Privacy Policy
Effective 1 September 2026. Last updated 1 September 2026.
1. Who we are
Elaichi is a product of Yin Yang, Inc., a Delaware corporation trading as Elaichi ("Elaichi", "we", "us", "our").
| Legal entity | Yin Yang, Inc. |
| Incorporation | Delaware, USA |
| Notice address | 9450 SW Gemini Dr, PMB 69868, Beaverton, Oregon 97008‑7105, USA |
| Affiliate | Yin Yang Technologies Private Limited (India), a wholly owned subsidiary |
| Privacy contact | [email protected] |
| Security contact | [email protected] |
This policy covers the elaichi.ai website, the Elaichi MCP control plane at
app.elaichi.ai, our HTTP and MCP APIs, and the Elaichi desktop companion
application (together, the "Service").
Elaichi is a business-to-business service. It is not offered to consumers and is not directed to children. You must be at least 18 years old and acting on behalf of an organization to use it.
2. Two roles: controller and processor
Which law applies to which data depends on the role we play when handling it. The distinction matters, so we state it plainly.
We are a processor (a "service provider" under US state law) for Customer Data. This is everything that flows through the control plane on your organization's instruction, connection metadata, tool-call metadata, audit records, and any personal data reachable through the SaaS tools your organization connects. Your organization is the controller. It decides what to connect, who may call which tool, and how long records are kept. We act only on its documented instructions, under the Data Processing Agreement.
We are a controller for Account and Site Data. This is the data we collect for our own purposes: who signed up, who pays us, who contacted support, and who visited the marketing site.
If you are an employee or end user of an organization that uses Elaichi and you want to exercise rights over data held in that organization's workspace, contact that organization. We will forward your request and assist them in responding, but we cannot act on it directly. See section 10.
3. Data we handle as a controller
- Account data, name, work email address, organization name, role, and authentication metadata. Where your organization uses SSO or SCIM, these fields arrive from your identity provider.
- Billing data, billing contact name and email, plan, subscription status, and invoice history. We never receive or store payment card numbers. Card data is collected and processed directly by Stripe; we hold only the resulting customer and subscription identifiers.
- Support and sales correspondence, messages you send us, and the contact details in them.
- Website data, pages viewed, referrer, approximate location derived from IP address, and device and browser type. Aggregate, cookieless measurement runs by default: Cloudflare Web Analytics, and PromptWatch, which measures how much of our traffic arrives from AI assistants and stores its data in the EU. Google Analytics 4 and Google Ads measurement run only after you accept cookies, and Google acts as our processor for them. See the Cookie Policy for the full list of cookies and how to change your choice.
4. Data we handle as a processor
4.1 Connection credentials
When your organization connects a SaaS account, the resulting credentials are held in a dedicated credential vault, encrypted at rest with AES‑256‑GCM. The control plane stores only the shape of what a connector requires, never the secret itself. Credentials are resolved server-side at the moment a tool executes. They are never exposed to end users, and never to an AI model.
Organizations on eligible plans may supply their own AWS KMS customer-managed key, in their own AWS account, to wrap this encryption (BYOK).
4.2 Tool-call metadata
Every MCP tool call writes one metadata record. That record contains:
- tool name
- connector
- connection identifier
- status
- duration
- error code, where applicable
- the record identifier returned by the third-party system
We do not write request arguments or response payloads to the log. The contents of a tool call, the message you sent, the record you fetched, the file you read, are processed in memory to fulfill the call and are not persisted by us. The same metadata-only record is what we forward to a customer-configured SIEM destination.
Note that a third-party record identifier can itself be personal data in some systems (for example, where a vendor keys records by email address). We treat these identifiers as personal data.
4.3 Audit records
Privileged actions in the control plane, role changes, connection creation, restriction changes, endpoint minting and rotation, member offboarding, are written to an append-only audit log alongside the acting user's identifier and a timestamp.
5. What we do not do
We want these commitments to be unambiguous:
- We do not train, fine-tune, or otherwise improve any model on Customer Data or tool-call content. Not our models, not anyone's.
- We do not log prompts or completions.
- We do not sell personal information. Never have.
- We never use Customer Data for advertising or profiling, and nothing reached through a connector is ever disclosed to an advertising network.
- Website advertising measurement is opt-in and limited. If you accept cookies on our marketing site, identifiers are disclosed to Google to measure whether an ad led to a signup, which California law calls "sharing". You are opted out by default, we honour Global Privacy Control, and you can opt out at any time via Your Privacy Choices. We have not enabled Google Signals.
6. AI model providers are your choice, not ours
Elaichi holds no model provider key of its own for the in-product assistant. An administrator in your organization supplies your organization's own API key for Anthropic, OpenRouter, Fireworks, or any OpenAI-compatible endpoint.
When the assistant runs, your content, messages, attachments, and tool results, is transmitted to the provider you selected, under your own account and your own agreement with that provider. We are not a party to that agreement. That provider is your processor, not our sub-processor, and its handling of your content is governed by its terms, not ours.
Your organization is responsible for choosing a provider whose terms and data handling meet its obligations. The API key you supply is stored in our credential vault under the protections described in section 4.1.
7. Sub-processors
We engage a deliberately small number of sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, compute, storage, queues, email delivery, rate limiting, and access control | Global, with EU/US jurisdiction pinning for organization data |
| Stripe, Inc. | Subscription billing and payment processing | USA |
| OVH SAS | Hosting of our self-hosted audit-log store | European Union |
| Yin Yang Technologies Private Limited | Engineering, operations, and support personnel; wholly owned affiliate | India |
The authoritative, current list, with each vendor's purpose and location, is published at /subprocessors/ and mirrored in our Trust Center at trust.elaichi.ai, where you can also subscribe to change notifications. We give 30 days' advance notice before adding a new sub-processor, and customers may object as set out in the DPA.
The following are not our sub-processors. They are services your organization elects to connect, under your own accounts and agreements: AI model providers (section 6), Datadog log forwarding, Slack, Google, GitHub and Microsoft social login, your own identity provider for SSO and SCIM, AWS KMS for BYOK, and every SaaS tool you connect through a connector.
8. Where data is stored
All Elaichi compute and primary storage runs on Cloudflare. We operate no AWS infrastructure of our own.
Regional pinning. An organization selects a region, US, EU, or APAC, when it is created, and this choice cannot be changed afterwards. For US and EU, the organization's Durable Object, which holds most organization data, is pinned to the corresponding Cloudflare jurisdiction.
Please read these limitations carefully:
- APAC is a placement hint, not a residency guarantee. Selecting APAC requests placement but does not contractually guarantee that data remains in that region.
- Certain shared stores are not region-pinned regardless of your selection: the global index of organization and user records, the session store, and stored logos.
- By design, the audit-log store is a single European Union instance serving all regions. If your organization is in the US or APAC, your audit metadata is stored in the EU. This is a permanent architectural property, not a transitional state.
If regional residency is a compliance requirement for your organization, please raise it with us before onboarding rather than relying on the region selector alone.
9. International transfers
We are a US company with an Indian affiliate, and we transfer personal data to both the United States and India. We are not certified under the EU–US Data Privacy Framework. Our transfer mechanism is the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum and the Swiss amendments, incorporated into our DPA.
EU representative (GDPR Art. 27) Rickert Rechtsanwaltsgesellschaft mbH – YIN YANG, INC. Colmantstraße 15, 53115 Bonn, Germany [email protected]
UK representative (UK GDPR Art. 27) Rickert Services Ltd UK – YIN YANG, INC. PO Box 1487, Peterborough PE1 9XX, United Kingdom [email protected]
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. Residents of California and other US states have rights described in our CCPA Notice. EEA, UK and Swiss residents have the rights described on our GDPR page.
How to exercise them:
- If your data is in a customer's Elaichi workspace, contact that organization directly. They control it; we process on their instructions. If you contact us instead, we will route the request to them and support their response.
- If we are the controller, you are an account holder, a billing contact, a support correspondent, or a website visitor, email [email protected]. We verify requests by confirming from the email address on file, and apply an additional check for deletion requests.
We respond within 45 days, extendable once by a further 45 days where a request is complex, with notice to you. There is no charge for a reasonable request.
You also have the right to lodge a complaint with your supervisory authority. We would appreciate the chance to address your concern first.
11. Retention
| Data | Retention |
|---|---|
| Audit and tool-call metadata | 90 days, then aged out |
| Organization data on deletion | Retained for a 30-day recovery period, then permanently deleted. An owner may choose to purge immediately instead |
| Audit history and usage counters | Deleted together with the organization |
| Account and billing records | Seven years after the end of the relationship, for tax, accounting, and legal purposes |
| Point-in-time recovery | Cloudflare provides 30-day PITR on D1 and Durable Objects. We operate no backups of our own |
Deletion revokes access immediately. The moment an organization is deleted, its API tokens, MCP endpoints, and connections stop serving, regardless of the recovery period. The recovery period governs only whether the data can still be restored. Third-party credentials are revoked at the provider, so restoring an organization does not restore its connections, every connection must be re-established. See the Terms of Service for the full mechanics.
12. Security
Credentials are vaulted and encrypted with AES‑256‑GCM. Session, API, MCP, and invite tokens are stored as keyed hashes and displayed exactly once at creation. Access is governed by role-based access control, connector and tool restrictions, enforced SSO, and TOTP multi-factor authentication.
Our current certifications, control posture, and security documentation are published in our Trust Center at trust.elaichi.ai, with gated documents released under NDA on request from [email protected]. To report a vulnerability, see /.well-known/security.txt.
No system is perfectly secure. We commit to notifying affected customers of a personal data breach without undue delay and within 72 hours of confirming it, as set out in the DPA.
13. Cookies
The marketing site and the application use cookies as described in our Cookie Policy. No cookie-setting analytics or advertising script loads until you accept, only cookieless measurement that stores nothing on your device, we honour the Global Privacy Control signal, and you can change your choice at any time through the Cookie settings link in the footer.
The Elaichi desktop companion application contains no telemetry, analytics, crash reporting, or update pings. It communicates with exactly one host: the Elaichi API URL you enter. Your API token is stored in your operating system's keychain.
14. Changes
We will post any change here and update the date above. For material changes we will give at least 30 days' notice to account administrators by email or in-product notice before the change takes effect.
15. Contact
| Purpose | Address |
|---|---|
| Privacy questions and rights requests | [email protected] |
| Data protection and DPA requests | [email protected] |
| Security and vulnerability reports | [email protected] |
| Legal notices | [email protected] |
Postal: Yin Yang, Inc., 9450 SW Gemini Dr, PMB 69868, Beaverton, Oregon 97008‑7105, USA.