Privacy Policy
Last updated 29 September 2026
Who we are
Eligna is a personal life coordination app that helps you follow through on your goals, habits, and daily life. It is operated by TRANSLOGISTIKA ES Ltd (“Eligna”, “we”, “us”). This policy explains what we collect, why, who else is involved, and what control you have. It should be read together with our Terms and Conditions, our Cookie Policy and our Acceptable Use Policy. Our full company details are at the end of this policy.
Questions or requests: privacy@eligna.app.
Who can use Eligna
Eligna is for adults. You must be at least 18 to use the Service, and this policy is written on that basis. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.
What we collect
- Account: your email address and display name.
- Your personal content: habits, goals, tasks, journal entries, contacts, and personal finance records you create.
- Household content: chores, shopping lists, meals, plants, household finance records, and admin notes you create or contribute to as part of a household.
- Subscription and billing data: the plan you choose, your subscription and trial status, and, for purchases made on the web, billing information processed by Stripe (we do not store your full card number). If you add a card during a free trial, Stripe keeps it and takes the first payment on the day the trial ends; nothing is charged before then. For purchases made through the Apple App Store or Google Play, Apple or Google process your payment and we receive confirmation of your subscription status, not your card details.
- Referral data: if you take part in a referral programme, your referral code and records of referrals and rewards.
- Receipt images: if you scan a shopping or bill receipt, we store the photo, and our AI provider reads it so we can show you the items and total. Receipts can be payment-adjacent, in that they may show what you bought and the amount. Only the last 10 per household are kept (see Keeping and deleting your data).
- Plant photos: if you scan a plant to check on it, our AI provider reads the photo, and it becomes that plant’s picture in your household.
- Device tokens: if you enable push notifications, a token used to deliver them.
- Support requests: if you contact us through the support form, the topic you choose, your message, and the email address to reply to.
- Feedback card: from time to time Eligna asks, in a short pop-up, one question about what got in your way. If you answer, your answer reaches us as a support request, with your name, email, your household’s name and number of members, and, if you are on a free trial, which day of it you are on, so we can understand the answer in context.
- Feedback on AI replies: if you use the “Give feedback” link under the AI chat, your message reaches us as a support request, and we include a reference to the conversation it came from so we can look into what went wrong. The reference is an identifier for the conversation, not a copy of it. Your conversations are saved to your account (see below), but we do not open one unless your message asks us to look into it.
- AI credit counts: how many AI credits you use each month, counted by kind of task (chat, photo scans, insights, journal summaries), to apply your plan’s allowance and to show you where your credits went.
- Analytics and diagnostics: if you consent, product-usage events and (optionally) session replays. Error diagnostics are collected regardless of consent, and are minimised. See the sections below.
Special category data
Eligna has no dedicated fields for special category data (sometimes called sensitive data), such as health, religious or philosophical beliefs, and we do not ask you for it. However, some features are free text, notably the journal, and also AI chat, habits and goals, so you may choose to write things that touch on your health, mood or beliefs. We recognise that reflective free-text content like this can amount to special category data even though there is no field for it.
Where you enter such content, it is user-generated and stored as part of your normal personal data. We do not use it to profile you or to make automated decisions about you, and we do not share it with anyone else in your household.
Storing what you write is covered by your contract with us: it is the service doing the thing you asked it to do. What needs more than that is letting our AI assistant read your journal entries and summarise them, because that sends special category data to a third party and creates new information about you. We rely on your explicit consent under Article 9(2)(a) of the UK and EU GDPR for that, and we obtain it properly rather than inferring it:
- It is off by default. Until you turn it on, the assistant does not read your journal, and knows only how many entries you have and how recently you wrote.
- When it is on, the assistant reads each new or edited entry once, writes a summary of two or three sentences, and saves it with that entry. You can read, edit or delete any summary. In conversations the assistant uses the summaries, never the full entries.
- Turning it on requires a separate, affirmative confirmation in the app, on its own, not bundled into accepting these policies or the Terms. The confirmation tells you what is shared, who it goes to, and that you can change your mind.
- We record that consent: the exact wording you were shown, its version, where you gave it, and when. That is how we can show the consent was informed rather than assumed.
- You can withdraw it at any time in Profile, in one tap, and it takes effect immediately. Withdrawing deletes every summary the assistant has written and stops it reading your entries. It does not delete any of your entries.
The same care applies to the statement about who you are that you can write in Profile (see AI context below). If that statement looks as though it mentions your health, beliefs, relationships or other special category information, the assistant does not receive it unless you have switched on Remember sensitive details. That switch is its own explicit consent under Article 9(2)(a), separate from journal insights, given and recorded in the same way, and you can withdraw it at any time in one tap.
You can edit or delete this content at any time, and deleting your account removes it.
How we use your data, and our lawful bases
- To provide the Service (run the app, sync your data across devices, operate Households): to perform our contract with you.
- To personalise the AI assistant with context relevant to you: to perform our contract, and, for reading your journal entries and using their summaries, or for sending a statement about yourself that mentions special category information, on your separate explicit consent.
- To take payment and manage subscriptions, trials and referrals: to perform our contract and to comply with legal (including tax and accounting) obligations.
- To send push notifications you have enabled, and to send you service, security and billing emails: to perform our contract; push notifications rely on your consent, which you can withdraw at any time in the app’s notification settings, or in your device or browser settings.
- To send you marketing emails (product news, tips and offers), only if you have turned this on: on your consent. It is off unless you switch it on in Account and Preferences, it is separate from the service, security and billing emails above (which you receive regardless because they are not marketing), and you can opt out at any time in the same place, which takes effect immediately. We keep a dated record of the wording you agreed to.
- To keep the app reliable and secure: for our legitimate interests in running a secure, working service.
Improving Eligna
We look at how Eligna is used so we can decide what to build and fix next. This is an ongoing part of how we develop the product. Where this uses product analytics or session replay, it runs only if you have turned it on (see the next section), and we rely on your consent. Where we look at usage in an aggregated or de-identified way, or use minimised diagnostics to understand reliability, we rely on our legitimate interest in improving the Service. We do not use this to advertise to you or to make automated decisions about you, and you can object to legitimate-interest processing at any time.
Analytics, session replay, and error monitoring: you are in control
Analytics and session replay are off until you switch them on, and you can change your mind at any time in Cookie preferences. We keep what is collected to a minimum, we do not use advertising or cross-site tracking, and we do not sell your data.
- Product analytics (your choice, off by default): if you turn it on, we record which pages and features are used, through PostHog (stored in the EU), so we know what to improve. To group activity into a session, this includes a device or session identifier and your account id and email. Nothing runs until you turn it on, and declining does not change how the app works.
- Session replay (a separate choice, off by default): if you turn it on, we capture a recording of how the interface responds while you use it, so we can find confusing screens and bugs. It can only be enabled if analytics is also enabled. Your text, form fields and photos are masked before anything leaves your device. It uses PostHog (EU) and Sentry (US) and stops as soon as you turn it off. We keep these recordings for a limited time, set out under Keeping and deleting your data below.
- Error monitoring (always on, kept minimal): when something crashes, a small technical error report is sent to Sentry so we can fix it. This keeps the app reliable and secure, and runs on that legitimate-interest basis rather than consent. It is deliberately minimal: no IP address, and no record of your clicks, typing, or the details in page addresses. You can object by contacting us.
Before you create an account. If you accept analytics, we collect anonymous product-usage and page-view events through PostHog. These are not linked to your identity. They are associated only with a temporary device identifier, never your name or email. If you go on to create an account, we connect this activity to your account. If you never create an account, these events stay anonymous and cannot be traced back to you.
Who processes your data
We use a small set of service providers to run Eligna. Each only receives what it needs for its job.
- Supabase: our database, sign-in, file storage, and backend. Receives your account and all app content. Location: European Union (Frankfurt, Germany).
- Google Cloud (Vertex AI): runs the AI assistant for us. Receives, when you use AI: your name, your message, recent chat history, a summary of your goals, habits, tasks, and household, your statement about who you are if you have written one, and the photos you ask it to read (receipts, bills and plant photos); and, only if you have switched on journal insights, the words of new or edited journal entries (to write their summaries) and those summaries. Location: European Union (Belgium). Google keeps the request and the reply for up to 30 days to check for abuse of the service, then deletes them, unless a safety investigation or the law requires otherwise. Google does not use this data to train its models. The model itself, Claude Haiku 4.5, is built by Anthropic, but your messages go to Google rather than to Anthropic, so Anthropic is not a processor of your data.
- PostHog: product analytics and session replay (only if you consent). Receives usage events, page views, and your account id and email as an identifier. Location: European Union (EU cloud).
- Sentry: error monitoring, and session replay (only if you consent). Receives crash and error reports; session replays only with your consent. Location: United States (data stored in Sentry’s US region, even though received through an EU endpoint).
- Stripe: handles payments when you subscribe on the web. Receives your payment details, email, and name. Location: United States.
- Google (Firebase Cloud Messaging): delivers push notifications to your devices and browser, if you enable them. Receives your device token and the content of each notification (for example a chat preview or a reminder title). Location: United States / global, under Standard Contractual Clauses in the Google Cloud Data Processing Addendum.
- Resend: sends transactional email (receipts, password resets, service and billing notices, and household invites you send). Receives the recipient email address and the message content. Location: United States.
- Brevo (Sendinblue SAS): sends marketing email, and only if you have asked for it. Receives your email address and whether you are opted in, and nothing else. Location: European Union (core infrastructure in France and Belgium). Brevo uses its own providers outside the EU, covered by Standard Contractual Clauses and the EU-US Data Privacy Framework. Marketing email is entirely separate from the service email above: turning it off never affects receipts, security or account messages.
- Cloudflare: runs the anti-bot check (Turnstile) on sign-in and sign-up. Receives your IP address and interaction signals, to tell humans from bots. Location: United States / global.
- Vercel: hosts the app and runs our server functions. Receives standard request data (IP address, browser headers). Location: European Union (Frankfurt, Germany). Vercel is a US-headquartered provider, so any access from outside the EU is covered by Standard Contractual Clauses.
- Apple and Google: where you subscribe through the App Store or Google Play, they process your payment and manage the subscription under their own privacy policies.
AI context and our AI provider
The Eligna AI assistant is powered by Claude Haiku 4.5, a model built by Anthropic and run for us by Google Cloud (Vertex AI) on servers in the European Union. When you send a message, we send it your name and message, your recent conversation (the last exchange in full, and short notes on up to 20 exchanges before it), and a summary of your active goals, habits, pending tasks, and household overview.
If you have switched on journal insights in Profile, the assistant reads new or edited journal entries once to write a short summary of each, and uses those summaries, never the full entries, in your conversations. Without it, the assistant knows only how many journal entries you have and how recently you wrote.
If you write a statement about who you are, Eligna’s assistant receives it with your messages so its suggestions fit you. You can stop this at any time with ‘Remember things about me’ in Profile. A statement that mentions your health, beliefs, relationships or other special category information is not sent unless you have turned on ‘Remember sensitive details’.
If you speak to the assistant instead of typing, your device’s or browser’s own speech recognition (for example Apple’s or Google’s) turns your voice into text under its provider’s terms. Eligna receives only the text.
Other household members’ personal data is never included. Your conversations are saved to your account on every plan, as described below. Neither Google nor Anthropic uses this data to train their models. Google keeps the request and the reply for up to 30 days so it can check for abuse of the service, after which they are deleted, unless they are needed for a safety investigation or the law requires them to be kept. We tell you which kinds of content are AI-generated rather than labelling each item: the assistant announces itself, and the AI disclosure page names the classes (illustrations, meal and plant imagery, generated suggestions). See our Terms and the AI disclosure page.
Your conversations with the assistant are saved to your Eligna account, so they follow you to any device you sign in on. They are stored in the European Union (Supabase, Frankfurt), and only you can see them; other members of your household cannot. Each conversation is deleted automatically 12 months after its last message. You can delete any conversation sooner from the chat history, and deleting your account deletes them all. Two things are recorded on our side: how many AI credits you use each month and on what kind of task, to apply your plan’s allowance, and, if you send feedback about a reply, a reference to the conversation you were in. The chat carries a standing note that you are talking to an AI and that it can be wrong, because you are entitled to know which of the two you are dealing with.
Household data and other members
If you are part of a household, other members can see shared data: chores, shopping lists, meals, plants, household finance records, and admin notes. Your personal data (habits, goals, tasks, journal, personal finance) is always private and is never visible to other members. If you enter data about other people, or invite someone to a household, please see the Terms and Conditions for your responsibilities.
Where your data is
Your account and app content are stored in the European Union (Supabase, Frankfurt), our server functions run in the EU (Vercel, Frankfurt), and product analytics is processed in the EU (PostHog).
The AI assistant runs in the European Union and your messages to it are not transferred to the United States. Some other processing still happens in the US: payments (Stripe), push notification delivery (Google Firebase Cloud Messaging), transactional email (Resend), the sign-in anti-bot check (Cloudflare), and error monitoring and session replay (Sentry, whose data is stored in the US even though received through an EU endpoint). These transfers rely on safeguards approved for transfers outside the EU. Stripe and Sentry (legal entity Functional Software, Inc.) are certified under the EU-US Data Privacy Framework. Cloudflare, Google, Resend, and Vercel rely on Standard Contractual Clauses. Supabase and PostHog store your data in the EU and use Standard Contractual Clauses for any access from outside it. Sign-in, payments, and email are needed to run those parts of the service.
Security
All data is encrypted in transit using HTTPS. Access to your data is restricted by row-level security tied to your account, so members of one household cannot read another’s, and your personal data stays yours.
So the app opens quickly and keeps working without a connection, it keeps a copy of your recent data on your device, together with any changes you make while offline until they are sent. That copy is cleared when you sign out.
Keeping and deleting your data
We keep your data while your account is active. When you delete your account, your personal data is permanently removed: habits, goals, tasks, journal entries, contacts, personal finance records, AI chat history, and device tokens.
Session replay recordings, if you turn replay on, are kept for a limited period and then deleted automatically by each processor: 30 days by PostHog (EU), and up to 30 days by Sentry (US) on our current plan. If our Sentry plan changes this may be longer, and we will update this policy. Turning replay off stops new recordings, and any existing recordings are deleted at the end of these periods or when you delete your account, whichever comes first.
Scanned receipt images are kept on a rolling basis: only the last 10 per household are stored, and older ones are deleted automatically when a newer one is scanned. They are stored in the EU (Supabase), scoped to your household, and are removed when you delete your account.
AI conversations are deleted 12 months after their last message, or sooner if you delete them or your account.
Support requests, including answers to the feedback card, are kept for 5 years after you send them, in case they relate to a question or a dispute about your account. After that we remove your name, email and household details and keep only the text, which can then no longer be linked to you.
We keep a limited amount of information after you leave, only where the law allows or requires it:
- Accounting and tax records, which may include your name, email and details of what you paid, kept for the periods Bulgarian law requires: payroll records for 50 years; accounting registers and financial statements for 10 years; other accounting source documents for 3 years; and VAT and tax invoices until 5 years after the statutory tax-limitation period expires (up to about 11 years).
- A minimal record to prevent abuse and fraud, including a one-way “hashed” version of your email, so that free trials and referral rewards cannot be repeatedly claimed by deleting and recreating accounts. This is kept on the basis of our legitimate interest in preventing abuse, and is not used to contact you.
Shared household items you contributed stay visible to other members, but references to you are anonymised. Text you typed into shared fields (titles, notes, descriptions) may remain as written. You can delete your account any time from Profile, then Account actions, then Delete account. Backups are cycled routinely, and deleted content is removed from them within our normal backup rotation.
Anonymous data collected before you had an account. Analytics events we collect before you create an account are stored against a temporary device identifier rather than your personal details. Because of this, we cannot single you out to retrieve or delete them individually. They are held under our analytics provider’s retention schedule and are not used to build a profile of you. Once you create an account, all of your account-linked data is fully covered by your access and deletion rights.
Your rights
As a UK or EU user, you have the right to: access a copy of your personal data; correct inaccurate data; erase your account and all associated data; receive your data in a machine-readable format (portability); ask us to restrict how we process your data; object to processing based on legitimate interest, including error monitoring and abuse-prevention; withdraw consent for analytics and session replay any time in Cookie preferences; and complain to a data protection authority.
To exercise any of these, contact privacy@eligna.app. We will respond within one month, as the law provides.
Eligna is operated from Bulgaria, so our lead supervisory authority is the Bulgarian Commission for Personal Data Protection (CPDP, cpdp.bg). If you are in the UK, you can also complain to the Information Commissioner’s Office (ICO, ico.org.uk), and EU users may contact their own local authority.
Our UK representative. Because we are established in Bulgaria, we have appointed a representative in the United Kingdom under Article 27 of the UK GDPR: Tihomir Svetoslavov Simeonov, privacy@eligna.app (subject line “UK representative”). You and the ICO can contact our representative about anything to do with how we process your personal data.
Users outside the UK and EU
Eligna is offered from Bulgaria and is aimed mainly at users in the UK and EU/EEA, but the app is available on global app stores. Wherever you are, we apply the same core protections to your personal data, and we honour requests to access, correct or delete your data regardless of where you live. If you are in a country with its own data-protection law (for example the United States or India), you may have additional local rights; contact us at privacy@eligna.app and we will help, and comply with any additional rights the law of your country gives you.
Changes
If we make material changes to this policy, or add or change what we store or who processes it, we will update this page and, where it affects your choices, ask you again in the app.
Contact and company details
For questions about your data or this policy, contact privacy@eligna.app.
- Company: TRANSLOGISTIKA ES Ltd
- Unified Identification Code (UIC): 200606587
- Registered office: Vuzrajdane, bl. 66, fl. 2, ap. 6, Varna 9025, Bulgaria
- Data protection contact: privacy@eligna.app