Security & Data Handling
Last updated: July 14, 2026
Edvin.ai is designed to help users work with goals, documents, websites, data, and generated outputs. Because users may upload important information, we take privacy, access control, and abuse prevention seriously.
1. What Edvin stores
Depending on your use, Edvin may store:
- account information
- chat messages
- uploaded files
- extracted file text
- generated documents and outputs
- optional memories
- website URLs you ask Edvin to review
- usage and reliability data
- security and abuse-prevention events
2. Data location
Edvin stores user data using cloud infrastructure located in the European Union where supported.
3. Encryption and access control
Data is protected with:
- authentication
- access controls
- encryption in transit
- cloud provider encryption at rest
- user/workspace-scoped access
- server-side verification for protected actions
- rate limits and usage limits
Edvin is not currently end-to-end encrypted. This means the system must be able to process selected content to provide AI features.
Workspace owners and administrators should enable multi-factor authentication with their identity provider and remove access promptly when a person leaves the team.
4. Files
Uploaded files are used to provide the features you request.
Files remain available until you delete them or delete the related account/workspace data, unless limited records must be kept for legal, security, or abuse-prevention reasons.
Do not upload files you do not have the right to use.
Do not upload passwords, API keys, private keys, payment information, or other secrets unless absolutely necessary.
5. Memory
Memory is optional.
When enabled, memory helps Edvin remember useful context.
You can review and delete memory.
Memory should not be used for passwords, secrets, payment information, or highly sensitive personal data.
6. AI providers
Edvin uses AI model providers to generate responses and outputs.
At launch, Edvin primarily uses Gemini.
Only selected context needed for the task should be sent to the model provider.
7. Connected accounts and email
If you connect Gmail or another account, Edvin should use that connection only to perform the work you ask for or the ongoing checks you enable.
Connected account access may include selected message metadata, message content, thread context, drafts, and delivery-related information depending on the permission you grant.
Edvin may draft emails and messages from connected context.
Edvin may send emails to you or confirmed colleagues when your settings and plan allow it.
External recipients stay approval-first unless you explicitly approve sending.
You can disconnect integrations from Edvin settings.
8. Ongoing checks
Edvin can run scheduled or ongoing checks when enabled. These checks may review project context, connected inbox signals, public web pages, research results, plans, reminders, risks, or previous work.
Each check should record what Edvin checked, what it did, what it skipped, and why it stayed quiet when no useful action was needed.
Edvin should avoid doing work only for the sake of activity. If no meaningful signal changed, it may record a quiet check instead of creating noise.
9. Auditability and controls
Workspace owners and managers can review important activity such as invitations, role changes, integration changes, billing changes, ongoing work activity, sent internal emails, drafts, and data export or deletion actions where supported.
Settings can control retention for activity history, audit records, email-derived summaries, created work, and quiet scheduled runs.
Users with the right access can export data or delete workspace data from settings where supported.
10. Abuse prevention
To protect users and the Service, Edvin may use automated safety checks.
These checks help detect or block:
- phishing
- malware-like requests
- credential theft
- fraud
- spam
- illegal activity
- privacy invasion
- unsafe tool use
- attempts to bypass safety systems
Manual review is not the default.
Manual review may occur for support, user reports, abuse investigation, security incidents, legal obligations, or appeals.
11. Admin access
Administrative access should be limited and logged.
Admins should access user content only when necessary for support, security, abuse investigation, legal compliance, or account appeals.
12. Deleting data
You can delete memories and uploaded files where supported.
You can contact [email protected] to request account or data deletion.
Some limited records may be kept where needed for legal, security, billing, dispute, or abuse-prevention purposes.
13. Security reports
If you find a security issue, contact: