Privacy Policy
Last updated: August 2026
Your Privacy Matters
At EVE AI Core, we are committed to protecting your privacy and being transparent about how we collect, use, and share your information.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Password (encrypted)
- Name (optional)
- Organization name (if applicable)
1.2 Usage Data
We automatically collect information about your use of the service:
- Conversation logs (encrypted)
- Feature usage patterns
- Error logs and performance data
- Device and browser information
- IP address
1.3 Payment Information
If you subscribe to a paid plan, we use Stripe to process payments. We do not store your full credit card number; Stripe handles all payment data securely.
1.4 Support and Service Communications
When you contact us or open a request through EVE CoreGuard Support (our support ticketing system), we collect and process:
- The subject and description of your request, and any subsequent replies or comments you add
- Files you choose to attach (e.g., logs or screenshots), restricted to a permitted set of file types and size limits
- Your identity and contact details (user ID and email) and the organization the request belongs to
- Any governance Decision ID you reference, used solely to retrieve the related signed decision evidence for investigation
Support records are isolated to your organization — no other customer can access them — every action on a ticket is recorded in a tamper-evident, hash-chained audit trail, and attachments are stored in a location partitioned per organization. We use this information only to receive, investigate, and resolve your request, to meet the service levels associated with your plan, and to maintain a compliant record of the interaction.
2. How We Use Your Information
We use the information we collect to:
- Provide and maintain the EVE AI Core service
- Process transactions and send related information
- Send you technical notices and support messages
- Respond to your comments, questions, and requests
- Analyze usage patterns to improve our service
- Detect, prevent, and address technical issues
- Research and develop new features
3. Data Storage and Security
3.1 Storage
Your data is stored on secure servers. Conversation data may be stored locally on the server for session continuity and is encrypted at rest.
3.2 Security Measures
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for sensitive data
- Regular security audits
- Access controls and authentication
- Secure password hashing (bcrypt)
- Deterministic governance enforcement (AIMS; FPGA hardware-isolation on the roadmap)
- Cryptographic attestation of all verification decisions
- Deterministic policy enforcement that cannot be bypassed
4. Governance Data Processing
EVE AI Core processes AI model outputs through our governance pipeline. This includes intent classification, charter compliance checks, and CRD scoring. No personal data is used in the governance verification process — only the AI output text is analyzed.
5. Audit Trail Data
Our cryptographic audit trail records verification decisions with SHA-256 hash chains. These records contain governance metadata (scores, verdicts, timestamps) but do not include personally identifiable information.
6. Data Sharing
We do not sell your personal information. We may share your information only in these circumstances:
- Service Providers: With third parties who help us operate our service (e.g., Stripe for payments)
- Legal Requirements: When required by law or to protect rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize sharing
7. Your Rights
You have the following rights regarding your data:
| Right | Description |
|---|---|
| Access | Request a copy of your personal data |
| Correction | Request correction of inaccurate data |
| Deletion | Request deletion of your personal data |
| Portability | Request your data in a portable format |
| Objection | Object to certain processing of your data |
7A. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you specific rights regarding your personal information. This section supplements the rest of this Privacy Policy.
7A.1 Categories of Personal Information We Collect
In the preceding 12 months we may have collected the following categories of personal information. In most cases this information relates to business contacts at our customer and prospect organizations rather than to consumers.
| Category | Examples | Sources | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Name, email address, organization name, account/user ID | Directly from you at sign-up or when you contact us | Provide and secure the service; account management; communications | Retained for the life of the account and for a limited period afterward to meet legal, tax, and audit obligations |
| Commercial information | Plan and subscription details, transaction records | From you and our payment processor (Stripe) | Process payments; billing; support | Retained for as long as required to satisfy tax, accounting, and audit obligations |
| Internet or other electronic network activity | Feature usage, error and performance logs, device and browser information, IP address | Automatically from your use of the service | Operate, secure, and improve the service | Retained for a limited period sufficient for security and operational purposes |
| Professional or employment information | Job role or title and employer for business (B2B) contacts | From you or your organization | Account administration; business communications | Retained for the duration of the business relationship and for a limited period afterward |
We disclose personal information for a business purpose to the categories of recipients described in Section 6 (Data Sharing) — principally our payment processor (Stripe) and hosting and infrastructure providers acting as service providers under contract, and to authorities where required by law. Account log-in credentials, including your authentication token, are used solely to authenticate you and secure your session; we do not use or disclose them for any other purpose, and we do not use sensitive personal information to infer characteristics about you.
7A.2 Your California Rights
- Right to know / access: Request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete: Request deletion of the personal information we collected from you, subject to legal exceptions.
- Right to correct: Request correction of inaccurate personal information.
- Right to data portability: Receive a copy of your personal information in a portable, readily usable format.
- Right to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information.
- Right to non-discrimination: We will not discriminate against you for exercising any of these rights.
We do not sell or share your personal information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share personal information, a “Do Not Sell or Share My Personal Information” link is not applicable to our service. We also do not use or disclose sensitive personal information for purposes that would require us to offer a “Limit the Use of My Sensitive Personal Information” option.
7A.3 How to Submit a Request
To exercise any of these rights, email legal@eveaicore.com describing the nature of your request. You may use an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization and may still ask you to verify your own identity directly. To protect your information, we will take reasonable steps to verify your identity before responding, which may involve confirming information already associated with your account. We will confirm receipt of your request within 10 business days and describe how we will process it. We will respond to verifiable requests within 45 days; if we require more time (up to an additional 45 days), we will notify you.
7B. European Economic Area, UK & Swiss Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the EU General Data Protection Regulation and the equivalent UK and Swiss frameworks give you the rights described below. This section supplements the rest of this Privacy Policy.
Data Controller
The controller responsible for your personal data is EVE NeuroSystems LLC, 3480 Preston Ridge Road, 5th Floor, Suite 5109, Alpharetta, GA 30005, United States. You can reach us on data protection matters at legal@eveaicore.com. We have not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR; individuals in the EEA, the UK, and Switzerland may contact us directly at that address regarding any data protection matter.
7B.1 Lawful Bases for Processing
We process personal data only where we have a lawful basis to do so. Depending on the circumstances, our lawful bases include:
- Performance of a contract: to provide the service you or your organization have requested and to administer your account.
- Legitimate interests: to secure, operate, maintain, and improve the service, prevent abuse, and communicate with business contacts — balanced against your rights and interests.
- Consent: where we ask for it, such as for optional communications or any non-essential cookies we may introduce in the future. You may withdraw consent at any time.
- Legal obligation: to comply with applicable laws, regulatory obligations, and lawful requests.
7B.2 Your Rights
- Access: obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: request deletion of your data (the “right to be forgotten”), subject to legal exceptions.
- Restriction: request that we limit how we process your data.
- Portability: receive your data in a structured, commonly used, machine-readable format.
- Objection: object to processing based on our legitimate interests.
- Withdraw consent: withdraw any consent you have given, without affecting processing already carried out.
7B.3 International Transfer Safeguards
We are based in the United States, so using the service involves transferring your personal data to the United States and potentially other countries. The specific safeguards we rely on for these transfers — principally the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable — are described in Section 11 (International Data Transfers).
7B.4 Lodging a Complaint
You have the right to lodge a complaint with your local data protection supervisory authority (for example, in the UK the Information Commissioner’s Office, and in Switzerland the Federal Data Protection and Information Commissioner). We would, however, appreciate the opportunity to address your concerns first — please contact us at legal@eveaicore.com.
7B.5 Data Retention
We keep personal data only for as long as necessary for the purposes described in this policy. In general, account data is retained for the life of the account and for a limited period afterward; billing records are retained for as long as required to meet tax, accounting, and audit obligations; and security and operational logs are retained for a limited period. See Section 9 (Data Retention) for further detail.
8. Cookies and Tracking
EVE AI Core uses cookies sparingly and only where they are strictly necessary for the service to function. We do not use analytics cookies, advertising cookies, or third-party tracking cookies on our website, and we do not build advertising or behavioral profiles of visitors.
| Cookie | Purpose |
|---|---|
| Session / authentication (JWT) | A strictly-necessary session cookie holding your signed authentication token. It is set only in the authenticated application areas (/app and /auth) to keep you signed in and secure your session. The service cannot function without it. |
Your interface preferences — such as light or dark theme — are stored locally in your browser using localStorage, not in a cookie. This information stays on your device and is not transmitted to us for tracking.
No analytics, no advertising, no data sale
We do not load Google Analytics, tag managers, advertising pixels, or other third-party trackers, and we do not sell or share your personal information for cross-context behavioral advertising. Because the session and authentication cookies we use are strictly necessary to deliver the service you request, consent is not legally required for those cookies; this notice is provided for transparency and is consent-ready should we introduce non-essential cookies in the future.
If we introduce analytics or any other non-essential cookies in the future, we will update this policy and request your consent before those cookies are set. This section is the authoritative description of the cookies we use.
Our web fonts are self-hosted from our own domain (no Google Fonts request), and we use no analytics, advertising, or tracking CDNs. Some interactive pages load open-source display libraries (e.g., Chart.js, three.js) from public content-delivery networks (jsDelivr, unpkg); those requests expose your IP address to the CDN as part of delivering the file but set no cookie and are not used to track you. See our licenses page.
8A. Automated Decision-Making and Profiling
EVE AI Core is governance infrastructure for our customers' AI systems. EVE does not use your personal information to make decisions that produce legal or similarly significant effects about you through solely automated means. Where our customers deploy AI that makes such decisions, the customer — not EVE — is the controller responsible for the corresponding obligations (including any right to obtain human review) under Article 22 of the GDPR and comparable laws. EVE's own automated processing of your information is limited to operating, securing, and supporting the service.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your account and associated data at any time.
Support tickets, comments, and attachments are retained for the life of your organization's account and may be removed on request. When support data is erased we generate a signed, tamper-evident deletion record so the erasure can be independently verified. Where a legal hold or regulatory retention obligation applies (for example, audit records tied to a governance decision), data may be retained for the period required to satisfy that obligation.
10. Children's Privacy
EVE AI Core is not intended for users under 18 years of age. We do not knowingly collect information from children under 18.
11. International Data Transfers
EVE NeuroSystems LLC is based in the United States, and your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we put appropriate safeguards in place — principally the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable — so that your personal data continues to receive an equivalent level of protection. We also apply appropriate technical and organizational measures, including encryption in transit and at rest, to protect data during and after transfer. To request more information about these safeguards, contact legal@eveaicore.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
12A. Accessibility
We want EVE AI Core to be usable by everyone, including people with disabilities, and we treat accessibility as an ongoing part of how we build and maintain the service.
Our Accessibility Commitment
We aim to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. Conformance is an ongoing effort and is currently partial; we continue to test and improve the accessibility of our website and application over time. We do not claim full or complete conformance.
If you encounter an accessibility barrier, or need information from this site provided in an alternative accessible format, contact us at legal@eveaicore.com or +1 (678) 578-4829. Please describe the barrier and the page or feature involved. We will respond within a reasonable time and work to provide the information or functionality you need in an accessible form.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, or to exercise your data rights, contact us at legal@eveaicore.com.
Questions?
For any privacy-related concern or to exercise your rights (access, correction, deletion, or portability), email legal@eveaicore.com or visit our documentation.