Privacy Policy
Effective: September 1, 2026 · Version 2026.09.01
Overwatch is provided by Elion Labs LLC (“Elion,” “we,” or “us”). Overwatch coordinates AI models, local tools, connectors, desktop and mobile sessions, and optional account sync. We do not sell personal information, serve behavioral advertising, or track visitors across unrelated websites. This notice explains the data paths that do exist.
Data we handle
- Account and organization data. If you sign in, we handle your user id, email, profile details, plan, team membership, roles, invitations, and account-security metadata.
- Sessions and synced settings. Session text, project and folder organization, model/account labels, commands, and related metadata may be stored locally and, when sync is enabled, in your account-scoped cloud record. The ordinary cross-device sync record does not contain provider API keys, OAuth tokens, passwords, or other credentials.
- Credentials and connected services. Credentials for locally executed models are kept on the device and sent only to the service they authenticate. If you explicitly connect a server-executed connector, its credential is stored in that connector’s private account record and used by our backend only to perform requests you initiate. Connector credentials are not copied into the general account-sync document.
- Prompts, outputs, files, and page content. We process the content you submit and the output returned to provide the feature you requested. Attachments, screenshots, and page content are sent to a model or connector only when that request requires them.
- Voice data. When you use dictation, microphone audio is processed for transcription. Depending on the selected mode, processing may occur on-device or through our authenticated transcription service and its configured speech provider. We use the audio to return text, not for advertising.
- Contacts and invitations. Contact import is optional. Overwatch requests only names and email addresses. The contact list remains on the device; only addresses you select are sent to our invitation service. Google contact import uses temporary permission to read names and emails, and the access token is revoked when import finishes.
- Billing and entitlement data. A payment provider handles payment details. We receive customer and subscription identifiers, plan, status, seats, and entitlement events, but not full card numbers.
- Product analytics and operations. The installed app may send first-party events such as app open, signup, paywall, purchase, and render-error metadata to Elion’s analytics service. These events may include an app-scoped anonymous id or signed-in user id. We use them to operate and improve Overwatch, not for advertising or cross-site profiling. Security and reliability logs may include timestamps, request status, app version, platform, and truncated error details.
How we use data
We use data to authenticate users; run sessions, models, connectors, sync, voice, invitations, billing, support, and security controls; diagnose failures; prevent abuse; comply with law; and improve the product. We do not use customer prompts or private workspace content to train an Elion model.
Where data goes
- Your selected AI or connector provider. Requests go to the provider shown in Overwatch for that model or connector. Common examples include Anthropic, OpenAI, Google, Meta, Moonshot, DeepSeek, xAI, Perplexity, and user-configured local services. The selected provider’s terms and privacy notice also apply.
- Infrastructure and delivery providers. Google Firebase and Google Cloud provide authentication, account-scoped storage, backend execution, and related infrastructure. Apple provides App Store and push-delivery services. Resend delivers service and invitation emails. The configured speech provider processes cloud transcription requests.
- Payments. Polar is the primary merchant-of-record integration. Where another checkout is presented, the named payment provider processes that transaction under its own notice.
- User-connected services. If you connect a service such as Google People/Drive, Cal.com, Apollo, Apify, Meta, Resend, or another in-app connector, requested data is sent to that service only to complete the action you initiated.
We may disclose data when legally required, to protect users or the service, or as part of a corporate transaction subject to appropriate confidentiality and notice. Providers may process data in countries other than yours under their applicable transfer safeguards.
Website privacy
The public Overwatch website does not load advertising pixels, third-party audience measurement, cross-site trackers, or nonessential analytics storage. We therefore do not use cookie banners or build profiles from website visits. Global Privacy Control and Do Not Track signals do not change this behavior because the website does not sell, share for targeted advertising, or perform cross-site tracking.
Chrome extension
The optional extension communicates with the signed Overwatch desktop app through a native messaging channel provided by the browser. It is inactive until you arm it locally for the current app launch. When you request browser work, page text, HTML, form data, or screenshots needed for that request may pass to Overwatch and then to your selected model. The extension does not operate an independent Elion browsing service and contains no advertising or third-party analytics code.
Retention and deletion
- Local data remains until you delete it, clear the relevant setting, or remove the app.
- Account and sync data remains while the account or feature is active and is removed through the in-app deletion workflow or a verified deletion request, subject to legal, fraud-prevention, and backup-lifecycle requirements.
- Connected providers retain data under their own policies. Disconnecting a connector stops new requests and removes the credential from Overwatch’s active connector record.
- Billing records may be retained as required for tax, accounting, disputes, and fraud prevention.
- Operational and analytics records are retained only for product, security, support, and legal needs, then deleted or aggregated under Elion’s retention schedule.
Your choices and rights
- Use local models and local sessions where available, without enabling account sync.
- Choose which model, connector, contact, file, page, or voice feature receives data.
- Delete sessions, disconnect connectors, revoke permissions in device settings, or delete your account.
- Request access, correction, deletion, portability, restriction, or objection where local law provides those rights. We may verify identity before fulfilling a request.
- Opt out of marketing email using the link in that message; service and security messages may still be sent.
We do not sell personal information or share it for cross-context behavioral advertising. To make a privacy request, email j@elionlabs.org.
Security
We use access controls, signed software, transport encryption, scoped service credentials, audit logging, and release checks designed to protect data. No system can guarantee absolute security; report suspected security issues to j@elionlabs.org.
Children
Overwatch is not directed to children and is intended for users 17 and older.
Changes
We version this notice and update the effective date when material data practices change. Where required, we will provide additional notice or obtain consent before the change takes effect.
Contact
Elion Labs LLC · Privacy and security requests: j@elionlabs.org.
Overwatch is made by Elion. Third-party product names belong to their respective owners; Elion is not affiliated with or endorsed by those providers unless expressly stated.