Privacy Policy
Effective date: July 6, 2026
Elmora provides managed AI worker services for inbox, booking, and back-office operations. This page explains how the website and private account-connection flow handle information.
Information we collect
This website does not collect personal information through public forms. During private onboarding, an authorized user can connect a Google account or an eligible non-Google, non-Microsoft IMAP/SMTP mailbox so their assigned worker can perform the tasks they approve.
How information is used
- To provide and improve managed AI worker services.
- To connect authorized workspace accounts to Elmora workflows.
- To maintain security, auditability, and reliable service operations.
Google user data
Google user data is used only to provide user-authorized Elmora features. Elmora does not sell Google user data. Connection material is handled server-side and routed only to the client runtime assigned during onboarding.
IMAP/SMTP credentials
For an eligible IMAP/SMTP mailbox, the email password or provider-issued app password is entered only in a private, short-lived connection form. The Elmora control-plane application keeps it only in request memory while sending it over an encrypted, signed server connection to the worker assigned during onboarding. The control plane does not save it in its database, files, cookies, browser storage, analytics, telemetry, or application logs. The assigned worker is the destination and may securely store the credential to provide the authorized mailbox service under the client's managed-runtime controls.
User-supplied IMAP and SMTP server settings are accepted only after automatic discovery returns a bounded failure state. The retry requires the password to be entered again; Elmora does not retain it from the failed attempt. Public and tenant status views are limited to lifecycle state, whether manual settings are needed, and bounded outcome codes. They do not disclose passwords, server settings, receiver addresses, signing keys, raw tokens, or runtime identifiers.
The password form rejects recognizable Gmail, Googlemail, Outlook, Hotmail, Live, and MSN addresses and is not intended for Google Workspace, Microsoft 365, or custom domains hosted by Google or Microsoft. Because an email address alone cannot identify every custom-domain provider, clients and operators must use the dedicated Google or Microsoft connection process when applicable.
Revocation and uncertain delivery
Expiring a one-time link or revoking a worker prevents later control-plane use, but it cannot recall a mailbox credential already accepted by the assigned worker. A network timeout can also make delivery status uncertain, in which case Elmora does not automatically replay the credential. To revoke mailbox access after delivery, remove the account from the worker and rotate or revoke the password or app password with the mailbox provider.
Data sharing
Elmora does not sell personal data. Data may be shared with infrastructure providers as needed to host and operate the service, or when required by law.
Contact
For privacy questions, contact the Elmora operator through the channel provided during onboarding.