Privacy Policy
Last updated: July 31, 2026
Elumre is an estimation and proposal tool for software teams, operated by STA.SH Jakub Wilk, a sole proprietorship registered in Poland (“Elumre”, “we”, “us”). This policy explains what personal data we collect when you use Elumre, why we collect it, who we share it with, and the rights you have.
We keep it in plain language on purpose. If anything is unclear, write to us at hello@elumre.com.
Who is responsible for your data
The data controller is STA.SH Jakub Wilk, registered in Poland. For every question, request or complaint about your personal data, contact hello@elumre.com.
One important exception: when a team uses Elumre to build estimates and proposals that contain their own clients’ data, that team is the controller of the data and we process it on the team’s behalf — see Content processed on behalf of teams.
What this policy covers
This policy applies to:
- the elumre.com website, including the documentation,
- the Elumre application at app.elumre.com and its API at api.elumre.com, including access by AI agents over MCP,
- public proposal pages shared through Elumre, including proposals served on a team’s own domain,
- emails we send as part of the service.
Data we collect
Account data. Your name, email address, password and optional profile picture. Passwords are stored only as salted hashes — we cannot read them. If you sign in with Google, we receive your name, email address and profile picture from your Google account; we never see your Google password.
Team data. Team name, who its members are and their roles, and pending invitations (the invited person’s email address).
Content you create. Estimates, modules and line items, rate cards and rates, comments, uploaded files such as logos and attachments, and branding settings. This content may include personal data you choose to put into it.
Billing data. Payments are handled by Polar, our merchant of record. We store your team’s subscription details — plan, status, number of seats and billing identifiers. Full payment card details never reach our servers.
Proposal activity. For proposals shared publicly: which scope options a visitor selects, comments (with the display name the commenter chooses to provide), acceptance of the proposal, and engagement events (proposal opened, sections read) linked to a random identifier stored in the visitor’s browser.
Usage data. How the product is used — pages and features visited, interactions and application errors — collected with PostHog, our product analytics tool. Analytics identities are created only for signed-in users, and only if you consent to analytics.
Website analytics. Visits to elumre.com, measured with Google Analytics — only if you consent to analytics cookies.
Technical data. IP address, browser and device information, and timestamps recorded in server and security logs.
Correspondence. Messages you send to hello@elumre.com.
Why we process it
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service — accounts, teams, estimates, proposals | Performance of a contract — Art. 6(1)(b) |
| Billing and subscription management | Performance of a contract — Art. 6(1)(b); legal obligations (tax) — Art. 6(1)(c) |
| Transactional email — verification, password reset, invitations, proposal notifications | Performance of a contract — Art. 6(1)(b) |
| Security, abuse prevention and server logs | Legitimate interest — Art. 6(1)(f): keeping the service secure and reliable |
| Product and website analytics | Consent — Art. 6(1)(a), given through the cookie prompt and withdrawable any time |
| Answering your messages | Legitimate interest — Art. 6(1)(f) |
| Establishing or defending legal claims | Legitimate interest — Art. 6(1)(f) |
Content processed on behalf of teams
Estimates and proposals often contain personal data of a team’s own clients — names, email addresses, project details. The same applies to proposal activity: comments, scope selections and engagement events. For that data, the team that created the estimate is the data controller, and we act as their processor: we store and display the data on the team’s instructions and do not use it for our own purposes.
If you received a proposal through Elumre and want data about you corrected or removed, the fastest route is the team that sent it. You can also write to us and we will assist or pass your request on.
Data Processing Agreement
If your team processes its clients’ personal data through Elumre, our Data Processing Agreement — GDPR Article 28 terms covering our role as your processor, including the list of subprocessors — applies automatically. A countersigned copy is available on request at hello@elumre.com.
Who we share data with
We use a small set of service providers to run Elumre. We never sell personal data, and we do not share it with advertisers or data brokers.
| Provider | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure — application servers, database, file storage | Germany / Finland (EU) |
| Cloudflare, Inc. | Serving and protecting the elumre.com website | Global edge network; US company |
| Google (Google Ireland Ltd. / Google LLC) | “Sign in with Google”; Google Analytics on elumre.com | EU / US |
| PostHog, Inc. | Product analytics | Data stored in the EU; US company |
| Polar Software, Inc. | Payments, subscriptions, invoicing and tax, as merchant of record | US |
| Resend, Inc. | Delivering transactional email | US |
Polar sells our subscriptions as merchant of record: it is responsible for processing payments, issuing invoices and handling applicable tax on purchases, and it processes payment data under its own privacy policy.
Beyond these providers, we disclose personal data only if we are legally required to (for example, by a valid court order).
International transfers
Elumre’s application data is hosted in the EU (Hetzner), and product analytics are stored in the EU (PostHog’s EU cloud). Some of our providers are US companies or operate globally, so certain data may be processed outside the European Economic Area. Where that happens, transfers are protected by European Commission adequacy decisions — including the EU–US Data Privacy Framework for certified providers — and/or Standard Contractual Clauses.
How long we keep data
- Account, team data and content — for as long as the account or team exists. After deletion, data is removed or anonymized within 30 days, and residual copies expire from backups within a further 30 days.
- Billing records — as long as tax and accounting law requires; in Poland, generally 5 years from the end of the relevant tax year.
- Server logs — up to 30 days.
- Product analytics — deleted together with the account they relate to, and at the latest 24 months after your last activity.
- Website analytics — up to 14 months.
- Correspondence — up to 3 years after the matter is closed.
- Proposal activity — follows the proposal it belongs to and is deleted with it.
Your rights
Under the GDPR you can:
- access your data and get a copy of it, in a portable format,
- correct inaccurate data,
- delete your data (“right to be forgotten”),
- restrict or object to processing based on our legitimate interests,
- withdraw consent at any time, without affecting processing that already happened.
We voluntarily extend these rights to every user, wherever you live. To exercise them, email hello@elumre.com — we may need to verify your identity, and we respond within one month.
If you believe we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl), or with your local supervisory authority in the EEA.
Security
All traffic to Elumre is encrypted in transit (TLS). Passwords are stored only as salted hashes. Access rules are enforced on the server for every request, application data lives in EU data centers, and production access is limited to what operating the service requires. No online service can promise absolute security — but if a breach ever affects your data, we will notify you and the authorities as the law requires.
Cookies
We use a small set of first-party cookies and browser storage — see the Cookie Policy for the full list and your choices.
Children
Elumre is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Changes to this policy
When we change this policy, we update the date at the top. If a change meaningfully affects your rights, we will announce it in the app or by email before it takes effect.
Contact
STA.SH Jakub Wilk — hello@elumre.com