Privacy Policy

Last updated: August 2026

Your Privacy Matters

At EVE AI Core, we are committed to protecting your privacy and being transparent about how we collect, use, and share your information.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

1.2 Usage Data

We automatically collect information about your use of the service:

1.3 Payment Information

If you subscribe to a paid plan, we use Stripe to process payments. We do not store your full credit card number; Stripe handles all payment data securely.

1.4 Support and Service Communications

When you contact us or open a request through EVE CoreGuard Support (our support ticketing system), we collect and process:

Support records are isolated to your organization — no other customer can access them — every action on a ticket is recorded in a tamper-evident, hash-chained audit trail, and attachments are stored in a location partitioned per organization. We use this information only to receive, investigate, and resolve your request, to meet the service levels associated with your plan, and to maintain a compliant record of the interaction.

2. How We Use Your Information

We use the information we collect to:

3. Data Storage and Security

3.1 Storage

Your data is stored on secure servers. Conversation data may be stored locally on the server for session continuity and is encrypted at rest.

3.2 Security Measures

We implement industry-standard security measures including:

4. Governance Data Processing

EVE AI Core processes AI model outputs through our governance pipeline. This includes intent classification, charter compliance checks, and CRD scoring. No personal data is used in the governance verification process — only the AI output text is analyzed.

5. Audit Trail Data

Our cryptographic audit trail records verification decisions with SHA-256 hash chains. These records contain governance metadata (scores, verdicts, timestamps) but do not include personally identifiable information.

6. Data Sharing

We do not sell your personal information. We may share your information only in these circumstances:

7. Your Rights

You have the following rights regarding your data:

Right Description
Access Request a copy of your personal data
Correction Request correction of inaccurate data
Deletion Request deletion of your personal data
Portability Request your data in a portable format
Objection Object to certain processing of your data

7A. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you specific rights regarding your personal information. This section supplements the rest of this Privacy Policy.

7A.1 Categories of Personal Information We Collect

In the preceding 12 months we may have collected the following categories of personal information. In most cases this information relates to business contacts at our customer and prospect organizations rather than to consumers.

Category Examples Sources Purpose Retention
Identifiers Name, email address, organization name, account/user ID Directly from you at sign-up or when you contact us Provide and secure the service; account management; communications Retained for the life of the account and for a limited period afterward to meet legal, tax, and audit obligations
Commercial information Plan and subscription details, transaction records From you and our payment processor (Stripe) Process payments; billing; support Retained for as long as required to satisfy tax, accounting, and audit obligations
Internet or other electronic network activity Feature usage, error and performance logs, device and browser information, IP address Automatically from your use of the service Operate, secure, and improve the service Retained for a limited period sufficient for security and operational purposes
Professional or employment information Job role or title and employer for business (B2B) contacts From you or your organization Account administration; business communications Retained for the duration of the business relationship and for a limited period afterward

We disclose personal information for a business purpose to the categories of recipients described in Section 6 (Data Sharing) — principally our payment processor (Stripe) and hosting and infrastructure providers acting as service providers under contract, and to authorities where required by law. Account log-in credentials, including your authentication token, are used solely to authenticate you and secure your session; we do not use or disclose them for any other purpose, and we do not use sensitive personal information to infer characteristics about you.

7A.2 Your California Rights

We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share personal information, a “Do Not Sell or Share My Personal Information” link is not applicable to our service. We also do not use or disclose sensitive personal information for purposes that would require us to offer a “Limit the Use of My Sensitive Personal Information” option.

7A.3 How to Submit a Request

To exercise any of these rights, email legal@eveaicore.com describing the nature of your request. You may use an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization and may still ask you to verify your own identity directly. To protect your information, we will take reasonable steps to verify your identity before responding, which may involve confirming information already associated with your account. We will confirm receipt of your request within 10 business days and describe how we will process it. We will respond to verifiable requests within 45 days; if we require more time (up to an additional 45 days), we will notify you.

7B. European Economic Area, UK & Swiss Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the EU General Data Protection Regulation and the equivalent UK and Swiss frameworks give you the rights described below. This section supplements the rest of this Privacy Policy.

Data Controller

The controller responsible for your personal data is EVE NeuroSystems LLC, 3480 Preston Ridge Road, 5th Floor, Suite 5109, Alpharetta, GA 30005, United States. You can reach us on data protection matters at legal@eveaicore.com. We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR; individuals in the EEA, the UK, and Switzerland may contact us directly at that address regarding any data protection matter.

7B.1 Lawful Bases for Processing

We process personal data only where we have a lawful basis to do so. Depending on the circumstances, our lawful bases include:

7B.2 Your Rights

7B.3 International Transfer Safeguards

We are based in the United States, so using the service involves transferring your personal data to the United States and potentially other countries. The specific safeguards we rely on for these transfers — principally the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable — are described in Section 11 (International Data Transfers).

7B.4 Lodging a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority (for example, in the UK the Information Commissioner’s Office, and in Switzerland the Federal Data Protection and Information Commissioner). We would, however, appreciate the opportunity to address your concerns first — please contact us at legal@eveaicore.com.

7B.5 Data Retention

We keep personal data only for as long as necessary for the purposes described in this policy. In general, account data is retained for the life of the account and for a limited period afterward; billing records are retained for as long as required to meet tax, accounting, and audit obligations; and security and operational logs are retained for a limited period. See Section 9 (Data Retention) for further detail.

8. Cookies and Tracking

EVE AI Core uses cookies sparingly and only where they are strictly necessary for the service to function. We do not use analytics cookies, advertising cookies, or third-party tracking cookies on our website, and we do not build advertising or behavioral profiles of visitors.

Cookie Purpose
Session / authentication (JWT) A strictly-necessary session cookie holding your signed authentication token. It is set only in the authenticated application areas (/app and /auth) to keep you signed in and secure your session. The service cannot function without it.

Your interface preferences — such as light or dark theme — are stored locally in your browser using localStorage, not in a cookie. This information stays on your device and is not transmitted to us for tracking.

No analytics, no advertising, no data sale

We do not load Google Analytics, tag managers, advertising pixels, or other third-party trackers, and we do not sell or share your personal information for cross-context behavioral advertising. Because the session and authentication cookies we use are strictly necessary to deliver the service you request, consent is not legally required for those cookies; this notice is provided for transparency and is consent-ready should we introduce non-essential cookies in the future.

If we introduce analytics or any other non-essential cookies in the future, we will update this policy and request your consent before those cookies are set. This section is the authoritative description of the cookies we use.

8A. Automated Decision-Making and Profiling

EVE AI Core is governance infrastructure for our customers' AI systems. EVE does not use your personal information to make decisions that produce legal or similarly significant effects about you through solely automated means. Where our customers deploy AI that makes such decisions, the customer — not EVE — is the controller responsible for the corresponding obligations (including any right to obtain human review) under Article 22 of the GDPR and comparable laws. EVE's own automated processing of your information is limited to operating, securing, and supporting the service.

9. Data Retention

We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your account and associated data at any time.

Support tickets, comments, and attachments are retained for the life of your organization's account and may be removed on request. When support data is erased we generate a signed, tamper-evident deletion record so the erasure can be independently verified. Where a legal hold or regulatory retention obligation applies (for example, audit records tied to a governance decision), data may be retained for the period required to satisfy that obligation.

10. Children's Privacy

EVE AI Core is not intended for users under 18 years of age. We do not knowingly collect information from children under 18.

11. International Data Transfers

EVE NeuroSystems LLC is based in the United States, and your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.

Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we put appropriate safeguards in place — principally the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable — so that your personal data continues to receive an equivalent level of protection. We also apply appropriate technical and organizational measures, including encryption in transit and at rest, to protect data during and after transfer. To request more information about these safeguards, contact legal@eveaicore.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

12A. Accessibility

We want EVE AI Core to be usable by everyone, including people with disabilities, and we treat accessibility as an ongoing part of how we build and maintain the service.

Our Accessibility Commitment

We aim to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. Conformance is an ongoing effort and is currently partial; we continue to test and improve the accessibility of our website and application over time. We do not claim full or complete conformance.

If you encounter an accessibility barrier, or need information from this site provided in an alternative accessible format, contact us at legal@eveaicore.com or +1 (678) 578-4829. Please describe the barrier and the page or feature involved. We will respond within a reasonable time and work to provide the information or functionality you need in an accessible form.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, or to exercise your data rights, contact us at legal@eveaicore.com.

Questions?

For any privacy-related concern or to exercise your rights (access, correction, deletion, or portability), email legal@eveaicore.com or visit our documentation.