Privacy Policy
Last updated: June 2026
This Privacy Policy explains how EvenBase ("we", "us") collects, uses, stores, and shares information when you visit evenbase.io or use EvenBase applications and automations, including the demo applications hosted at demos.evenbaselabs.com (together, the "Services"). Contact: info@evenbase.io, Istanbul, Türkiye.
1. Information We Collect
a) Website contact form. If you use the "Contact Us" form, we collect the details you choose to share (name, email address, phone, subject and message) and use them only to respond to your request and prepare a service proposal. Apart from that, our website collects no automatic data about your visit unless you acknowledge the notice shown at the bottom of the page, with the exception of the third-party image loading described in Section 6.
b) Connected account data (Google and Microsoft sign-in). Some EvenBase applications let you connect your Google Account or your Microsoft account. We request only the permissions needed for the features you use, and we access only the data types listed below.
Google user data:
- Basic profile (name, email address, profile picture). Used to identify your session and deliver outputs to you.
- Gmail: read, label, and send (gmail.modify). Used by the Mail Automation to read incoming messages in order to categorize them, to create and apply category labels, and to send replies and notifications from your account using templates you configure. We do not delete your emails.
- Google Calendar: availability and events (calendar.events, calendar.freebusy). Used to check your free time slots and to create meeting events you or your correspondents confirm.
- Google Drive, Docs, Sheets, and Slides: per-file access (drive.file). Used by the Research application to create new documents, spreadsheets, presentations, folders, and ZIP archives in your own Google Drive. With this permission, our application can only access files that it creates for you; it cannot see, open, or modify any of your existing Drive files. The files created belong to you.
Microsoft account data (via Microsoft Graph):
- Basic profile (name, email address). Used to identify your session.
- Outlook Mail: read, categorize, and send (e.g., Mail.ReadWrite, Mail.Send). Used by the Mail Automation to read incoming messages in order to classify them, to apply categories/flags, and to send replies and notifications from your account using templates you configure. We do not delete your emails.
- Outlook / Microsoft 365 Calendar: availability and events (e.g., Calendars.ReadWrite). Used to check your free time slots and to create meeting events you or your correspondents confirm.
The exact permissions requested are always shown to you on the Google or Microsoft consent screen before you approve them.
2. How We Use Connected Account Data
We use Google user data and Microsoft account data solely to provide and improve the user-facing features you actively request: classifying and labeling your incoming email, drafting and sending replies you have configured, scheduling meetings, and generating research documents in your Drive. We do not use this data for advertising, we do not sell it, and we do not use it for any purpose unrelated to these features.
3. AI and Automated Processing
Our features use large language models operated by third-party AI service providers to perform tasks you request (for example, classifying an email, drafting a reply from your templates, or structuring a research report). Relevant content is transmitted to these providers only to produce that output and is processed under API/business terms that do not permit the provider to use the data to train their models.
We do not use Google user data (in raw, derived, aggregated, or anonymized form) to develop, improve, or train generalized or foundational AI/ML models. The same commitment applies to Microsoft account data. Improvements we make to our automations (such as adjusting prompts or workflow logic) are made without incorporating any customer's connected account data.
4. Limited Use and API Policy Compliance
EvenBase's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Our access to and use of Microsoft account data is limited to the permissions you grant on the Microsoft consent screen and complies with Microsoft's applicable API terms and policies.
5. Storage, Security, and Retention
- Access tokens. Google and Microsoft access tokens are short-lived, stored in access-controlled workflow infrastructure within our workflow infrastructure only while your automation session is active, and are not usable after they expire. In demo applications, sessions expire automatically after approximately one hour. Disconnecting your account invalidates our access. For live deployments, an encrypted refresh credential may be stored for as long as the automation remains enabled and is deleted when you disconnect your account.
- Email content. Message content (Gmail or Outlook) is processed transiently for classification and reply generation. We retain only the resulting label/category metadata needed to avoid re-processing; message bodies are not stored on our systems.
- Generated documents. Research outputs (Docs, Sheets, Slides, images, ZIP archives) are created directly in your Google Drive and are owned by you. To embed generated images into your documents, a file we created may be shared via a temporary link during generation; this temporary permission is removed automatically once embedding completes.
- Demo showcase. In the demo environment, research outputs may be listed in our public results gallery. Please do not submit confidential topics in demos.
We protect data in transit with TLS and restrict internal access to personnel who need it to operate the Services. Human access to connected account data is not permitted except with your explicit consent, for security purposes, or to comply with applicable law.
6. Sharing
We share data only with the service providers necessary to operate the Services (hosting and workflow infrastructure, and the AI providers described in Section 3), each bound by confidentiality obligations. We do not sell personal data or share it with third parties for their own marketing. We may disclose information where required by law. Business data of corporate clients is protected under dedicated confidentiality agreements (NDA).
There are two exceptions. Advertising measurement: once you acknowledge the notice at the bottom of the page, the Google Ads conversion tag loads and your IP address, the page you view and the referring address are sent to Google; until you acknowledge it, the tag is not loaded. Image content: some logos on the integrations page load from Composio's content network, and that request carries your IP address to their server regardless of the notice. Details are set out in the Cookie Policy.
7. Your Rights and Revoking Access
You may at any time:
- Revoke EvenBase's access to your Google Account via myaccount.google.com/permissions;
- Revoke EvenBase's access to your Microsoft account via account.live.com/consent/Manage (personal accounts) or myapplications.microsoft.com / your organization's administrator (work or school accounts);
- Request access to, correction of, or deletion of your data by emailing info@evenbase.io. We honor deletion requests within 30 days;
- Exercise your rights under applicable data-protection law, including the Turkish Personal Data Protection Law (KVKK No. 6698) and, where applicable, the GDPR.
8. Changes and Contact
We may update this policy from time to time; the current version is always available at this address with its "Last updated" date. Questions: info@evenbase.io.