EvaltudeBack to the experiment

Product policy

Privacy and data retention

Last updated August 3, 2026

Evaltude is currently a read-only static site. It does not accept scenario text, files, account details, or other user submissions. This policy describes that current behavior and the safeguards that must be finalized before any submission feature is launched.

What Evaltude does today

The public site serves prebuilt pages and a prebuilt, synthetic evaluation dataset. There is no account system, form submission, file upload, application programming interface, or server-side scenario runner. The “Run your scenario” control is disabled and marked as planned.

Search terms and dashboard filters are handled in your browser. Evaltude does not send those values to an Evaltude application server. As with any website, the page and asset requests themselves pass through the hosting provider.

Analytics, cookies, and browser storage

Evaltude does not currently use a product analytics service, advertising tracker, tracking pixel, or third-party embed. The Evaltude application does not set cookies.

If you switch the site theme, the browser stores the value light ordark under the themekey in local storage. It stays on your device and is used only to restore that preference. You can remove it using your browser’s site-data controls.

Cloudflare may use strictly necessary cookies or diagnostic mechanisms when its security or network features require them. At the date above, ordinary requests to the production site did not return a Set-Cookie header. This statement will be reviewed if the hosting or security configuration changes.

Hosting and request metadata

Evaltude is a static site hosted on Cloudflare Pages. Requests therefore pass through Cloudflare’s global network. Cloudflare may process IP addresses, requested URLs, timestamps, browser or device information, traffic-routing data, and security signals to deliver, protect, and diagnose the service. Production responses also enable Cloudflare network-error reporting.

Evaltude does not operate an origin application server and has not enabled an Evaltude-owned store of page contents, search terms, or dashboard-filter values. Cloudflare controls its own network processing and retention under its privacy terms. The site owner may have access to aggregate traffic or security information made available by Cloudflare, but does not claim that an internet request is anonymous merely because Evaltude has no application database.

Retention and deletion today

Because Evaltude does not accept submissions or maintain user accounts, it has no user-submission records to retain or delete. The theme preference remains in your browser until you clear it. Cloudflare retains or aggregates network and security data according to the service configuration and its own policies; Evaltude cannot promise deletion of data controlled solely by Cloudflare.

If you believe personal information has nevertheless reached the site owner, use the contact below with the relevant URL, approximate time, and the action requested. Do not include additional sensitive information in that message.

Rules before scenario submissions can launch

Evaltude will not enable or promote scenario submission until the data flow, retention period, deletion process, and service providers are documented here. If that feature launches, the permitted data classes will be limited to:

  • scenario text and any configuration choices intentionally submitted;
  • generated outputs, evaluation results, and validation errors;
  • technical metadata needed for reliability and abuse prevention, such as timestamps, request identifiers, model or system version, latency, token counts, and security signals; and
  • account or contact details only if an account or support feature is separately offered and clearly labeled.

Users will be instructed not to submit secrets, credentials, regulated data, confidential client information, or personal data that is unnecessary for the evaluation. Submitted content will not be used to train models unless a later policy says so clearly and an appropriate choice is provided.

Submission content and results will be deleted after 30 days, while minimal security and billing records may be kept longer only where their purpose and period are stated. A verified deletion request will be completed or answered within 30 days. Backups, if introduced, must have a documented expiry and must not silently restore deleted active data.

Service providers

The current product subprocessor is Cloudflare, Inc., which provides DNS, content delivery, security, TLS termination, and Cloudflare Pages hosting. No model provider receives visitor-submitted prompts because Evaltude does not currently accept or run them.

Before submissions launch, this section will name every provider that may process submitted content, telemetry, support messages, or account data, along with its role. A new provider will not be hidden behind the general phrase “service providers.”

Security boundaries

HTTPS protects data in transit between your browser and Cloudflare. It does not make a public page private, prevent all attacks, or guarantee that a visitor’s device or network is secure. Today’s narrowest protection is architectural: there is no submission endpoint or user-data database in the product.

If collection is introduced, Evaltude will document access controls, encryption, separation of production data, incident handling, and the providers that can access submitted content before accepting that content.

Contact and policy changes

Privacy, deletion, and security reports: [email protected].

Material changes will be dated on this page before they take effect. If Evaltude begins accepting submissions, the revised policy will explain what is collected, why, where it goes, how long it remains, and how to request deletion before the input control is enabled.

Provider references