Legal
Privacy Policy
Effective July 28, 2026
What we collect
- Account data — your email address and authentication details. If you sign in with Google or Apple, we receive the email address and basic profile details (such as your name) those providers share.
- Your content — the projects, documents, claims, private evidence, and reports you create in the workspace.
- Billing data— your subscription status and usage counts (how many claims you’ve verified). Payment card details go directly to our payment processors and never touch our servers.
- Operational logs — standard server logs (IP address, request metadata) kept for security and debugging.
How we use it
We use your data to run the product: storing your workspace, extracting and verifying claims you queue, metering usage against your plan, and emailing you transactional messages (confirmation, password reset). We do not sell your data, and we do not use your documents to train AI models.
Who processes your data
Eustace is built on a small set of processors, each receiving only what its job requires:
- Supabase — database and authentication (stores your account and workspace content).
- Vercel — application hosting and AI Gateway routing.
- AI model providers (via Vercel AI Gateway, currently Anthropic) — receive document text (and, for scanned PDFs, the uploaded file itself so it can be transcribed) and claims to perform extraction and verification.
- Tavily — web search; receives search queries derived from claims being verified (not your whole document).
- RevenueCat and Stripe — subscription billing and overage invoices. We store your subscription status and billing references (such as a Stripe customer ID); card details go to Stripe directly and never touch our servers.
- Cloudflare — bot protection (Turnstile) on the sign-in, sign-up, and password-reset forms. Your browser connects to Cloudflare, which evaluates request signals (IP address, browser characteristics) to filter automated abuse. Cloudflare also routes mail sent to our support address.
- Sentry — error monitoring. When something breaks, Sentry receives the error report (stack trace, request metadata) and a small sample of performance timings so we can find and fix faults. Not your documents.
Retention and deletion
Your content stays in your workspace for as long as you keep your account. You can remove private evidence you’ve added at any time; deleting your account removes everything. If you need a specific project or document removed sooner, write to support@eustace.app and we’ll remove it for you. Encrypted backups age out on a rolling schedule.
You can delete your entire account and all of its data yourself from Settings. If a Pro subscription is still live — including one in a billing-issue grace period — cancel it first; deletion then takes effect immediately, and any remaining paid time is given up. Billing records held by our payment processors (for example, invoices) are retained by them as their own legal obligations require. If you’d rather we handle deletion, or you can’t sign in, contact support@eustace.app and we’ll complete it for you.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Deletion is self-serve in Settings (after canceling any active subscription); for anything else, email support@eustace.app and we’ll honor these requests. Reports you export are yours — Markdown files you can keep anywhere.
Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production data is restricted, and rows in the database are isolated per account.
Cookies
We use the cookies required to keep you signed in (authentication session), plus strictly necessary cookies our payment provider sets during checkout for fraud prevention. The sign-in forms also load Cloudflare’s Turnstile bot check, which may set its own cookie, scoped to Cloudflare, while it runs. No advertising or cross-site tracking cookies.
Changes and contact
If this policy changes materially, we’ll notify you before the change takes effect. Questions or requests: support@eustace.app. See also the Terms of Service.