Privacy Policy

Last updated: July 31, 2026

Elumre is an estimation and proposal tool for software teams, operated by STA.SH Jakub Wilk, a sole proprietorship registered in Poland (“Elumre”, “we”, “us”). This policy explains what personal data we collect when you use Elumre, why we collect it, who we share it with, and the rights you have.

We keep it in plain language on purpose. If anything is unclear, write to us at hello@elumre.com.

Who is responsible for your data

The data controller is STA.SH Jakub Wilk, registered in Poland. For every question, request or complaint about your personal data, contact hello@elumre.com.

One important exception: when a team uses Elumre to build estimates and proposals that contain their own clients’ data, that team is the controller of the data and we process it on the team’s behalf — see Content processed on behalf of teams.

What this policy covers

This policy applies to:

  • the elumre.com website, including the documentation,
  • the Elumre application at app.elumre.com and its API at api.elumre.com, including access by AI agents over MCP,
  • public proposal pages shared through Elumre, including proposals served on a team’s own domain,
  • emails we send as part of the service.

Data we collect

Account data. Your name, email address, password and optional profile picture. Passwords are stored only as salted hashes — we cannot read them. If you sign in with Google, we receive your name, email address and profile picture from your Google account; we never see your Google password.

Team data. Team name, who its members are and their roles, and pending invitations (the invited person’s email address).

Content you create. Estimates, modules and line items, rate cards and rates, comments, uploaded files such as logos and attachments, and branding settings. This content may include personal data you choose to put into it.

Billing data. Payments are handled by Polar, our merchant of record. We store your team’s subscription details — plan, status, number of seats and billing identifiers. Full payment card details never reach our servers.

Proposal activity. For proposals shared publicly: which scope options a visitor selects, comments (with the display name the commenter chooses to provide), acceptance of the proposal, and engagement events (proposal opened, sections read) linked to a random identifier stored in the visitor’s browser.

Usage data. How the product is used — pages and features visited, interactions and application errors — collected with PostHog, our product analytics tool. Analytics identities are created only for signed-in users, and only if you consent to analytics.

Website analytics. Visits to elumre.com, measured with Google Analytics — only if you consent to analytics cookies.

Technical data. IP address, browser and device information, and timestamps recorded in server and security logs.

Correspondence. Messages you send to hello@elumre.com.

Why we process it

PurposeLegal basis (GDPR)
Providing the service — accounts, teams, estimates, proposalsPerformance of a contract — Art. 6(1)(b)
Billing and subscription managementPerformance of a contract — Art. 6(1)(b); legal obligations (tax) — Art. 6(1)(c)
Transactional email — verification, password reset, invitations, proposal notificationsPerformance of a contract — Art. 6(1)(b)
Security, abuse prevention and server logsLegitimate interest — Art. 6(1)(f): keeping the service secure and reliable
Product and website analyticsConsent — Art. 6(1)(a), given through the cookie prompt and withdrawable any time
Answering your messagesLegitimate interest — Art. 6(1)(f)
Establishing or defending legal claimsLegitimate interest — Art. 6(1)(f)

Content processed on behalf of teams

Estimates and proposals often contain personal data of a team’s own clients — names, email addresses, project details. The same applies to proposal activity: comments, scope selections and engagement events. For that data, the team that created the estimate is the data controller, and we act as their processor: we store and display the data on the team’s instructions and do not use it for our own purposes.

If you received a proposal through Elumre and want data about you corrected or removed, the fastest route is the team that sent it. You can also write to us and we will assist or pass your request on.

Data Processing Agreement

If your team processes its clients’ personal data through Elumre, our Data Processing Agreement — GDPR Article 28 terms covering our role as your processor, including the list of subprocessors — applies automatically. A countersigned copy is available on request at hello@elumre.com.

Who we share data with

We use a small set of service providers to run Elumre. We never sell personal data, and we do not share it with advertisers or data brokers.

ProviderWhat they doWhere
Hetzner Online GmbHCloud infrastructure — application servers, database, file storageGermany / Finland (EU)
Cloudflare, Inc.Serving and protecting the elumre.com websiteGlobal edge network; US company
Google (Google Ireland Ltd. / Google LLC)“Sign in with Google”; Google Analytics on elumre.comEU / US
PostHog, Inc.Product analyticsData stored in the EU; US company
Polar Software, Inc.Payments, subscriptions, invoicing and tax, as merchant of recordUS
Resend, Inc.Delivering transactional emailUS

Polar sells our subscriptions as merchant of record: it is responsible for processing payments, issuing invoices and handling applicable tax on purchases, and it processes payment data under its own privacy policy.

Beyond these providers, we disclose personal data only if we are legally required to (for example, by a valid court order).

International transfers

Elumre’s application data is hosted in the EU (Hetzner), and product analytics are stored in the EU (PostHog’s EU cloud). Some of our providers are US companies or operate globally, so certain data may be processed outside the European Economic Area. Where that happens, transfers are protected by European Commission adequacy decisions — including the EU–US Data Privacy Framework for certified providers — and/or Standard Contractual Clauses.

How long we keep data

  • Account, team data and content — for as long as the account or team exists. After deletion, data is removed or anonymized within 30 days, and residual copies expire from backups within a further 30 days.
  • Billing records — as long as tax and accounting law requires; in Poland, generally 5 years from the end of the relevant tax year.
  • Server logs — up to 30 days.
  • Product analytics — deleted together with the account they relate to, and at the latest 24 months after your last activity.
  • Website analytics — up to 14 months.
  • Correspondence — up to 3 years after the matter is closed.
  • Proposal activity — follows the proposal it belongs to and is deleted with it.

Your rights

Under the GDPR you can:

  • access your data and get a copy of it, in a portable format,
  • correct inaccurate data,
  • delete your data (“right to be forgotten”),
  • restrict or object to processing based on our legitimate interests,
  • withdraw consent at any time, without affecting processing that already happened.

We voluntarily extend these rights to every user, wherever you live. To exercise them, email hello@elumre.com — we may need to verify your identity, and we respond within one month.

If you believe we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl), or with your local supervisory authority in the EEA.

Security

All traffic to Elumre is encrypted in transit (TLS). Passwords are stored only as salted hashes. Access rules are enforced on the server for every request, application data lives in EU data centers, and production access is limited to what operating the service requires. No online service can promise absolute security — but if a breach ever affects your data, we will notify you and the authorities as the law requires.

Cookies

We use a small set of first-party cookies and browser storage — see the Cookie Policy for the full list and your choices.

Children

Elumre is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

Automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

Changes to this policy

When we change this policy, we update the date at the top. If a change meaningfully affects your rights, we will announce it in the app or by email before it takes effect.

Contact

STA.SH Jakub Wilk — hello@elumre.com