Last updated October 4, 2026

# Privacy Policy

Your data, the purposes we use it for, and the choices you have.

## 1. Who is responsible

The controller under the General Data Protection Regulation (GDPR, or DSGVO in German) is:

Jannis Arndt - Programmierung und Handel  
Oldekopstrasse 38b  
30659 Hannover  
Germany  
[info@getevident.app](mailto:info@getevident.app)

Evident is the service name of this business, not a separate legal entity. This notice covers our website, waitlist, newsletter, inquiries, our own account administration, and billing. The rules for personal data entrusted to us by customers are explained below.

## 2. Website delivery and security

When you visit, Cloudflare delivers and protects the website. This involves your IP address, requested URL, request time, browser and operating system information, referrer, response status, and security signals. These data are needed to send you the requested page, prevent attacks, and investigate errors.

Our legal basis is Article 6(1)(f) GDPR. Our legitimate interests are a functioning, secure website and preventing abuse. Data strictly necessary to provide a service you request may also be processed under Article 6(1)(b) GDPR. Fonts and the website’s integration logos are served as website assets; viewing a logo does not connect your account to that provider.

Our form abuse protection keeps a hashed email address, attempt counter, and expiry in application memory for a ten-minute rate-limit window. Expired entries are discarded when subsequent requests are processed or the process restarts. We do not use this information for advertising.

## 3. Contact and support

When you contact us, we process your name, email address, message, attachments you choose to send, and related correspondence to answer and follow up. The website contact form sends your message to our team through Loops; it does not subscribe you to marketing.

Article 6(1)(b) GDPR applies to inquiries about your own contract or a requested offer. For other inquiries, including correspondence with someone acting for a business, Article 6(1)(f) GDPR applies: our legitimate interest is communicating and resolving the request. Please avoid sending payment-card details, passwords, or unnecessary information about other people.

## 4. Waitlist, newsletter, and service emails

The waitlist uses your email address and the name you provide for early-access messages. The newsletter is a separate subscription for occasional Evident product news. Submitting either signup requests only that subscription; a purchase or analytics consent is not required.

We use consent under Article 6(1)(a) GDPR and Section 7(2) no. 2 UWG for these optional emails. We ask you to confirm a new subscription by email (double opt-in). Subscription and confirmation records help demonstrate that consent. You can unsubscribe through the link in an email or by writing to us, without giving a reason. Withdrawal does not affect processing before withdrawal.

Necessary login, support, security, and contractual notices are separate from marketing and rely on Article 6(1)(b), (c), or (f) GDPR according to their purpose. Loops processes addresses, names, message content, subscription choices, and delivery/bounce information to send and manage emails. Website analytics consent does not authorize email open or click tracking.

## 5. Accounts and authentication with WorkOS

Where you use an Evident account, WorkOS handles registration, login, verification, and session management. Depending on your login method, this includes your name, email, account and organization identifiers, verification status, authentication tokens, login times, IP address, and security information. If you choose single sign-on, your identity provider supplies the identity information needed for that login. An organization that invites you or administers your workspace may also supply your work email, organization membership, and access role.

Article 6(1)(b) GDPR applies where needed to provide your account and contract. For organizational users who are not themselves our contracting party, Article 6(1)(f) GDPR supports our and the organization’s interest in authorized access. Security and abuse prevention also rely on Article 6(1)(f). Necessary authentication storage is used only for the login service you request, under Section 25(2) no. 2 TDDDG.

The public landing page does not create an account when you join the waitlist. A waitlist entry is not an account registration.

## 6. Payments, subscriptions, and usage billing

We use Stripe for checkout and payment processing, and Autumn (Rebase, Inc.) to manage plans, subscriptions, feature entitlements, and billable usage. This can involve your name, email, billing address, tax details, customer and subscription identifiers, selected plan, invoices, amounts, payment status, and usage records needed to calculate the agreed charges.

Payment credentials entered in Stripe Checkout are handled by Stripe. Evident receives the payment and billing records needed to manage your purchase, rather than needing your complete card number or security code. Autumn receives customer, subscription, and usage information relevant to billing. Server records needed to calculate your agreed charges are separate from optional website analytics. This does not authorize optional device tracking without consent.

We rely on Article 6(1)(b) GDPR to perform your contract, Article 6(1)(c) for tax and accounting duties, and Article 6(1)(f) for the legitimate interests of preventing payment misuse and managing business-customer relationships. Billing information comes from you, your organization where applicable, the service’s usage records, and updates from Stripe and Autumn.

Stripe acts as a processor for some payment activities and as an independent controller for others, including its own legal compliance and fraud prevention. Its privacy notice explains those purposes, recipients, and rights. Payment-method providers and banks also receive information needed to execute the payment. A visit to the public landing page alone does not open Stripe Checkout.

## 7. Optional website analytics

With your Analytics consent, Databuddy measures page visits, referrer and campaign information, browser/device characteristics, approximate location derived from an IP address, sessions, and page performance. The browser sends visitor/session identifiers and technical request information. We send named events when a form request succeeds, without including the entered name, email, or message in those events.

Databuddy uses browser storage for identifiers even though it does not use conventional analytics cookies. We therefore request consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR before loading its script or collecting analytics. These identifiers should not be treated as inherently anonymous. We do not call Databuddy’s identity-linking feature on this website.

You can reject analytics without losing access to the website or forms. To change your choice or withdraw consent, use Cookie preferences. See the [Cookie Policy](https://getevident.app/cookies) for storage details. We do not currently use Google advertising tags or Meta Pixel.

## 8. Consent preferences

We use c15t to remember and apply your privacy choices. It stores chosen categories, a timestamp, and consent identifiers in a first-party cookie and browser local storage.

This website also uses a consent backend to record and apply your choice. It receives consent records and technical request information, including the IP address needed to deliver the request. This is separate from optional website analytics.

Necessary device storage relies on Section 25(2) no. 2 TDDDG. Recording and demonstrating consent relies on Article 6(1)(c), read with Articles 5(2) and 7(1) GDPR; applying a refusal and preventing unwanted tracking also serves our legitimate interest under Article 6(1)(f).

## 9. Customer evidence and our role as processor

If a customer connects business tools or supplies evidence, the customer normally determines the purpose and legal basis for that data. It can include customer identifiers, transaction/subscription records, payment authentication, support correspondence, usage signals, and dispute materials. Processing personal data on a customer’s behalf requires an Article 28 GDPR data processing agreement (DPA) before that processing begins. The customer’s documented instructions govern that processing, subject to applicable law. Where the customer is itself a processor, the chain must also be authorized by its controller.

The DPA must identify the actual integrations, subprocessors, security measures, retention/deletion instructions, and international transfers for that service. This privacy notice does not replace it or give us permission to use customer evidence for unrelated purposes.

If a business uses Evident to process your data, contact that business to exercise your rights. You may also contact us; we will help route your request and assist the controller. Illustrative customer records in the public website demos are fictional.

## 10. Database storage with Neon

We use Neon for database storage in an EU region. The database supports account and workspace records and data used to provide the service. Our controller purposes and legal bases are those described for accounts, security, and billing above. Customer evidence remains subject to the customer’s instructions and the applicable DPA.

The database’s EU location does not mean that every service provider, support operation, or AI request is located in the EU. Database storage, access from other countries, backup retention, and downstream processing are separate parts of the data lifecycle.

## 11. AI classification and dispute preparation

Evident uses OpenRouter to access AI models for classifying data and preparing dispute material. The models we use include Google Gemini, OpenAI models, and Jev by TypeSafe AI. We access these model services through OpenRouter’s API integration within the product.

Before inference, we obscure personal details and limit the information supplied for the task. Depending on the task, this can include masked evidence, transaction context, and text needed for classification or drafting. Removing direct identifiers does not necessarily make all contextual data anonymous. The output can also relate to a person when combined with the customer’s records.

OpenRouter is configured to exclude providers that train on the requests. This is a no-training setting; it is not a promise of zero retention or EU-only inference. Request metadata, security processing, and any provider retention are separate from model training. OpenRouter and the provider serving the selected model can process the information needed to fulfil the request.

For customer-controlled personal data, this processing must stay within the customer’s instructions and the agreed processing and transfer safeguards. We do not obtain a general permission to train models on customer evidence by publishing this notice. Generated classifications and drafts need review for accuracy and suitability before they are relied on or submitted.

## 12. Recipients and international processing

Access is limited to people who need it for their work and providers used for the relevant purpose. The following providers are part of our service:

- **Cloudflare, Inc., United States:** hosting, delivery, and security. [Privacy notice](https://www.cloudflare.com/privacypolicy/); [data processing terms](https://www.cloudflare.com/cloudflare-customer-dpa/).
- **WorkOS, Inc., United States:** account authentication. [Privacy notice](https://workos.com/legal/privacy); [data processing terms](https://workos.com/legal/data-processing-addendum).
- **Astrodon Corporation (Loops), United States:** email delivery and subscription management. [Privacy notice](https://loops.so/privacy); [data processing terms](https://loops.so/dpa).
- **Stripe:** checkout and payments, involving its European entities and international affiliates as specified in its [privacy notice](https://stripe.com/privacy) and [data processing agreement](https://stripe.com/legal/dpa).
- **Rebase, Inc. (Autumn), United States:** subscription administration, entitlements, and usage billing. [Privacy and transfer information](https://useautumn.com/privacy).
- **Databuddy Analytics, Inc.:** optional analytics. [Data processing and infrastructure information](https://www.databuddy.cc/data-policy); [data processing terms](https://www.databuddy.cc/dpa).
- **c15t:** consent software and consent-record handling as described above. [Privacy resources](https://c15t.com/privacy).
- **Neon, part of Databricks:** database hosting in an EU region. [Neon service terms](https://neon.com/platform-terms); [data processing terms](https://www.databricks.com/legal/data-processing-addendum).
- **OpenRouter, Inc., United States:** AI request routing and inference services. [Privacy notice](https://openrouter.ai/privacy); [data processing terms](https://openrouter.ai/data-processing-agreement); [downstream provider data handling](https://openrouter.ai/docs/guides/privacy/provider-logging). The model services described above include Google Gemini, OpenAI models, and TypeSafe AI’s Jev; the provider serving a model depends on its route. TypeSafe AI, Inc. publishes its [privacy notice](https://typesafe.ai/legal/privacy-policy).

These providers can involve processing outside the European Economic Area, including in the United States. EU database storage and no-training settings do not, on their own, prevent international transfers. Cloudflare, WorkOS, and Loops publish contractual transfer safeguards in their data processing terms, including EU Standard Contractual Clauses. An adequacy decision can apply only where its requirements are met; US location alone does not establish Data Privacy Framework coverage. Stripe publishes a data processing agreement and transfer terms; Autumn’s privacy notice describes Standard Contractual Clauses for relevant transfers. Databuddy’s locations depend on its infrastructure and enabled services.

You can request information about the safeguards applicable to your data, including a copy, using the contact above. We may redact information needed to protect others. We may also disclose necessary information to professional advisers or authorities where required by law or necessary for legal claims, under Article 6(1)(c) or (f) GDPR.

## 13. How long data is kept

Retention follows the purpose of each record, applicable legal duties, and any specific dispute. Where a fixed duration cannot be given, the following criteria apply:

- **Inquiries:** until resolved and any necessary follow-up is complete. Correspondence that documents a transaction or claim is retained separately for the applicable legal period.
- **Subscriptions:** while the subscription is active; waitlist data is no longer needed when invitations and related follow-up are complete. Unconfirmed requests are not used for marketing. A limited suppression record may be retained to respect an unsubscribe, and necessary consent evidence to demonstrate lawful sending or defend a claim.
- **Accounts:** for the account relationship and its closure, except for specific records required for legal duties, security investigations, or claims. Customer evidence follows the customer’s DPA and deletion instructions.
- **Security logs:** for the investigation and prevention of incidents and the operation of the relevant Cloudflare or WorkOS feature; an incident can require longer preservation of the specific records involved.
- **Consent storage:** the c15t cookie is configured for 180 days. Local storage has no browser-enforced expiry and remains until replaced or cleared. Any separately retained proof of consent is distinct from permission to keep tracking.
- **Analytics:** Databuddy retains project data until deletion is requested or the project/account is deleted; its published data policy does not guarantee automatic expiry. Withdrawing consent stops future collection and does not itself delete historical records. You may also request erasure under the conditions described below; browser storage duration does not determine the retention of server records.
- **Database and AI records:** evidence and derived outputs follow the relevant customer’s instructions and DPA, including return, deletion, and any necessary backup or legal-hold treatment. The OpenRouter no-training setting does not establish a retention period for inference content or request metadata.
- **Required business records:** where applicable, German law generally requires ten years for books and annual accounts, eight years for accounting vouchers, and six years for commercial correspondence (Section 147 AO / Section 257 HGB). The type of record, statutory starting point, and any permitted extension determine the actual period.

Legal retention does not justify keeping an entire account or using archived records for new marketing. Restricted records are kept only for their remaining lawful purpose.

## 14. Your GDPR rights

Subject to the applicable conditions, you can request access (Article 15), correction (16), erasure (17), restriction (18), and a portable copy of data processed by automated means on consent or contract (20). You can withdraw consent at any time (7(3)), without affecting prior lawful processing.

**Right to object:** under Article 21, you can object to processing based on Article 6(1)(f) for reasons relating to your situation. We will stop unless we demonstrate overriding compelling grounds or need the processing for legal claims. You can object to direct marketing at any time, including associated profiling, without giving a reason; we will stop that use.

Email [info@getevident.app](mailto:info@getevident.app) or write to the address above. Requests are normally free. We respond without undue delay and within one month of receipt. If a lawful extension of up to two further months is needed, we will explain it within the first month. We request additional identification only where needed to resolve reasonable doubt about identity.

You can complain to a supervisory authority, especially where you live or work or where the alleged infringement occurred. Our local authority is [Der Landesbeauftragte für den Datenschutz Niedersachsen](https://www.lfd.niedersachsen.de/), Prinzenstraße 5, 30159 Hannover, Germany; [poststelle@lfd.niedersachsen.de](mailto:poststelle@lfd.niedersachsen.de). You do not need to contact us first.

## 15. Requests from US residents

US state privacy rights depend on your state, the activity, and whether the relevant law applies to that processing. Where applicable, rights may include access, correction, deletion, a portable copy, and opting out of sale, targeted advertising, or certain profiling, as well as protections for sensitive information. The GDPR rights above apply to processing within the scope of the GDPR regardless of nationality.

Send requests to [info@getevident.app](mailto:info@getevident.app). Tell us which right you wish to exercise and, for a state-law request, your state of residence. We use proportionate identity checks when needed; an authorized agent may submit a request with evidence of authority where permitted by law. We do not require identification merely to block this website’s optional analytics.

We respond within the applicable legal deadline and explain any permitted extension or refusal. Where a state law gives you an appeal right, reply to our decision or email us with “Privacy appeal” and the reasons for your appeal. We will explain the outcome and any applicable route to your state regulator. Exercising a protected privacy right does not result in unlawful discrimination.

This public website does not use Meta Pixel or Google advertising tags. It blocks optional Databuddy analytics when your browser communicates Global Privacy Control or Do Not Track, even if Analytics was previously selected. See the [Cookie Policy](https://getevident.app/cookies). For data handled on behalf of a business customer, that customer normally handles the request as controller, with our assistance. This section does not imply that every US state privacy law applies to every use of Evident.

## 16. Required data and automated decisions

You do not have to join a mailing list or allow analytics. An email address is needed to reply or send a requested subscription; account identity information is needed to authenticate you. If required information is not supplied, we cannot provide the corresponding function. Other legal or contractual requirements will be identified when information is requested.

We do not make solely automated decisions about website visitors or mailing-list subscribers that have legal or similarly significant effects under Article 22 GDPR. Any assessment of automated decisions involving a customer’s evidence must consider that customer’s actual workflow and responsibilities. The website is not directed at children.

## 17. Changes and contact

We update this notice when our processing changes and show its revision date at the top. Where a material change requires advance information, we provide that information before the changed processing, using the service or an appropriate direct communication. New purposes or providers that require consent will not be authorized merely by updating this page. Contact us using the details above for privacy questions, requests, or copies of relevant safeguards.

Canonical page: https://getevident.app/privacy
