Plain-language policy

Privacy policy

Eva is built around a simple promise: access should be purposeful, data handling should be explainable, and control should remain with the person Eva serves.

Effective 30 August 2026

01

Scope and current status

This policy describes the Eva private-beta project and the information it processes when an authorized person connects an account. Eva is currently an experimental personal assistant operated in private development. It is not accepting public account connections.

This policy applies to this website and Eva's connected services. A service provider such as Google may also process information under its own terms and privacy policy.

02

Data Eva handles

Depending on the features explicitly connected, Eva may process:

  • Account identity: the Google account email address used to verify the connected mailbox and associate it with the correct Eva workspace.
  • Gmail message metadata: provider identifiers, thread identifiers, timestamps, labels, sender and recipient fields, and subject lines.
  • Gmail message content: readable plain-text or HTML-derived message bodies needed to understand a newly received email.
  • Attachment metadata: filenames, media types, provider identifiers, and sizes. The current ingestion flow does not store attachment binary.
  • Authorization material: OAuth refresh information needed to maintain the connection. Short-lived access tokens and their expiry are removed before credentials are persisted.
  • Operational records: connection status, synchronization cursors, processing state, audit identifiers, errors stripped of message content, and records needed for reliability and deduplication.
  • Interaction data: messages, approvals, and preferences that an authorized person provides when conversational channels are enabled later.
03

How data is used

Eva processes connected information only to:

  • establish and maintain an account connection requested by the user;
  • detect and normalize relevant new events from connected sources;
  • relate those events to user-defined goals and ongoing situations;
  • provide explanations, notifications, and user-requested assistance;
  • protect account boundaries, prevent duplicates, and recover from failures;
  • debug, secure, and improve the private-beta service.

Eva does not use connected Google data for advertising. We do not sell personal data or connected account data.

04

Read-only Gmail access

Eva requests the read-only Gmail permission. This allows Eva to read mailbox information needed for the assistant workflow. It does not allow Eva to send, delete, modify, label, archive, or otherwise change email in the connected account.

Current boundary

New-email ingestion begins from the connection boundary. Historical backfill and public account onboarding are not part of the current private beta.

05

Credentials and security

OAuth authorization material is stored separately from application records using managed secret infrastructure. Access is restricted to the service components that need it. Current access tokens and expiry values are stripped before credential material is persisted.

Eva also uses workspace ownership checks, least-privilege cloud permissions, transaction boundaries, idempotency, and content-free operational errors. No security measure eliminates every risk, and Eva does not promise absolute security.

06

Sharing and service providers

Eva does not sell or rent personal information. Data may be processed by infrastructure providers required to operate the service, including Google Cloud services used for Gmail notifications, secret storage, messaging, and hosting. Those providers process information under their own contracts and policies.

Information may also be disclosed when required by applicable law, to protect rights or safety, or with the connected user's direction. Eva does not share Google user data with data brokers, advertising platforms, or unrelated third parties.

07

Retention and deletion

During private beta, Eva retains connected data and operational records only as needed to provide, secure, debug, and evaluate the service. The project does not yet promise a fixed automatic retention period. Backups and provider logs may persist for a limited period according to infrastructure-provider lifecycle controls.

An authorized user may revoke Google's access at any time through their Google Account permissions. Because the current beta is limited to its operator, account disconnection and deletion requests are handled directly. A private support channel will be published before any external users are invited; do not post sensitive data in a public repository issue.

08

Google API Services User Data Policy

Eva's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Google user data is used only to provide or improve the user-facing assistant features described here. It is not transferred for advertising, creditworthiness, surveillance, or sale.

09

Other information

International processing

Infrastructure providers may process data in locations different from the user's location. Their safeguards and regional controls apply to that processing.

Children's privacy

Eva is not directed to children and is not offered for use by anyone under 18. The project does not knowingly collect children's personal information.

Policy changes

This policy may change as Eva's capabilities and operating model evolve. Material revisions will appear on this page with an updated effective date before broader access is offered.

10

Contact

General questions about this policy may be raised through the Eva source repository. Do not include mailbox content, credentials, or other sensitive information in a public issue. The current private-beta operator handles account-specific requests directly.