Privacy notice
Privacy, in plain language.
Your information, the help it makes possible, and the controls you have.
Last updated September 24, 20261. What this notice covers
This notice covers Elysona’s personal workspace: accounts, conversations with Sona, tasks, weekly plans, notes, saved memories, and optional Google connections.
2. What you choose to share
Elysona stores your account name and email, a salted password hash, preferences, and the content you save. Conversation attachments are stored as text with the conversation. Voice input uses your browser’s speech recognition service when available; its processing is governed by your browser provider. Elysona does not store microphone recordings.
3. How Sona uses your information
When you ask Sona for help, your prompt, recent messages, and relevant workspace context are sent to Google Gemini to generate a response or carry out supported actions. Saved memories are included only when memory is enabled. Web research uses Google Search and displays source links and search suggestions with the answer. Avoid including information you do not want processed by these providers. Provider retention policies may apply even when response storage is disabled in the API request. Google Search grounding can retain prompts, context, and output for 30 days. See the Gemini API data terms.
4. Gmail, Calendar, and Drive when you connect them
Connecting Google allows Elysona to read relevant Gmail messages and your primary calendar, search Google Drive and read supported documents when requested, prepare emails, and create calendar events. Google content needed to answer your request may be sent to Google Gemini. Emails and calendar writes require approval in For your review before execution. Access and refresh tokens are encrypted in the application database. Disconnecting removes Elysona’s stored connection and attempts to revoke access with Google. You can also revoke access in your Google Account.
5. Browser tasks and live voice
Live voice sends microphone audio directly from your browser to Google Gemini using a short-lived token; Elysona saves the transcribed turns in your conversation, not the raw audio. A browser task opens the public page you provide in an isolated browser, sends its readable content and your goal to Gemini, and waits for you to approve the exact research note before saving it. The browser does not sign in or submit forms.
6. Cookies and technical information
An essential, HTTP-only session cookie keeps you signed in for up to 30 days. Rate limits use account identifiers and hashed network information to reduce abuse. Hosting providers may process request logs and technical information needed to operate the service. Optional Vercel Analytics runs only when enabled by the operator. Password reset emails are delivered through Resend when recovery is configured.
7. Storage and your choices
Your workspace is saved until you remove items or delete your account. Use Settings to export your saved content or delete your account. Deletion removes the account, sessions, stored Google credentials, and workspace records from the active application database. It does not undo email sends or remove events already written to Google. Provider logs and infrastructure backups may have separate retention periods. Pausing memory stops its use in new assistant requests; it does not erase memories or existing conversations. You can delete those separately.
8. Guest workspaces
A guest workspace is stored on the server and accessed through your browser session. If you clear the session or it expires, you may lose access. Create an account to preserve access across devices. You can export or delete a guest workspace in Settings before leaving it.
9. Updates
This notice may change as Elysona evolves. The date above identifies the current version. Review the notice before connecting a new service or sharing additional information.