EVALS AX / PRIVACY

Privacy policy

Version 2026-09-08 · Effective September 8, 2026

THOR APPS, LLC, a Florida company, operates Evals AX and is responsible for the personal data described here. Contact erik@evals.ax or write to 109 Mallard Trail, Ponte Vedra Beach, FL 32082, United States.

This policy covers the website, hosted accounts, API and information sent to the service by the CLI. Local experiment files stay on your machine unless you choose to upload them. We use personal data to provide the work you request, protect the service and understand use of its features.

Public website reports

Submitting a URL creates a saved report. Anyone with its unguessable report link can view the submitted URL, findings, and page snippets included as evidence. Reports ask search engines not to index them, but links can be forwarded. Only submit public pages and URLs you are comfortable sharing; query strings can contain sensitive information.

Your history

A secure browser cookie identifies your report history without signup. Clearing cookies loses access to this guest history; existing report links still work. After signing in, choose “Add browser reports” to attach that browser’s existing history to the displayed account. New reports belong to your signed-in account. History pages are private and are not cached publicly.

What is stored

We store the submitted URL, timestamps, audit results and selected evidence snippets. We do not store the full fetched HTML, forward your cookies to the target site, or use your browser’s login session to audit it. A keyed hash of the connection IP is stored to enforce usage limits. Account sign-in uses the existing Stack Auth service. Hosting and database providers process requests to operate the service.

The authentication provider holds your account and sign-in information, including an email address and profile information you supply. We use its account ID to associate your saved work. Host credential records also retain an account label, which may be your email address or display name, so you can identify the connected account.

Deleting a report

Use Delete in your report history to erase the submitted URL and report contents and disable the shared link. Basic admission metadata remains for abuse prevention. Deletion cannot recall copies that other people downloaded or provider backups. Anonymous CLI report contents expire after 7 days. Browser and account reports remain available during early access until deleted.

Private interface reports

API, CLI and MCP inspections run on your host. Uploading a report stores its title, interface inventory, diagnostic observations, output hashes and collection metadata in your private account. Raw process output is not included by the collector by default. Review the report before uploading because names and observations can still be sensitive. These reports remain until you delete them and share the account storage allowance.

Private experiments and agent telemetry

Projects, experiment manifests and uploaded results are private to the account. Manifests can contain task prompts and local paths; review them before uploading. Raw local agent traces are not attached by the CLI. Uploaded results are evidence reported by the originating host, not a certification that this service observed the run.

Agent telemetry is opt-in. Submitted usage events and content-free audit measurements are retained for 30 days; daily cleanup removes expired records. Missing usage and cost values remain unknown. Access tokens are stored as hashes on the service and can be revoked from the account. The CLI stores its credential privately on the host machine until logout or expiration.

Projects and experiments remain until you delete them. Audit admission metadata, daily admission counters and host token metadata currently have no automatic expiry. They support usage limits, abuse investigation and credential management. Revoking a token prevents its use but does not erase that metadata. We review retention and coordinate erasure when handling an account-closure or data request, subject to legal needs; closing an authentication account alone does not perform that cleanup.

Agreement records and communications

When you explicitly accept the terms, we store your internal account ID, the terms version and the server-recorded acceptance time. We do not add your IP address or email to this record. Earlier use is not treated as acceptance. Agreement history has no automatic expiry: we retain it while the account is open and review retention after closure according to the time needed to establish the agreement, handle disputes and meet legal requirements.

If you contact us, we receive the address and information you provide. We keep correspondence as needed to respond, resolve the matter and meet applicable legal requirements. Please omit sensitive material that is not needed for the request.

First-party product measurements

Product measurement collection is currently enabled. This is separate from the operational records and optional agent usage submissions described above. When enabled, our server records fixed events such as project creation, experiment upload and result retrieval. It records account and resource identifiers and timestamps, including a signup date supplied by the authentication provider when available. These identifiers are pseudonymous, not anonymous.

These product events contain no email addresses, submitted URLs, IP addresses, prompts, page snippets or agent traces. We do not add an advertising cookie, session replay or browser fingerprint. We use aggregate counts to understand adoption and where work stops; a retrieved result does not prove someone inspected it or obtained a benefit.

Product events expire after 90 days. Account observation profiles expire after 90 days of inactivity; an active profile can retain its original observation and provider signup dates for longer. Authorized operators can view aggregates. These product records stay in our service database.

Signed-in users can erase their retained product measurements with the authenticated API, including while collection is paused: evx api DELETE /account/product-telemetry. This erases the current records, not your projects or provider account. Future use can create new observations if collection is enabled. Deleting an authentication account does not yet automatically erase every separate service record; contact us for a coordinated request.

Purposes and legal grounds

Where a legal basis is required, we process account information and requested reports or uploads to provide the service under our agreement with you. Our legitimate interests support proportionate abuse prevention, service security and first-party product measurement: understanding whether features are used helps us maintain the service and decide what to improve. We limit those product events to the fields and retention described above, use aggregate operator views and do not use them for advertising or decisions with legal or similarly significant effects on individuals. These interests are subject to your rights and reasonable expectations.

We also process information when necessary to comply with legal obligations or establish or defend legal claims. If a particular activity requires consent under applicable law, we will request it before that activity; accepting the terms is not consent to unrelated data uses. You may contact us to object to processing based on legitimate interests. We will assess the request under the applicable law; the self-service erasure command alone is not a continuing opt-out.

Providers and local storage

Vercel hosts the service, Neon stores service records, and Stack Auth handles account authentication and sign-in messages. They process data needed to provide those services and may maintain their own security logs and backups. Your chosen agent provider receives the inputs used by local experiments under your configuration and its own terms.

Essential browser storage supports authentication, guest history and your appearance preference. Clearing it can sign you out or disconnect guest history. Local CLI credentials are separate from browser cookies; use evx auth logout to revoke the saved host login.

Our operator is in the United States. Hosting, database and authentication providers may process information in other locations under their service arrangements. Provider information is available from Vercel, Neon and Stack Auth (now Hexclave). Contact us for information about the safeguards applicable to a particular transfer. Evals AX does not claim certification under the EU–US Data Privacy Framework.

We do not sell personal data or share it for cross-context behavioral advertising. We may disclose information to comply with a valid legal requirement, protect rights and service security, or complete a corporate transaction subject to continued protection of the information and any legally required notice.

Your rights and requests

Depending on the law that applies to you, you may request access, correction, deletion, a portable copy, restriction of processing or objection to certain uses. Where processing depends on consent, you may withdraw it without affecting earlier lawful processing. You may complain to your local data-protection or consumer-protection authority where applicable. We will not discriminate against you for exercising a protected right.

Contact erik@evals.ax about access, correction, deletion or concerns about your data. We may need to verify account ownership. Do not send passwords, magic links or access tokens by email. Legal preservation requirements and provider backup cycles can limit immediate erasure; we will explain any applicable limits when handling a request.

Children and policy changes

The account service is intended for adults. If you believe a child has provided personal data, contact us so we can investigate and remove it where required.

We date and version this policy and will provide notice of material changes where required. The collection status above reflects the current deployment. A policy update does not retroactively record consent or agreement.