Who We Are
ElevateIQ is an endpoint privilege-elevation service for Windows and macOS operated by Tiny Electrons LLC ("we", "us", "our"). The service consists of:
- An agent (the "Agent") deployed on each managed Windows or macOS endpoint, including an elevation broker that gates privilege-elevation requests against tenant policy and signed rule bundles.
- A web admin console (the "Admin Console") used by IT administrators.
- A backend API and PostgreSQL data store hosted on our infrastructure.
Together these are referred to as the "Service".
Roles
ElevateIQ is a B2B service. Our customer (typically an IT department or a managed service provider deploying ElevateIQ on behalf of an organization) is the data controller for personal data processed through the Service. Tiny Electrons LLC acts as the data processor on the customer's instructions, governed by a Data Processing Addendum where required.
This policy describes what we, Tiny Electrons LLC, collect, why, and how. It does not replace your employer's or organization's own privacy notice; if you are an end-user on a managed endpoint, your organization is the controller of your personal data.
Data We Collect
From managed endpoints (via the Agent)
- Device identity: hostname, machine ID, OS version + architecture, serial number, manufacturer, model, agent version, last-seen timestamp.
- User identity (per request): Windows SID, the user-name reported by Windows, and (when present) the email address bound to the Windows account.
- Elevation requests: the path, hash, file name, version, publisher, signature status, and code-signing thumbprint of the binary the user is trying to run; the working directory; the command-line arguments; the parent process; the user's free-text reason; AMSI scan result; AI risk score; ML risk score.
- Access requests (User Settings): which built-in Windows User Setting class the user is requesting (Network, Display, Devices, Printers, Power, Date & Time), the duration requested, the user's free-text reason, MFA proof.
- MFA proof: a signed nonce produced by Windows Hello, a hardware passkey, or a TOTP authenticator. We do not store biometric template data, passkey private keys, or TOTP secrets on our backend, only the cryptographic proof that a challenge was completed.
- Compliance posture (optional, controller-configurable): domain-join state, BitLocker / firewall / antivirus / WDAC state, encryption status, MDM-managed flag.
From the Admin Console
- Account profile of administrators using the console: email, name, role, MFA enrollment status, organization membership.
- Authentication artifacts: signed session cookies (see Cookie Policy), passkey credentials registered for sign-in, TOTP secrets (encrypted at rest).
- Audit log entries: every approval, denial, dismissal, rule change, login, logout, role change, and revocation, with timestamp, actor, and originating IP.
Automatically
- HTTP request metadata (method, path, status code, IP, user-agent) for security and operations logs.
- Device fingerprint: a low-entropy summary (browser, platform, masked IP) attached to admin sessions for anomaly detection.
- Aggregate, non-identifying usage metrics for service health (request counts, queue depth, latency).
What we do NOT collect: keystroke data, screen captures, browsing history, document contents, file contents from outside elevation requests, microphone or camera input, or biometric templates.
How We Use Your Data
- Operate the Service: evaluate elevation and access requests against your organization's rules; route pending requests to administrators; deliver approval/denial decisions back to the endpoint.
- Security: detect anomalous sign-in patterns, throttle abusive endpoints, validate MFA proofs, and rotate session tokens.
- Audit & compliance: maintain a tamper-evident record of every privilege change so your organization can prove who approved what, when, and why.
- Improve the AI risk model: a nightly job retrains our in-house risk model on the approve and deny verdicts administrators record. It learns from ten numeric signals only (signature validity, prior approval and denial counts, approval rates, time of day, and the AI legitimacy and confidence scores). No file names, paths, publisher names, user names or free-text reasons are used as training input, and the model is shared across all tenants. There is no per-tenant opt-out today; if you need one, contact us and we will handle it manually.
- Notify administrators of pending requests, security events, and product updates.
- Billing based on the active endpoint count.
Legal Bases (GDPR / UK GDPR)
- Performance of a contract with the customer, operating the Service the customer subscribed to.
- Legitimate interests, security monitoring, fraud prevention, abuse detection.
- Compliance with legal obligations, tax records, lawful disclosure requests.
AI & Automated Decision-Making
ElevateIQ uses an AI model (currently Google Gemini) to score the risk of each elevation request and recommend an action. We also train our own model in-house on the approve and deny decisions administrators make, and it runs alongside the Gemini score. The AI's recommendation is advisory only: a request is not approved or denied automatically based on the score unless your organization has explicitly configured a rule to do so. A human administrator reviews every novel request.
Where the customer has enabled auto-approve for matching rules, the decision is governed by the rule (a deterministic policy your administrators configured), not by the AI. You can request a manual review of any automated decision by contacting your administrator or, if needed, support@elevateiq.me.
Sub-Processors
We use a small number of vetted sub-processors to operate the Service:
- Amazon Web Services (cloud hosting), for the API, database, and static assets. United States.
- Amazon Web Services (Simple Email Service), for transactional email: notifications, password reset, and MFA enrollment links.
- Google (Gemini), for the risk-scoring model.
- Google (Sign-In), where an administrator signs in with a Google account. Google receives the sign-in request; we receive the account's email address and basic profile (OpenID scopes
openid email profile). - Microsoft (Entra ID / Sign-In), where an administrator signs in with a Microsoft work account. We request the
User.Readscope, which returns the account's email address and basic profile. - Apple (Sign in with Apple), where an administrator signs in with an Apple ID. We request the
nameandemailscopes. Apple may supply a private relay address instead of the real one. - Apple (Push Notification service), to deliver approval alerts to the iOS app. Apple receives the device push token and the notification text. Depending on the request type, that text names either the application or device involved (elevation and USB requests) or the requesting user (access requests); the message body itself is a fixed generic string.
- Stripe, for subscription billing and payment processing.
- Functional Software, Inc. (Sentry), for diagnostic stack traces; PII is redacted before transmission.
A current sub-processor list is available on request to support@elevateiq.me.
International Transfers
Our primary infrastructure is hosted in the United States. Where personal data is transferred from the EEA, the UK, or Switzerland to the United States, we rely on Standard Contractual Clauses or adequate-decision frameworks where applicable.
Retention
- Active session data: until logout or session expiry (7 days, or 30 days for "Remember me").
- Audit log (including security events, with full IP addresses): ordinary entries are retained for 90 days by default while the subscription is active, then deleted automatically. Entries flagged as security events are kept longer, for a minimum of 365 days. Both kinds live in the same audit log and record the full client IP address, which is not truncated or anonymised. This automatic cleanup runs against active tenants only, so audit entries belonging to a closed account are retained rather than purged on a schedule.
- Elevation request payloads: retained for the lifetime of the account. We do not currently run an automatic purge of elevation history, and retention is not yet self-service configurable. Deletion of specific records is available on request to support@elevateiq.me.
- Billing records: 7 years for tax/audit compliance.
What account closure actually does. We want to be precise here rather than reassuring, because "deleted" means different things in different products.
Closing an account starts a 30-day grace period, during which the request can be cancelled. When it completes, we irreversibly scrub the directly identifying fields on the user record: the email address is overwritten, and the name, password hash, MFA secret and recovery codes are erased. The account is deactivated and can no longer be signed in to or used to authenticate. Closing an organization deactivates every user in it and marks the organization closed.
Operational records created during the subscription are not erased by this process. That includes device inventory, elevation and access-request history (with the free-text reasons and risk scores attached to them), rules, audit entries, and registered passkey credentials (public keys and their metadata, which cannot be used to sign in once the account is deactivated). Those records remain in the database, associated with the closed account, after the scrub has run. We retain them because the audit trail is the evidentiary record of who was granted administrative privilege on which machine, and a privilege-management product that silently discarded that history would be less trustworthy, not more.
Backups follow their own cycle: our database retains automated backups for 30 days, so a copy of the pre-scrub state exists within that window and ages out of it.
If you need the operational records erased as well, contact support@elevateiq.me and we will carry that out manually. If you are exercising a statutory erasure right, say so and we will treat it as such.
Security
- TLS 1.2+ in transit; AES-256-GCM at rest.
- Argon2 password hashing.
- HttpOnly, Secure, SameSite session cookies (see Cookie Policy).
- Per-elevation MFA proofs signed on the endpoint.
- Hardware-backed certificate verification on every code-signed binary.
- Tenant-isolated database row-level-security policies.
- Annual penetration testing and continuous SAST + dependency scanning in CI.
Your Rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure ("right to be forgotten").
- Restrict or object to processing.
- Data portability.
- Lodge a complaint with your supervisory authority.
Because we process most personal data on behalf of our customer (your employer or IT provider), the most direct route is usually to make the request to them. You can also contact us at support@elevateiq.me and we will route the request appropriately.
Children
The Service is not directed to children under 16 and is intended for use in a workplace or managed-IT context. We do not knowingly collect personal data from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in the Admin Console and via email to account owners. The "Last updated" date at the top of this page reflects the latest revision.
Contact
Tiny Electrons LLC
Support: support@elevateiq.me
Effective Date: 2026-09-14