Privacy policy
Erlyc — AI-assisted application design and code generation platform
Last updated: September 22, 2026 · Version: 1.6
Data controller: EXELLECT SAS
Address: 30 bis, rue du Vieil Abreuvoir, 78100 Saint-Germain-en-Laye, France
Email: [email protected]
Data Protection Officer: [email protected]
EXELLECT SAS is committed to protecting and respecting your privacy. This policy explains how personal data is processed on Erlyc. By using Erlyc, you accept the practices described here, and you confirm that you have reached the legal age required in your country of residence or obtained authorization from your parents or legal guardians.
1. Information we collect
Information you provide
- Account data: your name, email address and password (stored hashed, never in clear text), and the date you accepted the terms of service.
- Project content: the ideas, board answers, specifications, diagrams, questions and generated code produced in your projects.
- Community content: showcase publications, comments, ratings, likes and forum posts, associated with your account name.
- Support requests: tickets and messages you send to support.
- Waitlist requests: if you ask for access from the landing page while Erlyc is invite-only, we store the email address you submit, optionally your name and a short description of what you would build, the date you gave consent, and a one-way hash of your IP address used solely to detect automated abuse of the form. The legal basis is your consent, given by ticking the box on the form. This data is used only to contact you about access — never for marketing — and you can ask us to delete it at any time at [email protected].
Information collected automatically
- Technical data: IP address, browser type, operating system, session information.
- Usage statistics: which pages are viewed and for how long, recorded against a random identifier stored in your browser (see Cookies below). This identifier is not derived from your IP address or browser details — neither is stored with it — and it never follows you to other sites. For signed-in users the page view is linked to the account solely to distinguish registered usage from guest usage.
- AI processing records: each AI call stores what was sent and received, for debugging and billing (see Retention below).
- Security screening logs: when the prompt-injection filter flags an input, a short excerpt of the flagged text is recorded with your account, to review false positives and abuse.
- Billing records: your credit balance, credit grants and credit transactions.
Information from other sources
Payments: purchases and subscriptions are processed by Stripe (Stripe Payments Europe, Ltd.) on its own hosted checkout pages. No payment-card data is ever collected, transmitted or stored by the platform — it stores only the references Stripe returns (customer, subscription and payment identifiers) together with the Account's purchase history. There is no third-party login.
2. How we use your information
- Providing the services: managing your account, projects, boards, specifications and generated code (performance of the contract).
- AI processing: sending your project content to third-party language models to produce boards, specifications and code (performance of the contract) — details in section 3.
- Billing: metering AI usage in credits and keeping the corresponding ledger (performance of the contract, legal obligations).
- Security: screening inputs against prompt-injection attacks, preventing fraud and abuse (legitimate interest).
- Community: operating the showcase and forum according to your sharing choices.
- Support: answering your tickets and forum questions.
- Improvement and learning: analyzing aggregate usage, and the decisions, corrections and design patterns recorded in your projects, to improve Erlyc's questions, suggestions, reference patterns and generated output, and to build internal test and evaluation datasets (legitimate interest). Material derived from your projects and reused outside them is anonymized and carries no link to you, your account or your project. You may object to this reuse at any time at [email protected].
- Important notices: informing you of substantial changes to the service or these documents.
Erlyc does not send marketing communications; if a newsletter is introduced later, it will be opt-in with the ability to unsubscribe at any time.
3. Sharing your information
Service providers (processors)
- Hosting: Hostinger International Ltd — secure servers in the European Union.
- Payments: Stripe Payments Europe, Ltd. (Ireland) — operates the hosted checkout and processes card payments; the platform never sees card data.
- AI routing: OpenRouter, Inc. (United States), which routes AI requests to third-party model providers and to the inference operators that serve them. Your content is processed to produce responses. Provider data practices differ, and which provider handles a request follows from your plan and your project's model selection: for models routed under our restricted-privacy policy, Erlyc instructs OpenRouter to exclude endpoints that use API content to train their own models; for other models that exclusion does not apply, and a provider may use content submitted through its API to improve its own models. The model and the provider that served each AI action are recorded in your AI processing records.
- Code publication (opt-in): GitHub, Inc. (United States) — when you choose to publish your generated code as a public repository under the Erlyc organization, that code and the repository metadata are hosted by GitHub under its own terms.
There are no advertising networks, no analytics processors and no data brokers. We never sell your personal data.
Community sharing (according to your choices)
- Publishing a project to the showcase makes the selected snapshot publicly visible; you can remove it at any time.
- Your forum posts, comments and ratings are visible to other users and associated with your account name.
- Optionally deploying a generated application to the Erlyc test server places it at a public address for approximately 72 hours, after which it is wiped automatically.
- Optionally publishing your generated code to GitHub makes it a public repository; unpublishing archives it (still publicly visible) and you can have it deleted at any time — copies and forks made by others while it was public cannot be recalled.
Legal obligations
We disclose personal information if required by law or court order, to protect our rights or those of other users, or in case of sale or transfer of EXELLECT SAS (with prior information).
4. Storage, security and international transfers
- Location: platform data is stored on secure Hostinger servers in the European Union.
- Security: hashed passwords, encrypted transport, firewalled servers, controlled access, regular backups.
- International transfers: AI processing via OpenRouter and the model providers it routes to, and opt-in code publication via GitHub, may take place outside the European Union — in the United States and in other countries where those providers operate. Which countries are involved depends on the model used for your project. Erlyc relies on the safeguards available for each provider (EU–US Data Privacy Framework certification and/or standard contractual clauses); the provider that served each AI action is recorded in your AI processing records.
- Your password: you are responsible for its confidentiality — choose a strong password and do not share it. Two-factor authentication is available in Settings → Security.
5. Retention
- Account and project data: kept for as long as your account exists. Account deletion (Settings → Profile) is immediate and permanent: it deletes your projects and their data, showcase entries, community posts, support tickets, credit history, AI processing records and security-log entries. Deleted data cannot be recovered. Anonymized material already derived from your projects and reused elsewhere, which carries no link to you, your account or your project, is not affected — see Improvement and learning in section 2.
- AI processing records: the verbatim content of what was sent and received is pruned after 30 days; aggregate billing metadata (token counts, cost, credits) and the model and provider used are kept for accounting while the account exists. Anonymized material derived under Improvement and learning, once it carries no link to you or your project, is kept independently of this window and of account deletion.
- Security screening excerpts: flagged-text excerpts are pruned after 30 days; anonymous aggregates are kept.
- Usage statistics: raw page-view records are deleted after 90 days (and immediately with your account); beyond that, only anonymous daily aggregates with no identifiers of any kind are kept.
- Seed library: demo values from your projects are only reused elsewhere after human administrator approval, at which point they are kept anonymized, without any link to you or your project; unreviewed values are deleted with the project or account.
- Waitlist requests: deleted automatically 12 months after they are submitted if no invitation follows. If a request leads to an account, the entry is kept for as long as that account exists, as the record of how it was created.
- Accounting records for manually settled purchases (invoices, bank transfers) are kept outside the platform for the statutory retention periods.
6. Your rights
In accordance with the GDPR and French law, you have the right to:
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate data (name and email are directly editable in Settings → Profile)
- Erasure — delete your account and data yourself in Settings → Profile, or request deletion
- Portability — retrieve your data in a standard format (specifications and generated code are directly downloadable; other data on request)
- Restriction and objection — restrict or object to processing based on our legitimate interest
- Withdrawal of consent — at any time, for processing based on consent
How to exercise them: [email protected] or the in-app support page. Response within 1 month maximum; proof of identity may be requested.
7. Protection of minors
Erlyc does not intentionally collect age information. In France, the digital consent age is 15. If we learn that a user is under that age, we require joint consent from the minor and their parents, special protections apply, and parents can exercise the rights above on behalf of their child. Contact: [email protected].
8. Cookies
Erlyc uses only the cookies required to operate the site: a session cookie, a CSRF token and, if you choose "remember me", an authentication cookie. There are no advertising or analytics cookies and no third-party trackers.
For audience measurement, Erlyc stores a single random identifier in your browser's local storage. It is strictly first-party and serves exclusively to count unique visitors and time spent on Erlyc itself; it involves no advertising, no cross-site tracking and no sharing with third parties, and the resulting statistics are aggregate only — the conditions under which the CNIL exempts audience measurement from consent, which is why there is no consent banner. You can remove the identifier at any time by clearing your browser's site data.
9. Automated decision-making
- Prompt-injection screening: inputs bound for the AI pipeline are automatically screened; a flagged input can be blocked. You can contest any blocking via the support page — a human reviews it.
- Community moderation: new forum content is first reviewed by an AI moderator; removals can be contested and are reviewed by a human moderation queue.
- There is no profiling for advertising and no automated decision producing legal effects about you.
10. Changes to this policy
We may modify this policy to reflect the evolution of our services, legal changes or improved practices. Important modifications are notified by email and an in-app banner 30 days in advance; minor modifications are published on this page. If you disagree with a change, you can delete your account before it takes effect.
11. Complaints and supervisory authority
Before any external complaint, contact us: [email protected] (DPO: [email protected]).
If you are not satisfied with our response, you can file a complaint with:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
www.cnil.fr · www.cnil.fr/plaintes · Phone: 01 53 73 22 22
Summary of your rights
✓ Access: see what data we have about you
✓ Rectification: correct inaccurate information
✓ Erasure: delete your account and data yourself, immediately
✓ Portability: download your specifications and code; other data on request
✓ Objection / restriction: object to or restrict certain processing
✓ Withdrawal: withdraw consent at any time
✓ Complaint: file a complaint with the CNIL
Quick contact: [email protected] — response within 1 month maximum.
This policy is effective from July 30, 2026 and applies to all users of Erlyc, operated by EXELLECT SAS in accordance with French and European data protection law.