Privacy Policy

Your safety is engineered, not promised.

We treat privacy as a system-design problem rather than a marketing claim. ELPIS collects almost nothing, routes what little we handle through encrypted infrastructure in Sweden, and erases operational records the moment your service is complete.

Last updated · May 22, 2026 Applies to all ELPIS services
i.

Less to collect

No ID documents, no test-registration accounts, no application materials. We cannot lose what we never had.

ii.

Less to find

Operational records live only inside amnesic systems hosted under one of Europe's strictest privacy regimes.

iii.

Less to keep

Contact details and session traces are securely overwritten as soon as the work is done.

Section 01

What we do not collect

We avoid collecting identity-bearing information at every step. This is the foundation of our privacy model: the most reliable way to protect a record is to never create it.

You will not be asked for:

  • Government-issued identification documents
  • ETS or other testing-agency account credentials
  • University application materials
  • Other highly sensitive personal data not directly required to perform the service

If a piece of information isn't needed to do the work, we don't want it on our systems.

Section 02

Where your data lives

Our backbone servers run in Sweden. Everything we process is therefore governed by the EU's General Data Protection Regulation[1] and Sweden's Data Protection Act (2018:218)[2] — together, two of the strongest legal frameworks in the world for personal-data handling, security, and disclosure.

In practice this gives you two things. Unauthorized access to communications between you and ELPIS is treated as a serious legal violation across the European Union. And our infrastructure is required to operate under technical and organizational safeguards that the regulation enforces with substantial penalties for non-compliance.

We call this offshore data sovereignty. Our clients connect from every part of the world, and surveillance environments vary widely from one jurisdiction to the next. But the legal home of your data is determined by where it physically resides — not by where you live, and not by where you connect from. The moment a request reaches our infrastructure, it is governed by Swedish and EU law[7]. Whichever country you happen to be in, your protection travels with the data, not with your passport.

Section 03

Encryption & routing

Inside that legal envelope, we run our own technical one.

Every connection between you and ELPIS travels through a multi-hop relay network built on the same principles as Tor[3]: no single node along the path knows both who you are and what you're requesting. Payloads are wrapped in AES-256 encryption[4] — the same standard used by national security agencies to protect classified material.

The practical consequence: even in the worst plausible scenario — a compromised home router, surveillance of your local network, or a key leaked from a non-TPM device — what an interceptor captures is ciphertext. Without the endpoint keys, it stays ciphertext.

Section 04

How records disappear

When your service is complete, the temporary records we held to deliver it are removed from both sides of the exchange.

On your side, the same secure-erase principle is applied with whichever utility fits your operating system — GNU shred[5] on Linux, sdelete on Windows, or diskutil secureErase on macOS. The effect is uniform: contact records and session traces are overwritten with multiple passes of zeros and random data, leaving nothing meaningful behind for forensic recovery.

On our side, our operators work from Tails[6] — an amnesic operating system that runs entirely in memory and discards everything when it shuts down. Each service session runs on a fresh Tails instance, and that instance is decommissioned the moment the work is done. There is no long-lived customer database accumulating in the background, because we never build one.

Section 05

UUID warranty

If everything is deleted, how do we honor warranty and after-sales support?

When your service concludes, you receive a UUID — a randomly generated identifier with no link to your name, your contact details, or your account. In our records, that UUID is stored alongside only the service date. A lookup confirms "a session with UUID XXXX took place on [date]" and nothing else.

Whichever channel you later reach us on — Xiaohongshu, Telegram, Signal, WeChat — presenting your UUID is how we recognize you. This trades the comfort of a name-based system for something structurally stronger: even if a government agency or other adversary were somehow to obtain a copy of our records, the database itself would reveal nothing about who our clients are.

A few things follow from that design:

  • If you lose your UUID, we have no other way to identify you and cannot provide further support.
  • Anyone holding your UUID will be treated as you. Keep it the way you'd keep a private key.
  • We will never ask for additional personal information to "verify" your identity. If someone claiming to be ELPIS does, it isn't us.
Section 06

What no system can promise

We've described the specific controls we run because we believe specifics earn more trust than slogans.

Encryption, multi-hop routing, amnesic operating systems, and secure-erase utilities meaningfully reduce risk — but they do not eliminate it. Your endpoint security, your operational habits, and the threat model you're facing all matter. We've designed our side of the exchange to be the strongest link we can make it. We encourage you to do the same on yours.

Section 07

References

  1. European Union. Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR).
  2. Government Offices of Sweden. Act containing supplementary provisions to the EU GDPR (SFS 2018:218).
  3. The Tor Project. Overview: How Tor works.
  4. National Institute of Standards and Technology. FIPS 197: Advanced Encryption Standard (AES).
  5. GNU Coreutils Manual. shred: Remove files more securely.
  6. The Tails Project. About Tails — how the amnesic system works.
  7. Swedish Authority for Privacy Protection (IMY). When the GDPR applies — territorial scope and cross-border processing.
ELPIS · Privacy by design, not by disclaimer.
Document version 2.0 · May 2026