Privacy Policy
Last updated: April 6, 2026
Elyxia ("we", "us", "our") operates the elyxia.ai website. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
1. Information We Collect
Account Information
When you create an account: email address, display name, and hashed password.
Usage Data
Chat messages you send and receive, AI-generated images and media, conversation metadata (timestamps, message counts), and anonymous analytics data (page views, feature usage).
Technical Data
IP address (stored as a one-way hash — we cannot reverse it to your real IP), browser user agent, and session cookies for authentication.
Anonymous Users
If you use the Service without an account, we assign a random session identifier stored in your browser. We do not collect personally identifiable information from anonymous users.
2. How We Use Your Data
- Provide and operate the AI chat service
- Generate AI images and media based on your interactions
- Maintain conversation history and relationship state
- Enforce rate limits and prevent abuse
- Improve the Service through anonymous, aggregated analytics
- Send notifications you have opted into (push notifications)
3. Third-Party Services
We use third-party AI services to generate text responses and images. Your chat messages and image prompts are sent to these providers for processing. These providers process data according to their own privacy policies.
We use a self-hosted analytics tool to understand how the Service is used. Analytics data is aggregated and does not include personal information or chat content.
4. Cookies and Local Storage
We use:
- Session cookies — to keep you logged in (httpOnly, secure)
- Age verification — stored in your browser to remember your 18+ confirmation
- User preferences — persona settings stored locally in your browser
- Analytics cookies — anonymous usage tracking (no personal data)
5. Data Retention
Account data and conversation history are retained for as long as your account is active. Anonymous session data is retained for up to 90 days of inactivity. You may request deletion of your data at any time (see Section 7).
6. Data Security
Passwords are cryptographically hashed and never stored in plaintext. IP addresses are stored as irreversible hashes. Sessions are protected with secure, httpOnly cookies. We implement rate limiting to prevent abuse.
While we take reasonable measures to protect your data, no method of transmission over the Internet is 100% secure.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request deletion of your account and associated data
- Opt out of analytics tracking
- Export your conversation data
To exercise these rights, contact us at privacy@elyxia.ai
8. Age Restriction
The Service is intended for users aged 18 and older. We do not knowingly collect data from individuals under 18. If we become aware that we have collected personal information from a minor, we will delete it immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the Service constitutes acceptance of the updated policy.
10. Contact
For privacy-related questions, contact us at privacy@elyxia.ai