Privacy Policy

Effective date: August 5, 2026

Elevate Boardroom LLC(“Elevate Boardroom,” “we,” “us,” or “our”) operates an AI-powered virtual boardroom service. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you use our public website, signed-in application, and related services (collectively, the “Service”). It is a privacy notice, not a request for consent to every activity described below.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, authentication-provider identifiers, email-verification and Terms-acceptance status, and an optional profile photo. We do not receive your password when you use a third-party sign-in provider.

Business and Company Information

You may provide your company name, website, industry, size, location, goals, financial or operating information, and other facts in your editable company brief. This information can come from onboarding, meetings, documents you upload, an import you provide, and public web research you ask the Service to perform. The Service also maintains private internal board context derived from ended meetings so your board can carry decisions, strategic threads, and progress into later meetings. That context is not exposed as a user-editable product surface and changes as newer meetings supersede earlier understanding.

Meeting and Document Data

We collect meeting titles and discussion briefs, AI advisor configurations, chat messages and AI responses, uploaded document files and extracted content, pinned decisions, action items, summaries, and exports. A meeting has one live human account owner and AI advisors; we do not provide multi-user live participation at this time.

Billing and Communications

Stripe processes payment details and returns billing identifiers, subscription status, invoices, payment-method summaries, and transaction outcomes to us. We do not store full card numbers or card security codes. We also maintain transactional email delivery and suppression records needed to send account, billing, meeting, and service messages reliably.

Operational Usage and Diagnostics

To operate, secure, bill, and troubleshoot the Service, we process meeting and feature counts, token and credit usage, model/provider categories, request status, timestamps, coarse performance measurements, security attestations, and minimized error diagnostics. Hosting and security providers may also process IP address, browser or device information, and request metadata. We do not run a per-minute activity heartbeat.

Optional Product Analytics

Firebase Analytics, powered by Google Analytics 4, is disabled by default and does not initialize unless you grant the separate analytics choice. We save that choice to your account with its policy version and decision time, then apply it when you sign in on another browser. If enabled, events use generalized page routes and bucketed feature measurements rather than meeting IDs, company IDs, titles, file names, or conversation content. We do not use product analytics for advertising.

Optional Advertising Conversion Measurement

If you separately allow advertising measurement on our marketing site or in Settings, LinkedIn and Meta may receive the safe signup or subscription page URL, referring page, general browser and device data, IP-derived location, their cookie identifiers, and controlled events such as completed registration or a new subscription. Subscription events may include the plan category, price, and currency. We do not send meeting content, documents, company details, email addresses, or Elevate user IDs to these tools, and we do not use advanced matching.

2. Cookies and Similar Technologies

Signing up or accepting our Terms and this Privacy Policy does not grant permission for optional analytics or advertising storage. The Service uses the following categories:

  • Strictly necessary storage: Firebase Authentication stores signed-in session state. Firebase App Check and reCAPTCHA help attest legitimate app traffic and prevent abuse. We also store security, legal-acceptance, interface, and consent preferences needed to provide your account.
  • Billing and fraud prevention: Stripe may use cookies or similar technology when you open billing or payment components, as described in the Stripe Privacy Policy.
  • Optional analytics: If you grant the separate analytics choice, Google Analytics may set identifiers such as _ga to distinguish browsers and sessions. Unknown or denied preference states remain off.
  • Optional advertising measurement: If separately allowed, Meta may set _fbp or _fbc, LinkedIn may set li_fat_id or related measurement cookies, and Elevate stores an eb-ad-consent-shared cookie on the shared elevateboardroom.ai domain so the marketing-site choice applies to signup and subscription conversion events in the app.

Optional analytics can be refused without losing account functionality and can be withdrawn at any time in Settings. Your latest choice is account-wide. Withdrawal disables collection on the current browser immediately, removes accessible Google Analytics identifiers, and is applied to your other browsers when they next load your account. Google's processing is described in the Google Privacy Policy.

Advertising measurement is a separate browser-level choice and can be changed in Settings or the marketing site's cookie settings. Withdrawal stops future Elevate conversion calls and removes accessible first-party advertising identifiers. LinkedIn and Meta processing is described in their respective privacy policies.

3. How We Use Information and Our Legal Bases

  • Perform our contract: Create and administer your account, run meetings, process documents, generate AI responses and summaries, provide exports, manage subscriptions, and send necessary service messages.
  • Comply with legal obligations: Maintain tax, accounting, transaction, suppression, and legal-acceptance records and respond to lawful requests.
  • Protect legitimate interests: Secure the Service, prevent fraud and abuse, diagnose failures, improve reliability, enforce our Terms, and understand aggregate service cost and health. We minimize these records and balance these interests against your rights.
  • Use consent where required: Run optional analytics, measure advertising conversions, or send communications that legally require consent. Consent may be refused or withdrawn without affecting processing needed to provide the Service.

4. AI Processing and Model Providers

We transmit the meeting and business context needed to answer your request to one or more selected or fallback AI providers. Depending on your configuration and service availability, these may include Google (Gemini and Vertex AI), Anthropic (Claude through Vertex AI Model Garden), OpenAI (GPT through OpenAI's API), xAI (Grok through Vertex AI Model Garden), Meta (Llama through Vertex AI Model Garden), and Mistral AI through Vertex AI Model Garden.

We do not use your meeting data to train or fine-tune our own models, and we use commercial API arrangements intended not to use API customer content for general model training. Provider processing and limited abuse-monitoring retention can vary by provider and endpoint. Uploaded files are stored privately in Firebase Storage and processed server-side or by the selected model provider when needed for the meeting.

AI output may be inaccurate. The Service assists your decision-making but does not make legal or similarly significant decisions about you solely through automated processing.

5. Service Providers and Disclosure

We do not sell personal information. If you allow advertising measurement, our sharing of pseudonymous browsing and conversion signals with LinkedIn and Meta may be treated as targeted-advertising or cross-context sharing under some privacy laws. Otherwise, we disclose only what is reasonably necessary to:
  • Infrastructure and security providers: Google Cloud and Firebase for hosting, database, file storage, authentication, App Check, and reCAPTCHA; Sentry and Google Cloud Logging for minimized operational diagnostics.
  • Payment and communications providers: Stripe for billing and fraud prevention; SendGrid for email delivery, bounce handling, and suppression.
  • AI and content providers: The model providers listed above and public news or web sources needed for features you request.
  • Optional analytics: Google Analytics only after the separate permission described above.
  • Optional advertising measurement: LinkedIn Insight Tag and Meta Pixel only after the separate advertising permission described above.
  • Legal and safety needs: Comply with law or valid legal process, protect rights and safety, investigate abuse, or enforce agreements.
  • Business transfers: Support a merger, financing, acquisition, restructuring, or sale, subject to appropriate confidentiality and notice requirements.

See our current Subprocessor Register for provider purposes and data categories.

6. Data Storage, Security, and International Transfers

We use technical and organizational safeguards including encryption in transit and at rest, owner-scoped Firebase Security Rules, server-side authorization, private document paths, abuse attestation, restricted service credentials, payment-webhook signature verification, audit logging, dependency review, and production error redaction. No storage or transmission method is completely secure.

We and our providers operate primarily in the United States. When personal data is transferred from the EEA, United Kingdom, or Switzerland, we rely on an adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism as applicable.

7. Data Retention

  • Account and company data: Kept while your account or workspace is active, then deleted or de-identified unless a legal obligation requires longer retention.
  • Meeting data: Kept for the life of your account unless you delete the workspace or account. Changing or canceling a subscription does not shorten meeting history. Account and workspace deletion remove the associated meetings through the durable deletion process.
  • Documents: Kept for the meeting lifecycle and removed when the meeting is deleted, subject to short-lived backup and operational deletion cycles.
  • Data exports: Private export chunks and the completed downloadable artifact are kept for up to seven days, then removed by scheduled cleanup. Starting account deletion cancels and removes an active export.
  • Company brief and internal board context: Kept while the workspace exists. You can edit the factual brief. Internal board context is derived from ended conversations and can change when newer meetings supersede earlier understanding. Deleting one meeting does not automatically unwind facts already synthesized into later context; account deletion removes the workspace and its internal context.
  • Raw metering records: Customer usage and AI provider-attempt records are kept for 90 days, then folded into compact monthly totals and the raw records are deleted.
  • Operational records: Chat-turn coordination records are short-lived. Email, webhook, billing-operation, security, and deletion-job records have bounded retention based on reliability, dispute, suppression, tax, and fraud-prevention needs. Billing and tax records may be retained for up to seven years.
  • Provider diagnostics and optional measurement: Sentry, Cloud Logging, AI providers, and, if enabled, Google Analytics, LinkedIn, and Meta retain minimized data under configured provider schedules. We periodically review those settings and access controls.

Account deletion removes active application data and initiates provider cleanup, but data in bounded security logs, delivery records, fraud records, legal records, or backups may remain until the applicable retention period expires.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent; and complain to a data-protection authority. You may export or delete your account in Settings, edit your company brief, manage optional product analytics, advertising measurement, and email preferences, and unsubscribe from marketing messages. You cannot directly edit the private internal board context. Contact privacy@elevateboardroom.ai for other requests. We may need to verify your identity before completing a request.

9. European Privacy Rights

If the GDPR or UK GDPR applies, Elevate Boardroom LLC acts as controller for the Service. You may object to processing based on legitimate interests and may lodge a complaint with your local supervisory authority. Where we rely on consent, withdrawal does not affect processing that occurred before withdrawal. Providing account and meeting information is generally necessary to perform the Service; optional analytics is not. Contact privacy@elevateboardroom.ai to exercise these rights or ask about our transfer safeguards.

10. California and Other U.S. State Rights

If applicable state privacy law covers our processing, you may request access, correction, deletion, or portability, opt out of targeted-advertising or cross-context sharing through advertising settings, and appeal a denied request. We do not sell personal information. Contact privacy@elevateboardroom.ai to submit a verifiable request.

11. Children's Privacy

The Service is not directed to anyone under 18. We do not knowingly collect personal information from children. Contact privacy@elevateboardroom.ai if you believe a child provided information to us.

12. Changes to This Policy

We may update this policy as the Service or law changes. We will post the revised policy and effective date here and provide additional notice when a change is material or law requires it. If a change requires new consent, continued use alone will not substitute for that consent.

13. Contact Us