Privacy Policy
Last updated · May 23, 2026
This policy describes what Attevia ("we") collects when you use the platform, how we use it, and the controls you have. We deliberately collect the minimum required to operate the service. If anything here is unclear, email privacy@attevia.dev.
What we collect
- Account data: email, organisation name, plan tier, and any details you enter in onboarding.
- Run inputs: the thesis text you submit, the run configuration you pick, and the resulting memo / backtest / signature. Stored encrypted at rest and scoped to your tenant.
- Operational telemetry: per-request timestamp, route, tenant id, latency, status code, upstream model + token counts. Used to debug tickets, bill usage, and detect abuse.
- Cookies: a single HMAC-signed session cookie. No third-party analytics, no ad networks, no Facebook pixel.
What we do not collect
- We do not store the body of your thesis in any logging or observability system — only in the encrypted run object scoped to your tenant.
- We do not opt your data into any third-party model provider's training programs. Anthropic and OpenAI are called on their non-retention business endpoints.
- We do not run third-party trackers on attevia.vercel.app.
Subprocessors
We use a small set of vendors. Each receives only the data required to perform its function and is bound by a DPA.
- Vercel — hosting + edge functions. US-East region by default.
- Upstash — Redis persistence (encrypted at rest). US-East region.
- Anthropic — Claude model inference. Default non-retention API endpoint.
- OpenAI — GPT model inference. Default non-retention API endpoint.
- Browser Use — sandboxed browser sessions when the Researcher needs to scrape a public site as a fallback. Sessions are isolated and do not run user JavaScript against your account.
How long we keep your data
Runs and receipts persist until you delete them. Operational telemetry is retained for 90 days. Backups roll on the same schedule and are encrypted with a separate key.
Your rights
You can export, correct, or delete your data at any time. Use /app/settings for self-serve actions, or email privacy@attevia.dev for a full export (JSONL, fulfilled within 30 days).
Security disclosures
See /security for the deep dive. Report suspected vulnerabilities to security@attevia.dev — we respond within 24 hours.
Children
Attevia is not directed at users under 18. We do not knowingly collect data from anyone in that age group.
Changes
Updates to this policy are announced on /changelog and via email to account owners. The "Last updated" date at the top reflects the latest version.