Privacy Policy
Last updated: 3 September 2026
EBD Sweden AB (org. no. 559332-0384), trading as EvidInvest ("we", "us", "our"), operates evidinvest.com, the EvidInvest mobile app, and the EvidInvest API and MCP server. We are the data controller for the personal data described here. This policy explains what we collect, why, who we share it with, and what you can ask us to do about it.
Questions or requests: info@evidinvest.com.
1. Information We Collect
For each account we hold:
- Account information — your email address, your name if you give one, and which sign-in method you used. Accounts are handled by our authentication provider, Clerk (email, Google, or GitHub sign-in).
- Your saved work — watchlists, saved valuations, and investment theses you create, together with any alert settings attached to them.
- API keys and connected apps — see section 2.
- Usage logs — one record per API or MCP call: the tool called, the timestamp, which API key or connection made the call, the response status and latency, the IP address and user agent the call came from, and any error message. We do not store the arguments you pass to a tool. We use these logs to meter usage, enforce rate limits, debug, and detect abuse.
- Credit ledger — the credits you bought or were granted and the credits you spent.
- Payment information — card details are collected and processed directly by Stripe and never reach our servers. We store the resulting Stripe customer and payment identifiers, and the invoices we are required to keep.
- Email preferences — your settings for the newsletter, feature updates, tips, and system update emails. These start switched on when you create an account; every email we send carries an unsubscribe link, and turning a category off stops it immediately.
- First-touch attribution — the UTM parameters and landing page from the visit on which you first arrived, so we can tell which marketing works.
- Technical data — IP address, user agent, and request metadata, used for security, rate limiting, and fraud prevention.
2. API Keys and Connected Apps (OAuth)
EvidInvest can be used from your own code through an API key, or connected to an AI client — Claude, ChatGPT, Cursor, and similar — through our MCP server using OAuth.
- API keys are shown to you once, at creation. We store only a SHA-256 hash of the key, alongside its label, description, scopes, creation date, expiry, and last-used date. We cannot recover a key for you; if you lose it, revoke it and create a new one. The one exception is the emailed MCP activation link: that key is held so the activation page can show it to you once, and is erased when you claim it or within 24 hours, whichever comes first.
- OAuth connections record the connecting application (for example "Claude", "ChatGPT", or "Cursor"), the scopes you granted, and when the connection was made. Access and refresh tokens are stored only as hashes, never in clear text.
- You stay in control. You can list and revoke API keys and connected apps at any time in your account settings. Disconnecting an app deactivates its key and revokes every access and refresh token issued through it, so that client stops reaching your account immediately.
- Calls made with a key or a connection are attributed to your account and charged to your credit balance, so treat them as you would a password.
3. Data You Send Through AI Clients
Two distinct data flows are worth being explicit about, because they leave our systems in different directions.
AI features on EvidInvest
When you use our AI chat or AI-generated analysis, your prompt and the relevant context are sent through the Vercel AI Gateway to the model provider serving that feature. Every model we run today is Anthropic's (Claude), with OpenAI configured only as a failover if Anthropic is unreachable. The gateway may serve those models from the provider directly or through Amazon Bedrock or Microsoft Azure. If we add a further provider we will name it in the sub-processor table below. Under these providers' API terms, what we send is used to answer the request and not to train their models. We store the conversation so you can come back to it, and you can delete it.
Our API and MCP server
When you connect EvidInvest to an AI client, that client sends us tool calls and we return financial data and analysis to it. What happens to that response afterwards is governed by the privacy policy of the client you connected — Anthropic for Claude, OpenAI for ChatGPT, and so on — not by this policy. We do not control, and cannot see, what the client does with the response, how long it keeps it, or whether it feeds it into its own model context.
We log the fact and shape of each call (see section 1) but we do not use the content of your queries to train any model of our own, and we do not sell it.
4. How We Use Your Information, and Our Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the platform, API, and MCP server to you; authentication | Performance of a contract |
| Taking payment, metering credits, issuing invoices | Contract; legal obligation (accounting law) |
| Security, rate limiting, abuse and fraud prevention | Legitimate interests |
| Debugging, measuring, and improving the product | Legitimate interests |
| Account and service emails (billing, security, breaking changes) | Contract; legitimate interests |
| Newsletter and product update emails to account holders | Legitimate interests (soft opt-in to our own customers), with an unsubscribe link in every email |
| Newsletter sign-up by a visitor who is not an account holder | Consent (withdrawable at any time) |
| Advertising and analytics cookies in the EEA, UK, and Switzerland | Consent |
| Responding to legal requests and keeping required records | Legal obligation |
5. Sub-processors
We do not sell your personal data. We share it only with the providers below, each under a data processing agreement, and where the law requires us to.
| Provider | What it does for us | Where it processes |
|---|---|---|
| Vercel | Website and app hosting, edge delivery, aggregate traffic analytics | EU / US |
| Amazon Web Services | Application database and the API / MCP gateway | US (us-east-1) |
| Clerk | Authentication and account management | US |
| Stripe | Payments, invoicing, tax | EU / US |
| Upstash | Redis cache and rate-limit counters | EU / US |
| Resend, Amazon SES | Transactional and newsletter email delivery | EU / US |
| Anthropic, and OpenAI on failover — reached through the Vercel AI Gateway, which may serve them via Amazon Bedrock or Microsoft Azure | Model inference for AI chat and AI analysis | US |
| Google (Ads), Meta | Advertising measurement on marketing pages, with consent | US |
International transfers. Some of these providers process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework, together with encryption in transit and at rest.
6. Marketing and Analytics
Product analytics without cookies. We run Umami, self-hosted on our own infrastructure (umami.ebdsweden.com), and Plausible. Neither sets tracking cookies or collects personal data; both report aggregate page and feature usage only.
Advertising and measurement tags. On our marketing pages we run Google Analytics, Google Ads conversion tracking, and the Meta pixel and Conversions API, so we can tell which ads bring people to the product. These do set cookies and can send a hashed identifier to Google or Meta.
Consent. If you are in the EEA, the UK, or Switzerland, these tags are held in a denied state until you accept via our cookie banner — nothing is stored on your device and no advertising data is sent until then. Elsewhere they load by default and declining stops them. You can change your mind at any time using the "Cookie Settings" link in the footer, and you can block cookies in your browser. Essential cookies — the ones that keep you signed in and note your consent choice — are always required for the site to work.
7. Data Retention
- Account data, saved work, keys, and connections — kept until you delete them or close your account, then deleted within 30 days.
- Usage logs — held against the API key or connection that made the call, and deleted together with it when your account is deleted. Revoking a key or disconnecting an app stops further calls but keeps the existing history, which we need for billing and abuse investigations.
- Invoices and accounting records — kept for seven years, as the Swedish Bookkeeping Act (bokföringslagen) requires. This applies even after you close your account.
8. Security
All access is over HTTPS, and data is encrypted in transit and at rest. API keys and OAuth tokens are stored only as hashes. Access to production data is limited to the people who need it and is authenticated through our cloud provider rather than shared credentials. No system is perfectly secure, but we work to industry-standard practice and will notify you and the supervisory authority of a breach where the law requires.
9. Your Rights
Under the EU General Data Protection Regulation and Swedish law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data ("right to be forgotten")
- Export your data in a portable format
- Object to or restrict processing based on our legitimate interests
- Withdraw consent at any time, without affecting processing already carried out
You can revoke API keys and disconnect apps yourself, in account settings. Email preferences are changed from the link at the bottom of any email we send. To access, export, or delete your account and its data, email info@evidinvest.com from your account address — we will respond within one month, and there is no charge.
If you think we have handled your data wrongly, you may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se, or to the supervisory authority where you live.
10. Children
EvidInvest is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to This Policy
We may update this policy. We will change the "last updated" date above and, for material changes, tell you by email or in the product before they take effect.
12. Contact
EBD Sweden AB (trading as EvidInvest)
Org. no. 559332-0384 · Stockholm, Sweden
Email: info@evidinvest.com
Your use of the Service is also governed by our Terms of Service and Credit & Billing Terms.