← Eve

Eve Privacy Policy

Last updated: 25 September 2026. Eve is operated by Alexa Loste. Contact: alexa@evecortex.com.

1. What this covers

This policy covers Eve, the memory service at evecortex.com, including the Eve web app and the Eve connector you add to Claude, ChatGPT, or another assistant.

2. What we collect

Your account. When you sign in with Google we receive your email address and your name. We ask Google for nothing else at sign-in: the scope is openid email profile. We store that email and name in a per-user file.

Your memories. Eve stores structured memories: people, events, topics, concepts, places, beliefs, rules, documents, and questions. These are written by your assistant as you talk to it, or by you directly in the Eve app. Each memory records its own text, when it was written, how confident it is, and whether it came from a conversation, from a consolidation pass, or from you typing it.

Your conversations with Eve in the Eve web app. If you chat with Eve on evecortex.com, that conversation is written to a durable per-user transcript on our server and kept. This is separate from your memories, and there is no automatic expiry on it today. Conversations you have in Claude or another assistant are not copied to us. The connector only receives the specific tool calls your assistant makes.

Files you point Eve at. If you connect Google Drive, Eve reads files you create through Eve or hand to it through the Google file picker. If you import a chat export from another AI tool, we hold the uploaded file while the import runs and delete it when the import completes, or after 7 days if you start an import and never finish.

Your settings, usage and billing. Preferences, token and cost totals used to enforce your plan's spend cap, and your subscription state. Payment is handled by Stripe. We never see or store your card details.

How you use the Eve web app. The app records which screens you open and time on those screens in 15-second increments, which setup steps you finish, which features you use (consolidate, export, share or upload), and when an error appears. These are event names only, never the text of your memories, messages or files. We use them to see what works. Only the operator sees them, per person.

An access log. Every time someone who is not you reaches your memories, we write a record: who, when, which path, and why. You can read your own log at any time. An empty log is the normal answer.

3. What we do with it

We use your data to run Eve: to build memories out of what you tell your assistant, to find them again when you ask, to keep them tidy, and to bill you.

We do not train models on your data. We do not sell it. We do not share it for advertising. No third-party analytics or session-recording tools run in Eve. The usage events above stay on our own server.

4. Who else sees it

If you add files from Google Drive or upload files, Eve sends their text to the same model providers when it reads or indexes them.

Companies that can see the text of your memories

Fireworks AI — builds and retrieves memories. Eve's language model runs on Fireworks. Fireworks receives the text Eve is turning into a memory and returns the structured result.

Fireworks' Terms of Service §3.6 says they will not use our content to train their models or to improve their service, and commits them to a zero data retention policy: they will not log our content for human review, and will not keep it beyond the time it takes to generate and return an answer. Two exceptions are written into that same clause, and we would rather name them than let you find them: the commitment does not apply where law requires otherwise or where they need the content to provide support to us, and they reserve the right to run safety screening tools over it. The commitment covers inference, which is all we use them for. We call only their standard inference endpoint and none of the features that retain data by design.

Their Data Processing Addendum is incorporated into those Terms (§2.4) and includes the EU Standard Contractual Clauses (DPA §12.1). It obliges them to tell us about a security incident within 48 hours (DPA §10.1) and to delete our data after the agreement ends (DPA §11.2). They hold SOC 2 Type II, ISO 27001, ISO 27701 and ISO 42001. They do log request metadata such as token counts in order to run the service.

Fireworks' Terms of Service, last updated 10 July 2026, and the DPA it incorporates, both read in full on 22 September 2026. Region: United States.

OpenAI — makes memories searchable. Memory text is sent to OpenAI's embeddings API (text-embedding-3-small) to be turned into vectors. OpenAI does not train on data submitted through their API. It may keep that data for up to 30 days to check for abuse, then deletes it. We intend to move embeddings onto the same provider as inference so there is one processor instead of two. Region: United States.

Your assistant's maker. When you use Eve through a connector, the assistant you connected is the thing calling Eve. Whatever it asks for, it receives, and it is covered by that company's own privacy policy, not ours. If you use Eve inside Claude, Anthropic sees what Claude sees.

Companies that receive something, but never your memories

Fly.io — hosting and storage. Fly runs the application and holds the volume your data sits on. As our host, Fly has the access any hosting provider has to its own infrastructure, including, structurally, the key that unlocks our at-rest encryption, because Eve has to restart unattended. We say that plainly rather than implying our encryption defends against our own host. Region: United States, San Jose.

Google — sign-in, and Drive or Calendar if you connect them. See section 7.

GitHub — optional, only if you connect it. Scope repo read:user.

Stripe — payments.

Google (SMTP) — sends your invite and shared-space emails from our own Gmail account.

Pushover — sends the founder a phone alert when Eve goes down. Service status only. No user data, no account identifiers, no memory content.

Us

We can reach your data operationally, the way the operators of any hosted service can reach their own systems. Eve is not end to end encrypted and we will not describe it that way: memories are built and consolidated on our servers while you are asleep, so there is no moment when only your device could hold the key.

Two things constrain that. Admin routes are gated behind a separate admin token with read and write split apart, and every access to a cortex by someone who is not its owner is written to your access log, which you can read. The honest limit, stated in our own source: that log lives on the same machine as the data, so an operator with root could alter it. It is a real deterrent and a record of good faith. It is not tamper proof attestation.

5. Who can read a memory

By default, only you. Each person's memories live in their own database directory, not as rows in a shared table with a filter over them. When you use the connector, the access token's subject is the only thing that selects a cortex, and no user id is ever read from the request.

Shared spaces. For any shared memory space you create or join: you invite someone by email and they join a space you both write into. A member is an owner, a contributor who can read and write, or a reader who can only read. Memory Lane shows who added each memory. Reads of a shared space by another member are recorded in the owner's access log with the kind shared_cortex. Your personal memories are never visible to members of a shared space. Joining or leaving a shared space does not touch your personal memories.

6. Deletion

Deleting a memory removes it from the graph immediately, so Eve stops recalling it, and keeps a copy in your own trash so you can restore it. That trash is yours. Eve does not read from it.

Emptying the trash destroys the content. What is left behind is a content-free record that something was forgotten, not the thing itself.

Asking Eve to forget a fact goes further than deleting one card. It replaces the fact wherever it appears, including in memories derived from it, and it also removes the fact from three places outside the graph that would otherwise bring it back: your trash, the undo snapshot a consolidation pass leaves behind, and the queue of saves waiting to retry. If removing a pending save takes unrelated content with it, we tell you how many and why rather than doing it silently.

Restoring a backup does not undo your erasure. We keep a tombstone outside the backed-up data recording which records were erased, and we replay it after any restore. The tombstone stores the ids and a salted hash, never the forgotten value itself. The limit, stated rather than discovered later: replay re-erases exactly what was erased before, so a backup that contains an older carrier of the same fact will not be caught. A restore is a moment to ask you to confirm, not to promise silence.

Deleting your account. There is no button for this yet. Email alexa@evecortex.com and we will delete everything we hold about you within 30 days: your memories, your trash, your conversations with Eve, your settings, your usage records, your access log and your sign-in identity. You will get confirmation when it is done. If you want a copy first, export from the account menu or ask us and we will send you one.

7. Google Drive and Google Calendar

Both are optional and separate from sign-in. Neither is requested when you first log in.

Drive uses one scope, https://www.googleapis.com/auth/drive.file. That scope is enforced by Google to cover only files Eve itself created and files you explicitly hand to Eve through the Google picker. Eve cannot see the rest of your Drive. We deliberately removed the broader "see your whole file tree" scope.

Calendar uses calendar.readonly and calendar.events. It runs against a separate Google OAuth client in a separate Google Cloud project from sign-in. Both scopes are requested when you connect even though today's code only reads, so that adding writes later does not drag every connected user back through a second consent screen.

You can disconnect either at any time from your Google account permissions page or from Eve's settings.

8. Security

In transit: HTTPS everywhere, forced at the edge.

At rest: your data sits on an encrypted filesystem under a key we hold, separate from the disk. The application refuses to start if the encrypted volume does not mount and verify, so there is no path where Eve quietly starts writing your memories in plaintext. The encryption is authenticated, which means tampering with stored data produces a hard read error rather than plausible wrong answers. For a memory product that matters as much as confidentiality.

What that does and does not cover, plainly: it protects offline copies, a stolen disk, a leaked backup, decommissioned hardware. It does not make us unable to read your memories, and it does not defend against our hosting provider.

Logs. Our application logs record events, identifiers and error types, never the text of your memories, your queries or your documents. We audited every log statement in June 2026 and fixed the ones that leaked content. Logs are not shipped anywhere off-platform: there is no log drain and no third-party log aggregator.

What we do not have. No SOC 2 and no ISO certification. We are a very small team and we have not been through an audit. We would rather say that than imply coverage we do not have.

No BAA, so please do not put health records in Eve. Our model provider's terms also prohibit sending health information without a separately negotiated agreement, and we do not have one.

9. Children

Eve is not for people under 13, or under the minimum age for consenting to online services in your country if that is higher (16 in some EU countries), and we do not knowingly collect their data.

10. Your rights

You can see everything Eve holds about you in the Eve app. You can edit any memory, delete any memory, or ask Eve to forget a fact across everything derived from it. You can export your memories as JSON and Markdown at any time, free, from the account menu. That export covers your memory graph. It does not currently include your Eve web-app conversation transcript, your uploaded attachments, or your access log. If you want those, ask and we will send them.

If you are in the EU or the UK: we process your data to perform our contract with you, and we rely on the EU Standard Contractual Clauses for transfers to our US processors. You have the right to access, correct, delete and port your data, and to complain to your data protection authority.

11. Changes

If this policy changes we will update it here and tell existing users. Our processor list is part of this policy, and we will say when it changes.

12. Contact

alexa@evecortex.com. You will reach the founder, not a queue. We will complete a vendor security questionnaire on request.

The short version is on what Eve stores.