NewEvoras for AI agents
Evoras

Privacy Policy - Evoras

Privacy Policy

Last updated: 28 June 2026

TECH RACCOONS LTD (company number 16336615), a company registered in England and Wales (“Evoras”, “we”, “us”, or “our”), operates the Evoras service (the “Service”). This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, how long we keep it, and the rights you have over it.

We are the “controller” of the personal data described here, except where we process personal data contained in your content on your behalf, in which case we act as your “processor” and our Data Processing Addendum applies.

Evoras is a business service; this policy is written for our customers and the people who use our Service and visit our websites.

1. Personal data we collect

Account and profile data. Your name, email address, password (stored only as a secure hash, never in plain text), profile image if you set one, and whether your email is verified.

Authentication data. Session tokens, your IP address, your browser and device (user-agent) information, and sign-in timestamps, which we use to keep you logged in and to protect your account.

Google sign-in and Search Console data. If you sign in with Google or connect Google Search Console, we receive your Google profile and email and OAuth access and refresh tokens (encrypted at rest), and — for the properties you choose — read-only Search Console metrics such as search queries, impressions, clicks, and average positions. We use this only to prioritise your keyword plan. We never post to, or change anything in, your Google account.

Site and content configuration. The website URLs, niche, descriptions, positioning, competitors, target audiences, tone, content settings, brand colours, sitemaps, and the internal links we crawl from your site in order to generate relevant, well-linked content.

Generated content. The articles, keywords, images, SEO scores, and research sources produced for you through the Service.

Integration credentials. The API keys, tokens, application passwords, and webhook secrets for the CMS and destinations you connect. These are encrypted at rest and used only to publish content on your behalf.

Billing data. Billing is handled by our payment provider, Polar. We store identifiers and metadata such as your Polar customer and subscription IDs, your plan, your number of sites, and your billing period. Polar processes your payment details; we do not store your full card number.

Usage, technical, and security data. Records of how the Service is used, including AI usage and cost records, rate-limit counters, audit logs (the action taken, who took it, the source IP address, and a timestamp), and server logs. We use these to operate, secure, debug, and improve the Service.

Analytics data. Privacy-friendly, cookieless analytics about how our websites and app are used, and (where enabled) error reports and session replays used to diagnose problems and improve usability. See our Cookie Policy for details.

Communications. The content of messages you send us (for example support requests) and any feedback you provide, including any reason you give when you delete your account.

2. How we collect personal data

We collect personal data: directly from you, when you sign up, configure sites, or contact us; automatically, through server logs, security tooling, and our privacy-friendly analytics as you use the Service; and from third parties you connect or that help us run the Service, such as Google (sign-in and Search Console), Polar (billing), and our keyword-data provider.

3. How we use personal data, and our legal bases

Under the UK GDPR and EU GDPR we must have a legal basis for using your personal data. We use it as follows:

  • To provide and operate the Service — including account setup, authentication, researching, generating, scheduling, and publishing content, and running autopilot. Basis: performance of our contract with you.
  • To take payment and manage subscriptions — and to prevent payment fraud. Basis: performance of our contract; and compliance with legal obligations.
  • To secure and maintain the Service — rate-limiting, abuse prevention, audit logging, and debugging. Basis: our legitimate interests in keeping the Service safe, available, and reliable.
  • To measure and improve the Service — using privacy-friendly analytics. Basis: our legitimate interests in understanding and improving our product.
  • To communicate with you — about your account, security, and changes to the Service. Basis: performance of our contract and our legitimate interests.
  • To send product or marketing updates — where you have opted in. Basis: consent or legitimate interests.
  • To comply with law and enforce our terms — and to establish, exercise, or defend legal claims. Basis: compliance with legal obligations and our legitimate interests.

4. AI processing of your content

To generate articles and images, we send your site configuration, briefs, keywords, and related inputs to our AI sub-processors (Anthropic and Google). We do not use your content to train our own models, and our AI providers do not use data submitted through their business and API services to train their models. AI Outputs may still be inaccurate — see our Terms of Service.

5. How we share personal data

We do not sell your personal data. We share it with the service providers (“sub-processors”) that help us run the Service. Each is bound by contract to protect your data and to use it only to provide their service to us:

  • Anthropic — AI text generation — United States
  • Google — AI text and image generation (Gemini), Google sign-in, and Google Search Console — United States and global
  • DataForSEO — keyword data — Estonia
  • Polar — payments and subscriptions — United States / EU
  • Resend — transactional email — United States
  • Swetrix — cookieless analytics — United Kingdom
  • Hetzner — hosting — Germany (EU)
  • Cloudflare — object storage (R2) and CDN — United States / global

6. Data retention

We retain your personal data for as long as your account is active, plus a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce our agreements. You can delete sites and your account, and export your articles, directly in the Service at any time.

7. Your rights

Under UK and EU data protection law, you have rights to: access your personal data; rectify inaccurate data; erase your data (“right to be forgotten”); restrict processing; object to processing; data portability; and not be subject to automated decision-making that significantly affects you. To exercise any of these rights, email privacy@evoras.app.

8. Contact

TECH RACCOONS LTD
Company number 16336615
Registered in England and Wales
Email: privacy@evoras.app