Who and what this statement covers

Elevate is maintained by Frode Hus. This statement explains data handling by the product website, the macOS and Windows apps, the command-line tool, and project support. Frode Hus is responsible for personal information provided directly to the project for support or privacy enquiries.

Your organization controls its Microsoft tenant and the access-management data processed there. Microsoft and GitHub handle data through their respective services. Their responsibilities and policies are separate from the maintainer’s handling of project correspondence.

Visiting this website

The Elevate website does not add analytics, advertising, tracking pixels, cookies or browser storage. It has no sign-in form and does not request access to your Microsoft account. Fonts, images and scripts are served with the site. The copy-command button writes the displayed command to your clipboard only when you click it; it does not read your clipboard.

The site is hosted on GitHub Pages. GitHub states that it logs visitors’ IP addresses for security purposes, including visits made without signing in. Hosting therefore involves data processing even though the Elevate website has no analytics. See GitHub Pages data collection and the GitHub Privacy Statement.

Links to GitHub, Microsoft and other websites take you to services governed by their own privacy policies.

Data used by the apps and CLI

Elevate processes the information needed to display and manage your eligible access: account identifiers and names, tenants, role and group assignments, activation policies, active and pending requests, profiles, settings, and access-package information.

When you activate a role, make an approval decision or request an access package, the relevant account, role, duration, justification and other required request details are sent to Microsoft services. Tenant administrators and approvers may be able to see these details under your organization’s policies. Avoid putting unnecessary personal or confidential information in justifications.

Authentication takes place through Microsoft sign-in. Elevate receives authentication tokens to perform permitted actions as the signed-in user; it does not operate its own password service. See the app-registration and permissions guide.

The project publishes an optional shared multi-tenant app registration you may sign in with instead of creating your own. Using it sends nothing to the maintainer: there is no backend, no telemetry and no notification of who signs in. Tokens are issued by Microsoft to your device and stay there, and administrator consent is recorded between your organization’s tenant and Microsoft. The registration is offered as a convenience with no service level, and organizations that need control over it should register their own. See the shared app registration guide.

Local storage and credentials

Account and tenant information, remembered reasons, profiles, cached configuration and settings are stored locally. Token protection is separate from ordinary app settings: macOS uses Keychain, Windows uses a DPAPI-protected cache, and the CLI uses the platform’s protected credential storage, including the Linux keyring.

On Linux, the CLI can explicitly be configured to use an unprotected file cache when a keyring is unavailable. That option stores tokens without keyring protection. See the CLI documentation before enabling it. Protect your user account, device and backups.

Local data may remain until you remove accounts, clear the relevant state or credential cache, or delete it using your operating system’s tools. Uninstalling alone may leave settings or credentials behind. Removing local data does not delete records or audit logs already held by Microsoft or your organization.

Network connections and telemetry

Elevate does not send usage analytics, automatic crash reports or account and role data to a maintainer-operated backend. Normal operation connects to the Microsoft identity platform, Microsoft Graph and Azure Resource Manager.

The update check contacts GitHub’s releases API, normally once a day. GitHub receives ordinary connection information such as the source IP address. The update check can be controlled through app settings or organizational policy.

If your organization configures a remote profile set, Elevate also fetches it from the configured HTTPS address and caches it locally. The server operator can receive connection information. See managed profiles.

Microsoft services and organizational audit logs have their own retention and access rules. Refer to your organization’s privacy information and the Microsoft Privacy Statement.

Support information you choose to share

If you open an issue or send a report, the project receives your GitHub identity and whatever information you include. That information is used to respond, troubleshoot and maintain the project. The basis for this handling is the legitimate interest in supporting users and maintaining a secure open-source project, subject to your rights.

Public GitHub issues and comments are visible to others and may remain as part of the project’s public history. Private correspondence is retained only as long as needed to handle the enquiry, maintain relevant security records or meet legal obligations. GitHub manages storage and retention on its platform under its own policies.

Diagnostic reports are not submitted automatically. Review and redact reports before sharing them. Never publish access tokens, passwords or confidential tenant details. Use GitHub’s private vulnerability reporting for security vulnerabilities.

Your choices, rights and contact

You can stop using Elevate, remove its local data, and ask your tenant administrator about revoking app consent or access. Your organization may manage some settings centrally.

Where applicable, you can request access to, correction or deletion of personal information, restriction of processing, or data portability, and object to processing based on legitimate interests. These rights depend on the circumstances and applicable law. For information held by your organization, Microsoft or GitHub, contact that organization or service directly.

For privacy questions or requests concerning information held by the maintainer, open a GitHub issue requesting a private contact channel. Do not put your personal data or the details of the request in the public issue.

You may also complain to your local data-protection authority. In Norway, this is Datatilsynet.

Changes to this statement

This statement describes the current website and documented application behavior. It will be updated when relevant data-handling practices change, with the revision date shown above. Source and policy changes can be reviewed in the project repository.