Privacy
EE Works LLC ("we", "us"), trading as Elvin Engineering, is registered in the United States.
We are the data controller for account, security, support, and website data. Responsibility for customer-directed content depends on the feature and agreement.
Applies to
Governed separately
Nap
Our native agentic platform service and this website.
Boardist
boardist.io ↗Has its own terms and privacy policy.
Consulting
Governed by your engagement agreement.
Nap components
Nap is built from these parts. Which parts run depends on how you use it.
Client apps
- Default behavior
- Works with files stored locally on the device.
- Stored locally
- Working files, local app and device settings, and network references.
- Connected features
- Depending on the features you use, the client may connect to the Account service, Nap Network, and Nap VPS.
- Technical access
- The client processes local information on the device. Information sent to a connected component is handled as described for that component.
Account service
- Purpose
- Authorises devices to join Nap Network and enables access to Nap Network relay and Nap VPS.
- Information stored
- Account identity, network membership, roles, invitations, linked devices, and VPS deployment records.
- Technical access
- NAP software and authorised administrators can technically access these account and authorisation records.
Nap Network
- Purpose
- Connects authorised devices peer to peer or through a NAP-operated relay.
- Information processed
- End-to-end encrypted traffic and the connection metadata needed to establish and deliver connections.
- Technical access
- Participating devices can read the content they exchange. NAP-operated network and relay services cannot decrypt that content.
Nap VPS
- Purpose
- Coordinates agents, events, and ongoing work across connected Nap services.
- Required services
- Uses the Account service to authorise access and Nap Network to exchange data with connected devices.
- Information processed
- Files, persistent service state, schedules, events, program inputs and outputs, and information processed during browser activity.
- Technical access
- Data is end-to-end encrypted while travelling through Nap Network. The VPS is an endpoint, so its runtime decrypts the information it needs to coordinate services and perform work.
Nap VPS
All Nap VPS models store persistent service state and coordinate services for ongoing work. They differ in who shares the VPS and who can administer it.
The infrastructure provider, hosting location, and provider privacy terms depend on the VPS arrangement and will be disclosed before access is provided.
Shared VPS
- Who uses it
- More than one Nap customer runs work on the same NAP-operated VPS.
- Separation
- Nap account permissions separate customers.
- Administrative access
- NAP administers the VPS.
Managed VPS
- Who uses it
- One customer organisation and its invited users run work on the VPS.
- Separation
- Other Nap customers do not run workloads on this VPS.
- Administrative access
- NAP administers the VPS.
Dedicated VPS
- Who uses it
- One customer organisation runs the VPS in its own infrastructure-provider account.
- Separation
- Other customers do not run work there, and NAP has no standing administrative shell on the VPS.
- Administrative access
- NAP has no standing administrative shell on the VPS.
Third parties
A third-party site or service contacted by you or an agent receives the data sent to it and handles that data under its own privacy policy.
Analytics and diagnostics
We do not send the content you work with to a separate analytics service or use it for advertising or model training.
Nap may collect technical diagnostics and feature-usage counts. These are aggregated on the VPS and sent to NAP only as a summary.
Processors we use
- Stripe — processes payments. Stripe's privacy policy applies.
- Apple — processes purchases made through an Apple app. Apple's privacy policy applies.
Retention
When a subscription ends, the VPS stops at the end of the period you paid for. The disk is kept for 30 days after that. Resume inside those 30 days and your deployment comes back as it was. After 30 days the disk is destroyed, and so is what the account service held about you.
Billing records are the exception. Whoever took the payment holds the record of it, and tax and accounting law requires us to keep it for years rather than days. That is the one record we will not delete on request.
Your rights
You can ask to see, correct, export, or delete the personal data we hold by emailing hello@elvin.engineering. We answer within the time the law allows, and may need to check the request really came from you.
If you are in the European Union, the EEA, or the United Kingdom and you think we have handled this badly, you can complain to your national data protection authority. You do not need our permission and you do not have to come to us first.
This website
- No tracking — elvin.engineering sets no cookies, runs no analytics, and loads nothing from a third party.
- Email — write to us and we keep your address and the message for as long as it is useful for support and as a record of what was agreed.
- Payments — Stripe takes the payment and keeps the record of it. What reaches us is your name, email, and the transaction. Card numbers go to Stripe and never to us.