Legal

Privacy Policy

Last updated · May 23, 2026

This policy describes what Attevia ("we") collects when you use the platform, how we use it, and the controls you have. We deliberately collect the minimum required to operate the service. If anything here is unclear, email privacy@attevia.dev.

What we collect

  • Account data: email, organisation name, plan tier, and any details you enter in onboarding.
  • Run inputs: the thesis text you submit, the run configuration you pick, and the resulting memo / backtest / signature. Stored encrypted at rest and scoped to your tenant.
  • Operational telemetry: per-request timestamp, route, tenant id, latency, status code, upstream model + token counts. Used to debug tickets, bill usage, and detect abuse.
  • Cookies: a single HMAC-signed session cookie. No third-party analytics, no ad networks, no Facebook pixel.

What we do not collect

  • We do not store the body of your thesis in any logging or observability system — only in the encrypted run object scoped to your tenant.
  • We do not opt your data into any third-party model provider's training programs. Anthropic and OpenAI are called on their non-retention business endpoints.
  • We do not run third-party trackers on attevia.vercel.app.

Subprocessors

We use a small set of vendors. Each receives only the data required to perform its function and is bound by a DPA.

  • Vercel — hosting + edge functions. US-East region by default.
  • Upstash — Redis persistence (encrypted at rest). US-East region.
  • Anthropic — Claude model inference. Default non-retention API endpoint.
  • OpenAI — GPT model inference. Default non-retention API endpoint.
  • Browser Use — sandboxed browser sessions when the Researcher needs to scrape a public site as a fallback. Sessions are isolated and do not run user JavaScript against your account.

How long we keep your data

Runs and receipts persist until you delete them. Operational telemetry is retained for 90 days. Backups roll on the same schedule and are encrypted with a separate key.

Your rights

You can export, correct, or delete your data at any time. Use /app/settings for self-serve actions, or email privacy@attevia.dev for a full export (JSONL, fulfilled within 30 days).

Security disclosures

See /security for the deep dive. Report suspected vulnerabilities to security@attevia.dev — we respond within 24 hours.

Children

Attevia is not directed at users under 18. We do not knowingly collect data from anyone in that age group.

Changes

Updates to this policy are announced on /changelog and via email to account owners. The "Last updated" date at the top reflects the latest version.

Privacy Policy · Attevia