Skip to content
EANVI

Privacy Policy

What we store, why we store it, and how encrypted secret values are treated.

Last updated

Information we collect

Eanvi collects account information you provide (name, email, password hash), organization and project metadata, encrypted secret values, audit log events, billing identifiers from Paddle, and notification preferences. We also store session tokens in HTTP-only cookies.

Secret values are encrypted at rest with AES-256-GCM before they are written to the database. We do not use secret values for advertising or model training.

How we use information

We use account data to authenticate you, authorize access to organizations, deliver product email (verification, invites, security alerts, billing), and enforce plan limits. Audit logs record sensitive operations so workspace owners can review activity.

Payment processing is handled by Paddle. We store Paddle customer, subscription, and invoice identifiers needed to show plan status and invoices in settings.

Cookies and sessions

Authentication uses secure HTTP-only session cookies issued by Auth.js. We also store a sidebar preference cookie and an active organization cookie to keep the dashboard consistent across reloads. These are functional, not advertising cookies.

Sharing

We do not sell personal information. We share data with infrastructure providers required to run the product (database hosting, email delivery via Resend, realtime via Ably, payments via Paddle) under their respective processing terms.

Retention and your rights

Audit log retention follows your plan (7, 30, or 90 days). Account and workspace data remain until you delete the organization or account from Settings. You may request export or deletion by contacting us through the contact form.

If you are in a region with additional privacy rights, contact us and we will honor legally required access, correction, and deletion requests.