Skip to content

Privacy and legal

Privacy and GDPR

What Elyv stores about you, for how long, who processes it, and how to use your rights.

In short

What is stored about you

DataWhyHow long
Username and hashed passwordTo sign you inUntil the account is deleted
IP address of the latest sign inSecurity and abuse preventionReplaced at each sign in
Sessions, stored as a hashTo keep you signed in30 days of inactivity, 90 days at most
Law enforcement request, only if you send one: sector, organisation, role, country, work email, purposeTo verify the agencyWhile the account exists
Plan, quota usage and payment ordersTo provide what you paid forFor accounting, while the account exists
Search history with its resultsSo you can reopen a search30 or 90 days by plan, never for Incognito
Link analysis casesYour own boardsUntil you delete them
Profile photoShown in your dashboardUntil you remove it

Who else processes data

ServiceRole
CloudflareNetwork, security and the sign up check in front of the site.
The breach index providerReceives the identifier of a search to check it against breach data.
LeakOsintReceives the identifier of an Advanced Search.
Public sources of each moduleReceive the identifier you look up, as any lookup requires.
MapboxDraws maps and locates addresses shown in results.

Your rights and how to use them

Under the GDPR you can ask to access, correct, delete, export or restrict your data, and object to its processing.

  • Delete searches yourself in History, one by one or all at once.
  • Download a JSON copy of everything stored about your account in Account, Your data. It asks for your two-factor code.
  • Ask for your account to be deleted in Account, Your data, confirmed with your two-factor code. Once the Elyv team approves it, the account is erased with your searches, cases, watchlist and API keys. Remaining plan time is not reimbursed.
  • Export single results as PDF, CSV, JSON or text, and History as CSV.
  • Remove your profile photo and sign out other devices from Account.
  • For any other request, contact support from your account name. The GDPR sets one month to answer.
  • If you are not satisfied, you can complain to your data protection authority, the CNIL in France.

Cookies and browser storage

Elyv sets one cookie, the session that keeps you signed in. It is HttpOnly and Secure. Your theme, navigation position, starred modules and result tags are kept in the local storage of your browser and never leave your device.

If you are the person searched

Elyv shows what public sources and published breach catalogues already say, and does not keep its own copy of that data. To have something removed, ask the site that publishes it. For misuse of Elyv against you, contact support and read Responsible use.

How your data is protected

  • Every page is served over HTTPS with strict transport security.
  • Passwords and sessions are stored as hashes, never in clear.
  • A strict content security policy limits what can run on the site.
  • Admins never create sessions on user accounts.

Where to go next

Still stuck? Contact support with your username and what happened.