legal
Privacy Policy
last updated: july 2026
Overview
Evenfall (“we”, “our”) is an AI chat client. This policy explains what information we collect when you use Evenfall — whether through the web app or the Evenfall browser extension — how we use it, and what rights you have over it.
This is a working document for a product under active development. If anything changes that affects how we handle your data, we'll update this page and note the change in the “last updated” line above.
What we collect
We collect the minimum needed to deliver the service:
- Account data — your email address (for sign-in) and, if you use Google OAuth, your Google account identifier.
- Conversation data — the messages you send, the assistant responses they produce, and per-conversation settings you configure (title, custom instructions, model).
- Usage data— counts of how many messages you've sent in the current rate-limit window, and timestamps for sign-in sessions.
- Payment data — if you upgrade, our payment providers (Stripe, NOWPayments) process your card or crypto details directly. We see the transaction result (success/failure, amount, plan), not the underlying payment method.
- Technical data — IP address and request headers, used for rate limiting and abuse prevention. Not joined with your conversations.
What we don't collect
- We don't track you across other sites.
- We don't sell your data or share it with advertisers.
- We don't use your conversations to train AI models.
How we use it
- Deliver the chat service (send prompts to the AI provider, stream responses back).
- Persist your conversations so you can return to them.
- Rate limiting and abuse prevention.
- Billing for paid plans.
- Transactional emails (welcome, account notifications). No marketing emails.
Third parties we use
- Supabase — authentication, Postgres database (conversations, messages, accounts).
- AI model provider — a third-party provider that generates responses. Your prompts are sent to it to produce replies.
- Stripe — card payments.
- NOWPayments — cryptocurrency payments (when enabled).
- Vercel — hosting and edge delivery.
- Resend — transactional email delivery.
Each of these providers has their own privacy policy and processes data on our behalf.
Retention
Conversations stay in your account until you delete them. Deleting a conversation removes its messages from our database. Deleting your account removes everything.
While stored, conversation content is encrypted at the application layer (AES-256-GCM) before it reaches the database, with per-conversation encryption keys held outside the database. This is in addition to standard disk-level encryption and TLS in transit. Our servers decrypt conversation content to generate replies and to operate the service; this is not end-to-end encryption.
Payment and authentication logs may persist longer where required by our providers or applicable law.
Your rights
You can:
- Access your data — your conversation history is visible in the app at any time.
- Delete individual conversations or your entire account from Settings.
- Request an export or further information by emailing support@vilgren.com.
Depending on where you live, you may have additional rights under GDPR, CCPA, or equivalent local laws. Contact us and we'll honor them.
Cookies
We use cookies for session management (keeping you signed in). That's it — no advertising cookies, no third-party trackers.
Browser extension
The Evenfall browser extension is a side-panel companion to the same service, using the same account. Everything above applies to it. In addition:
- Page content— the extension can attach text from the page you're viewing (its title, address, selected text, and a bounded portion of its visible text) to a message, but only when you explicitly ask it to: by tapping the page-context button on a message, or by choosing an Evenfall item in the right-click menu. Reading page text also requires an optional browser permission that is off by default, requested via Chrome's own prompt when you enable it, and fully revocable in the extension's settings. The extension never reads pages automatically or in the background, and collects no browsing history.
- On-device storage— your extension settings and, in the default “local only” mode, your extension chat history and local notes are stored only in your browser's extension storage on your device. They are never sent to our servers unless you switch on account sync. Deleting them in the extension, or removing the extension, deletes that local data.
- Sign-in — the extension uses your existing evenfall.ai session cookie. It stores no passwords or tokens of its own.
- Where data goes — the extension communicates only with evenfall.ai (plus our storage provider for displaying images you attach). It contains no analytics and no trackers. Messages and notes you choose to sync are handled exactly as described in the rest of this policy.
Changes
If we change this policy, we'll update the date at the top. Material changes that affect what data we collect or how we use it will be announced in-app or via email.
Contact
Questions or requests? support@vilgren.com
Data controller
The data controller responsible for your personal data is:
Vilgren OÜRegistry code: 14810642Väike-Aru tn 4-40, 80036 Pärnu linn,Pärnu maakond, EstoniaEmail: support@vilgren.com