Privacy policy
Customer evidence stays local by default.
This page describes the current Evalt SDK and free early-access workspace. Last updated July 23, 2026.
Data the local SDK keeps
Prompts, inputs, outputs, approved examples, evaluation cases, images, model responses, route history, feedback, reports, local evidence-library items, provider credentials, and raw request/response data remain on the computer running Evalt unless you deliberately send them elsewhere. The SDK uses a local SQLite route database and local files you choose.
Data the optional workspace receives
When you explicitly connect a workspace, Evalt may synchronize a route name, selected model/configuration labels, aggregate quality/cost/latency values, bounded progress events, route/run/version identifiers, evidence-strength labels, timestamps, and aggregate health deltas. Server allowlists reject customer-content fields. Access records contain an opaque grant ID, role, bounded label, creation/expiry/revocation/last-used times, and a one-way capability digest.
Prompts, inputs, outputs, cases, images, approved answers, raw responses, provider keys, webhook secrets, custom scorer code, email addresses, IP addresses, or browser fingerprints.
Provider calls
Model calls are made through the provider configuration you choose, currently including OpenRouter paths. Evalt requests zero-data-retention routing and denies provider data collection where supported, but the provider’s own terms and technical behavior govern its service. Review those terms before sending sensitive data.
Hosting and retention
The public site and hosted API run on third-party infrastructure, including Render and, when configured, encrypted Cloudflare R2 object storage. Workspace records are encrypted at rest by the application. Browser workspace capabilities are stored in that browser’s local storage. Disconnecting a browser forgets its local capability; an owner can remove a dashboard route copy or revoke delegated access. Local route evidence is controlled by you and is not deleted by removing a dashboard copy.
Accounts, analytics, and sale of data
The current private workspace does not require an email account. Evalt does not sell customer data. The current product does not intentionally add advertising trackers or behavioral analytics to these pages. Basic infrastructure logs may be produced by hosting providers for security and operations.
Questions and deletion
For non-sensitive privacy questions, open an issue in the public repository without including customer content or credentials. To remove a synchronized route, use the dashboard’s dashboard-copy removal control. Revoke delegated access from Workspace access. Local files remain under your control.