What Elastova collects, why, and the promises we make about it.
Elastova is operated by ELASTOVA (SMC-PRIVATE) LIMITED, a private limited company incorporated in Rawalpindi, Punjab, Pakistan, and registered with the Securities and Exchange Commission of Pakistan under the Companies Act 2017.
We are the company responsible for your personal information — in legal terms, the data controller.
Privacy contact: privacy@elastova.com
Our full company details are at the end of this document.
Elastova is an iOS app for people living with loose skin after major weight loss. It keeps an honest, private record of your own body and lets you talk to an AI assistant about it.
Elastova is not a medical service. It does not diagnose, treat or assess any medical condition, and it is not a substitute for advice from a qualified clinician.
These are commitments, not aspirations. Everything below in this policy is consistent with them.
| What | Why we need it |
|---|---|
| Your email address | To sign you in and let you recover your account |
| An internal account identifier we generate | To connect your data to your account without using your email as a key |
| Sign-in identifiers from our login provider | To recognise you when you return |
| Proof that your email was verified, and when | To stop someone else claiming your account |
| The date your account was created | To operate the account |
If you connect more than one way of signing in (for example email and Apple), we record which sign-in methods belong to your account, and short-lived proof that you controlled both at the time you linked them.
This is the sensitive part, and we treat it as such. Depending on what you choose to tell or show Elastova, this may include:
We collect this only because it is what the service does. You asked Elastova to keep a record of your body and to answer questions about it; it cannot do that without the information you give it.
We do not collect this for any other purpose. We do not infer things about you to sell, we do not build advertising profiles, and we do not share it to be analysed by anyone else for their own ends.
We use a small number of suppliers to run Elastova. Each of them acts only on our instructions, under a written contract that forbids them from using your information for their own purposes.
| Supplier | What they do | Where |
|---|---|---|
| Microsoft Azure | Hosts our servers, database and file storage | United States |
| Auth0 (Okta) | Handles sign-in and email verification codes | United States |
| Microsoft Azure OpenAI Service | Runs the AI model that generates the assistant's replies | United States |
| Cloudflare | Serves our website and this policy | Global edge network |
We share your information with nobody else. No advertisers, no data brokers, no analytics companies, no insurers, no employers, no other users.
When you send a message to the assistant, the text of your conversation is sent to Microsoft's Azure OpenAI Service so a reply can be generated.
We want to be precise about what that means, because vague reassurance is worse than the truth:
We do not send your photographs to the AI model.
We would prefer that 30-day window did not exist, and we are pursuing the exemption that removes it. If we change AI supplier or configuration in a way that changes this, we will update this policy and tell you.
Our company is in Pakistan. Our servers are in the United States. This means your information is transferred internationally: it is stored in the United States, and our team in Pakistan can access it in order to operate and support the service.
We protect it with the measures in section 7 wherever it is, and our contracts with our suppliers apply regardless of location.
These are the actual measures in place, not a wish list:
No system is perfectly secure, and we will not pretend otherwise. If your health information is ever exposed in a way that requires it, we will notify you, and the U.S. Federal Trade Commission, as the Health Breach Notification Rule requires.
You can delete your account and your data at any time from within the app. When you do:
One thing deliberately survives. We keep a minimal permanent record — the identifiers of the deleted sign-in method, the date of deletion, and a reference number — with no health information, no email, and no name. This exists so that a deleted account cannot be silently resurrected by someone who later gains access to the same sign-in method. It is a safety measure, and we think you would want it.
We also keep a tamper-evident log that a deletion happened, for the same reason.
Whoever and wherever you are, you can:
We answer requests free of charge, up to twice a year per person.
If you are in the United States, you may have additional rights under your state's law. Washington State residents: please also read our separate Consumer Health Data Privacy Policy, which the My Health My Data Act requires us to publish.
We keep your information for as long as you have an account. When you delete your account, we delete it — see section 8.
We do not keep your health information "just in case", and we have no interest in holding data for people who have left.
Elastova is for adults. You must be 18 or over to use it, and by accepting the Terms of Service you confirm that you are. We do not ask for or verify your date of birth. If we learn that an account belongs to someone under 18, we delete it.
We do not knowingly collect information from children.
If we change how we handle your information, we will update this policy and change the date at the top. If the change is significant — a new category of information, a new supplier, a new purpose — we will tell you in the app and ask for your agreement before it applies to you.
We will not quietly broaden what we do with your data.
Questions, requests or complaints:
privacy@elastova.com