Privacy Policy
Last updated: July 14, 2026
This Privacy Policy explains how Edvin.ai (“Edvin”, “we”, “us”, or “the Service”) collects, uses, stores, and protects personal data.
Controller: Edvin.ai
Contact: [email protected]
Business address: Available on request until public company details are finalized.
1. What data we collect
We may collect and process the following data:
Account data
- name
- email address
- login/authentication information
- account settings
- plan and billing status
Workspace and product data
- workspace name
- company or project information you choose to add
- preferences and configuration
- saved context
Messages and requests
- chat messages
- prompts
- instructions
- questions
- generated responses
Files and extracted content
- uploaded files
- file names
- file type
- file size
- extracted text or structured data from files
- summaries and chunks created to help Edvin answer questions about files
Generated work
- documents
- drafts
- audits
- plans
- checklists
- charts
- data tables
- reports
- emails
- other outputs created by Edvin
Memory
- optional saved memories that you choose to enable or approve
- user preferences
- useful project or business context
- prior decisions or facts you want Edvin to remember
Website and tool data
- URLs you ask Edvin to review
- public page text and metadata retrieved for requested scans
- tool results
- validated summaries of tool/script results
Usage and technical data
- usage events
- work capacity / usage status
- timestamps
- request status
- error logs
- browser/device information
- security and abuse-prevention events
Payment data
If paid plans are available, payments may be processed by a payment provider. We do not intentionally store full card numbers.
2. How we use data
We use data to:
- provide Edvin’s AI-assisted work features
- authenticate users
- create and manage accounts
- respond to prompts and requests
- process uploaded files
- generate documents, charts, plans, and other outputs
- scan public web pages when requested
- save optional memory when enabled
- enforce usage limits
- process payments
- provide support
- improve reliability and product quality
- prevent abuse, fraud, spam, phishing, malware, and illegal use
- comply with legal obligations
3. Legal bases for processing
If GDPR applies, we rely on the following legal bases:
Contract
We process data to provide the Service you request, including account access, AI responses, files, generated outputs, and paid features.
Legitimate interests
We process limited data to secure the Service, prevent abuse, monitor reliability, improve performance, enforce usage limits, and protect users and Edvin from misuse.
Consent
We use consent where required, including optional memory features and certain communications.
Legal obligation
We may process or retain data when required by law, regulation, legal process, or security obligations.
4. AI processing
Edvin uses AI model providers to generate responses and outputs.
At launch, Edvin primarily uses Gemini for AI processing.
When you use Edvin, selected parts of your messages, files, memories, settings, or other context may be sent to the AI provider only as needed to provide the requested feature.
We aim to send only the context needed for the task. For example, if you upload a large file, Edvin should use relevant parts rather than sending the entire file unnecessarily.
Do not submit highly sensitive information unless it is necessary for your use of the Service.
5. Where data is stored
Edvin stores user data using cloud infrastructure located in the European Union where supported.
We do not describe internal database structure publicly for security reasons.
6. Memory
Memory is optional.
If enabled, Edvin may save useful context to improve future work.
You can review and delete memory.
Memory should not be used to store passwords, API keys, secrets, payment details, government ID numbers, or other highly sensitive information.
7. File uploads
Files you upload are processed to provide the requested feature.
Files remain stored until you delete them, delete the related workspace/account data, or request deletion, unless we need to retain limited information for legal, security, or abuse-prevention reasons.
When you delete a file, we aim to delete the associated extracted text and processing data.
8. Data retention
We keep account data while your account is active.
Chat history, generated outputs, uploaded files, and work Edvin created are kept until you delete them, delete your account, or request deletion, unless we are required or permitted to retain limited information for legal, security, billing, dispute, abuse-prevention, or operational reasons.
Usage and security logs may be kept for a limited period to operate and protect the Service.
Safety and abuse-related records may be retained where needed to investigate misuse, enforce policies, protect the Service, or comply with legal obligations.
9. Abuse prevention and safety checks
We use automated and manual safety measures to prevent misuse of Edvin.
This may include detecting or blocking:
- phishing
- malware-like requests
- credential theft
- fraud or scams
- spam
- illegal activity
- harassment or threats
- privacy invasion
- tool abuse
- attempts to bypass safety systems
We do not manually review private user content by default.
Manual review may occur when needed for:
- user support
- user reports
- abuse investigation
- security incidents
- suspected policy violations
- legal obligations
- account appeals
When possible, abuse monitoring uses metadata, categories, hashes, and short excerpts rather than full content.
10. Who we share data with
We may share data with service providers that help us operate Edvin, such as:
- cloud hosting and database providers
- AI model providers
- email providers
- payment providers
- analytics or reliability tools, if used
- security or abuse-prevention tools
These providers may process data only as needed to provide their services to Edvin.
We may also disclose data if required by law, legal process, or to protect rights, safety, and security.
11. International transfers
Some service providers may process data outside your country. Where required, we use appropriate safeguards for international transfers.
12. Security
We use technical and organizational measures to protect data, including:
- authentication
- access controls
- encryption in transit
- cloud provider encryption at rest
- usage limits
- safety checks
- restricted admin access
- logging for sensitive administrative actions
No system is perfectly secure. You are responsible for keeping your account secure.
13. Your rights
Depending on where you live, you may have rights to:
- access your personal data
- correct inaccurate data
- delete data
- export data
- restrict or object to processing
- withdraw consent where processing is based on consent
- complain to a data protection authority
To exercise rights, contact [email protected].
We may need to verify your identity before fulfilling a request.
14. Deleting your data
You can delete certain data inside the product, such as memories and uploaded files, where supported.
You can also contact [email protected] to request account deletion or data deletion.
Some limited records may be retained where required for legal, security, fraud-prevention, billing, dispute, or abuse-prevention purposes.
15. Children
Edvin is not intended for users under 16.
If we learn that a user under 16 has created an account, we may delete or restrict the account.
16. Changes
We may update this Privacy Policy from time to time.
If changes are material, we will provide notice where appropriate.
17. Contact
For privacy requests or questions: