Effective Date: September 15, 2026
AILYZE, Inc. ("AILYZE", "we", "us", or "our") is the provider of Evidano, the AI research platform available at www.evidano.com (the "Service").
This Privacy Policy describes how we collect, use, store, share, and protect personal information in connection with your use of the Service. It applies to information collected through the Service and through electronic communications between you and us. By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy.
This Policy forms part of, and should be read together with, our Terms of Service. Capitalized terms used but not defined here have the meanings given in the Terms of Service.
The following capitalized terms have the meanings given to them below:
Our obligations under data protection law depend on which data we are handling, and this Policy applies differently to each.
A Data Processing Agreement covering our role as your processor is available on request at info@evidano.com; see Section 14.
If you choose to sign in to the Service using a third-party identity provider, we receive limited profile information from that provider in order to create and authenticate your account.
When you sign in with Google, the Google user data we receive consists of your basic profile information — specifically your name, primary email address, Google account identifier, profile picture URL, and locale — as authorized by you through Google’s OAuth consent screen. Signing in requires only theopenid,email, andprofilescopes.
Separately, the Service offers optional integrations that you may connect at your own initiative. These are never part of sign-in, are never enabled by default, and each is authorized through its own Google consent screen that you can decline or revoke at any time. Where an integration requests a sensitive or restricted Google API scope, we request the narrowest scope that supports the feature, and we use the resulting data only to power that feature:
forms.body.readonly,forms.responses.readonly, anddrive.metadata.readonly. We read the titles of your forms so you can choose one, then read the questions and responses of the form you select. That content is imported into your Evidano workspace as Customer Data and analyzed at your direction. We do not modify or delete anything in your Google account.meetings.space.readonlyanddrive.readonly, which Google classifies as a restricted scope. We use this access solely to locate and retrieve the specific meeting recordings you select so they can be transcribed and analyzed within the Service. We do not browse, index, or retain the wider contents of your Google Drive.Content you import through these integrations is treated as Customer Data under this Policy: it is stored and processed on the same terms, it is never used to train our AI models, and you can delete it at any time. You may disconnect an integration at any time from within the Service, or revoke access directly from your Google account permissions page.
We use the information described above only for the following purposes:
Where the GDPR or UK GDPR applies and we act as a controller, we rely on the following legal bases under Article 6:
Where we process Customer Data as your processor, you determine the legal basis for that processing; we process it only on your instructions.
Google user data received through Google Sign-In is used solely to (a) create and authenticate your Evidano account, (b) display your name and profile picture within the Service so you can identify yourself, and (c) send you service-related emails at the address associated with your Google account.
Google user data received through the optional Google Forms and Google Meet integrations described in Section 4.3 is used solely to deliver the feature you connected it for — importing the form responses or meeting recordings you select, and transcribing or analyzing them at your direction. We do not use it for any other purpose.
We do not use Google user data for advertising of any kind. We do not sell Google user data. We do not use Google user data — nor any data received from Google APIs, including Google Workspace APIs — to develop, improve, train, or fine-tune any generalized or non-personalized artificial intelligence or machine learning model. Our use of Google user data is limited to providing and improving user-facing features that are prominent in the Service.
We operate our own AI models, which run on Microsoft Azure infrastructure. We do not use OpenAI, Anthropic, or any other general-purpose AI provider to process your Customer Data. Your prompts, uploaded documents, and generated analysis output stay within the Microsoft Azure environment we operate.
We do not use Customer Data to train, retrain, fine-tune, or otherwise improve our AI models. Customer Data is used exclusively to provide the analysis and features you request during your active use of the Service.
The following commitments apply to all data we process:
We engage a deliberately small number of service providers to help us operate the Service. Each acts as our processor under written contractual terms that restrict use of the data to providing the contracted service. We do not authorize any of them to use your data for their own purposes.
Two sub-processors handle Customer Data and the billing information attached to it:
Sub-processors that receive account and usage data. A small number of additional sub-processors support error monitoring, application delivery, product analytics, and customer support. They receive account and service metadata — for example file sizes, in-product actions, and processing error logs. They do not receive your Customer Data. The one exception is Communications Data: if you voluntarily paste an excerpt or attach a file to a support message so we can diagnose an issue, that message reaches our support sub-processor along with whatever you put in it.
Optional integrations you connect yourself. Dropbox, Microsoft OneDrive, Google Drive, Google Forms, Google Meet, and Zoom are third-party sources you may connect at your own initiative to import content into the Service. We access only the items you select, and only after you authorize the connection. These are your service providers, not our sub-processors, and your use of them is governed by their own terms. We are not responsible for the privacy practices, security, or data handling of these third-party platforms prior to the data entering the Service.
We maintain an up-to-date list of all sub-processors, including those that receive only account and usage data, and we provide it on request to info@evidano.com. We will notify you prior to adding new sub-processors or making material sub-processor changes, providing an opportunity to object on reasonable data protection grounds.
We do not transfer or disclose Google user data to third parties except (i) as necessary to provide or improve user-facing features of the Service, in which case the recipient is limited to the sub-processors named in Section 6.2 acting on our instructions; (ii) to comply with applicable law or valid legal process; (iii) as part of a merger, acquisition, or sale of assets, in which case the recipient is bound by terms at least as protective as this Privacy Policy; or (iv) with your explicit consent.
We do not transfer or disclose Google user data for advertising, targeted or personalized advertising, retargeting, credit-worthiness assessment, lending, sale to information resellers or data brokers, or to develop, improve, train, or fine-tune any generalized or non-personalized AI or ML model.
We may disclose information when we believe in good faith that disclosure is required to comply with a legal obligation, respond to lawful requests from public authorities, protect the rights, property, or safety of AILYZE, our users, or others, or enforce our Terms of Service. Where we are legally permitted to do so, we will notify you before disclosing Customer Data in response to legal process, so that you may seek to challenge it.
If AILYZE is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to confidentiality obligations and continued protection consistent with this Privacy Policy. We will notify you before your Personal Data becomes subject to a materially different privacy policy.
We maintain administrative, technical, and physical safeguards designed to protect Personal Data and Customer Data from unauthorized access, alteration, disclosure, or destruction. Our security program has been validated by an independent SOC 2 Type 2 audit covering the Security, Availability, Confidentiality, and Privacy trust services criteria, and is renewed annually. The current SOC 2 Type 2 report is available to customers on request under a non-disclosure agreement.
All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 with FIPS 140-2 compliant cryptographic modules. Access to production systems is limited to authorized personnel on a least-privilege basis using role-based access control. Our infrastructure is protected by web application firewalls and stateful network firewalls, and we perform continuous vulnerability scanning together with annual third-party penetration testing by an independent firm.
Your Customer Data is encrypted, and our systems and access policies are designed so that engineers and other staff do not read your prompts, uploaded content, or Service output in the ordinary course of operating the Service. The narrow exceptions are: (a) when you contact support and voluntarily share the content with us to diagnose an issue, or (b) when required by applicable law or valid legal process. In each case, access is limited to personnel who are subject to written confidentiality obligations, is logged, and is limited to the minimum data necessary.
Security and abuse investigations do not involve reading your Customer Data. When we investigate a suspected security incident or misuse of the Service, we limit that investigation to Account Data, Communications Data, and Usage Data (such as file sizes, in-product actions, and processing error logs). Your uploaded research files and generated analysis output will not be reviewed.
The Service explicitly forbids the uploading of Protected Health Information (PHI) under HIPAA, or equivalent sensitive health data under international privacy laws, without a prior written agreement (such as a Business Associate Agreement). Uploading such data without an executed agreement is a violation of our Terms of Service, is grounds for immediate account termination, and you agree to fully indemnify us for any resulting liabilities. If your organization requires a BAA or similar agreement to process health data, one is available on request from info@evidano.com.
Our obligations differ depending on whose data is affected and in which role we hold it.
We retain Personal Data and Customer Data only for as long as your account is active, plus a limited period afterward where the legal retention exceptions below apply. When a retention period expires, the data is deleted.
Concrete timelines. Customer Data you delete is immediately removed from our production systems, and it may take up to thirty-five (35) days to be overwritten in our encrypted backups, except where retention is required by a valid legal hold or subpoena. Account Data is deleted on the same basis when you close your account, subject only to the legal retention exceptions.
Export. You can export your Customer Data at any time through the export tools in the Service.
Deletion. You can delete Customer Data at any time from within the Service. When you delete it, we remove it from our production systems immediately, and from our backups within thirty-five (35) days, except where a legal hold applies. You can also delete your account, and all associated Account Data and Customer Data, from within the Service. Closing your account, or a deletion request we have verified, deletes both the same way. If you sign in using Google, revoking the Service’s access from your Google account settings will stop future access to Google user data.
Inactive free accounts. If a Free Plan account is inactive for twelve (12) consecutive months, we may delete the account and its Customer Data. We will email you at least thirty (30) days beforehand so that you can sign in or export your data first. This is described in Section 5.1 of our Terms of Service.
Legal retention exceptions. We retain specific records beyond the periods above only where we are required to, and only for as long as the requirement lasts: invoices and transaction records we must keep under applicable tax and accounting law; records subject to a legal hold, litigation, or a regulatory or law-enforcement request; and records we need in order to establish, exercise, or defend legal claims. Anything retained on this basis is limited to the specific records required, is not used for any other purpose, and is deleted once the requirement ends.
Subject to applicable law, you have the right to:
California residents have the right to:
You may use an authorized agent to submit a request on your behalf. We will ask the agent for written permission signed by you and may ask you to verify your identity directly.
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island — have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to opt out of targeted advertising, the sale of Personal Data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in any of those three activities. Where a state provides a right to appeal a refused request, you may appeal by replying to our decision or writing to info@evidano.com, and we will respond within the period that state law allows.
To exercise any of the rights above, contact us at info@evidano.com. We will respond in accordance with applicable data protection law. We may need to verify your identity before acting on your request, and we will not use the information you give us for verification for any other purpose. Exercising these rights is free unless your request is manifestly unfounded or excessive. These rights are subject to the legal retention exceptions described in Section 8.
If you are an interview participant, survey respondent, or other individual whose information appears inside a customer’s workspace, we hold that information as a processor on that customer’s behalf, and they — not we — decide what happens to it. Please direct your request to the organization that collected your information. If you contact us instead, we will forward your request to that customer without undue delay and assist them in responding.
Automatic regional residency. Customers located in the United States are hosted in the United States (Microsoft Azure US East). All other customers are hosted in the European Union (Microsoft Azure West Europe). We assign your region automatically based on your detected location at registration; no manual request is required. Your Customer Data is stored and processed in the region assigned to you. If you use a VPN or mask your location, your data may be hosted in the incorrect region.
What may leave your region. Account and service metadata — such as file sizes, in-product actions, and processing error logs — may be handled by the sub-processors described in Section 6.2, some of which operate outside your region. Customer Data is not transferred out of your region.
Transfer safeguards. To the extent Personal Data is transferred out of the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction that has not received an adequacy decision, we strictly limit this transfer to Account Data, Communications Data, and Usage Data (such as file sizes, in-product actions, and processing error logs). Your uploaded research files and generated analysis (Customer Data) are not transferred. For these limited transfers, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) with our sub-processors as an appropriate safeguard, together with supplementary technical measures including encryption in transit and at rest.
We have designated DataRep as our representative under Article 27 of the GDPR and under Article 27 of the UK GDPR. DataRep acts for us in both capacities.
Either office can also be reached by email at datarep@evidano.com.
Individuals in the European Economic Area and the United Kingdom, and supervisory authorities, may contact our representative on any matter relating to the processing of their Personal Data, in addition to contacting us directly at info@evidano.com. You may exercise any of the rights in Section 9 through either route.
The Service is strictly for individuals 18 and older. We do not knowingly permit anyone under 18 to create an account, nor do we knowingly collect Personal Data directly from anyone under 18. Notwithstanding this age restriction, and in accordance with the Children’s Online Privacy Protection Act (COPPA), we specifically do not knowingly collect Personal Data directly from children under 13. If you believe someone under 18 has created an account, or that a child has provided us with Personal Data, please contact us at info@evidano.com and we will delete the account and the information.
This restriction is about who may hold an Evidano account and use the Service. It does not limit the research data our customers may lawfully upload: a customer may, for example, analyze interviews conducted with minors, provided the customer has the necessary consents and a lawful basis. That Customer Data is governed by Sections 3 and 5.4 like any other.
Evidano's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Consistent with those requirements, we affirm that we use Google user data solely to provide or improve user-facing features that are prominent in the Service; we do not transfer or use Google user data for serving advertising; and we do not allow humans to read Google user data unless we have your affirmative agreement to do so, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized. We do not use Google user data — including data obtained through any Google Workspace API — to develop, improve, or train generalized or non-personalized AI or machine-learning models.
For customers subject to the GDPR, the UK GDPR, the CCPA/CPRA, or another law that requires written terms with a processor or service provider, our standard Data Processing Agreement (DPA) is available on request at info@evidano.com. Our DPA incorporates the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply, sets out the security measures described in Section 7, and includes the sub-processor notification and objection rights described in Section 6.2.
If your organization requires a custom executed DPA or Business Associate Agreement for HIPAA compliance (see Section 7.2), you can obtain one on request from info@evidano.com. Where an executed agreement and this Policy conflict, the executed agreement governs.
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Effective Date" at the top of this page and notify you by email or through a notice in the Service at least thirty (30) days before the changes take effect, unless a change must take effect sooner to comply with law. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy. If you do not accept it, you may close your account and export your data as described in Section 8.
If you have questions about this Privacy Policy or our data practices, or if you wish to exercise any of the rights described above, please contact us. We aim to acknowledge privacy inquiries within five (5) business days and to resolve them within the period applicable law allows.
AILYZE, Inc.Product updates, research, and tips — straight to your inbox.
© Evidano, All Rights Reserved.