Legal
Privacy Policy
Last updated: 12 September 2026
This Privacy Policy explains how evex (“evex”, “we”, “us”) collects, uses, stores, and protects your information when you use evex — on WhatsApp, on this website (evex.chat) and in the evex app. We’ve written it to be clear and honest — if anything is unclear, email us at hello@evex.chat.
1. Who we are
evex is a personal assistant that also handles your time, and it lives in WhatsApp, on the web and in the iPhone app. You tell it what needs to happen — as text, a photo, a voice note or a document — and it puts the event in your calendar, checks conflicts, plans your week around your real free time, keeps your to-dos, and answers questions about your time. It writes to Google Calendar, Outlook (Microsoft), Apple iCloud Calendar, or the evex calendar — which lives only in our own database and needs no third-party permission. This policy applies to the service on every surface and to this website.
2. Information we collect
We collect only what we need to provide the service:
- Your account identity. Depending on how you sign in: your phone number (WhatsApp, and phone + code sign-in); your email address and name (Google, Microsoft or Apple sign-in, or email + password — the password is stored only as a one-way hash, never in clear); Apple’s stable user identifier when you sign in with Apple. The phone number is the identifier that links your WhatsApp chat to your account.
- Message content you send to evex. The text you type, the images and documents you send (a flyer, a timetable, a PDF), and voice notes you record — on WhatsApp, in the web chat, in the app, and, where email-in is enabled, in emails you send evex (the message body, attachments, your sender address and the mail’s authentication headers). Voice notes are transcribed and the transcript is stored with the message; evex’s replies are stored too. We also keep the recording itself for 7 days, with a note of its type, size and length: so evex can understand what you said, so it can try again when a recording could not be made out or its transcript was lost, and so a support request you file about a voice note has the note behind it. After 7 days the recording is deleted automatically and only the transcript remains, with the rest of the conversation. Recordings are never public: they are stored under an unguessable address and can only be opened by us, signed in, for the reasons above.
- Calendar access and a copy of your events. When you connect a calendar we store the credential the provider issues — Google and Microsoft OAuth tokens, or the Apple app-specific password you create — encrypted at rest. We keep a synchronised copy (“mirror”) of the events on the calendars you connect — titles, times, locations, descriptions and attendees — so evex can check conflicts, find the event you mean, plan around your busy time and answer “what’s on Tuesday” without a round-trip to the provider.
- What evex builds for you. A log of the events evex created, changed or cancelled (with your original message and the model’s reading of it, so mistakes can be traced); your tasks and reminders; your plans and routines; the corrections you make on an event card; contacts you teach evex (names, emails, phone numbers); the people you invite to events and their RSVPs; settings such as timezone, week start, language, home location and transport mode if you set them, and your taste preferences.
- Conversation memory and support. A rolling summary of your recent conversation plus the last few turns, kept for seven days so evex can answer “why did you…”; records of exchanges where something went wrong (your message, evex’s reply); and, when you open a support ticket in the chat, your report in your own words, evex’s summary of it, and the stretch of conversation around what went wrong — the messages either way, the lookups evex ran and the version of evex that was live — recorded at the moment you opened the ticket. If that stretch contains voice notes, evex asks you once whether the team may listen to them; only if you say yes is a copy of those recordings attached to the ticket, and it is deleted after 90 days.
- Waitlist and invitations. If you join the waitlist we keep the email address or phone number you gave us. If someone invites you with a link, we record which link you used.
We do not collect payment card details through evex, and we do not knowingly collect data from anyone under the age of 16.
3. Google user data & Google API Services User Data Policy
To work with your Google Calendar, evex requests permission to read and manage events on the calendars you own, to list your calendars and read your calendar settings, and to see your email address. We request the narrowest access that makes the service work and nothing more.
evex’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the calendar scheduling features you request.
- We do not transfer or sell Google user data to third parties for advertising, marketing, or any unrelated purpose.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read your Google data unless we have your explicit consent for a specific purpose (for example, to resolve a support issue you raised), it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymized.
- Our use of Google data received via these scopes is limited to the practices described in this policy.
You can review and revoke evex’s access to your Google account at any time from your Google Account permissions page. The same applies to Microsoft (your Microsoft account’s app permissions) and Apple (delete the app-specific password in your Apple ID settings).
4. How we use your information
- To read your messages and understand what you asked for.
- To create, update, cancel and confirm events in the calendar you connected — Google, Outlook, iCloud or the evex calendar.
- To answer questions about your time, plan your week, keep your tasks, and send you the optional evening digest and morning brief.
- To send you replies and confirmations over WhatsApp, in the web chat and in the app — and, if you turn it on, to email calendar invitations to people you name.
- To look up and route to the locations you mention (see Google Maps below).
- To operate, maintain, secure, and improve the reliability of the service.
- To provide customer support and respond to your requests.
5. How your data is processed
evex is built on a small set of service providers (“sub-processors”) that process data on our behalf and under our instructions. Each holds only what its job needs:
- WhatsApp Business Platform (Meta). Delivers messages between you and evex; Meta sees the messages you exchange with evex as it does any WhatsApp business chat.
- Google. Calendar and sign-in (your events and identity); the Gemini API (AI processing — section 6); Google Maps Platform (the event locations you mention, to find the place and the route).
- Microsoft. Sign-in identity, and Outlook calendar events when you connect one.
- Apple. Sign in with Apple, and iCloud Calendar events when you connect one.
- Vercel. Hosts the website, the app’s servers and the message pipeline; stores the images you send in the chat and the voice notes you record (Vercel Blob) for seven days.
- Neon. The database — everything listed in section 2 lives here.
- Upstash. A short-lived cache: message de-duplication, rate limits, sign-in codes (as one-way hashes), your conversation memory and the current plan proposal.
- Inngest. The queue that runs each message reliably — every message passes through it while it is being handled.
- Resend. Sends our emails (calendar invitations, password resets, replies to emails you send evex) and, where email-in is enabled, receives the emails you send evex.
- Better Stack and Sentry. Operational logs and error reports, so we can see when something breaks. Phone numbers and message content are hashed or removed before anything is logged.
- GitHub. Holds an encrypted nightly backup of the database, kept for 90 days.
6. AI processing
Understanding your messages is done by an AI model — the Google Gemini API, which we use on its paid tier. When you send evex a message, the content you authored (your text, an image or document you sent, or your voice note and its transcript) is processed by the model to work out what you asked for and any event details — title, date, time, location. The model also writes the short conversation summary described in section 2. Specifically:
- The message content you author is processed by the AI model.
- To answer your questions and plan your time, evex sends the relevant parts of your calendar (event titles, times and locations you or your calendars provide) to our AI provider under its paid, no-training terms. It is never used to train models and is not retained by the provider. You can turn this off in Settings; evex will then answer only from what you tell it in chat.
- Under the Gemini API’s paid-tier terms, the content we submit is not used to train or improve AI models.
7. Data retention
We retain your account information, your messages and transcripts, your events, tasks and settings, and any support tickets for as long as your account is active, so the service remains useful to you and so mistakes can be traced. Some data is deleted automatically: the working record of each batch of extracted events after 90 days; copies of images you sent after 7 days; the voice-note recordings themselves after 7 days (their transcripts stay with the conversation); voice notes you agreed to attach to a support ticket after 90 days; your rolling conversation memory after 7 days; sign-in codes within minutes. Backups are kept for 90 days. When you ask us to delete your data, or after a prolonged period of inactivity, we delete or anonymize your personal information, including your stored calendar credentials, within a reasonable period unless we are required to retain it to comply with legal obligations.
8. How we protect your data
- Calendar credentials (OAuth tokens and Apple app-specific passwords) are encrypted at rest, stored server-side, and never exposed to your browser, to the app or to other users. Passwords are stored only as one-way hashes.
- Access to production data is limited to the people who operate the service.
- Phone numbers and message content are hashed or removed before they reach our logs or error reports.
- Data is transmitted over encrypted connections (HTTPS/TLS) between services.
No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information.
9. Sharing your information
We do not sell your personal information. We share data only with the sub-processors listed above to operate the service, with the people you ask us to invite to an event (they receive the invitation and an RSVP link), or where required by law, legal process, or to protect the rights, safety, and security of our users and the service.
10. Your rights and choices
- Access & correction. You can ask what data we hold about you and request corrections.
- Export. Download everything evex holds that is yours as one file from Settings (“Download my data”).
- Deletion. You can ask us to delete your account and associated data at any time by emailing hello@evex.chat.
- Revoke calendar access. Disconnect any calendar from your evex Settings, or revoke evex from your Google, Microsoft or Apple account at any time.
- What the AI may see. Turn calendar access for the AI off in Settings, or tell evex in the chat.
- Quiet. The evening digest and morning brief are optional and can be switched off in Settings or in the chat.
- Stop using evex. You can stop messaging evex at any time; you may also request that we remove your number.
11. Cookies
The website uses only the cookies it needs to work: your sign-in session, and short-lived cookies while you sign in, link an account or accept an invitation. Your light/dark preference is kept in your browser’s local storage. We use no advertising or analytics cookies.
12. International users
Your information may be processed on servers located in countries other than your own. Where we transfer data internationally, we take steps to ensure it remains protected in line with this policy.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you.
14. Contact us
Questions, requests, or concerns about your privacy? Email us at hello@evex.chat.