1. What we collect
Account data: email, name, hashed password, workspace membership, role and last-login timestamp.
Workspace content: projects, test plans, datasets, evaluation runs, runtime traces, credentials for external providers.
Billing data: workspace-level Stripe customer ID, subscription state and usage counters. Payment card data is stored by Stripe and never touches EvaliQA servers.
Operational logs: request-level correlation IDs, service errors and audit events for security-sensitive actions.
2. How we use it
To operate the evaluation workspace, run scheduled jobs, and enforce plan entitlements.
To notify you about account activity: email verification, password reset, workspace invites and billing lifecycle events.
To debug and improve the product using aggregate, non-identifying signals.
3. What we do not do
We do not sell your data.
We do not use your prompts, datasets, evaluations or traces to train models on your behalf.
We do not share account or workspace data with third parties except sub-processors listed below.
4. Sub-processors
Stripe — payment processing and subscription lifecycle.
Resend — transactional email delivery.
Model providers you configure — invoked through your keys at request time.
Cloud infrastructure providers hosting the EvaliQA cloud instance you signed up to.
5. Retention and deletion
Workspace data is retained according to the plan-level retention window.
You can export data at any time.
Deleting a workspace removes its data from all EvaliQA data stores after a short grace period.
Account data is deleted on request unless retention is required by law.
6. Contact
For privacy questions and data-subject requests, contact privacy@qamentor.com.