ELY / ANDROID APP
App privacy policy
How the ELY app for Android accesses, uses and shares data, and how to delete it.
Last updated:
This English translation is provided for convenience. In case of discrepancy, the French version prevails.
The app and its developer
App: ELY (ELY 2) for Android
Developer: Franck OLLIVIER, Vienne (86), Nouvelle-Aquitaine, France
Privacy contact: contact@agent-ely.fr
ELY is a free and open source personal AI agent, distributed under the MIT license and developed in a personal, non-professional capacity. The Android app is an interface. It connects to an ELY 2 installation, called an “instance”, which you host yourself or which is hosted by the person who administers it.
This policy applies to the app and to the ELY 2 software it gives access to. The agent-ely.fr website has its own privacy policy.
Where your data is
The developer operates no server for app users and has no access to your data. The app displays no ads and includes no audience measurement, tracking or crash reporting tool.
What you enter in the app is sent to your instance’s server, at the address you open in the app, and stored there. This server is operated by you or by your instance’s administrator. The administrator chooses the AI models and connected services, and is responsible for the processing carried out on their server.
If you use someone else’s instance, that administrator can access the data stored on their server. Contact them with any question about their practices.
Data processed
Depending on the features you use, ELY processes the following data on your instance:
Account
Email address, name, password (stored only as a hash), session tokens and the type of browser or device used to sign in.
Conversations and content
Messages, attachments, images, files created or downloaded by ELY, content you share to ELY from another app, and the results of the actions carried out.
Profile and memory
Information ELY remembers to help you: identity, relatives, work, places, preferences and habits, health, accounts and services used, as well as skills learned over the course of tasks. This information may include sensitive data, such as health data, if you share it.
Calendar, contacts and email
Events and contacts managed by ELY. If you connect your Google account or your mailbox, ELY accesses your emails, calendar and contacts within the limits of the access granted.
Credentials and connections
Usernames and passwords you choose to save in ELY’s vault so that it can act on your behalf, access tokens for connected services (Google, LinkedIn, Facebook), email account credentials and Telegram chat ID.
Browsing
A browser profile specific to your account, with the sessions and cookies of the sites ELY visits, as well as the content and screenshots of the pages viewed for your tasks.
Voice
Dictation recordings, when you use the microphone, sent to be transcribed into text.
Notifications and usage
Notification subscription, technical task log (tools used and their parameters) and AI model usage volume.
On your device
Display and voice reading preferences: language, voice, reading speed.
The app does not collect your location, your phone’s contacts or any advertising ID.
Android permissions
Microphone: used only when you start dictation.
Notifications: to receive messages from ELY, such as a completed task, a reminder or a security alert.
Internet access: to communicate with your instance.
You can revoke these permissions at any time in Android settings. The corresponding features then stop working.
Third-party services and sharing
No data is sold or used for advertising. Depending on your instance’s configuration, the data needed for your requests is sent to the following services:
AI model providers
The provider chosen by the administrator, for example Anthropic, OpenAI, Google (Gemini), Mistral, DeepSeek, OpenRouter, Groq or xAI, or a locally run model. They receive your messages, attachments and images, the content and screenshots of the pages viewed, and the relevant parts of your profile and memory. When a task requires a credential saved in the vault, that credential may be sent to the model.
Voice and images
Dictation is transcribed by Groq or OpenAI, or by your device’s speech recognition service. Image generation uses OpenAI or Google (Gemini).
Search and information
The configured search engine (DuckDuckGo by default) and Open-Meteo for weather.
Services you connect
Google (Gmail, Calendar, Contacts), LinkedIn, Facebook, Telegram, your email account, MCP servers added by the administrator and the websites ELY visits for your tasks.
Notifications
Notifications are delivered by your browser’s notification service (Google for Chrome on Android), or by Telegram if you have connected it.
These services process data under their own terms and privacy policies. Some are located outside the European Union. Review their policies before enabling them.
Security
ELY account passwords are stored as hashes (scrypt), never in plain text. The session relies on a token stored in a cookie that scripts cannot read. Sign-in attempts are rate-limited and an alert is sent after several failures. The interface runs no third-party scripts.
Traffic between the app and the instance must use an encrypted connection (HTTPS), for example with Tailscale or a reverse proxy. Setting it up is the administrator’s responsibility.
Vault credentials, connection tokens and other data are not encrypted by ELY on the server. Their protection depends on the server’s security: restricted access, updates, disk encryption and backups.
Retention
Data is kept on your instance until it is deleted by you or by the administrator. Images and screenshots in conversations are deleted automatically after 30 days. A sign-in session expires after one year at most.
Preferences saved on the device are kept until the app is uninstalled or its data is cleared. Data sent to third-party services is kept under their own rules.
The developer keeps no app data. Only the emails you send them are kept, for up to three years after the last exchange.
Deleting your data and account
From the app
You can delete your conversations, memories, skills, files, saved credentials, service connections and scheduled tasks.
Deleting your account
Ask your instance’s administrator to delete your account. They do so from ELY’s administration. Deletion permanently erases the account and all associated data: conversations, memories, files, browser profile, connections, notification subscriptions and usage history. The account is not merely deactivated.
If you administer your instance
You can delete accounts from the administration. To erase the entire instance, delete its data folder. Any backups you have made are your responsibility.
Other measures
Uninstalling the app erases the preferences saved on the device, but not the instance’s data. You can also revoke ELY’s access from the settings of your Google, LinkedIn or Facebook accounts.
The developer has no access to your instance and cannot delete your data themselves. They can, however, help you at contact@agent-ely.fr.
Your rights
Under the conditions set out in the GDPR, you have the rights of access, rectification, erasure, restriction, objection and data portability. For the data on your instance, exercise them with its administrator, who is responsible for it.
For any question about the app or this policy, write to contact@agent-ely.fr. You will receive a reply within one month.
You may lodge a complaint with the French data protection authority (CNIL) (website in French).
Intended audience
The app is intended for adults. It is not designed for children.
Updates to this policy
This policy may change along with the app. The date shown at the top of the page indicates the last update. The app terms of use supplement this policy.
A question? contact@agent-ely.fr