Legal
Privacy
Last updated: 31 August 2026
The short version
Evidloom Studio is local-first. Your conversations, projects, and the agent's learned skills live on your computer in plain files you can back up, search, or delete without our help. We run a hosted LLM proxy because that's what makes the included-usage + flat-rate top-up pricing work — and we make it loud and clear what we see and what we don't.
What stays on your machine
Every chat transcript, every file the agent has read or written for you, every project, every skill the agent has learned, and most locally configured tool credentials. The Evidloom Studio runtime runs locally — those files never leave your disk unless you explicitly move or share them. BYOK provider keys are transmitted over HTTPS and stored in hosted encrypted infrastructure so the proxy can use them.
If you delete a chat or a project from inside the app, the
files are deleted (or archived to a dated backup folder per
our user-data-preservation policy — never silently destroyed).
If you uninstall the app, your data stays on disk in
~/.yupiter-studio/ until you choose to remove it.
What we see at the proxy
When the agent calls a large language model on your behalf,
its prompt and the model's response pass briefly through our
proxy at proxy.evidloom.com. We need to forward
them to your chosen model provider (OpenAI, Anthropic,
etc.) and to count tokens for billing.
We log token counts, the model used, the originating tenant (anonymized to a tenant id), and the cost per request. We do not log prompt or response bodies. Evidloom does not sell personal data or use your content to train Evidloom models. Your selected model provider handles prompts under its own API terms and data controls.
In bring-your-own-keys mode, requests still pass through Evidloom's proxy for routing and account controls, while inference charges go to your provider account. Studio BYOK costs $10/month plus your provider's charges.
Account & billing data
We collect the email you sign up with, the tenant id we mint for you, and your billing details (stored only with Stripe — we never see your full card number). We retain this for the life of your account plus 7 years for tax compliance, then delete or anonymize.
Telemetry & error reports
During the public preview, nonessential automatic diagnostic and error-report storage is code-pinned off. Those endpoints return a no-store acknowledgement before parsing the submitted body. After the no-store gate went live, historical records in those paused diagnostic namespaces—including the retired raw-field formats—were deleted. All covered prefixes were verified empty twice before this privacy text was published.
The device's private local audit log remains enabled because it is required to enforce approvals and investigate local actions. Remote desktop-audit intake is paused with the other automatic diagnostic routes. Hosted account, billing, and control-plane operations keep their own service-side audit records under the schemas described for those services. Preexisting remote desktop-audit records are retained under restricted operator access for security investigation and can contain bounded event summaries, surface names, and resource identifiers.
Cloudflare provides connection metadata such as source IP and user agent for abuse prevention and rate limiting. Feedback is sent when you submit it. When skill sharing is enabled, the app may automatically submit bounded skill or adaptation candidates for review; you can disable skill sharing in Settings. These paths retain submitted content and bounded connection metadata so we can reply, review candidates, and prevent abuse.
Your rights
You can access, export, correct, or delete your account data at any time. Email [email protected] with the subject line "Privacy request" and we'll respond within 30 days. The local data on your machine is yours to export or delete directly — it's just files.
Contact
Privacy questions, data-rights requests, or anything else: [email protected].