elements-live
Elements Pricing Log in Sign up

Privacy Policy

Last updated 10 August 2026

Who we are

elements-live is operated by [ENTITY], the controller of the personal data described here. For anything in this policy — including access, export, or deletion requests — write to legal@elements-live.com.

The short version: we collect what's needed to run accounts, take payment, and understand how the product is used. We don't sell data, we don't run advertising, and there are no third-party ad or social trackers on this site.

What we collect

If you create an account

  • Your email address, and whether it's been verified.
  • A password hash — never the password itself. If you sign in with GitHub or Google we store an identifier from that provider instead, and no password at all.
  • Your plan, and the dates it changed. Every tier change is recorded in an audit log, including who or what made it.

If you subscribe

  • Stripe customer and subscription identifiers.
  • No card details. Payment data goes directly to Stripe and never touches our servers. Stripe's own privacy policy governs it.

What you create in the product

  • Favourite elements, bookmarked clusters and papers, projects, and any descriptions you write.
  • Research packets you generate, and their share links and view counts.
  • Your credit balance, grants, and what they were spent on.

How the product is used

  • Product analytics events — page views, clicks, which element was viewed, and key funnel steps such as registration and checkout — with a timestamp and a random session identifier. These are stored in our own database, not sent to an analytics vendor.
  • Referral attribution: if you arrive through someone's shared packet link and then register, we record that connection once, in order to credit them.
  • Standard server logs kept by our hosting provider, which include IP addresses, for security and debugging.

Cookies

We use four, all functional. None are advertising cookies.

  • Session cookie — keeps you signed in.
  • CSRF token — protects forms against cross-site request forgery.
  • els_sid — a random product-analytics session identifier. It isn't tied to your identity unless you're signed in.
  • els_ref — records which shared link brought you here so the referrer can be credited. Expires after 30 days.

Why we're allowed to hold it

  • To perform our contract with you — accounts, subscriptions, and the features you're paying for.
  • Legitimate interests — understanding product usage, preventing abuse, keeping the service secure and working.
  • Legal obligation — tax and accounting records for payments.

Who else processes it

We use a small number of providers, each doing one job, none of them permitted to use your data for their own purposes:

  • Stripe — payments and subscription management.
  • Postmark — transactional email (verification, password resets, notifications).
  • Render — application hosting.
  • Neon — database hosting.
  • GitHub / Google — only if you choose to sign in with them.

We do not sell personal data, and we don't share it for advertising. We would disclose data if legally required to, or as part of a business transfer — in which case this policy travels with it.

Where it's stored

On servers in the United States. If you're in the UK, EU, or elsewhere, using the service involves transferring your data there, under the safeguards our providers offer.

How long we keep it

  • Account and content — while your account exists, and for a short period afterwards so an accidental deletion can be undone.
  • Credit records — credits expire 90 days after being granted; the ledger entry is retained for accounting.
  • Analytics events — retained in aggregate to understand product trends over time.
  • Payment records — as long as tax and accounting law requires, typically several years.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it, and you can object to processing based on legitimate interests. Depending on where you live these rights come from the UK GDPR, the EU GDPR, or state laws such as the CCPA — we apply them to everyone regardless.

To delete your account, email legal@elements-live.com or support@elements-live.com from the address on the account. There is no self-service delete button yet; we do it by hand, and we'll confirm when it's done. Cancel any active subscription first, or ask us to cancel it as part of the same request.

We aim to respond within 30 days. If you're in the UK or EU and unhappy with how we've handled a request, you can complain to your data protection authority.

Security

Traffic is encrypted in transit. Passwords are stored only as salted hashes. Forms are CSRF-protected, and request limits apply across the site. No system is perfectly secure, and we won't pretend otherwise — but if you find a problem, tell us at support@elements-live.com and we'll take it seriously.

Children

This service isn't directed at children, and we don't knowingly collect data from anyone under 16. If you believe a child has given us personal data, get in touch and we'll remove it.

A note on shared packets

Packet share links are public to anyone holding the URL. Don't put anything in a packet description that you wouldn't want read by a stranger. See the Terms of Service.

Changes

If we change this policy, the date at the top changes with it. Material changes will be emailed to account holders.

Contact

legal@elements-live.com — privacy questions, data requests, and account deletion.

elements-live — a living index of research attention. Data via Semantic Scholar, OpenAlex, CrossRef & CORE. Snapshot updated daily. Element properties via PeriodicTableOfElements.org. About · Contact · Terms · Privacy · © 2026 · v1.0