Evidite Privacy Policy
Effective Date: August 5, 2026 | Version 1.0.0
This Privacy Policy describes how Evidite, Inc. ("Evidite," "we," "us," or "our") collects, uses, and protects information when you use our services, including CitateScreen, CitateGenie, QuotateGenie, BluebookGenie, CitateVerifier, BlindnoteGenie, and evidite.com (collectively, the "Service").
The short version: We collect only what we need to operate the Service. We do not sell your personal data. We do not use AI to analyze your documents. Your uploaded documents are not stored after processing.
1. Information We Collect
1.1 Information You Provide
- Account information: Email address and password (stored as a hashed value — we never store plaintext passwords) when you create an account
- Payment information: Billing details are collected and processed directly by Stripe, Inc. We receive only a transaction confirmation and the last four digits of your card — never your full card number
- Documents you upload: Files submitted for processing. These exist temporarily in server memory during processing only and are not stored after your session ends
- Communications: If you contact us by email, we retain that correspondence
1.2 Information We Collect Automatically
- Usage data: Number of documents processed, credit consumption, timestamps of activity
- Technical data: IP address, browser type, operating system, referring URL — collected in server logs for security and debugging purposes
- Cookies and local storage: We use browser local storage to maintain your authentication session. We do not use third-party tracking cookies or advertising cookies
1.3 Information We Do NOT Collect
- We do not collect, retain, or analyze the content of your uploaded documents beyond what is necessary to process them
- We do not collect demographic data, behavioral profiles, or sell your information to data brokers
- We do not use your documents to train AI models
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Authenticate your identity and maintain your account
- Process payments and manage your credit balance
- Send transactional emails (account verification, password reset, purchase receipts)
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
- Respond to your support requests and communications
We do not use your information to:
- Sell or rent it to third parties
- Target you with advertising
- Profile your behavior for marketing purposes
3. How We Share Your Information
3.1 Service Providers
We share limited information with vendors who help us operate the Service:
These vendors are contractually prohibited from using your data for their own purposes.
3.2 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect rights, property, or safety.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you via email before your data is transferred and becomes subject to a different privacy policy.
3.4 No Sale of Personal Data
We do not sell, trade, or rent your personal information to third parties. Period.
4. Data Retention
- Account data (email, hashed password, credit balance): Retained while your account is active. Deleted within 90 days of account termination at your request
- Uploaded documents: Not retained. Deleted from server memory when your session ends
- Transaction records: Retained for 7 years as required for financial and tax compliance
- Server logs: Retained for 90 days for security purposes, then deleted
5. Security
We implement industry-standard security measures:
- All data transmitted between your browser and our servers is encrypted via TLS (HTTPS)
- Passwords are hashed using bcrypt before storage — plaintext passwords are never stored
- Authentication uses JSON Web Tokens (JWT) with expiration
- Our infrastructure runs on Google Cloud Platform with access controls and audit logging
- Payment data never touches our servers — Stripe handles it directly
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to security@evidite.com.
6. Cookies and Tracking
We use browser local storage (not traditional cookies) to store your authentication token so you remain logged in across page loads. We do not use:
- Third-party advertising or tracking cookies
- Analytics services that track individual behavior across sites (e.g., Google Analytics)
- Fingerprinting or cross-site tracking technologies
7. Your Rights
7.1 All Users
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and personal data
- Portability: Request your data in a machine-readable format
7.2 EU/EEA Residents (GDPR)
If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to restrict processing
- Right to object to processing based on legitimate interests
- Right to lodge a complaint with your local supervisory authority
Our legal bases for processing are: (a) contract performance — to provide the Service you signed up for; (b) legitimate interests — security, fraud prevention, and service improvement; and (c) legal obligation — financial record-keeping.
7.3 California Residents (CCPA/CPRA)
California residents have the right to know what personal information we collect and how we use it, to request deletion, to opt out of "sale" (we do not sell data), and to not be discriminated against for exercising these rights.
To exercise any of these rights, contact us at privacy@evidite.com. We will respond within 30 days.
8. Children's Privacy
The Service is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at privacy@evidite.com and we will delete it promptly.
9. International Data Transfers
Evidite is based in the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.
10. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective Date" and notify you via email. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions, requests, or concerns:
* * *