ELEVANE

Privacy & trust

What your company promises its people — and what we enforce for you

If you're evaluating ELEVANE for your company, this is the page for legal, security, and your own peace of mind: six commitments you can stand behind, each one enforced structurally, not just promised.

  1. 1

    You can promise: their answers are theirs alone

    Tell your people, truthfully, that no manager, HR contact, or coworker — including you — can see how they personally responded. Not their scores, not their open answers, not even whether they completed a check-in on a given day.

  2. 2

    You only ever see group patterns

    Everything your dashboard shows is aggregated — averages across teams of at least 5 people, never anything traceable to fewer. This isn't a policy we ask you to follow; it's enforced by how the data is computed, every time, with no exceptions and no override, not even for your own admin account.

  3. 3

    You're not collecting names, and you don't have to protect them

    Nothing links an account to an identity beyond the email someone signs in with. There's no name field, no employee ID, no HR-system sync — nothing for your people to worry you're building a file on them.

  4. 4

    Every account belongs to the person, not to you

    Anyone can delete their account and everything in it, permanently, with one tap, anytime — no request to your HR team, no waiting period. You're not the custodian of that decision; they are.

  5. 5

    Small teams are protected automatically

    If a team is too small for anonymity — under 5 people — we simply don't show its results yet, even to you. Rather than lower the bar for a department you're curious about, we wait until there's enough people for the aggregate to protect everyone in it.

  6. 6

    You know who's joined — never what they said

    You can see that someone you invited has joined ELEVANE and which team they're assigned to. That's the ceiling. Never what they answered, never whether they've completed a check-in, never anything they do inside the product.

"A private space to check in on how work is really going."

The exact words your people see, and agree to, before they answer a single question.

How it actually works

The group-of-5 threshold, end to end

When someone completes a check-in, their individual answers are stored under their account, accessible only to them. To produce any organisational view — a department's trend line, a company-wide pattern — our system runs an aggregation query that requires at least 5 distinct people's data for that exact slice before it will return anything at all. Ask for a department with 4 people in it, and the answer is nothing, not an approximation. This threshold is enforced in the database layer itself, not in application code that a bug could bypass.

How an answer travels through ELEVANE An employee's answer moves from them into an encrypted vault only they can access, then through an aggregate door that only opens once at least 5 people's data is present, and only then into the company dashboard as a group pattern. A dashed line marked "no path exists" shows there is no direct route from the vault to the dashboard. No path exists from vault to individual view — not a permission, an absence Your employee answers privately Encrypted vault theirs alone n≥5 Aggregate door opens only at 5+ people Your dashboard group patterns only

The technical honesty

No policy grants access — the path doesn't exist

Most privacy promises are policy: a rule someone agreed to follow. Ours is architectural — the part your security review will actually want to see. The database rules that govern ELEVANE's data (row-level security policies, enforced by Postgres itself) simply never grant any HR account, admin account, or company role a route to an individual's raw responses. There's no toggle to flip, no override for a difficult request, no back door for an urgent one — not even for your own admin account. If a company account tries to query below the group-of-5 threshold, the database returns nothing — not because a rule says not to, but because no path to that data was ever built. We'd rather a feature be structurally impossible than depend on nobody misusing it.

For your security review

The boring specifics

The facts a compliance or security reviewer actually needs — not the pitch.

Hosting
EU (Frankfurt), on Supabase infrastructure.
GDPR
ELEVANE acts as data controller for individual accounts. Employees see and affirmatively accept our privacy commitments before their first check-in. Data minimisation is built into the schema, not added after the fact.
Encryption
In transit (TLS) and at rest, for all stored data.
Subprocessors
  • Supabase — database and authentication (EU)
  • Vercel — application hosting
  • Brevo — transactional email (EU)
  • Anthropic — AI-generated summaries, computed only from aggregated, threshold-gated data; individual responses are never sent
Right to erasure
Honoured instantly, via in-app account deletion — no support ticket, no waiting period.
Security questions
Welcome any time, via the contact form.

Even our own analytics are cookieless

We use Plausible, a privacy-friendly, EU-hosted analytics tool — no cookies, no cross-site tracking, no cookie banner needed.

Ready to see how this looks for your company?

Explore the demo with sample data, or get started with your own team.