Open source & history
Changelog
All notable changes to the /policies documentation set are recorded here. Format loosely follows Keep a Changelog. Each product change that affects legal documentation should add an entry under a new version with the affected documents and the reasoning.
[1.5] — 2026-07-21 — Embeddings go local, Gemini fallback disclosed, BYOK/limits corrected (UPDATE mode)
A batch of factual corrections, driven by _facts.md, propagated across the set to close drift between the published documents and the real implementation.
Changed — embeddings now run locally
- Voyage AI is no longer a subprocessor. Evidence is embedded on our own
infrastructure (self-hosted
bge-large-en-v1.5viafastembed/ONNX, CPU) — chunk text never leaves our server. This is a privacy upgrade: there is no longer an embedding subprocessor at all, with or without BYOK. Every Voyage AI reference removed and replaced with a local-embeddings note.
Changed — Gemini fallback disclosed as a conditional subprocessor
backend/app/clients/llm.pysilently fails a platform-key Anthropic call overto Google's Gemini API (
GEMINI_API_KEY, conditional; BYOK-Anthropic orgs never fail over). Now documented everywhere Anthropic was listed as the LLM subprocessor. Anthropic remains under a signed no-training, zero/low-retention agreement; the Gemini fallback is disclosed as relying on Google's stated no-training terms for that API tier, not a bespoke signed agreement — any "signed agreement with every AI subprocessor" phrasing was corrected to draw this distinction.
Changed — BYOK provider list corrected
- The real BYOK options are **Anthropic, OpenAI, Gemini, a local Ollama endpoint,
and a custom OpenAI-compatible endpoint (
frontend/app/settings/keys/page.js), not "Anthropic and/or Voyage AI." Added, where BYOK is first explained in each doc: non-Anthropic BYOK data is governed by the customer's own agreement with that provider, and embeddings are never BYOK** (always the local platform model).
Changed — other factual corrections
- Free-plan limits corrected to 10 documents / 50 questions (code was already
right; the docs said 50/500). Paid stays 5,000 docs / 100,000 questions, $150/mo.
- PDF OCR intake disclosed: scanned/image PDF pages are rendered as images and
sent to Anthropic (vision) at intake to extract questions, in addition to the existing answer-time data flow. Born-digital pages are unaffected.
- Topology corrected: production runs Traefik + a backend tier + a separate
Arq worker tier + Redis for answering, not single-replica in-process answering.
- ToS §3 no longer contradicts the live "Sign in with Google" feature; the
Trust Center's Auth row now lists it too.
- Removed a stray
voyage-3reference from the AI Usage Policy models table;corrected
subprocessors.md's maintainer note (already-named Hostinger, not a stale hosting vendor);open-source/third-party-licenses.mdandNOTICE.mddependency lists updated (removedvoyageai; addedfastembed,onnxruntime,pypdfium2,pillow,arq,google-genai,httpx,redis; corrected MinIO and Postgres from "local dev only" / "managed" to self-hosted in production too). - Repo root
README.mdcorrected from "Haiku 4.5 in production" toclaude-sonnet-4-6, and updated its LLM/embeddings/BYOK summary line.
Affected documents
ai-usage-policy.md, acceptable-use-policy.md, subprocessors.md, data-processing-addendum.md, billing-policy.md, privacy-policy.md, service-level-agreement.md, trust-center.md, terms-of-service.md, security-overview.md, open-source/third-party-licenses.md, open-source/NOTICE.md, and repo-root README.md. refund-policy.md, cookie-policy.md, contact.md, licensing.md, and responsible-disclosure-policy.md were checked and required no changes.
[1.4] — 2026-07-21 — Refunds: discretionary → strict no-refund policy (UPDATE mode)
Founder decision: paid subscriptions are non-refundable. The Free plan carries the full feature set, so evaluation happens before payment ("if you trust it, then buy"); refunds are not part of the offer. Two carve-outs are retained because they cannot be removed: genuine billing errors (duplicate charge, charge after timely cancellation, wrong amount — always corrected via Paddle) and non-waivable consumer rights under applicable law. Paddle, as merchant of record, administers refunds/chargebacks, and its buyer terms still apply to the payment transaction.
Changed
refund-policy.md— rewritten (v1.1): "Subscription refunds" (discretionary) replaced by"No refunds" + "Billing errors"; the
[REFUND_WINDOW]and[REFUND_RESPONSE_DAYS]placeholders and their operator note are removed (no longer applicable); cancellation-vs- refund explanation retained.billing-policy.md§9 andterms-of-service.md§8 — refund cross-references now state thenon-refundable position instead of only linking out.
Resolved (from the open-placeholder list)
[REFUND_WINDOW],[REFUND_RESPONSE_DAYS]— resolved by policy decision (no refundwindow exists; billing-error reports go to legal@logethos.com).
[1.3] — 2026-07-12 — Payment provider: Dodo Payments → Paddle (UPDATE mode)
The merchant of record changed. Both providers are merchants of record (tax was already handled and remains so), so the tax and card-data claims are unchanged in substance — but the named subprocessor, its jurisdiction, and the cancellation semantics all moved.
Changed — subprocessor
- Payment processor Dodo Payments → Paddle (Paddle.com Market Ltd), still acting as
merchant of record (sells to the customer, collects and remits VAT/sales tax).
- Subprocessor jurisdiction corrected: India/global → United Kingdom/global — a real change
for the transfer disclosures, not a rename. Affected:
_facts.md, Subprocessors, Privacy Policy §subprocessors, Vendor Policy, Trust Center. - Removed the
dodopaymentsSDK from the third-party license list — the Paddle integrationcalls the REST API over the Python standard library and adds no new dependency.
Changed — checkout
- Checkout is now inline on our own domain (Paddle.js) rather than a redirect to a hosted
page. Card fields are still served and handled by Paddle; we still never see or store card numbers. Documented in Billing Policy §4.
Changed — cancellation (substantive, customer-facing)
- Cancellation is now explicitly effective at the end of the period already paid for, not
immediately: paid limits are retained until that date, no further charge is made, and no data is deleted when it lapses. The Billing Policy already described this outcome; the Terms and Refund Policy now state it plainly, and the implementation now matches. Added a note to the Refund Policy distinguishing cancelling (keep what you bought, no money back needed) from a refund (money back for a period already charged).
- Pausing is not offered — cancel is the only exit.
[1.2] — 2026-06-30 — Brand, legal entity & infra-truthfulness pass (UPDATE mode)
Operator-supplied launch values were finalized, and three security/infra claims were corrected to match the real self-hosted deployment. Brackets that originate in _facts.md were filled and propagated across the set.
Changed — naming & legal entity
- Product name Evigater → Evigate; company/operator brand introduced as Logethos.
- Domain evigater.com → logethos.com, including every mailbox (
privacy@,grievance@,security@,support@,legal@). [LEGAL_ENTITY_NAME]→ Logethos, a sole proprietorship based in Surat, Gujarat, India(explicitly not an incorporated company — fixed Privacy §1 "a company established in India" and the README "registered company name" wording). Governing-law venue → Surat, Gujarat. Registered address → B-204, Rajhans Tower, Mota Varachha, Surat, Gujarat, India.
- Grievance Officer rendered as the role ("The Grievance Officer",
grievance@logethos.com),no personal name (DPDP Act 2023, s.13).
[EFFECTIVE_DATE]→ July 31, 2026 across all documents.
Changed — infrastructure truthfulness
- Hosting corrected from "managed Postgres / cloud provider" to a single Hostinger VPS
running a self-hosted Postgres container and self-hosted MinIO object storage (Mumbai, India). Affected:
_facts.md, Security Overview, DPA §8, SDLC, Backup Policy, Disaster Recovery, Access Control, Vendor Policy, Subprocessors. - Encryption-at-rest claims removed (VPS disk encryption is not enabled): dropped
object-store SSE (AES-256) and managed-Postgres at-rest encryption from
_facts.md, Security Overview §2, Privacy §9, DPA Annex II (Art. 32), Trust Center, Subprocessors, and Vendor Policy. Retained the true claims: BYOK keys under Fernet, passwords under scrypt, and TLS/HSTS in transit. - Subprocessors reconciled in three places — published
subprocessors.md,_facts.md, andbackend/app/api/public.py:_SUBPROCESSORS— naming Hostinger and dropping "encrypted at rest". - Backup/recovery values set (Backup Policy, SLA): daily backups 02:30 UTC, 14-day
retention, RPO ≤ 24h, best-effort RTO, and no uptime SLA (best-effort). Certifications stated as None (not SOC 2 / ISO 27001).
Still open (flagged in README)
- Create the
logethos.commailboxes; appoint a GDPR Art. 27 EU/UK representative(Evigate is offered worldwide); configure SMTP; confirm the off-site backup region and run a test restore. If disk encryption is later enabled, restore the at-rest claims.
[1.1] — 2026-06-29 — "Sign in with Google" added (UPDATE mode)
Product change: an optional "Sign in with Google" (OAuth 2.0 / OIDC) sign-in path was added alongside email + password. It is active only when the operator configures Google OAuth credentials (GOOGLE_CLIENT_ID/GOOGLE_CLIENT_SECRET); the code-side subprocessor list (_SUBPROCESSORS) appends Google conditionally so it can never drift from reality.
Changed
_facts.md— added Google to the subprocessor table (conditional), rewrote theAuthentication section (was "email + password only"), and flipped the product-surface row for Google sign-in from *Not implemented* to *Live (optional)*.
- Privacy Policy — added "Federated sign-in data" to data collected, noted the password
is omitted for Google-only accounts, and added Google (conditional) to the subprocessor-sharing table.
- Subprocessors — added Google under Conditional subprocessors (engaged only when
the feature is configured; receives account email + Google profile id, never content).
- Data Processing Addendum — clarified Google acts as a subprocessor for authentication
only and never receives Customer Content.
- Cookie Policy — listed the short-lived
g_oauth_state/g_oauth_noncecookies setonly during a Google sign-in attempt.
Note
- Supersedes the v1.0 grounding correction "No Google OAuth / SSO" below — that was
accurate as of 2026-06-28 and is retained for history. SAML / other SSO remain not implemented.
[1.0] — 2026-06-28 — Initial generation (GENERATE mode)
Created the complete legal, privacy, security, and compliance documentation set, grounded in the Evigate codebase as of this date.
Added — Customer-facing
- Privacy Policy — DPDP Act (India) primary, GDPR + CCPA addressed; no-training,
low-retention posture; subprocessors; data residency Mumbai, India.
- Terms of Service — accounts, content ownership, human-review guarantee,
Dodo Payments as merchant of record, warranties/liability, Indian governing law.
- Cookie Policy — strictly necessary cookies only (
session,csrf_token); noadvertising/analytics cookies.
- AI Usage Policy — RAG pipeline, models (Claude Sonnet 4.6 / Voyage voyage-3),
grounding/citations/abstention, mandatory human review, no-training, BYOK.
- Acceptable Use Policy — content/conduct rules, security boundaries, fair-use of
AI compute and cost controls.
- Refund Policy & Billing Policy — Free vs Paid ($100/mo) differ by limits only;
merchant-of-record mechanics; BYOK cost ownership.
- Security Overview — full technical posture (encryption, isolation, auth, upload
screening, secrets/BYOK, logging).
- Responsible Disclosure Policy — scope, rules of engagement, safe harbor.
- Data Processing Addendum (DPA) — processor obligations, SCC-based transfers,
breach notice, deletion.
- Subprocessors — Anthropic, Voyage AI, Dodo Payments, hosting (Mumbai); matched to
the live
/api/public/subprocessorsendpoint. - Service Level Agreement — hosted-service support targets (uptime numbers left as
operator placeholders pending the single-replica architecture reality).
- Licensing — hosted + self-hosted licenses, open-source components, trademarks.
- Contact — support, privacy, DPDP Grievance Officer, security, billing/legal.
- Trust Center — hub linking all of the above plus at-a-glance posture.
Added — Internal (not published)
- Information Security Policy, Access Control Policy, Password & Authentication
Policy, SDLC, Change Management Policy, Vendor & Subprocessor Management Policy, Backup Policy, Disaster Recovery Policy, Incident Response Plan. Grounded in real CI/CD, migrations, config, and the single-replica topology; operational numbers (RPO/RTO, backup cadence, breach windows) left as explicit operator commitments.
Added — Open source
- Third-Party Licenses (from
pyproject.toml/package.json) and NOTICE.
Grounding decisions / corrections vs. assumptions
- Billing is Dodo Payments, not Stripe — corrected across all docs to match
config.py/_SUBPROCESSORS. - No Google OAuth / SSO — auth is email + password only; removed from privacy/
cookie/security claims.
- AI providers are Anthropic + Voyage AI only — OpenAI appears in a DB
constraint but has no client and is rejected; not listed as a subprocessor.
- Browser Extension, public API, and team roles are planned-not-live — described
as future, not current functionality.
- Jurisdiction = India, data region = Mumbai, per owner input.
Open action items (see README.md)
- Fill bracketed placeholders (entity name, address, contacts, hosting vendor,
effective date, Grievance Officer, EU/UK rep).
- Name the real hosting subprocessor in
backend/app/api/public.py:_SUBPROCESSORS. - Wire finalized content into the live
/privacy,/terms,/securitypages. - Set real SLA/backup/DR/breach numbers only once verified.
- Run a license scanner to finalize Third-Party Licenses / NOTICE.