Privacy Policy
Last updated: July 8, 2026
This Privacy Policy explains how Elephruit LLC ("Elephruit," "we," "us") collects, uses, and protects information when you use the Elephruit website, browser extension, bookmarklet, and phone scanner (the "Service"). The Service is intended only for users at least 13 years old and located in the United States.
Information we collect
- Account information. Your email address and authentication details when you sign in (handled through Google Firebase Authentication).
- Billing information. Subscription plan and payment status. Card payments are processed by Stripe; we do not receive or store full card numbers.
- Usage and metering. The number of scans you've used, plan limits, and basic product-event and log data needed to operate, secure, and troubleshoot the Service.
- Device data. Standard technical data such as browser type and IP address, used for security and to deliver the Service.
Scanned card data (driver's licenses & insurance cards)
The Service can read two kinds of cards, and in both cases the reading happens on your own device:
- Driver's licenses / state IDs. The PDF417 barcode is decoded on-device into fields such as name, date of birth, address, and license number.
- Health-insurance (Medicare) cards. These carry no barcode, so the printed text — such as the Medicare Beneficiary Identifier (MBI) and coverage dates — is read by on-device optical character recognition (OCR). The recognition engine runs entirely inside your browser; card images are not sent to us or to any third-party OCR service. This information may be considered health or medical information, which we treat as sensitive.
The decoded fields and any camera images are processed transiently, in your devices' memory, to fill your web form. This data:
- Is end-to-end encrypted between your phone and your paired computer when you use the phone scanner. The encryption key is exchanged directly between your devices via the pairing QR code and never reaches our servers.
- Passes through our relay only as ciphertext we cannot read, and is deleted once delivered to your computer.
- Is never stored on our servers, never used for advertising, and never sold.
You are responsible for having a lawful basis to scan any identity or insurance document and for how you handle the resulting data once it reaches your computer.
Browser extension storage
The Chrome browser extension requests the storage permission for one narrow purpose: to keep your
most recent scan available while you fill out a form. Chrome closes the extension's popup whenever it loses
focus — for example when you click into a form field or move to the next page of a multi-page form — which
would otherwise discard the scan. To prevent that, the extension holds a single item — the
most recent decoded scan result — in chrome.storage.session, so it survives the
popup closing and can auto-fill the page you are on. This session storage:
- Lives in memory only; it is never written to disk.
- Is automatically cleared when you close the browser, and is overwritten on each new scan and removed when you click Clear.
- Stays entirely on your device — it is never transmitted to us or any third party, never used for advertising, and never sold.
The extension does not use chrome.storage.local or chrome.storage.sync, so no scanned
document data is persisted to disk or synced to your Google account.
How we use information
- To provide, maintain, and secure the Service.
- To create and manage your account and enforce plan limits.
- To process subscriptions and payments through Stripe.
- To respond to support requests and send important service or billing notices.
- To detect, prevent, and address fraud, abuse, or technical issues, and to comply with law.
We do not sell your personal information, and we do not use scanned license data for advertising or analytics.
How information is shared
We share limited information only with service providers that help us run the Service, and only as needed:
- Stripe — payment processing and subscription management.
- Google Firebase / Google Cloud — authentication, hosting, and backend infrastructure.
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer. We do not sell or rent personal information to third parties.
Data retention
We keep account and billing information for as long as your account is active and as needed to comply with legal, tax, and accounting obligations. Scanned license data is not retained on our servers. You can request deletion of your account information as described below.
Security
We use encryption in transit, end-to-end encryption for scanned data, and access controls to protect information. No method of transmission or storage is completely secure, but we work to protect your information and limit what we hold.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
Your privacy rights
Depending on your state of residence (for example, California under the CCPA/CPRA, and similar laws in other U.S. states), you may have the right to:
- Access or receive a copy of the personal information we hold about you;
- Correct inaccurate personal information;
- Request deletion of your personal information — you can delete your account and its data at any time from the app or via our Delete Your Account page;
- Opt out of the "sale" or "sharing" of personal information — note that we do not sell or share your personal information as those terms are defined under applicable law.
We will not discriminate against you for exercising these rights. To make a request, contact us using the details below; we may need to verify your identity before responding.
Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, provide additional notice where appropriate.
Contact
Questions or privacy requests? Contact Elephruit LLC at support@elephruit.com.
