Privacy Policy

Last updated: August 21, 2026

This policy describes what data Evident ("we", "us", "our") collects when you use Evident (the "Service"), why, who we share it with, and how long we keep it.

1. Evident never runs your code

Your repository, your secrets and your tools stay on the machine you run the runner on — nothing executes on Evident's servers, and Evident keeps no copy of your repository. Chat traffic is proxied through Evident to reach your machine, and the messages you send are stored so they can be queued while your runner is offline. The rest of this policy covers what that storage involves.

2. Information we collect

  • Account information. Your name and email address, collected and authenticated through our identity provider (Clerk) when you sign up or sign in.
  • Connector data. What's needed to relay messages to and from your runner — for example a Slack workspace/app installation, a GitHub App installation, or the inbound email address assigned to your runner. We don't read your Slack or GitHub workspace beyond what those platforms' own permission grants allow.
  • Messages you send to trigger a run. The content of a message, any attachment metadata, and — if the run fails — the resulting error text. See §4 for how long we keep this.
  • Billing information. Subscription and payment details are handled by our billing provider; we don't store your card number ourselves.
  • Usage and analytics data. Standard web analytics (via PostHog, hosted in the EU) on how the marketing site and product are used — pages visited, feature usage, and similar events. We don't send message content or code to our analytics provider.

3. How we use it

We use this information to:

  • Operate the Service — authenticate you and relay messages to your runner;
  • Bill you for your plan and provide support;
  • Understand how the Service is used, so we can improve it; and
  • Detect and prevent abuse, and keep the Service secure.

4. How long we keep it

A queued message's content, any error text, and attachment metadata are cleared 30 days after the message finishes processing. The underlying record — that a message existed, when, and its outcome — is kept indefinitely, since it's what our usage reporting and support tooling rely on; only the content itself is cleared. The identifier of who sent a message is kept a bit longer than the content — up to 180 days after the message finishes processing — because it's used for usage analytics (like active-user counts) over that window; after that, it's cleared too.

Account and billing records are kept for as long as your account is active, and afterward as required for accounting or legal purposes.

5. Who we share it with

We share data with the providers that make the Service work, and with no one else, except where the law requires it:

  • Clerk — authentication and subscription billing.
  • Cloudflare — hosting and running our API.
  • Our database provider — storing the data described above.
  • PostHog (EU region) — product and site analytics.
  • AWS — only if you choose to deploy a runner into your own AWS account (currently in preview); in that case AWS hosts your runner, not us.
  • Slack, GitHub, your email provider, and your model provider — only to the extent you connect them, so messages and results can flow to and from your runner.

We don't sell your data.

6. Cookies and analytics

Our marketing site and product use PostHog, hosted in the EU, to understand how they're used. To ask us not to track your usage, email support@evident.run.

7. Your rights

You can ask us to access, correct, or delete the personal data we hold about you, or export it, by emailing support@evident.run. We'll respond within a reasonable time. Deleting your account removes your account and connector data; message content already redacted under §4 cannot be restored.

8. Children's privacy

The Service is intended for business use and isn't directed at children. We don't knowingly collect personal data from children.

9. International data

Because our providers operate internationally, your data may be processed in a country other than your own. We choose providers that apply appropriate safeguards for that transfer.

10. Changes to this policy

We may update this policy as the Service evolves. We'll update the "Last updated" date above when we do, and for material changes we'll make reasonable efforts to let you know before they take effect.

11. Contact

Questions about this policy, or a request under §7? Reach us at support@evident.run.