Privacy policy
Your work is yours. Here is the data around it.
Evantually is built to keep tool content out of its own database. This policy explains the narrower account, billing, security, and AI-processing data needed to run the service.
Effective August 8, 2026
1. Scope and who we are
This policy applies to Evantually's website, accounts, subscriptions, and tools (the “Service”). “Evantually,” “we,” and “us” refer to the operator of the Service.
Data controller. Evantually LLC [PLACEHOLDER: replace with your registered entity], [PLACEHOLDER: registered business address]. For privacy questions, requests, or complaints, email privacy@evantually.com. We aim to acknowledge every request within 10 days and to resolve it within the period your local law allows (generally 30 days, extendable where the law permits and we tell you why).
This policy explains what we do with personal information. It does not create rights beyond those given by applicable law, and where mandatory local law gives you stronger rights than this policy describes, that law controls.
2. Information we process
Account and authentication data
When you create or use an account, our authentication provider, Clerk, processes information such as your email address, name if provided, account identifiers, session data, and security signals. We use this information to sign you in, secure the Service, and connect your account to subscription access.
Billing data
Stripe processes checkout and payment information. We receive limited records such as your Stripe customer ID, plan, transaction or subscription status, and billing events. We do not receive or store full payment-card numbers.
Tool content
Browser-only tools process content on your device. Evantually does not receive that content. For AI-assisted tools, the input needed for your request is sent through our server to Anthropic's commercial API and the response is returned to you. Evantually does not write those inputs or outputs to a content database.
Anthropic is a separate processor with its own practices. Anthropic says commercial API inputs and outputs are deleted from its backend within 30 days by default, subject to exceptions such as legal obligations, usage-policy enforcement, or a different written arrangement, and are not used to train its generative models by default. Review Anthropic's retention information and training information before submitting sensitive content.
Technical and communications data
We and our infrastructure providers may process IP address, browser and device information, request timestamps, error records, cookie or session identifiers, and basic usage or security events. We use an IP address or account ID for rate limiting. If you contact us, we process the message and contact details you provide.
Workbench votes
If you vote on a workbench idea, we store the tool you selected and a one-way hash of your Clerk account identifier. This lets us count one vote per signed-in account and lets you remove your vote without putting your email address in the voting database. Voting does not add you to the marketing list.
Email list
When you join the newsletter, we store the address, the time you submitted it, and which form you used.
- Newsletter. You ask us to send one new tool a week and related launch notes.
Tool access and marketing are separate. Free tools do not require an email address. We never treat the act of using a tool as agreement to receive marketing.
If you do opt in, we use a double opt-in: we send one message asking you to confirm the address, and nothing further unless you click that link. We use the list only to send the launch note, to tell you when a new tool goes live, and to honor removal requests. We do not sell it, rent it, or share it with advertisers.
Every message includes a one-click unsubscribe link that works without signing in. You can also email privacy@evantually.com to be removed. We keep an address until you unsubscribe or ask for deletion; unconfirmed addresses are removed periodically.
The list is stored in the hosted data store connected to our Vercel deployment. Messages are delivered by Resend, which processes your address solely to deliver them on our behalf. The signup endpoint also uses a one-way hash derived from an IP address for short-lived rate limiting; we do not add the raw address to the list.
3. Why we use information
- Provide accounts, tools, workbench voting, saved subscription access, support, and requested AI results.
- Process payments, renewals, cancellations, refunds, and tax or accounting records.
- Secure the Service, prevent abuse, enforce limits, debug errors, and maintain reliability.
- Comply with law, respond to valid legal requests, and establish or defend legal claims.
- Send service messages and, only where permitted, product communications you requested.
Where laws such as the GDPR or UK GDPR apply, our legal bases are performance of our contract with you, our legitimate interests in securing and improving the Service, compliance with legal obligations, and consent where the law requires it. You may withdraw consent at any time without affecting earlier processing.
4. When information is disclosed
We disclose information only as needed for the following purposes:
- Clerk for authentication and account management.
- Stripe for payments, billing, fraud prevention, and legally required financial records.
- Anthropic for AI-assisted requests you choose to run.
- Vercel and Upstash for website hosting, email-list and vote storage, delivery, and abuse prevention.
- Resend for delivering confirmation, welcome, and new-tool emails to addresses on our list.
- Hosting and infrastructure providers for delivery, security, logs, and uptime.
- Professional advisers and authorities when reasonably necessary to comply with law, protect rights or safety, or complete a corporate transaction.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use third-party advertising cookies. If that changes, we will update this policy and provide legally required choices before beginning the new practice.
5. Cookies and similar technology
The Service uses cookies and local storage that are necessary for sign-in, security, checkout continuity, and preferences. Blocking these technologies may prevent account or subscriber features from working. We do not currently use advertising cookies.
6. Retention
We keep account and subscription records while your account is active and afterward only as reasonably needed for security, dispute resolution, financial recordkeeping, and legal obligations. We keep support messages as needed to resolve the request and maintain an appropriate business record. Operational logs and rate-limit records are kept for limited periods set by us or our providers. Tool content is not retained by Evantually as a saved content record; provider-side processing and retention are described above.
We keep a workbench vote while the idea remains open for voting or until you remove the vote or ask us to delete it. Vote records are pseudonymous and are not used for marketing.
We keep a launch-note email until the requested launch message has been sent, you unsubscribe or ask us to delete it, or the list is retired. You can request removal at any time by emailing privacy@evantually.com.
7. Your privacy rights
Depending on where you live, you may have rights to know or access, correct, delete, restrict or object to processing, obtain a portable copy, withdraw consent, or appeal a denied request. We will not discriminate against you for exercising a privacy right, and exercising one will never reduce your access to a free tool.
Complaints.You may complain to your local supervisory authority at any time and without contacting us first. In the EEA that is the authority for your country of residence, work, or the alleged infringement; in the UK it is the Information Commissioner's Office; in other places it is your national or state privacy regulator. We would prefer the chance to fix a problem first, but nothing here requires you to give us one.
Automated decision-making. We do not make decisions that produce legal or similarly significant effects about you using automated processing alone, and we do not profile you for that purpose. AI-assisted tools generate suggested text at your request; they do not decide anything about you, and their output has no bearing on your account, pricing, or access.
Submit a request to privacy@evantually.com. Include the email tied to your account and the country or U.S. state where you live. We may verify your identity and authority before acting. Authorized agents may submit requests where applicable law permits.
8. U.S. state disclosures
In the preceding 12 months, the categories described in Section 2 may have been collected from you, your device, Clerk, Stripe, and service infrastructure; used for the purposes in Section 3; and disclosed to the service-provider categories in Section 4. We have not sold those categories or shared them for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 18.
California residents may request access to categories or specific pieces, deletion, correction, and information about collection and disclosure, subject to legal exceptions. Because we do not sell or share personal information for cross-context behavioral advertising, there is no sale or sharing to opt out of at this time.
Sensitive personal information. We do not collect personal information for the purpose of inferring characteristics, and we do not use or disclose sensitive personal information for purposes that require an opt-out right under the CPRA. Anything you type into a tool is yours; we do not read it, retain it, or derive anything from it.
Opt-out preference signals. We honor the Global Privacy Control (GPC) and similar browser signals. Because we do not sell or share personal information, receiving one changes nothing in practice. But if that ever changes, a GPC signal will be treated as a valid opt-out request without you having to do anything else.
Residents of other U.S. states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as they take effect, have comparable rights to access, correct, delete, obtain a portable copy, and appeal a refused request. Use the same address in Section 7. If we deny your request you may appeal by replying to our decision, and we will respond within the period your state's law requires.
9. International transfers
Evantually and its providers operate in the United States and other countries. Information may be transferred to a country whose laws differ from yours and which your regulator may not consider to provide equivalent protection.
Where the GDPR or UK GDPR applies, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement, as applicable) with providers outside the EEA or UK, together with supplementary technical and organizational measures where a transfer risk assessment calls for them. You can request a copy of the relevant safeguards, with commercial terms redacted, at privacy@evantually.com.
10. Security incidents
We maintain administrative and technical safeguards appropriate to the limited information we hold, and we keep the amount we hold deliberately small, the single most effective control available to a service this size.
If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your personal information, and that breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a highrisk to you, we will also notify you directly and without undue delay, describing what happened, the likely consequences, and the steps we are taking. Where U.S. state breach-notification law applies, we will notify affected residents and any required regulator within that state's statutory deadline.
11. Security, children, and changes
We use reasonable administrative and technical safeguards appropriate to the information we process, but no online service is completely secure. Do not put highly sensitive, regulated, confidential, or third-party personal information into a tool unless you have the right and a sound reason to do so.
The Service is not directed to children under 13, and paid accounts are for adults or people old enough to form a binding contract where they live. If you believe a child provided personal information, contact us so we can investigate and delete it where required.
We may update this policy as the Service or law changes. We will post the new effective date and provide additional notice when required. Material new uses will not be applied retroactively without a lawful basis.