All policies

Legal & terms

Privacy Policy

Version 1.1Effective July 31, 2026Updated 2026-07-21

Summary

Evigate is a tool that drafts cited answers to security questionnaires from evidence you upload. This policy explains what personal data we handle, why, who it is shared with, and the rights you have. The short version:

  • We collect the minimum needed to run the service: your account details, the

    evidence and questionnaires you upload, the answers produced, and basic operational logs.

  • We never use your content to train AI models, and we never sell your data.
  • **Embeddings run locally, on our own infrastructure — chunk text never leaves

    our server. Only Anthropic, and conditionally Google's Gemini API** as an automatic fallback, ever receive customer-derived content, and only the minimum, and if you bring your own API keys, not even them.

  • Your content stays in the Mumbai, India region on a single-tenant VPS until

    you delete it. You can export or permanently delete all of it yourself at any time.


1. Who we are

Evigate is operated by Logethos, a sole proprietorship based in Surat, Gujarat, India ("Evigate," "we," "us"). Registered address: B-204, Rajhans Tower, Mota Varachha, Surat, Gujarat, India.

For privacy questions or to exercise your rights, contact privacy@logethos.com. Our Grievance Officer under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") is identified in Section 14.

2. Scope and roles

This policy covers the Evigate hosted service and our marketing site. Where Evigate offers self-hosted deployment, you run the software in your own infrastructure and you are the controller of all data within it; this policy then applies only to limited account, billing, and support interactions with us.

Two distinct relationships apply to the hosted service:

  • Account and billing data: name, email, organization name, subscription

    state. For this we are the data fiduciary / controller (DPDP Act; GDPR Art. 4(7)).

  • Customer content: the evidence documents, questionnaires, questions, and

    drafted answers you upload and generate. We process this on your behalf and under your instructions as a data processor (GDPR Art. 4(8); "service provider" under CCPA). Your own privacy notice governs the personal data your content may contain. Our handling of customer content as a processor is set out in the Data Processing Addendum.

3. What we collect

CategoryExamplesSource
Account dataEmail address, organization name, hashed password (scrypt); password omitted for accounts created via "Sign in with Google"You, at signup
Authentication dataServer-side session records (only a SHA-256 of the session token is stored), CSRF token, email-verification / password-reset tokens (stored only as hashes)Generated on login
Federated sign-in dataOnly if you choose "Sign in with Google": your Google account email and Google profile id (the stable subject identifier), used to create or sign in to your accountGoogle, when you use Google sign-in
Customer contentUploaded evidence (SOC 2 reports, policies, past questionnaires), incoming questionnaires, extracted questions, drafted answers, your reusable answer libraryYou, in use
Billing dataSubscription plan and status, billing/customer identifiersVia Paddle (our merchant of record)
Usage / meteringPer-organization counts of documents and questions, token/cost ledger of AI and embedding callsGenerated in use
Operational logsRequest metadata, a per-request request ID, error eventsGenerated automatically
BYOK keysYour own AI/embedding provider API keys, if you add them; encrypted at rest, write-onlyYou, optionally

We do not collect special-category data deliberately, and we do not log document contents or full AI prompts. Payment card details are handled entirely by Paddle; we never see or store full card numbers.

We use personal data only to operate the service for you:

PurposeData usedLegal basis (DPDP / GDPR)
Provide the service (store, retrieve, draft, review, export)Account, customer contentPerformance of contract / legitimate use for the service requested
Authenticate and secure accountsAccount, authentication dataContract; legitimate interests in security
Bill and manage subscriptionsAccount, billing dataContract
Meter usage and prevent abuse/cost overrunsUsage/metering, logsLegitimate interests
Send transactional email (verification, password reset)Email addressContract
Maintain, debug, and improve reliabilityLogs, error eventsLegitimate interests
Comply with lawAs requiredLegal obligation

We do not send marketing or lifecycle email and run no advertising. We do not make automated decisions producing legal or similarly significant effects about you; the service produces *draft* answers that a human always reviews.

5. AI processing of your content

Evigate is a Retrieval-Augmented Generation (RAG) tool. The detailed, plain-language description of how AI is used, what data leaves your environment, and the human-review guarantee lives in the AI Usage Policy. In summary:

  • At ingest, chunk text from your evidence is embedded **locally, on our own

    infrastructure** — it is never sent to a third party to produce retrieval vectors. For scanned/image PDF pages only, the page is also sent to Anthropic (vision) at intake to extract the questions on it.

  • At answer time, a single question plus the handful of retrieved snippets

    (never whole documents, never your full corpus) is sent to our AI provider to draft a grounded, cited answer. If that call to Anthropic errors, a platform-key request may automatically fail over once to Google's Gemini API (only when the operator has configured it); BYOK-Anthropic requests never fail over.

  • Your content is never used to train any model. Anthropic operates under a

    signed no-training, zero/low-retention agreement; the Gemini fallback relies on Google's stated no-training terms for that API tier rather than a bespoke signed agreement. Embeddings never leave our infrastructure at all.

  • With BYOK, LLM calls run on your own provider account instead of ours;

    embeddings are never BYOK and always run locally.

6. Who we share it with (subprocessors)

We use a small, fixed set of vendors. The authoritative, always-current list, including purpose and exactly what data each receives, is published at Subprocessors and served live from the application so it can never drift from what the system actually does. As of the last-updated date:

SubprocessorPurposeData sharedLocation
AnthropicAI provider, drafts answers; also reads scanned questionnaire page images at intakeA question + retrieved snippets at answer time; a scanned page image + extracted text at intakeUSA
Google — Gemini API *(conditional: only when GEMINI_API_KEY is configured, and only for the request that failed over)*Automatic LLM fallback if the Anthropic call errorsSame as the Anthropic call for that requestUSA
PaddlePayments (merchant of record)Billing details onlyUnited Kingdom / global
Google *(only if you choose "Sign in with Google")*Optional federated sign-inAccount email + Google profile idUSA
HostingerCloud VPS hosting + self-hosted storageYour data at rest on the VPSMumbai, India

Embeddings are computed locally on our own infrastructure and never appear in this table — there is no embedding subprocessor.

We do not sell personal data and do not share it for cross-context behavioral advertising (CCPA/CPRA). We may disclose data if required by law, or in connection with a merger or acquisition (you will be notified).

7. International data transfers

Your customer content is hosted in the Mumbai, India region on a Hostinger VPS (if the data region changes, this section will be updated and the analysis below applied to the new region). Our AI subprocessor, Anthropic, and conditionally Google's Gemini API (fallback only), are located in the United States, so a question plus retrieved snippets, and at intake for scanned PDF pages a page image, transit to the US. Embeddings are computed locally on our infrastructure in Mumbai and never transit anywhere.

  • DPDP Act: transfers outside India are permitted except to countries the

    Government of India may restrict; none of our subprocessors are in a restricted country.

  • GDPR (EU/EEA customers): transfers rely on the European Commission's

    Standard Contractual Clauses with each importer, as referenced in our DPA.

  • BYOK removes us from these AI transfers entirely: the LLM calls then run

    on your own provider account.

8. Retention

We retain customer content only as long as you keep it. There is no fixed expiry: your data stays until you delete a document or purge your organization. On deletion, we remove the database rows and the stored files. Account and billing records are retained for the life of the account and for a limited period afterward as required for tax, accounting, and legal purposes. Backups, where maintained, are cycled on a rolling basis. Operational logs are short-lived and never contain document contents or prompts.

9. Security

We protect data with encryption in transit (TLS/HTTPS with HSTS) and application-level encryption of secrets at rest (BYOK keys under authenticated encryption; passwords hashed with scrypt). Stored documents and database records reside on a secure, single-tenant, access-controlled VPS. For customers with specific disk-level encryption requirements, we offer a self-hosted option. We also apply strict per-organization and per-project isolation, hardened HttpOnly session cookies with CSRF protection, a strong-password policy, rate limiting and account lockout, and upload screening. The full technical description is in the Security Overview.

10. Your rights

Subject to the law that applies to you, you have rights to access, correct, update, export (portability), and delete your personal data, to withdraw consent, and to complain to a regulator. Most are self-serve in the product:

  • Access / portability: export a portable, secret-free JSON snapshot of your

    organization's data from Settings.

  • Deletion: delete any document, or permanently purge your entire

    organization and all its data, from Settings.

  • Correction: edit your account and content in the product, or contact us.

To exercise a right we cannot fulfill in-product, email privacy@logethos.com. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising a right.

  • India (DPDP Act): you may nominate another person to exercise your rights in

    the event of death or incapacity, and may escalate to our Grievance Officer and then the Data Protection Board of India.

  • EU/EEA/UK (GDPR): you may lodge a complaint with your supervisory authority.
  • California (CCPA/CPRA): you have the rights to know, delete, correct, and to

    opt out of "sale"/"sharing"; we do neither.

11. Cookies

Evigate uses only strictly necessary cookies (your authentication session and a CSRF token). We set no advertising or third-party analytics cookies. See the Cookie Policy.

12. Children

Evigate is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18. Under the DPDP Act, processing children's data requires verifiable parental consent; we do not target or knowingly serve children.

13. Changes

We may update this policy as the product evolves. Material changes will be reflected here with a new "last updated" date and noted in our public changelog. Continued use after an update constitutes acceptance.

14. Contact and grievances

  • Privacy / data requests: privacy@logethos.com
  • Grievance Officer (DPDP Act, s.13): The Grievance Officer, grievance@logethos.com
  • EU/UK representative (GDPR Art. 27): [EU_UK_REP], if appointed
  • Postal: Logethos, B-204, Rajhans Tower, Mota Varachha, Surat, Gujarat, India

*Effective date: July 31, 2026 · Last updated: 2026-07-21 · Version 1.1*