PRIVACY

Privacy Notice

What Elucora collects, why it is used, and how to request access or deletion.

Effective and last updated: August 13, 2026

Controller and contact

Elucora, operated by an individual sole proprietor in Bangkok, Thailand, controls the account and service data described here. Contact support.citeseal@gmail.com for privacy questions or rights requests.

Data we process

  • Account identity supplied through Sign in with ChatGPT, including the provider-specific user ID, email address, and optional display name.
  • Profile, workspace, notification, support, design-partner application, and API-key metadata. Secret API keys are shown once; Elucora stores a SHA-256 hash rather than the complete key.
  • Receipt inputs and outputs, including public source URLs, selected evidence, signed metadata, hashes, timestamps, transparency entries, and preserved source bytes.
  • Subscription identifiers, status, plan, invoices, and payment events from Stripe. Elucora does not store complete card numbers.
  • Operational information such as request IDs, timestamps, IP-derived abuse-control identifiers, errors, and security events.

Purposes and legal bases

We use data to provide and secure the service, authenticate accounts, enforce limits, process subscriptions, answer support requests, prevent abuse, maintain receipts, and comply with law. Depending on your location, processing is based on performing our contract, legitimate interests in operating and securing Elucora, consent for optional communications, and legal obligations.

Processors and international transfers

Elucora relies on OpenAI Sites and its hosting infrastructure for application delivery and account identity, Cloudflare services for database and object storage capabilities, and Stripe for subscriptions. These providers may process data in countries other than yours under their own security and transfer mechanisms.

Public receipt warning

Receipt payloads and verifier links are designed to be public. Do not submit secrets, private URLs, confidential research, personal data, or regulated information as selected evidence or signed metadata. Preserved artifact bytes remain restricted to the owning account, but their hashes and source URL may be public.

Retention and deletion

Current beta retention is described in the Retention Policy. We keep account and receipt data while needed to provide the service, meet security and billing obligations, resolve disputes, or comply with law. You may request export, correction, or deletion by email. We will verify the requester and explain any material that must be retained or cannot be removed from an already distributed receipt.

Your choices and rights

Depending on applicable law, you may request access, correction, portability, restriction, objection, or deletion, and may withdraw optional marketing consent. You may also complain to the data-protection authority where you live. We aim to respond to verified requests within 30 days.

Security and changes

We use access controls, hashed API credentials, encrypted transport, private artifact access, request limits, and cryptographic receipt signatures. No system is perfectly secure. Material changes to this notice will be posted here with a new effective date.