Dear Elly Ops is the private operations application of Dear Elly (“we”, “us”). It is used only by the people who run the company. It is not offered to customers or to the public, and it collects nothing from visitors to shopdearelly.com.
With the account holder’s authorization, the application reads business records from the tools Dear Elly already uses, so that the people running the company can see them in one place:
It shows the records to authorized users, computes figures such as revenue, cash and stock, keeps an audit log of who did what, and, when asked, sends the text of a message or a record to Anthropic’s Claude models to draft a reply, summarize a message or answer a question. That text is used to produce the answer and is not used to train models. Nothing is sold, rented or shared with advertisers.
The application runs on Vercel and stores its own records (settings, approvals, notes, the audit log and sign-in data) in Supabase, both in the United States. Records from the connected tools stay in those tools; the application keeps short-lived copies in memory to render pages and does not build a separate database of customer data. Access tokens for the connected tools are stored encrypted at rest and are never shown to users.
Only people named in the application’s user directory, each with a role that limits what they can do. Sign-in is through Google Workspace or a one-time email link, with a second factor for owners and administrators. Every write, sign-in and refused request is recorded in an audit log that owners and administrators can read.
Copies of connected-tool data are discarded within minutes. The application’s own records are kept for as long as Dear Elly uses it. Disconnecting a tool under Settings revokes its token, and removing a person from the directory ends their access at once. To have anything removed, or to ask a question about this policy, write to the company at the address on shopdearelly.com.
If this policy changes, the date at the top changes with it.