Site Logo

Evidano Privacy Policy

Effective Date: September 15, 2026

1. Introduction

AILYZE, Inc. ("AILYZE", "we", "us", or "our") is the provider of Evidano, the AI research platform available at www.evidano.com (the "Service").

This Privacy Policy describes how we collect, use, store, share, and protect personal information in connection with your use of the Service. It applies to information collected through the Service and through electronic communications between you and us. By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy.

This Policy forms part of, and should be read together with, our Terms of Service. Capitalized terms used but not defined here have the meanings given in the Terms of Service.

2. Definitions

The following capitalized terms have the meanings given to them below:

Customer Data
The documents, files, text, audio, prompts, and other data that you or your users upload, create, or process within the Service, together with the output the Service generates from them. Customer Data is the same thing the Terms of Service calls "Content". Customer Data may include Personal Data. Customer Data does not include your billing information, which is Account Data, nor does it include content sent through support or feedback channels, which is Communications Data.
Personal Data
Information relating to an identified or identifiable natural person. Where this Policy refers to "personal information", it means the same thing.
Account Data
Personal Data we collect to create and administer an account, including but not limited to name, email address, authentication credentials, profile images, and (for paying customers) the billing information required to complete a transaction.
Communications Data
Information you voluntarily share with us when contacting customer support, reporting bugs, or providing feedback.
Usage Data
Data generated automatically by your use of the Service or by the Service infrastructure itself, such as IP address, browser type, and session duration.
Google User Data
Personal Data that we receive from Google when you choose to sign in to the Service with your Google account, or that we access through any Google API you authorize us to use.
Sub-processor
A third party we engage to process Personal Data or Customer Data on our behalf, under written terms that restrict its use of that data to providing the service we have contracted it for.

3. Our Role: Controller and Processor

Our obligations under data protection law depend on which data we are handling, and this Policy applies differently to each.

  • Customer Data — we act as a processor. You decide what Customer Data to put into the Service and why. We process it only on your documented instructions, which are given through your use of the Service and through any Data Processing Agreement between us. Where Customer Data contains Personal Data about other people — interview participants, survey respondents, patients, employees — you are the controller of that Personal Data. You are responsible for having a lawful basis to collect it, for giving those people the notice they are owed, and for honouring their rights. We will assist you in doing so, as described in Section 9.4.
  • Account Data and Usage Data — we act as a controller. We decide how to use the data needed to create your account, bill you, secure the Service, and support you. Sections 5.1 and 5.2 set out those purposes and the legal bases for them. If your account was provisioned by your employer or academic institution, they are the controller of your Account Data and may have administrative rights to access, retain, or delete your account.
  • Google User Data — we act as a controller for the profile information used to authenticate you, and as a processor for content you import through an optional integration, which becomes Customer Data once it reaches your workspace.

A Data Processing Agreement covering our role as your processor is available on request at info@evidano.com; see Section 14.

4. Information We Collect

4.1 Information You Provide to Us

  • Account Data. When you register directly, we collect your name and email address, and (for paying customers) billing details required to complete a purchase.
  • Customer Data. You provide Customer Data when you use the Service’s features. This may include interview transcripts, research articles, reports, survey responses, social media content, audio files for transcription, or data collected from public websites.
  • Communications Data. When you contact us for support or otherwise correspond with us, we collect the information you choose to provide. This is distinct from your Customer Data.

4.2 Information We Collect Automatically

  • Usage and operational data. IP address, browser type, operating system, login times, actions performed within the Service, and security events.
  • Cookies. We use session cookies that are necessary for the Service to function, such as maintaining your login state. We do not use third-party advertising or cross-site tracking cookies.

4.3 Information We Receive from Third-Party Sign-In Providers

If you choose to sign in to the Service using a third-party identity provider, we receive limited profile information from that provider in order to create and authenticate your account.

When you sign in with Google, the Google user data we receive consists of your basic profile information — specifically your name, primary email address, Google account identifier, profile picture URL, and locale — as authorized by you through Google’s OAuth consent screen. Signing in requires only theopenid,email, andprofilescopes.

Separately, the Service offers optional integrations that you may connect at your own initiative. These are never part of sign-in, are never enabled by default, and each is authorized through its own Google consent screen that you can decline or revoke at any time. Where an integration requests a sensitive or restricted Google API scope, we request the narrowest scope that supports the feature, and we use the resulting data only to power that feature:

  • Google Forms import. If you connect Google Forms in order to import survey responses for analysis, we requestforms.body.readonly,forms.responses.readonly, anddrive.metadata.readonly. We read the titles of your forms so you can choose one, then read the questions and responses of the form you select. That content is imported into your Evidano workspace as Customer Data and analyzed at your direction. We do not modify or delete anything in your Google account.
  • Google Meet recording import. If you connect Google Meet in order to bring meeting recordings in for transcription and analysis, we requestmeetings.space.readonlyanddrive.readonly, which Google classifies as a restricted scope. We use this access solely to locate and retrieve the specific meeting recordings you select so they can be transcribed and analyzed within the Service. We do not browse, index, or retain the wider contents of your Google Drive.

Content you import through these integrations is treated as Customer Data under this Policy: it is stored and processed on the same terms, it is never used to train our AI models, and you can delete it at any time. You may disconnect an integration at any time from within the Service, or revoke access directly from your Google account permissions page.

5. How We Use Your Information

5.1 Purposes

We use the information described above only for the following purposes:

  • To provide, operate, maintain, and improve the Service.
  • To create and authenticate your account, and to associate your session with your identity.
  • To process transactions, deliver invoices, and send billing-related notices.
  • To respond to your support requests and other communications.
  • To monitor usage for security, fraud prevention, and operational stability.
  • To enforce our Terms of Service and comply with our legal obligations.

5.2 Legal Bases for Processing

Where the GDPR or UK GDPR applies and we act as a controller, we rely on the following legal bases under Article 6:

  • Performance of a contract (Article 6(1)(b)) — to create and authenticate your account, make the Service available to you, process payments, deliver invoices, and provide support.
  • Legitimate interests (Article 6(1)(f)) — to keep the Service secure and stable, prevent fraud and abuse, maintain operational logs, understand how the Service is used so we can improve it, and establish, exercise, or defend legal claims. We balance these interests against your rights and freedoms, and you may object as described in Section 9.1.
  • Legal obligation (Article 6(1)(c)) — to retain invoices and transaction records under tax and accounting law, and to respond to lawful requests from public authorities.
  • Consent (Article 6(1)(a)) — where you connect an optional third-party integration, or where we otherwise ask for your consent. You may withdraw consent at any time, which does not affect the lawfulness of processing carried out before you withdrew it.

Where we process Customer Data as your processor, you determine the legal basis for that processing; we process it only on your instructions.

5.3 How We Use Google User Data

Google user data received through Google Sign-In is used solely to (a) create and authenticate your Evidano account, (b) display your name and profile picture within the Service so you can identify yourself, and (c) send you service-related emails at the address associated with your Google account.

Google user data received through the optional Google Forms and Google Meet integrations described in Section 4.3 is used solely to deliver the feature you connected it for — importing the form responses or meeting recordings you select, and transcribing or analyzing them at your direction. We do not use it for any other purpose.

We do not use Google user data for advertising of any kind. We do not sell Google user data. We do not use Google user data — nor any data received from Google APIs, including Google Workspace APIs — to develop, improve, train, or fine-tune any generalized or non-personalized artificial intelligence or machine learning model. Our use of Google user data is limited to providing and improving user-facing features that are prominent in the Service.

5.4 Customer Data and AI Models

We operate our own AI models, which run on Microsoft Azure infrastructure. We do not use OpenAI, Anthropic, or any other general-purpose AI provider to process your Customer Data. Your prompts, uploaded documents, and generated analysis output stay within the Microsoft Azure environment we operate.

We do not use Customer Data to train, retrain, fine-tune, or otherwise improve our AI models. Customer Data is used exclusively to provide the analysis and features you request during your active use of the Service.

6. How We Share, Transfer, and Disclose Information

6.1 Our Core Commitments

The following commitments apply to all data we process:

  • We will never sell, rent, or trade your Personal Data or your Customer Data.
  • We will never use Customer Data or Google user data to train, retrain, fine-tune, or otherwise improve our AI models.
  • We will never send your prompts, uploaded documents, or analysis output to OpenAI, Anthropic, or any other general-purpose AI provider. Document, transcript, and prompt analysis is performed by models we operate inside Microsoft Azure.
  • We will never share your data with advertising networks, data brokers, information resellers, or any third party for marketing purposes.
  • We will never use Google user data to determine credit-worthiness or for lending decisions.
  • We will not read the contents of your Customer Data outside the narrow, logged exceptions set out in Section 7.1.

6.2 Sub-Processors

We engage a deliberately small number of service providers to help us operate the Service. Each acts as our processor under written contractual terms that restrict use of the data to providing the contracted service. We do not authorize any of them to use your data for their own purposes.

Two sub-processors handle Customer Data and the billing information attached to it:

  • Microsoft Azure — cloud infrastructure that stores Account Data, Customer Data, and Usage Data, and that provides the compute for the AI models we operate. We run our own AI models on Azure infrastructure; Microsoft Azure provides the hosting environment but does not use your data for its own purposes and does not share it with any AI vendor.
  • Stripe, Inc. — payment processing for paid subscriptions. Stripe receives the name, email address, and billing information required to complete a transaction. Card and bank account details are collected and stored directly by Stripe; we do not see or store your full card number. Stripe does not receive your documents, transcripts, audio, prompts, or analysis output.

Sub-processors that receive account and usage data. A small number of additional sub-processors support error monitoring, application delivery, product analytics, and customer support. They receive account and service metadata — for example file sizes, in-product actions, and processing error logs. They do not receive your Customer Data. The one exception is Communications Data: if you voluntarily paste an excerpt or attach a file to a support message so we can diagnose an issue, that message reaches our support sub-processor along with whatever you put in it.

Optional integrations you connect yourself. Dropbox, Microsoft OneDrive, Google Drive, Google Forms, Google Meet, and Zoom are third-party sources you may connect at your own initiative to import content into the Service. We access only the items you select, and only after you authorize the connection. These are your service providers, not our sub-processors, and your use of them is governed by their own terms. We are not responsible for the privacy practices, security, or data handling of these third-party platforms prior to the data entering the Service.

We maintain an up-to-date list of all sub-processors, including those that receive only account and usage data, and we provide it on request to info@evidano.com. We will notify you prior to adding new sub-processors or making material sub-processor changes, providing an opportunity to object on reasonable data protection grounds.

6.3 Sharing of Google User Data

We do not transfer or disclose Google user data to third parties except (i) as necessary to provide or improve user-facing features of the Service, in which case the recipient is limited to the sub-processors named in Section 6.2 acting on our instructions; (ii) to comply with applicable law or valid legal process; (iii) as part of a merger, acquisition, or sale of assets, in which case the recipient is bound by terms at least as protective as this Privacy Policy; or (iv) with your explicit consent.

We do not transfer or disclose Google user data for advertising, targeted or personalized advertising, retargeting, credit-worthiness assessment, lending, sale to information resellers or data brokers, or to develop, improve, train, or fine-tune any generalized or non-personalized AI or ML model.

6.4 Legal Disclosures and Business Transfers

We may disclose information when we believe in good faith that disclosure is required to comply with a legal obligation, respond to lawful requests from public authorities, protect the rights, property, or safety of AILYZE, our users, or others, or enforce our Terms of Service. Where we are legally permitted to do so, we will notify you before disclosing Customer Data in response to legal process, so that you may seek to challenge it.

If AILYZE is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to confidentiality obligations and continued protection consistent with this Privacy Policy. We will notify you before your Personal Data becomes subject to a materially different privacy policy.

7. Data Security

We maintain administrative, technical, and physical safeguards designed to protect Personal Data and Customer Data from unauthorized access, alteration, disclosure, or destruction. Our security program has been validated by an independent SOC 2 Type 2 audit covering the Security, Availability, Confidentiality, and Privacy trust services criteria, and is renewed annually. The current SOC 2 Type 2 report is available to customers on request under a non-disclosure agreement.

All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 with FIPS 140-2 compliant cryptographic modules. Access to production systems is limited to authorized personnel on a least-privilege basis using role-based access control. Our infrastructure is protected by web application firewalls and stateful network firewalls, and we perform continuous vulnerability scanning together with annual third-party penetration testing by an independent firm.

7.1 Human Access to Customer Data

Your Customer Data is encrypted, and our systems and access policies are designed so that engineers and other staff do not read your prompts, uploaded content, or Service output in the ordinary course of operating the Service. The narrow exceptions are: (a) when you contact support and voluntarily share the content with us to diagnose an issue, or (b) when required by applicable law or valid legal process. In each case, access is limited to personnel who are subject to written confidentiality obligations, is logged, and is limited to the minimum data necessary.

Security and abuse investigations do not involve reading your Customer Data. When we investigate a suspected security incident or misuse of the Service, we limit that investigation to Account Data, Communications Data, and Usage Data (such as file sizes, in-product actions, and processing error logs). Your uploaded research files and generated analysis output will not be reviewed.

7.2 Health Information

The Service explicitly forbids the uploading of Protected Health Information (PHI) under HIPAA, or equivalent sensitive health data under international privacy laws, without a prior written agreement (such as a Business Associate Agreement). Uploading such data without an executed agreement is a violation of our Terms of Service, is grounds for immediate account termination, and you agree to fully indemnify us for any resulting liabilities. If your organization requires a BAA or similar agreement to process health data, one is available on request from info@evidano.com.

7.3 Breach Notification

Our obligations differ depending on whose data is affected and in which role we hold it.

  • Where we process Customer Data as your processor, we will notify you without undue delay after becoming aware of a personal data breach affecting it, and will endeavor to do so within seventy-two (72) hours, so that you can meet your own notification deadlines. We will provide the information reasonably available to us and will assist you in notifying regulators and affected individuals.
  • Where we act as a controller — for Account Data and Usage Data — we will notify the competent supervisory authority and will endeavor to do so within seventy-two (72) hours of becoming aware of a personal data breach where the GDPR or UK GDPR requires it, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  • In all cases, notifications will describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures we have taken or propose to take. We will also meet any additional deadlines that apply under HIPAA or United States state breach notification laws.

8. Data Retention, Export, and Deletion

We retain Personal Data and Customer Data only for as long as your account is active, plus a limited period afterward where the legal retention exceptions below apply. When a retention period expires, the data is deleted.

Concrete timelines. Customer Data you delete is immediately removed from our production systems, and it may take up to thirty-five (35) days to be overwritten in our encrypted backups, except where retention is required by a valid legal hold or subpoena. Account Data is deleted on the same basis when you close your account, subject only to the legal retention exceptions.

Export. You can export your Customer Data at any time through the export tools in the Service.

Deletion. You can delete Customer Data at any time from within the Service. When you delete it, we remove it from our production systems immediately, and from our backups within thirty-five (35) days, except where a legal hold applies. You can also delete your account, and all associated Account Data and Customer Data, from within the Service. Closing your account, or a deletion request we have verified, deletes both the same way. If you sign in using Google, revoking the Service’s access from your Google account settings will stop future access to Google user data.

Inactive free accounts. If a Free Plan account is inactive for twelve (12) consecutive months, we may delete the account and its Customer Data. We will email you at least thirty (30) days beforehand so that you can sign in or export your data first. This is described in Section 5.1 of our Terms of Service.

Legal retention exceptions. We retain specific records beyond the periods above only where we are required to, and only for as long as the requirement lasts: invoices and transaction records we must keep under applicable tax and accounting law; records subject to a legal hold, litigation, or a regulatory or law-enforcement request; and records we need in order to establish, exercise, or defend legal claims. Anything retained on this basis is limited to the specific records required, is not used for any other purpose, and is deleted once the requirement ends.

9. Your Data Protection Rights

9.1 EEA, United Kingdom, and Switzerland (GDPR / UK GDPR)

Subject to applicable law, you have the right to:

  • Access the Personal Data we hold about you, and obtain a copy of it.
  • Request correction of inaccurate or incomplete Personal Data.
  • Request erasure of your Personal Data.
  • Restrict or object to processing based on our legitimate interests.
  • Request portability of Personal Data you have provided to us.
  • Withdraw your consent at any time, where we rely on consent. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions about you. The Service produces AI-generated analysis at your direction, which you review and can override; it does not decide anything about you.
  • Lodge a complaint with your local supervisory authority.

9.2 California (CCPA / CPRA)

California residents have the right to:

  • Know the categories and the specific pieces of Personal Data we have collected about them, the categories of sources, the business purposes for collecting it, and the categories of third parties to whom we disclose it.
  • Request deletion of their Personal Data.
  • Request correction of inaccurate Personal Data.
  • Limit the use and disclosure of sensitive personal information. We use sensitive personal information only to provide the Service and for the other purposes permitted without a right to limit, so no separate opt-out is offered.
  • Opt out of the sale or sharing of Personal Data. We do not sell or share Personal Data as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months, so no opt-out is required. Because we do not sell or share Personal Data for cross-context behavioral advertising, Global Privacy Control (GPC) signals do not affect how we treat your data, as your data is already protected from these activities.
  • Opt out of automated decision-making technology in connection with decisions that produce legal or similarly significant effects. We do not use Personal Data for such decisions.
  • Not be discriminated against for exercising these rights.

You may use an authorized agent to submit a request on your behalf. We will ask the agent for written permission signed by you and may ask you to verify your identity directly.

9.3 Other United States State Privacy Laws

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island — have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to opt out of targeted advertising, the sale of Personal Data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in any of those three activities. Where a state provides a right to appeal a refused request, you may appeal by replying to our decision or writing to info@evidano.com, and we will respond within the period that state law allows.

9.4 How to Exercise Your Rights

To exercise any of the rights above, contact us at info@evidano.com. We will respond in accordance with applicable data protection law. We may need to verify your identity before acting on your request, and we will not use the information you give us for verification for any other purpose. Exercising these rights is free unless your request is manifestly unfounded or excessive. These rights are subject to the legal retention exceptions described in Section 8.

If you are an interview participant, survey respondent, or other individual whose information appears inside a customer’s workspace, we hold that information as a processor on that customer’s behalf, and they — not we — decide what happens to it. Please direct your request to the organization that collected your information. If you contact us instead, we will forward your request to that customer without undue delay and assist them in responding.

10. Data Residency and International Transfers

Automatic regional residency. Customers located in the United States are hosted in the United States (Microsoft Azure US East). All other customers are hosted in the European Union (Microsoft Azure West Europe). We assign your region automatically based on your detected location at registration; no manual request is required. Your Customer Data is stored and processed in the region assigned to you. If you use a VPN or mask your location, your data may be hosted in the incorrect region.

What may leave your region. Account and service metadata — such as file sizes, in-product actions, and processing error logs — may be handled by the sub-processors described in Section 6.2, some of which operate outside your region. Customer Data is not transferred out of your region.

Transfer safeguards. To the extent Personal Data is transferred out of the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction that has not received an adequacy decision, we strictly limit this transfer to Account Data, Communications Data, and Usage Data (such as file sizes, in-product actions, and processing error logs). Your uploaded research files and generated analysis (Customer Data) are not transferred. For these limited transfers, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) with our sub-processors as an appropriate safeguard, together with supplementary technical measures including encryption in transit and at rest.

11. EU and UK Representative

We have designated DataRep as our representative under Article 27 of the GDPR and under Article 27 of the UK GDPR. DataRep acts for us in both capacities.

European Union

DataRep
77 Camden Street Lower
Dublin, D02 XE80
Ireland

United Kingdom

DataRep
85 Great Portland Street
London, W1W 7LT
United Kingdom

Either office can also be reached by email at datarep@evidano.com.

Individuals in the European Economic Area and the United Kingdom, and supervisory authorities, may contact our representative on any matter relating to the processing of their Personal Data, in addition to contacting us directly at info@evidano.com. You may exercise any of the rights in Section 9 through either route.

12. Age Restriction and Children’s Privacy

The Service is strictly for individuals 18 and older. We do not knowingly permit anyone under 18 to create an account, nor do we knowingly collect Personal Data directly from anyone under 18. Notwithstanding this age restriction, and in accordance with the Children’s Online Privacy Protection Act (COPPA), we specifically do not knowingly collect Personal Data directly from children under 13. If you believe someone under 18 has created an account, or that a child has provided us with Personal Data, please contact us at info@evidano.com and we will delete the account and the information.

This restriction is about who may hold an Evidano account and use the Service. It does not limit the research data our customers may lawfully upload: a customer may, for example, analyze interviews conducted with minors, provided the customer has the necessary consents and a lawful basis. That Customer Data is governed by Sections 3 and 5.4 like any other.

13. Google API Services — Limited Use Disclosure

Evidano's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Consistent with those requirements, we affirm that we use Google user data solely to provide or improve user-facing features that are prominent in the Service; we do not transfer or use Google user data for serving advertising; and we do not allow humans to read Google user data unless we have your affirmative agreement to do so, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized. We do not use Google user data — including data obtained through any Google Workspace API — to develop, improve, or train generalized or non-personalized AI or machine-learning models.

14. Data Processing Agreement

For customers subject to the GDPR, the UK GDPR, the CCPA/CPRA, or another law that requires written terms with a processor or service provider, our standard Data Processing Agreement (DPA) is available on request at info@evidano.com. Our DPA incorporates the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply, sets out the security measures described in Section 7, and includes the sub-processor notification and objection rights described in Section 6.2.

If your organization requires a custom executed DPA or Business Associate Agreement for HIPAA compliance (see Section 7.2), you can obtain one on request from info@evidano.com. Where an executed agreement and this Policy conflict, the executed agreement governs.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Effective Date" at the top of this page and notify you by email or through a notice in the Service at least thirty (30) days before the changes take effect, unless a change must take effect sooner to comply with law. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy. If you do not accept it, you may close your account and export your data as described in Section 8.

16. Contact Us

If you have questions about this Privacy Policy or our data practices, or if you wish to exercise any of the rights described above, please contact us. We aim to acknowledge privacy inquiries within five (5) business days and to resolve them within the period applicable law allows.

AILYZE, Inc.
77 Massachusetts Avenue
Cambridge, MA 02139, USA
Email: info@evidano.com