All policies

Open source & history

Changelog

Version 1.5Effective July 31, 2026Updated 2026-07-21

All notable changes to the /policies documentation set are recorded here. Format loosely follows Keep a Changelog. Each product change that affects legal documentation should add an entry under a new version with the affected documents and the reasoning.

[1.5] — 2026-07-21 — Embeddings go local, Gemini fallback disclosed, BYOK/limits corrected (UPDATE mode)

A batch of factual corrections, driven by _facts.md, propagated across the set to close drift between the published documents and the real implementation.

Changed — embeddings now run locally

  • Voyage AI is no longer a subprocessor. Evidence is embedded on our own

    infrastructure (self-hosted bge-large-en-v1.5 via fastembed/ONNX, CPU) — chunk text never leaves our server. This is a privacy upgrade: there is no longer an embedding subprocessor at all, with or without BYOK. Every Voyage AI reference removed and replaced with a local-embeddings note.

Changed — Gemini fallback disclosed as a conditional subprocessor

  • backend/app/clients/llm.py silently fails a platform-key Anthropic call over

    to Google's Gemini API (GEMINI_API_KEY, conditional; BYOK-Anthropic orgs never fail over). Now documented everywhere Anthropic was listed as the LLM subprocessor. Anthropic remains under a signed no-training, zero/low-retention agreement; the Gemini fallback is disclosed as relying on Google's stated no-training terms for that API tier, not a bespoke signed agreement — any "signed agreement with every AI subprocessor" phrasing was corrected to draw this distinction.

Changed — BYOK provider list corrected

  • The real BYOK options are **Anthropic, OpenAI, Gemini, a local Ollama endpoint,

    and a custom OpenAI-compatible endpoint (frontend/app/settings/keys/page.js), not "Anthropic and/or Voyage AI." Added, where BYOK is first explained in each doc: non-Anthropic BYOK data is governed by the customer's own agreement with that provider, and embeddings are never BYOK** (always the local platform model).

Changed — other factual corrections

  • Free-plan limits corrected to 10 documents / 50 questions (code was already

    right; the docs said 50/500). Paid stays 5,000 docs / 100,000 questions, $150/mo.

  • PDF OCR intake disclosed: scanned/image PDF pages are rendered as images and

    sent to Anthropic (vision) at intake to extract questions, in addition to the existing answer-time data flow. Born-digital pages are unaffected.

  • Topology corrected: production runs Traefik + a backend tier + a separate

    Arq worker tier + Redis for answering, not single-replica in-process answering.

  • ToS §3 no longer contradicts the live "Sign in with Google" feature; the

    Trust Center's Auth row now lists it too.

  • Removed a stray voyage-3 reference from the AI Usage Policy models table;

    corrected subprocessors.md's maintainer note (already-named Hostinger, not a stale hosting vendor); open-source/third-party-licenses.md and NOTICE.md dependency lists updated (removed voyageai; added fastembed, onnxruntime, pypdfium2, pillow, arq, google-genai, httpx, redis; corrected MinIO and Postgres from "local dev only" / "managed" to self-hosted in production too).

  • Repo root README.md corrected from "Haiku 4.5 in production" to

    claude-sonnet-4-6, and updated its LLM/embeddings/BYOK summary line.

Affected documents

ai-usage-policy.md, acceptable-use-policy.md, subprocessors.md, data-processing-addendum.md, billing-policy.md, privacy-policy.md, service-level-agreement.md, trust-center.md, terms-of-service.md, security-overview.md, open-source/third-party-licenses.md, open-source/NOTICE.md, and repo-root README.md. refund-policy.md, cookie-policy.md, contact.md, licensing.md, and responsible-disclosure-policy.md were checked and required no changes.

[1.4] — 2026-07-21 — Refunds: discretionary → strict no-refund policy (UPDATE mode)

Founder decision: paid subscriptions are non-refundable. The Free plan carries the full feature set, so evaluation happens before payment ("if you trust it, then buy"); refunds are not part of the offer. Two carve-outs are retained because they cannot be removed: genuine billing errors (duplicate charge, charge after timely cancellation, wrong amount — always corrected via Paddle) and non-waivable consumer rights under applicable law. Paddle, as merchant of record, administers refunds/chargebacks, and its buyer terms still apply to the payment transaction.

Changed

  • refund-policy.md — rewritten (v1.1): "Subscription refunds" (discretionary) replaced by

    "No refunds" + "Billing errors"; the [REFUND_WINDOW] and [REFUND_RESPONSE_DAYS] placeholders and their operator note are removed (no longer applicable); cancellation-vs- refund explanation retained.

  • billing-policy.md §9 and terms-of-service.md §8 — refund cross-references now state the

    non-refundable position instead of only linking out.

Resolved (from the open-placeholder list)

  • [REFUND_WINDOW], [REFUND_RESPONSE_DAYS] — resolved by policy decision (no refund

    window exists; billing-error reports go to legal@logethos.com).


[1.3] — 2026-07-12 — Payment provider: Dodo Payments → Paddle (UPDATE mode)

The merchant of record changed. Both providers are merchants of record (tax was already handled and remains so), so the tax and card-data claims are unchanged in substance — but the named subprocessor, its jurisdiction, and the cancellation semantics all moved.

Changed — subprocessor

  • Payment processor Dodo Payments → Paddle (Paddle.com Market Ltd), still acting as

    merchant of record (sells to the customer, collects and remits VAT/sales tax).

  • Subprocessor jurisdiction corrected: India/global → United Kingdom/global — a real change

    for the transfer disclosures, not a rename. Affected: _facts.md, Subprocessors, Privacy Policy §subprocessors, Vendor Policy, Trust Center.

  • Removed the dodopayments SDK from the third-party license list — the Paddle integration

    calls the REST API over the Python standard library and adds no new dependency.

Changed — checkout

  • Checkout is now inline on our own domain (Paddle.js) rather than a redirect to a hosted

    page. Card fields are still served and handled by Paddle; we still never see or store card numbers. Documented in Billing Policy §4.

Changed — cancellation (substantive, customer-facing)

  • Cancellation is now explicitly effective at the end of the period already paid for, not

    immediately: paid limits are retained until that date, no further charge is made, and no data is deleted when it lapses. The Billing Policy already described this outcome; the Terms and Refund Policy now state it plainly, and the implementation now matches. Added a note to the Refund Policy distinguishing cancelling (keep what you bought, no money back needed) from a refund (money back for a period already charged).

  • Pausing is not offered — cancel is the only exit.

Operator-supplied launch values were finalized, and three security/infra claims were corrected to match the real self-hosted deployment. Brackets that originate in _facts.md were filled and propagated across the set.

  • Product name Evigater → Evigate; company/operator brand introduced as Logethos.
  • Domain evigater.com → logethos.com, including every mailbox (privacy@, grievance@,

    security@, support@, legal@).

  • [LEGAL_ENTITY_NAME]Logethos, a sole proprietorship based in Surat, Gujarat, India

    (explicitly not an incorporated company — fixed Privacy §1 "a company established in India" and the README "registered company name" wording). Governing-law venue → Surat, Gujarat. Registered address → B-204, Rajhans Tower, Mota Varachha, Surat, Gujarat, India.

  • Grievance Officer rendered as the role ("The Grievance Officer", grievance@logethos.com),

    no personal name (DPDP Act 2023, s.13).

  • [EFFECTIVE_DATE]July 31, 2026 across all documents.

Changed — infrastructure truthfulness

  • Hosting corrected from "managed Postgres / cloud provider" to a single Hostinger VPS

    running a self-hosted Postgres container and self-hosted MinIO object storage (Mumbai, India). Affected: _facts.md, Security Overview, DPA §8, SDLC, Backup Policy, Disaster Recovery, Access Control, Vendor Policy, Subprocessors.

  • Encryption-at-rest claims removed (VPS disk encryption is not enabled): dropped

    object-store SSE (AES-256) and managed-Postgres at-rest encryption from _facts.md, Security Overview §2, Privacy §9, DPA Annex II (Art. 32), Trust Center, Subprocessors, and Vendor Policy. Retained the true claims: BYOK keys under Fernet, passwords under scrypt, and TLS/HSTS in transit.

  • Subprocessors reconciled in three places — published subprocessors.md, _facts.md, and

    backend/app/api/public.py:_SUBPROCESSORS — naming Hostinger and dropping "encrypted at rest".

  • Backup/recovery values set (Backup Policy, SLA): daily backups 02:30 UTC, 14-day

    retention, RPO ≤ 24h, best-effort RTO, and no uptime SLA (best-effort). Certifications stated as None (not SOC 2 / ISO 27001).

Still open (flagged in README)

  • Create the logethos.com mailboxes; appoint a GDPR Art. 27 EU/UK representative

    (Evigate is offered worldwide); configure SMTP; confirm the off-site backup region and run a test restore. If disk encryption is later enabled, restore the at-rest claims.

[1.1] — 2026-06-29 — "Sign in with Google" added (UPDATE mode)

Product change: an optional "Sign in with Google" (OAuth 2.0 / OIDC) sign-in path was added alongside email + password. It is active only when the operator configures Google OAuth credentials (GOOGLE_CLIENT_ID/GOOGLE_CLIENT_SECRET); the code-side subprocessor list (_SUBPROCESSORS) appends Google conditionally so it can never drift from reality.

Changed

  • _facts.md — added Google to the subprocessor table (conditional), rewrote the

    Authentication section (was "email + password only"), and flipped the product-surface row for Google sign-in from *Not implemented* to *Live (optional)*.

  • Privacy Policy — added "Federated sign-in data" to data collected, noted the password

    is omitted for Google-only accounts, and added Google (conditional) to the subprocessor-sharing table.

  • Subprocessors — added Google under Conditional subprocessors (engaged only when

    the feature is configured; receives account email + Google profile id, never content).

  • Data Processing Addendum — clarified Google acts as a subprocessor for authentication

    only and never receives Customer Content.

  • Cookie Policy — listed the short-lived g_oauth_state / g_oauth_nonce cookies set

    only during a Google sign-in attempt.

Note

  • Supersedes the v1.0 grounding correction "No Google OAuth / SSO" below — that was

    accurate as of 2026-06-28 and is retained for history. SAML / other SSO remain not implemented.

[1.0] — 2026-06-28 — Initial generation (GENERATE mode)

Created the complete legal, privacy, security, and compliance documentation set, grounded in the Evigate codebase as of this date.

Added — Customer-facing

  • Privacy Policy — DPDP Act (India) primary, GDPR + CCPA addressed; no-training,

    low-retention posture; subprocessors; data residency Mumbai, India.

  • Terms of Service — accounts, content ownership, human-review guarantee,

    Dodo Payments as merchant of record, warranties/liability, Indian governing law.

  • Cookie Policy — strictly necessary cookies only (session, csrf_token); no

    advertising/analytics cookies.

  • AI Usage Policy — RAG pipeline, models (Claude Sonnet 4.6 / Voyage voyage-3),

    grounding/citations/abstention, mandatory human review, no-training, BYOK.

  • Acceptable Use Policy — content/conduct rules, security boundaries, fair-use of

    AI compute and cost controls.

  • Refund Policy & Billing Policy — Free vs Paid ($100/mo) differ by limits only;

    merchant-of-record mechanics; BYOK cost ownership.

  • Security Overview — full technical posture (encryption, isolation, auth, upload

    screening, secrets/BYOK, logging).

  • Responsible Disclosure Policy — scope, rules of engagement, safe harbor.
  • Data Processing Addendum (DPA) — processor obligations, SCC-based transfers,

    breach notice, deletion.

  • Subprocessors — Anthropic, Voyage AI, Dodo Payments, hosting (Mumbai); matched to

    the live /api/public/subprocessors endpoint.

  • Service Level Agreement — hosted-service support targets (uptime numbers left as

    operator placeholders pending the single-replica architecture reality).

  • Licensing — hosted + self-hosted licenses, open-source components, trademarks.
  • Contact — support, privacy, DPDP Grievance Officer, security, billing/legal.
  • Trust Center — hub linking all of the above plus at-a-glance posture.

Added — Internal (not published)

  • Information Security Policy, Access Control Policy, Password & Authentication

    Policy, SDLC, Change Management Policy, Vendor & Subprocessor Management Policy, Backup Policy, Disaster Recovery Policy, Incident Response Plan. Grounded in real CI/CD, migrations, config, and the single-replica topology; operational numbers (RPO/RTO, backup cadence, breach windows) left as explicit operator commitments.

Added — Open source

  • Third-Party Licenses (from pyproject.toml / package.json) and NOTICE.

Grounding decisions / corrections vs. assumptions

  • Billing is Dodo Payments, not Stripe — corrected across all docs to match

    config.py / _SUBPROCESSORS.

  • No Google OAuth / SSO — auth is email + password only; removed from privacy/

    cookie/security claims.

  • AI providers are Anthropic + Voyage AI only — OpenAI appears in a DB

    constraint but has no client and is rejected; not listed as a subprocessor.

  • Browser Extension, public API, and team roles are planned-not-live — described

    as future, not current functionality.

  • Jurisdiction = India, data region = Mumbai, per owner input.

Open action items (see README.md)

  • Fill bracketed placeholders (entity name, address, contacts, hosting vendor,

    effective date, Grievance Officer, EU/UK rep).

  • Name the real hosting subprocessor in backend/app/api/public.py:_SUBPROCESSORS.
  • Wire finalized content into the live /privacy, /terms, /security pages.
  • Set real SLA/backup/DR/breach numbers only once verified.
  • Run a license scanner to finalize Third-Party Licenses / NOTICE.