계정과 개인정보
계정은 휴대폰 앱을 쓸 때만 필요합니다. 계정을 만들지 않으면 crew.elopstudio.com은 아무것도 모으지 않고, PC의 ELOP Crew는 이 서버에 접속하지도 않습니다. 이 페이지는 계정이 무엇을 두고 어떻게 지우는지 정리합니다. 법적인 내용은 개인정보처리방침이 정합니다.
로그인 방법
GitHub, Google 또는 Apple로 로그인합니다. 처음 로그인하면 계정이 생깁니다. 비밀번호는 없습니다.
- 이메일 주소는 요청하지 않습니다. GitHub에는 아무 권한도 요청하지 않고, Google에는 기본 프로필만 요청합니다. Apple은 이름도 이메일도 보내지 않습니다.
- 서버는 로그인한 서비스의 사용자 번호와 표시 이름만 둡니다. Apple로 로그인하면 이름이 없어 (이름 없음)으로 나옵니다.
- 로그인 방법마다 계정이 따로 생깁니다. GitHub로 만든 계정과 Google로 만든 계정은 합쳐지지 않습니다.
- 웹 로그인은 30일, 휴대폰 앱 로그인은 마지막으로 쓴 날부터 180일 동안 유지됩니다.
계정 페이지
crew.elopstudio.com/account에서 계정을 관리합니다. 휴대폰 앱에서는 더보기 → 계정 관리로 엽니다.
| 요금제 | 지금 요금제와 요금제마다 연결할 수 있는 PC 수. |
|---|---|
| 연결된 PC | 이름, 버전, 상태. 이름 변경과 해제를 할 수 있습니다. |
| 모바일 앱 | 앱에 로그인한 휴대폰과 마지막 사용 시각. 휴대폰마다 로그아웃할 수 있습니다. |
| 계정 삭제 | 계정과 그에 딸린 정보를 한 번에 지웁니다. |
구독이 있으면 결제 내역도 이 페이지에 나옵니다. 요금제와 결제를 보세요.
서버에 두는 것
| 계정 | 로그인한 서비스의 사용자 번호, 표시 이름, 요금제. |
|---|---|
| 로그인 유지 | 무작위 토큰. 서버에는 해시값만 둡니다. |
| 연결한 PC | 이름(처음엔 Windows PC, Mac, Linux PC), 운영체제, ELOP Crew 버전, 연결한 시각과 마지막 접속 시각, 공개키. 개인키나 비밀값은 두지 않습니다. |
| 앱에 로그인한 휴대폰 | 앱이 알려 주는 기기 이름, 로그인 시각과 마지막 사용 시각, 로그인 토큰의 해시. |
| 푸시 토큰 | 앱에서 알림을 허용한 경우에만. |
| 결제 | 유료 요금제를 쓰는 경우에만. Paddle의 고객·구독·거래 번호, 요금제와 주기, 금액, 결제일, 환불 여부. 카드 정보는 받지 않습니다. |
중계되는 내용
휴대폰 앱에서 보고 보내는 것, 곧 에이전트 목록과 상태, 대화, 보내는 메시지와 파일, 승인과 답, 실행하는 명령과 그 결과는 crew.elopstudio.com의 중계 서버를 거쳐 PC와 휴대폰 사이를 오갑니다.
- 오가는 동안 TLS로 암호화됩니다.
- 서버는 내용을 목적지로 넘기기만 합니다. 디스크, 데이터베이스, 로그 어디에도 남기지 않습니다.
- 종단간 암호화는 아닙니다. 전달되는 동안에는 서버의 메모리에 내용이 있습니다.
- PC의 ELOP Crew가 앱이 요청할 수 있는 것을 정합니다. Claude 로그인과 로그아웃, PC 연결 설정은 PC에서만 할 수 있습니다. PC의 접근 토큰은 앱에 주지 않습니다.
알림에 담기는 것
알림은 Expo를 거쳐 Apple(APNs) 또는 Google(FCM)이 휴대폰에 전달합니다. 알림에는 PC 이름, 에이전트 이름, 기다리는 일의 종류(예: Bash 허용)만 담깁니다. 명령, 질문, 대화 내용은 담지 않습니다.
모으지 않는 것
- 이메일 주소, 프로필 사진
- 대화, 명령, 파일 내용의 저장본
- Claude 계정 정보와 토큰
- PC의 호스트 이름
- 카드 같은 결제수단 정보. 결제 대행사 Paddle이 직접 받습니다.
PC 연결을 요청한 IP 주소는 남용을 막으려고 서버 메모리에만 10분 동안 둡니다. 웹 서버의 접속 기록(IP 주소, 시각, 경로)은 장애 대응을 위해 잠시 남을 수 있습니다.
얼마나 두는지
| 계정과 연결된 PC | 계정을 지울 때까지. 지우면 바로 없어집니다. |
|---|---|
| 해제한 PC | 해제하고 30일 뒤 지웁니다. |
| PC 연결 코드 | 10분. |
| 로그인 | 웹 30일, 앱은 마지막 사용 후 180일, 또는 로그아웃할 때까지. 푸시 토큰도 함께 지웁니다. |
| 결제 내역 | 계정을 지울 때까지. 법이 보관을 요구하는 거래 기록은 판매자인 Paddle이 보관합니다. |
| 백업 | 데이터베이스 백업에 최대 약 10일 남았다가 자동으로 지워집니다. |
PC에 두는 것
PC의 ELOP Crew는 연결 정보로 서버 주소, 기기 번호, 개인키만 데이터 폴더에 둡니다. 계정 이름과 요금제는 창이 열려 있을 때 서버에 물어서 메모리에만 둡니다. 서버에는 PC 종류, 운영체제, ELOP Crew 버전만 보냅니다.
휴대폰 로그아웃
앱의 더보기 → 로그아웃은 그 휴대폰만 로그아웃합니다. 휴대폰을 잃어버렸다면 계정 페이지의 모바일 앱에서 그 기기의 로그아웃을 누르세요. 그 휴대폰의 중계 연결이 바로 끊기고, 앱은 로그인 화면으로 돌아갑니다.
계정 삭제
- 계정 페이지의 맨 아래 계정 삭제를 누릅니다. 앱에서는 더보기 → 계정 삭제가 이 부분을 엽니다.
- 확인 창에서 한 번 더 확인합니다. 되돌릴 수 없습니다.
계정, 로그인 정보, 연결된 PC, 휴대폰 로그인이 바로 지워집니다. 연결돼 있던 PC와 휴대폰의 중계도 바로 끊깁니다. 그 PC의 ELOP Crew는 다음 확인 때 이를 알고 키를 지웁니다.
구독이 있으면 먼저 구독을 끝낸 뒤 지웁니다. 결제 서비스에 닿지 않으면 아무것도 지우지 않고 삭제하지 못했습니다. 잠시 뒤 다시 해 주세요.가 나옵니다.
구독은 바로 끝나며 남은 기간은 환불되지 않습니다. 결제한 지 7일이 안 됐다면 먼저 환불을 요청하세요. 요금제와 결제를 보세요.
문의
개인정보에 관한 문의와 요청(열람, 정정, 삭제, 처리정지)은 elopadmin@elopstudio.com으로 보내 주세요. 전체 내용은 개인정보처리방침과 이용약관에 있습니다.
Your account and privacy
You only need an account for the phone app. Without one, crew.elopstudio.com collects nothing, and ELOP Crew on your PC never connects to it. This page sums up what the account keeps and how to delete it. The legal text is the privacy policy.
How you sign in
With GitHub, Google or Apple. Your account is made the first time you sign in. There is no password.
- No e-mail address is asked for. GitHub is asked for no permissions, Google for the basic profile only, and Apple sends neither name nor e-mail.
- The server keeps only the user id and display name from that service. Signed in with Apple, there is no name, so it shows (no name).
- Each way of signing in is its own account. An account made with GitHub and one made with Google are not merged.
- You stay signed in for 30 days on the web, and in the phone app for 180 days from the last time you use it.
The account page
Manage your account at crew.elopstudio.com/account. In the phone app, More → Manage account opens it.
| Plan | Your plan and how many PCs each plan allows. |
|---|---|
| Linked PCs | Name, version and state, with Rename and Remove. |
| Mobile app | The phones signed in to the app and when each was last used, each with Sign out. |
| Delete account | Removes the account and everything about it at once. |
With a subscription, your payments are on this page too; see Plans and payment.
What the server keeps
| Your account | The user id and display name from the service you sign in with, and your plan. |
|---|---|
| Staying signed in | A random token; the server keeps only its hash. |
| Linked PCs | The name (Windows PC, Mac or Linux PC unless you rename it), operating system, ELOP Crew version, when it was linked and last seen, and its public key. Never a private key or a secret. |
| Phones signed in to the app | The name the app gives, when it signed in and was last used, and the hash of its token. |
| Push token | Only if you allowed notifications in the app. |
| Payments | Only on a paid plan: Paddle's customer, subscription and transaction ids, plan and cycle, amounts, payment dates and refunds. Never card details. |
What the relay passes on
What you see and send in the phone app (the agents and their state, conversations, messages and files you send, approvals and answers, commands you run and their output) travels between your PC and your phone through crew.elopstudio.com's relay.
- It is encrypted in transit with TLS.
- The server only hands it on. None of it is kept on disk, in a database or in logs.
- It is not end-to-end encryption: while being passed on, the content is in the server's memory.
- ELOP Crew on your PC decides what the app may ask of it. Claude sign-in and sign-out, and linking, stay on the PC. The PC's access token is never given to the app.
What a notification carries
Notifications go through Expo and are delivered by Apple (APNs) or Google (FCM). They carry the PC's name, the agent's name and what kind of thing it waits for (such as allowing Bash). Never the command, the question or the conversation.
What is not collected
- E-mail addresses and profile pictures
- Stored copies of conversations, commands or files
- Your Claude account or tokens
- Your PC's hostname
- Card or other payment details; Paddle, our payment processor, receives those directly
The IP address a PC asks to be linked from is held in the server's memory for ten minutes to stop abuse, and never stored. The web server's access log (IP address, time, path) may keep requests for a short time for troubleshooting.
How long
| Your account and linked PCs | Until you delete the account; gone at once when you do. |
|---|---|
| A removed PC | Deleted 30 days after it was removed. |
| Link codes | Ten minutes. |
| Sign-ins | 30 days on the web; in the app, 180 days after last use; or until you sign out. The push token goes with it. |
| Payments | Until you delete the account. Transaction records the law requires are kept by Paddle, the seller. |
| Backups | Up to about ten days in database backups, then deleted automatically. |
What stays on the PC
For the link, ELOP Crew on your PC keeps only the server's address, its device id and its private key in its data folder. Your account name and plan are asked for while the window is open and kept in memory only. The PC sends the server only its kind, operating system and ELOP Crew version.
Signing out phones
More → Sign out in the app signs out that phone only. If you lose a phone, press Sign out next to it under Mobile app on the account page. Its relay connection ends at once and the app goes back to the sign-in screen.
Deleting the account
- Press Delete account at the bottom of the account page. In the app, More → Delete account opens that section.
- Confirm. It cannot be undone.
The account, how you sign in, your linked PCs and the phones signed in are removed at once, and their relay connections end. ELOP Crew on those PCs finds out on its next check and deletes its key.
A subscription is ended first. If the payment service cannot be reached, nothing is deleted and the page says Could not delete it. Try again in a moment.
The subscription ends at once and the rest of the period is not refunded. Within seven days of a payment, ask for a refund first; see Plans and payment.
Contact
Questions and requests about your data (access, correction, deletion, stopping its use): elopadmin@elopstudio.com. The full text is in the privacy policy and the terms.