Elphi AI Privacy Policy
This page shows the same text as the app.
Contents
- 1. Who we are and how to contact us
- 2. Summary
- 3. On-device AI and what the app keeps on your device
- 4. Cloud models (Elphi AI Premium)
- 5. Elphi Account
- 6. Web search
- 7. Purchases, Premium and Cloud Credits
- 8. Other features that connect to the internet or your other devices
- 9. Security signals and network information
- 10. Categories of information
- 11. Why we use information and legal bases
- 12. How we share information
- 13. How long we keep information
- 14. Deleting your information and your choices
- 15. International transfers
- 16. Security
- 17. Your rights
- 18. Children and age limits
- 19. Test versions
- 20. Changes
- 21. Contact us
Effective date: 8 October 2026
Last updated: 8 October 2026
This Privacy Policy explains how Bosphorus Intelligence LLC ("we", "us") handles personal information in Elphi AI (the "app") on iPhone, iPad, Mac and Apple Watch and on our website www.elphiai.com. Our Terms of Use cover plans, prices and other commercial rules.
1. Who we are and how to contact us
Elphi AI is provided by Bosphorus Intelligence LLC, a Wyoming limited liability company, 30 N Gould St Ste N, Sheridan, WY 82801, United States (phone +1 (609) 300-0094). We are the controller (under Turkish law, the data controller) of the personal information described in this Policy. Privacy requests: [email protected]. Support: [email protected].
2. Summary
On-device AI is the default: it answers on your device without sending your messages to an AI provider, and your chats are stored on your device, not on our server. No account is required for on-device AI. Features you choose, such as web search and Premium's cloud models, send data off your device (sections 4, 6 and 8). The app tells you that you are chatting with AI and that responses may be inaccurate. It does not use an advertising identifier and has no third-party analytics, crash-reporting or advertising software.
3. On-device AI and what the app keeps on your device
On-device models run on your device and process your messages, images and documents there. Web search (section 6), cloud models, which also receive a chat's earlier messages (section 4), and sending chats, model downloads and Report (section 8) can send data off your device.
What is stored. The app keeps your chats, attached images, imported document text, memories, profile name, projects, scheduled items, statistics, settings, drafts and pairing details on your device. It does not sync them to iCloud or our server, but your device's backups include them (not downloaded models). The Keychain holds a random device identifier and, if you sign in, account tokens, a device key and an account summary.
Memory. After answers in normal chats, including cloud answers, the app may save facts you state about yourself, such as your name, where you live, your job or a health condition. Memories stay on your device and are not added to cloud requests (section 4.2). There is no switch to turn memory off, but temporary chats create none, and you can view and delete memories in Settings › Memory.
Images and voice. The app stores a resized copy of images you attach, which some on-device models can read. Voice mode uses Apple's on-device speech recognition; audio is not stored or sent.
Temporary chats stay in memory and are not saved on your device, though content-free statistics are still recorded. With a cloud model, the provider receives their messages and may keep them for a while (section 4.5).
Statistics and logs. The app keeps content-free records of each answer (such as model, speed, outcome and credits used) and system logs without message content; it does not send them to us. A damaged database is set aside on your device until you delete the app.
4. Cloud models (Elphi AI Premium)
4.1 When cloud models are used
Cloud models are optional and, where available, need an Elphi Account and Premium. Before any request, you confirm in the app that you are 18 or older, give separate explicit consent that sensitive information you choose to send may be processed by the selected AI provider, and allow each provider (section 4.6). Choosing Elphi Auto asks you to allow the providers it can use that you have not allowed yet or must allow again, never one you turned off. A cloud choice applies to the whole app on that device, including temporary chats, voice mode and Siri "Ask Elphi" requests, until you choose an on-device model; Apple Watch questions are always answered on-device. Chat titles, memories, web-search queries and scheduled items are always created on your device.
4.2 What is sent
Each cloud request contains:
- Elphi's instructions (including safety guidance), a reply-language note, today's date and the instructions of any Assistant you use;
- the chat's earlier messages, including those from before you chose a cloud model, limited in size and usually including the first; answers that failed, were cut off, refused or filtered, used your memories, or were written on your device from documents or web results are left out with their questions;
- your new message, typed or transcribed from your voice (never audio); and
- if your message uses them, matching document passages with their file names (a short document may go whole), web search results and the images attached to that message. Earlier images are not resent, and the app re-encodes each image first, removing its location, camera details, timestamps and other metadata.
The app never adds your saved memories, profile name or project details, but earlier messages can contain anything you or the AI wrote in that chat, including your name or project details if an on-device answer mentioned them.
Requests are linked to your Elphi Account to check your plan, permissions and credits. Our server passes them to the provider and returns the answer, without storing or logging your content. It adds a pseudonymous safety identifier (section 4.4), but not your name, email address, account ID, IP address or device identifiers.
4.3 Providers and Elphi Auto
Cloud models come from OpenAI (GPT), Anthropic (Claude), Google (Gemini) and SpaceXAI (Grok). Which providers and models are offered can vary by app version and region and change over time; the app shows those currently offered. A provider receives a request only when you choose one of its models or Elphi Auto picks one.
Elphi Auto picks from the providers you allowed and sends your message to one provider at a time. If that provider fails before its answer begins, the request may go to another allowed provider, with at most three attempts; once an answer begins, or if a provider refuses or filters the message, it never goes to another. A failed provider may already have received it, so one message can reach up to three providers. A model you chose may be retried once with the same provider, never with another. Every answer shows which model wrote it.
4.4 Safety checks, identifiers and restrictions
Before a message goes to an OpenAI model, our server sends your latest message (text and images, not earlier history) to OpenAI's moderation service, without any identifier. A flagged message is not sent, unless it was flagged only for possible self-harm; then it is sent, and Elphi's instructions ask the model to point to crisis support. With Elphi Auto, this check can run even if another model answers. Providers may also refuse or filter requests and answers.
Each request carries a pseudonymous safety identifier that differs by provider and stays the same for your account, so a provider can connect your requests, detect misuse and tell us about it. The pseudonymous identifier itself does not contain your name, email address or other direct account identifiers. We can link it to your account.
If OpenAI tells us it has blocked use connected to your account, our systems automatically suspend all cloud models for that account; on-device models and web search keep working. We may also restrict cloud models after reviewing another provider's notice; a provider's warning leads only to a review. Refusals, filtered answers, moderation flags, rate limits, capacity or budget limits and network errors do not by themselves lead to a restriction.
A restriction is recorded against your account, its Premium subscriptions and, through a keyed code, the Apple Account that bought them. It continues after account deletion or a transfer, applies to any Elphi Account that holds the subscription and can apply to Premium bought later with that Apple Account. A provider's block lasts until that provider lifts it; we cannot lift it. A restriction we placed does not expire on its own: you can ask a person at Elphi to review and contest it at [email protected], and we review it at least every 12 months, but a review falling due does not lift it. Our messages about it omit providers' case details; you can ask for a copy of your personal information (section 17).
4.5 What providers keep, and training
Each provider's terms govern its processing. As of the date of this Policy, they state that:
- OpenAI does not use API data to train its models unless the customer opts in. It keeps abuse-monitoring logs, which may include prompts, responses and safety-classifier results, for up to 30 days, or longer where law or safety requires, and keeps images flagged as possible child sexual abuse material for review. Our requests turn off its optional response storage, which does not affect those logs. See its privacy policy, terms, data controls and usage policies.
- Anthropic may not train models on API inputs and outputs under its Commercial Terms. It deletes them within 30 days, unless needed longer to enforce its Usage Policy or by law; if its systems flag a conversation, it may keep it for up to 2 years and the safety classification scores for up to 7 years. See its privacy policy, terms and usage policy.
- Google does not use prompts or responses of its paid Gemini API, which we use, to improve its products. It keeps them, with related context, for 55 days only to detect and prevent violations of its Prohibited Use Policy and for legal disclosures; its staff may review flagged content. Our requests turn off its optional request logging, which does not affect those logs. See its privacy policy, Gemini API terms and Prohibited Use Policy.
- SpaceXAI does not use API content to train its models under its enterprise terms. We use its zero data retention option, under which it keeps no logs of content and deletes it after answering, within an hour at most. SpaceXAI confirms this on every answer; without that confirmation, our server discards the answer and pauses SpaceXAI, though the request has reached it. Its terms do not say how long it keeps request metadata, such as the safety identifier. See its privacy policy, terms and acceptable use policy.
Providers may also cache parts of a conversation to answer faster: OpenAI encrypted for up to 24 hours, Anthropic in memory for at least 5 minutes, Google in memory for up to 24 hours and SpaceXAI for no fixed period. We do not train AI models on your content. Deleting a chat does not delete what a provider keeps.
4.6 Your choices
To stop, choose an on-device model. On the Models page, you can also switch off individual cloud models or Elphi Auto on that device.
Provider permissions. The AI provider permissions page in the app shows each provider's permission and the version you accepted, and lets you withdraw it (or email [email protected]). A withdrawal is recorded on our server for your whole account and applies from the next request: no request goes to that provider from any of your devices, Elphi Auto stops using it, and a model of it you had chosen shows as unavailable instead of switching to another provider. Turning a provider off also withdraws your sensitive-information consent for it. Withdrawal does not affect earlier processing.
New versions. Each permission is tied to a version of the provider's description. A material change, such as to the provider's identity, the data sent, how long it is kept or how it may be used, or the scope of sensitive information, raises that version, and the app asks you again before your next request to that provider; editorial changes do not. An app without the latest description asks you to update it first.
You can also sign out or delete your account (section 14).
5. Elphi Account
No account is required for on-device AI; you need an Elphi Account only for cloud models. When you sign in and when you first turn on cloud models, the app tells you that by continuing you agree to the Terms of Use and acknowledge this Policy. You can sign in with:
- Apple: we receive an identifier for you, not your name or email address. We keep Apple's sign-in tokens, encrypted, to check with Apple that you still use Sign in with Apple and to revoke them when you delete your account.
- Google: we ask only for your email address and Google account ID.
- Email: Resend (privacy policy) sends you a link and an 8-digit code, and receives your address, the link and code, your device type and the request time; it stores them in the United States, for about 30 days under its published plans.
We do not store your email address, only keyed codes made from it with a secret key and a masked hint such as b•••@gmail.com. If an email sign-in leads you to "Continue with Google", the address you typed goes to Google as a login hint.
Each signed-in device has a session record: a public key made on the device, platform, device type, app version, sign-in method, day of last use and security details. You can see and end sessions in the app.
6. Web search
Web search is optional and needs no account. It runs only for messages you turn it on for, after you accept the in-app explanation, and goes through our server to the Brave Search API.
- Query: your message, shortened if long, or, with an on-device model, a short query the model may write from your message and recent chat. The model is told to leave out personal details, and the app removes email addresses and phone numbers taken from earlier messages.
- Brave receives the query (which contains what you wrote), the language, number of results and a strict SafeSearch setting, but no account or device identifier; our server does not add your IP address. Brave keeps query records for up to 90 days (privacy notice). With a cloud model, the results also go to the provider (section 4.2).
- We keep your monthly search count and any bought searches under a keyed code, not the query. Bought searches do not expire.
- Your device keeps, with the answer, the query and a note that the web was searched, except in temporary chats. Result titles and links are shown with the fresh answer and are not saved.
7. Purchases, Premium and Cloud Credits
Apple processes payments. The Apple-signed purchase records the app sends us include identifiers of your purchases and of your Apple Account's copy of the app, the product, dates, price, currency and App Store country. They do not include your payment details, name or email address.
To confirm your plan, the app sends our server these records, its version, the platform and, where supported, an App Attest signature. It does so, for example, when you use web search or cloud models, open Web Search settings, or buy or restore a plan or search pack, and it may also do so at launch and when you open the plans screen, model menu or Models page, to check whether Premium is available, even if you use only on-device models. Our server keeps keyed codes made from the records, not the records, with counters, balances and dates, so your search counts, search packs, credits and any restriction (section 4.4) follow your Apple Account's purchases.
Premium bought while signed in carries a random code linking it to your Elphi Account in Apple's records, which we update if the subscription moves to another account. Apple notifies us of renewals and refunds. We keep keyed codes of the subscription's transaction identifiers, its period dates, renewal status and Cloud Credit balance.
8. Other features that connect to the internet or your other devices
- Model downloads come directly from Hugging Face, which sees your IP address and the files requested (privacy policy); we do not receive them.
- Pairing and sending chats use your local network, with encryption required. This device shows nearby devices its name (on a Mac, its computer name) and a random installation identifier only while you pair, send chats, open the Devices page or continue a chat with Handoff; otherwise, while the app is open and paired, it only looks for your devices without announcing itself. A chat you send (Plus) carries its messages, images and document passages. A paired device can also ask for a chat, for example after Handoff, and gets it automatically if Plus is active.
- Handoff (Plus) shares an open chat's title and identifier with your devices through Apple, except temporary chats.
- Apple Watch questions and answers pass between your watch and iPhone, which answers on-device; the watch can show the start of an answer in a notification.
- Siri and Shortcuts: "Ask Elphi" passes your question to the app and your chosen model, and Siri can show your chat titles.
- Notifications are created on your device; reminders can show a scheduled item's text on your Lock Screen.
- Report opens an email draft to [email protected] with the answer (up to 1,500 characters), your reason and note, the chat's model, and the app and system versions. Nothing is sent unless you send it.
- Our website sets no cookies of its own and uses no analytics; your theme choice stays in your browser. Our web server logs basic request details, such as the page and browser type, for 30 days. Cloudflare, which delivers it, sees request information such as your IP address and may set security cookies, under its own privacy policy (section 9).
9. Security signals and network information
- App Attest. Where supported, the app uses Apple's App Attest (one key per installation) only as a signal that requests come from a genuine copy of the app. Our server keeps the key's public part, a counter and the last-use time. We do not use DeviceCheck.
- IP addresses. Cloudflare, which hosts our server, receives your IP address and request information and may process network and security data under its privacy policy. Our server does not store IP addresses; it briefly uses a daily-changing code of your IP address to limit sign-in abuse.
10. Categories of information
- Content: messages, images, document passages, voice transcripts, web-search queries and results, memories and Assistant use.
- Account: account ID, Apple and Google identifiers, email address (as keyed codes and a masked hint), 18+ confirmation, provider permissions, sensitive-information consent and their history, and session records.
- Purchases and usage: keyed transaction codes, subscription status and dates, credit balances, search counts and packs, daily cloud usage counts per provider and model, and on-device statistics.
- Device and network: IP address and request information, device public key, platform, device type, app version and App Attest records.
- Security and safety: security events, provider safety identifiers, providers' notices about your account (with their case reference and policy category, but no message content), any restriction, its reviews and our notes.
- Communications and diagnostics: emails and reports you send us, and crash reports and aggregated statistics from Apple that do not identify you, if you share analytics with developers.
This information comes from you, your device, Apple, Google and AI providers.
11. Why we use information and legal bases
Where the GDPR or similar laws apply, we rely on:
- Contract: providing the app and features you ask for, such as cloud answers, your account, purchases, credits, web search, sending chats and support.
- Consent: sending your content to each cloud provider you allow. You can withdraw it at any time (section 4.6), without affecting earlier processing.
- Legitimate interests: security, fraud and abuse prevention, safety enforcement and reviews, reliability, aggregate statistics, other inquiries and legal claims. You can object (section 17).
- Legal obligation: complying with the law, including handling privacy requests and keeping records of consent.
Sensitive information. We do not ask for it, but some Assistants, such as the fitness, nutrition and relationship ones, invite you to discuss health or personal matters. On your device, it stays there and may be saved as a memory (section 3). For cloud models, the app asks for your separate explicit consent that sensitive information you choose to send may be processed by the selected AI provider, which may keep it as section 4.5 describes. You can withdraw that consent by turning the provider off (section 4.6), or leave such information out.
12. How we share information
- AI providers (OpenAI, Anthropic, Google and SpaceXAI): the content of the cloud requests sent to each and your safety identifier for that provider.
- Service providers: Cloudflare (our server, databases and website) and Resend (sign-in emails) act for us under data processing terms that limit their use of personal information and require them to protect it in line with this Policy and the law. Each also handles some network or email-delivery data for its own purposes as an independent controller.
- Apple: purchases, Sign in with Apple, App Attest, Siri and Shortcuts, Handoff and speech-recognition downloads, under its privacy policy.
- Brave (web search), Google (Google sign-in, under its privacy policy) and Hugging Face (model downloads, directly from your device).
- Your own devices, when you send chats or use Apple Watch.
- Legal and safety: where the law or legal process requires, or to protect the rights, safety or property of our users, the public or us. We may tell a provider what we did about its safety notice.
- Business transfers: in a merger, acquisition or asset sale, with equivalent protection.
The other companies named here handle personal information under their own terms and privacy policies, which also require them to protect it; this Policy notes where their practices differ from ours. We do not sell personal information or share it for cross-context behavioral or targeted advertising.
13. How long we keep information
- On your device: until you delete it or the app. Message content: not stored on our server.
- Elphi Account: until you delete it; inactive accounts are never deleted automatically.
- Sessions: end after 60 days unused or 365 days at most, and are deleted 30 days later. Sign-in links, codes and related records: about 24 hours.
- Provider permissions, 18+ confirmation and sensitive-information consent, with their history: while your account exists; after you delete it, a record of these choices (provider, version, grant or withdrawal, dates), without content, under the deleted account's random identifier, for 1 year.
- Security events (records of security-relevant account changes, such as linked sign-in methods, unusual sign-in activity, subscription moves and suspensions): 1 year, or until you delete your account. Provider safety notices: 1 year, even after you delete your account.
- Safety status and restrictions, with their reviews: on your account, until we lift them or you delete it; on a Premium subscription or the Apple Account that bought it, until we lift them (a provider's block, until the provider lifts it). Provider safety identifiers: while your account exists, then with its Premium subscription records.
- Cloud usage counts and App Store notification records: 180 days. App Attest records: 180 days after last use. Per-request credit records: about 1 hour.
- Premium subscription records: while the account holding them exists, even after the subscription ends; after account deletion, until 60 days after the last period ends, or while a restriction on them applies. Credit balances: about 60 days after each billing period ends.
- Sign in with Apple notification records, records of refunded billing periods and aggregate statistics: up to 400 days. Encrypted subscription identifiers for updating Apple's records: up to 7 days.
- Web search: request records about 5 minutes; monthly counts until shortly after the month ends; bought searches until used; keyed records of redeemed packs, with no set limit, so a purchase cannot be redeemed twice.
- Database backups: up to 30 days. Restore records of account changes (no content or contact details): 90 days. Website server logs: 30 days.
- Emails and reports: as long as necessary to handle your request, meet legal obligations and establish, exercise or defend legal claims, then deleted or anonymized.
14. Deleting your information and your choices
- On your device: delete chats, documents, memories and scheduled items in the app (Settings › Data and Settings › Memory), and reset your performance history on your Profile page. Deleting a chat does not delete memories saved from it. Deleting the app on iPhone or iPad removes its data except Keychain items such as the device identifier; on a Mac, its data folder can remain. Deleting the app does not delete your Elphi Account.
- Your Elphi Account: delete it on the Elphi Account page in the app (you may need to sign in again). We delete at once your account, sign-in methods, sessions, provider permissions, usage counts, security events and account-linked safety records, and ask Apple to revoke Sign in with Apple. For 1 year we keep the record of your consent choices and providers' safety notices (section 13). We keep the Premium subscription records and credits, so credits are not reset if the subscription moves to a new account, and your provider safety identifiers with them, so a provider's later notice still applies. Deletion does not lift a restriction (section 4.4); other records expire as section 13 says. Chats stay on your device unless you also delete this device's data. Deleting the account does not cancel a subscription.
- Web search: your counts and bought searches are kept under a keyed code, not linked to your name or Elphi Account, so we may not be able to find them from a request.
15. International transfers
We are based in the United States, and our server runs in Cloudflare data centers worldwide, usually near you. Our account database is created in Cloudflare's EU jurisdiction and stored in the European Union, though the code that uses it can run elsewhere; other server records, such as credit balances and search counts, may be stored elsewhere. The other companies named in this Policy may process information in the United States and other countries, which may offer less protection than your own. Where required, transfers rely on the EU Standard Contractual Clauses (with the UK Addendum and Swiss amendments) in our providers' data processing terms or, for certified companies such as Google, Cloudflare and Resend, the EU–US Data Privacy Framework and, where certified, its UK and Swiss extensions. Brave's terms do not treat search queries as personal data, and our server sends them without your identifiers.
16. Security
We use reasonable safeguards, including encrypted connections, device-bound sessions, encrypted sign-in tokens, request logging turned off on our server and data minimization. On iPhone and iPad, the app's database cannot be read while your device is locked, unless the app has it open. No system is completely secure. Report security issues to [email protected]. We notify you and the authorities of a breach where the law requires.
17. Your rights
17.1 All users
You can ask us to access, copy, correct or delete your personal information, or withdraw consent, by emailing [email protected]. We cannot access data stored only on your device. We may ask you to verify a request, for example by writing from the email address you sign in with. We respond free of charge within the legal deadline and explain any refusal.
17.2 EEA, UK and Switzerland
You can also restrict or object to processing, receive your data in a portable format, and ask for a person to review and contest an automated decision, such as the suspension in section 4.4. You can complain to your data protection authority (see the EDPB list, the UK Information Commission (ICO) or the Swiss FDPIC).
17.3 Türkiye (KVKK)
This Policy is our information notice under Article 10 of Law No. 6698 (KVKK). We process personal data for the purposes in section 11 on the grounds in Articles 5 and 6 (contract, legal obligation, legitimate interest and, where required, explicit consent, including for sensitive information) and transfer it abroad to the recipients in section 12, as section 15 describes. Your Article 11 rights include those in section 17.1, learning who receives your data, notice to recipients, objecting to results of solely automated analysis and claiming compensation. Apply in Turkish or English to [email protected] from the email address you use with your Elphi Account, with a secure electronic signature, or in writing to our address. We respond free of charge within 30 days. You can complain to the Personal Data Protection Board (kvkk.gov.tr) within 30 days of our answer, and no later than 60 days after applying.
17.4 US states
Depending on your state, you can know, access, correct, delete and get a portable copy of your personal information, and appeal our decision by replying "Appeal", then contact your state Attorney General if we deny it. We do not sell or share personal information or use it for targeted advertising, and we use sensitive personal information only to provide the service. You can use an authorized agent, and we will not discriminate against you for using your rights.
18. Children and age limits
Elphi AI is for people aged 13 and over, or older where local law requires; children under 13 must not use it, and users under 18 need a parent's or guardian's permission (see our Terms of Use). Cloud models are only for people aged 18 and over: you confirm your age in the app and we record your confirmation with your account. We do not ask for your date of birth or an ID and do not verify your age. If a child under 13 has given us personal information, contact [email protected] and we will delete it.
19. Test versions
Test versions, such as TestFlight builds, connect to our test servers, which keep the same kinds of records, and test purchases are not charged. Their providers, models and features can differ from the App Store version. TestFlight feedback you send reaches us through Apple.
20. Changes
When we update this Policy, we change the "Last updated" date and take reasonable steps to tell you about material changes in advance, asking for your consent where the law requires, as for a provider's new version (section 4.6).
21. Contact us
Bosphorus Intelligence LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States. Privacy and data protection requests: [email protected]. Support and everything else: [email protected].