Privacy Policy
Last updated: January 29, 2026
AI-Powered Platform Notice
Evaro is an AI-powered platform that processes data using artificial intelligence and machine learning technologies. This policy explains how we collect, use, store, and protect your data, including data processed by our AI systems.
1. Introduction
At Evaro ("we," "our," or "us"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI chatbot platform and services. This policy applies to all users of our Services, including business customers ("Customers") and end users who interact with chatbots created by our Customers ("End Users").
2. Information We Collect
2.1 Customer Account Information
When you create an account, we collect:
- Name, email address, and contact information
- Company name and business details
- Billing and payment information (processed via secure third-party providers)
- Account credentials and authentication data
2.2 Chatbot Configuration Data
To power your AI chatbots, we collect and store:
- Business information (products, services, FAQs, policies)
- Knowledge base documents and training materials
- Custom instructions, personality settings, and bot configurations
- Automation workflows and business rules
- Integration credentials for third-party platforms
2.3 Conversation Data
Important: All conversations between chatbots and end users are stored in our database.
We collect and store:
- Message content: All messages exchanged between chatbots and end users
- Message metadata: Timestamps, message types, and conversation thread identifiers
- Attachments: Files, images, and documents shared during conversations
- Lead information: Names, email addresses, phone numbers, and other data voluntarily provided by end users
- Session data: Conversation history, bot responses, and interaction patterns
2.4 Social Media Data for Personality Bots
For personality-based AI chatbots, we may collect publicly available information from social media platforms, including:
- Public posts, tweets, and content from X (Twitter)
- Public LinkedIn profile information
- Public Instagram posts and profile data
- Other publicly accessible social media content
Note: We only access publicly available information. We do not access private messages, protected accounts, or data requiring authentication. Customers are responsible for ensuring they have authorization to create personality bots based on any individual's public data.
2.5 Automatically Collected Information
When you use our platform, we automatically collect:
- Usage data (pages visited, features used, time spent)
- Device information (browser type, operating system, screen resolution)
- IP addresses and approximate geographic location
- Cookies and similar tracking technologies
- Log data (access times, error logs, API calls)
3. How We Use Your Information
We use the collected information for:
- Service Delivery: Provide, maintain, and improve our AI chatbot services
- AI Training and Improvement: Enhance our AI models and algorithms (see Section 4)
- Conversation Processing: Store and process conversations to enable chatbot functionality
- Analytics: Generate insights, reports, and analytics for Customers
- Communication: Send service updates, security alerts, and support messages
- Billing: Process payments and manage subscriptions
- Security: Detect and prevent fraud, abuse, and security incidents
- Compliance: Meet legal and regulatory requirements
4. AI and Machine Learning
How We Use AI
Evaro uses artificial intelligence and machine learning technologies to power our chatbot services. This includes:
- Natural Language Processing: Understanding and generating human-like text responses
- Conversation Analysis: Processing conversations to provide relevant responses
- Knowledge Retrieval: Searching knowledge bases to answer questions accurately
- Personality Modeling: Creating AI personas based on provided data and social media content
- Automation: Executing workflow automations based on conversation triggers
Third-Party AI Providers: We use third-party AI model providers (such as OpenAI) to power our chatbots. Conversation data may be transmitted to these providers for processing. These providers are bound by their own privacy policies and data processing agreements.
5. Data Storage and Security
5.1 Where We Store Data
Your data is stored on secure cloud infrastructure. Our primary data centers are located in the United States. Data may be replicated across multiple regions for redundancy and performance.
5.2 Encryption and Security Measures
Our Security Practices
- Encryption in Transit: All data transmitted between your browser/application and our servers is encrypted using TLS 1.2 or higher (HTTPS)
- Encryption at Rest: Data stored in our databases is encrypted using AES-256 encryption
- Database Security: Conversation data, user information, and attachments are stored in encrypted database systems
- Access Controls: Role-based access controls limit who can access your data
- Multi-Tenant Isolation: Your data is logically separated from other customers' data
- Regular Backups: Encrypted backups are performed regularly for disaster recovery
- Security Monitoring: Continuous monitoring for suspicious activity and potential threats
5.3 What We Cannot Guarantee
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the security of your account credentials and any API keys.
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your data only in these situations:
- Service Providers: Third-party vendors who assist in service delivery (e.g., cloud hosting, payment processing, AI model providers)
- AI Processing: Third-party AI providers for natural language processing and chatbot functionality
- Customer-Directed Integrations: When you connect third-party services (CRM, messaging platforms, etc.)
- Legal Requirements: When required by law, court order, or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize sharing
7. End User Data
If you are an end user interacting with a chatbot powered by Evaro:
- Your conversations are stored by Evaro and accessible to the Customer who created the chatbot
- Any personal information you provide (name, email, phone) may be used by the Customer for their business purposes
- The Customer is the data controller for your information; Evaro acts as a data processor
- To exercise your data rights, please contact the Customer directly or reach out to us at privacy@evaro.com
8. Your Rights
Depending on your location, you may have the following rights regarding your data:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your data (subject to legal obligations)
- Portability: Receive your data in a machine-readable format
- Objection: Object to certain data processing activities
- Restriction: Request restricted processing of your data
- Withdraw Consent: Revoke previously given consent
- Opt-Out of AI Training: Request that your data not be used for AI model improvement
To exercise these rights, contact us at privacy@evaro.com. We will respond within 30 days (or as required by applicable law).
9. Data Retention
We retain your information according to the following schedule:
- Account Data: Retained for the duration of your account plus 90 days after closure
- Conversation Data: Retained according to Customer settings (default: indefinitely while account is active)
- Billing Records: Retained for 7 years for legal and tax compliance
- Log Data: Retained for 90 days
- Backup Data: Retained for 30 days after primary data deletion
Customers can request earlier deletion of conversation data. Some data may be retained longer if required by law or for legitimate business purposes.
10. Cookies and Tracking
We use cookies and similar technologies to enhance your experience, analyze usage, and deliver personalized content. You can control cookies through your browser settings, though this may affect some platform functionality. Our cookies include:
- Essential Cookies: Required for platform functionality and authentication
- Analytics Cookies: Help us understand how users interact with our platform
- Preference Cookies: Remember your settings and preferences
11. Third-Party Services
Our platform integrates with third-party services including:
- Messaging platforms (Facebook Messenger, WhatsApp, Instagram, etc.)
- AI model providers (OpenAI, etc.)
- Payment processors (Stripe, etc.)
- Cloud infrastructure providers
- Social media platforms (for personality bot data)
These services have their own privacy policies. We encourage you to review them.
12. International Data Transfers
Your data may be transferred to and processed in countries other than your own, including the United States. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where applicable.
13. Children's Privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
14. California Privacy Rights (CCPA)
California residents have additional rights under the CCPA, including the right to know what personal information we collect, the right to delete, and the right to opt-out of the sale of personal information. We do not sell personal information. To exercise your California privacy rights, contact us at privacy@evaro.com.
15. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, you have rights under the GDPR including access, rectification, erasure, restriction, portability, and objection. Our legal bases for processing include contract performance, legitimate interests, and consent. For data protection inquiries, contact our Data Protection Officer at dpo@evaro.com.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through our platform. The "Last updated" date at the top indicates when the policy was last revised. Continued use after changes constitutes acceptance of the updated policy.
17. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or have concerns about our data practices, please contact us:
Evaro Privacy Team
Email: privacy@evaro.com
Data Protection Officer: dpo@evaro.com
Address: 123 AI Street, San Francisco, CA 94105