
Free demonstration requests must come from a work email address and must not contain protected health information (PHI), personally identifiable information (PII), confidential information, proprietary information, claims level information, member level information, financial records, credentials, or other restricted data.
If Elephruit works with a customer’s proprietary or protected data, the permitted data, purpose, access controls, service providers, retention, deletion, and other safeguards will be defined through a separate written and governed engagement. Where applicable, those contractual terms, including any data processing or business associate agreement, control over this general website policy.
Scanned card data
The scanning features can read driver’s licenses, state IDs, and health insurance cards on your own device. Driver’s license PDF417 barcodes are decoded on device. Printed information on health insurance cards may be read using optical character recognition that runs inside your browser. Card images are not sent to Elephruit or a third party OCR service.
Decoded fields and camera images are processed transiently in device memory to fill a web form. When a phone scanner is used, data is encrypted from end to end between the phone and paired computer. The encryption key is exchanged directly between the devices. Our relay handles ciphertext it cannot read and deletes it after delivery. Scanned card data is not stored on our servers, used for advertising, or sold.
You are responsible for having a lawful basis to scan any identity or insurance document and for handling the resulting data after it reaches your computer.
Browser extension storage
The Chrome browser extension uses the storage permission to hold one item, the most recent decoded scan result, in chrome.storage.session while you fill out a form. This session storage remains in memory, is cleared when the browser closes, is overwritten by a new scan, and can be removed by selecting Clear. It stays on your device and is not transmitted to Elephruit or a third party. The extension does not use chrome.storage.local or chrome.storage.sync for scanned document data.
How we use information
- To provide, maintain, secure, and troubleshoot the Service.
- To understand website traffic and improve content, navigation, and performance.
- To respond to inquiries and prepare requested sample analyses.
- To communicate about potential or active business engagements.
- To create and manage accounts, enforce plan limits, and process subscriptions through Stripe.
- To send important service, security, support, or billing notices.
- To detect and prevent fraud, abuse, or technical issues and to comply with law.
We do not sell personal information, and we do not use scanned card data for advertising or analytics.
How information is shared
We share limited information with service providers only as needed to operate the Service. These providers include Stripe for payment processing and subscription management, Google Firebase and Google Cloud for authentication, hosting, analytics, and backend infrastructure, and email providers used to receive and respond to inquiries.
Additional providers used in a proprietary data engagement will be addressed through the applicable written agreement. We may also disclose information if required by law, to protect rights or safety, or in connection with a business transfer. We do not sell or rent personal information.
Data retention
We keep account and billing information while an account is active and as needed for legal, tax, accounting, security, and dispute resolution obligations. We retain business inquiries and related correspondence for as long as reasonably needed to respond, manage the relationship, document the request, and meet legal obligations. Scanned card data is not retained on our servers. Retention for a governed proprietary data engagement is defined in the applicable written agreement.
Cookies and similar technologies
Elephruit does not place advertising cookies. Google Analytics may use cookies or similar identifiers to measure page views, sessions, referrals, device characteristics, and website interactions. Elephruit and its infrastructure providers may also use essential storage, authentication mechanisms, and technical logs needed to provide and secure the Service. You can limit cookies through your browser settings.
Security
We use encryption in transit, end to end encryption for scanned data, access controls, and data minimization practices. No transmission or storage method is completely secure, but we work to protect information and limit what we hold. Email is not an approved channel for PHI, PII, confidential, proprietary, or other protected data unless Elephruit has expressly established an appropriate governed process.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us and we will take appropriate steps to delete it.
Your privacy rights
Depending on your state of residence, including California under the CCPA/CPRA and similar laws in other U.S. states, you may have rights to access, correct, receive a copy of, or request deletion of personal information. You may also have the right to opt out of the sale or sharing of personal information. Elephruit does not sell or share personal information as those terms are defined under applicable law.
We will not discriminate against you for exercising an applicable privacy right. To submit a request, contact us below. We may need to verify your identity before responding, and legal exceptions may apply.
Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date and provide additional notice for material changes where appropriate.
Contact
Questions or privacy requests may be sent to Elephruit LLC at support@elephruit.com. Market insight inquiries may be sent to insights@elephruit.com.