Trust
Security
A short overview of how ElseLane handles trust and data. Full legal detail lives in the Privacy Policy.
Transport security
Production traffic is served over HTTPS/TLS. Secrets and API keys are never logged in plaintext in application responses.
What we store
Account identity (email, auth credentials/hashes or OAuth links), credit balance, API key hashes, and usage metadata (status, model, provider, credits, latency, attempts summary). Prompt and answer bodies are not retained after the request completes.
What providers receive
To generate an answer, the prompt (and optional system message) is sent to the AI providers tried for that request. Those providers process data under their own terms.
PII guardrails
High-risk patterns such as SSNs, payment card numbers, private keys, and common cloud secrets are blocked by default before any provider call. Admins may configure redact mode.
Payments
Card data is handled by Stripe. ElseLane stores Stripe customer/session references and credit ledger events — not raw card numbers.
Your controls
Revoke API keys, export usage as CSV, unlink OAuth providers, and permanently delete your account from the dashboard.
Security concerns: privacy@elselane.com or contact form.