Privacy policy
Last updated: 14/09/2026 · Controller: DRICLE LLP (OC453390), 5 Brayford Square, London E1 0SG, United Kingdom
1. What we collect
At signup we collect your name, email address, a hashed password, the organization name you give, and the projects and role you hold inside it. This is what an account is: nothing here is optional, and it exists to let you log in and to attribute actions to a person.
Using the product creates operational records tied to your organization: sending logs, credit ledger entries, and the input and output of each AI agent run (site analysis, target profile derivation, company qualification, contact extraction, sequence writing, LinkedIn, X and Bluesky post drafting, Reddit opportunity triage and reply drafting, reply handling). Agent run payloads, which can contain prospect names and email addresses, are treated as short lived: Eveil's policy is to clear them 90 days after the run. Agent run metrics (which model ran, how long, how many tokens, whether it succeeded) hold no personal data and are kept indefinitely, since they feed billing history. See Data retention for the full table and its current enforcement status.
2. Prospect data
Companies and contacts are found and read live at qualification time, over a bundled search engine and the company's own public pages. Nothing here is a purchased or scraped contact database. For the prospects you choose to contact, you (or your organization) are the data controller; Eveil processes that data on your instructions, as a processor, and the disclosure obligation toward the person contacted (for example under GDPR Article 14) sits with you.
A reply of "STOP", or any equivalent opt-out, is recorded permanently in a suppression list and checked before every future send. When someone asks to be forgotten, or you erase a lead yourself, their name, email address, and any other identifying fields are cleared from the record, and the subject and body of every message tied to them are blanked. What survives is a one-way hash of the email address, kept specifically so that person can never be re-added and re-contacted, even by a later import or discovery run. The hash cannot be reversed into an address. Details of how this is scoped and enforced are in Data retention.
3. Mailbox credentials
SMTP and IMAP credentials for the mailbox you connect are encrypted at rest with a dedicated encryption key, held separately from the key that protects sessions and cookies, so that rotating one never touches the other. Nobody at Eveil reads these credentials in the course of normal operation; they exist only for the application to send and read mail on your behalf. Message bodies fetched over IMAP are stored, not just their metadata, for the threads a campaign actually touches, so replies can be threaded and shown to you; they are cleared when the lead they belong to is erased.
4. AI processing
The hosted edition's agents currently run on Anthropic's Claude models. Site content, target profile drafts, company and contact information, message drafts, LinkedIn, X and Bluesky post drafts, and public Reddit thread text are sent to Anthropic's API to be processed and are subject to Anthropic's own commercial API terms, under which API inputs are not used to train their models by default. If that changes, or if we add or switch providers, this section will say so before it takes effect.
On a self-hosted instance, the operator supplies their own AI provider key and chooses the provider and model for each agent; nothing is sent to Eveil or to any provider we choose on the operator's behalf. Provider keys are encrypted at rest the same way mailbox credentials are.
5. Subprocessors
Not listed because they are not third parties: the bundled search engine and page cache run as part of the Eveil infrastructure itself, not an outside vendor. Outreach mail is sent and read over the mailbox you connect, directly over SMTP and IMAP, with no relay in between.
6. Your rights
Where applicable law grants them, you have the right to access, rectify, erase, or port your personal data, and to object to how it is processed. Send a request to [email protected]; we respond within the deadline your law sets (for example, one month under the GDPR, extendable once for complex requests). If you are not satisfied with our response, you may complain to your local data protection supervisory authority; for a request concerning us as controller, that is the UK Information Commissioner's Office.
7. Self-hosted instances
This policy covers the eveil.cloud hosted service only. If you run the AGPL-3.0 source on your own infrastructure instead, none of your instance's data passes through us: you are the controller for everything it stores, and this policy does not apply to it.