EvidofSign in

Evidof legal

Privacy Policy

Effective July 31, 2026

This Privacy Policy explains how BasimDigital Lab. Co., operating Evidof and EvidofOS (“Evidof,” “we,” “us,” or “our”), handles information when you use evidof.com, EvidofOS, our APIs, and related support services (collectively, the “Services”). If your organization has a separate written agreement with Evidof, that agreement may include additional privacy terms.

Information we collect

  • Account and workspace information: name, email address, password hash, organization details, memberships, roles, and account preferences.
  • Organization content: nonprofit profiles, programs, funding requests, evidence, opportunity and funder records, campaign content, approvals, outcomes, uploaded files or media, and communications with support.
  • Integration information: connection settings, encrypted credentials and OAuth tokens, selected social accounts or pages, publishing activity, and customer-configured storage details.
  • Public and third-party information: public nonprofit, IRS Form 990, funder, award, and opportunity information from sources such as ProPublica, government systems, licensed sources, or records you import.
  • AI inputs and outputs: prompts, selected workspace context, generated drafts, recommendations, summaries, and related review or approval records when you use AI-assisted features.
  • Technical and usage information: IP address, browser and device information, request metadata, timestamps, feature usage, audit events, error details, and security signals needed to operate and protect the Services.

The Services are designed for organizational funding work, not for storing unnecessary sensitive beneficiary, donor, employee, health, financial-account, or government-ID data. Only provide personal information that your organization is authorized to use.

How we use information

We use information to:

  • provide, secure, troubleshoot, and improve the Services;
  • authenticate users and enforce organization roles and permissions;
  • build evidence-backed profiles, recommendations, workflows, and audit trails;
  • process customer-directed AI generation, search, imports, and integrations;
  • send service, security, support, and account communications;
  • prevent abuse, investigate incidents, and comply with legal obligations; and
  • create aggregated or de-identified operational insights that do not identify a person.

AI-assisted features

When you invoke an AI feature, Evidof may send the prompt and the workspace context needed for that task to the AI provider configured for your environment, such as OpenAI or Anthropic. AI output can be inaccurate or incomplete and requires human review. Do not submit sensitive personal information to AI features unless your organization has a lawful basis and has determined that the use is appropriate. AI providers process data under their applicable service terms and your organization’s configuration.

How we disclose information

We may disclose information:

  • within your organization according to its roles and permissions;
  • to infrastructure and service providers that support hosting, databases, storage, email, security, AI, and service operations;
  • to social networks, storage providers, funding-data providers, or other integrations when an authorized user directs the Services to connect or publish;
  • to professional advisers or authorities when reasonably necessary or legally required;
  • in connection with a merger, financing, reorganization, or transfer of the Services; or
  • with your organization’s instruction or consent.

Evidof does not sell personal information or share it for cross-context behavioral advertising. We do not use third-party advertising trackers in the current Services.

Browser storage and cookies

EvidofOS uses browser local storage for access and refresh tokens and the selected workspace, and session storage to complete OAuth connection flows. Our infrastructure may use strictly necessary cookies or similar technologies for security and service delivery. We do not currently use advertising cookies. Clearing browser storage will sign you out and may reset local preferences.

Retention

We retain information while an account or workspace is active and as reasonably needed to provide the Services, maintain security and audit integrity, resolve disputes, enforce agreements, and meet legal obligations. Retention varies by record type. Deleted data may remain temporarily in protected backups or logs. Public-source records may remain available from their original source even after removal from a workspace.

Your choices and requests

You may update account and organization information through the Services. Depending on your location, you may also have rights to request access, correction, deletion, or a copy of personal information, or to object to certain processing. Organization-managed data requests may need to be directed to your organization’s administrator. Contact [email protected] to submit a request. We may verify your identity and authority before responding.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, environment-managed secrets, encrypted third-party credentials, role-based access, tenant-scoped queries, private object storage, and security and activity logging. No service can guarantee absolute security. Report a suspected vulnerability through our Security page.

Children

The Services are intended for organizations and adults acting in a professional capacity, not for children under 18. Do not use EvidofOS to create accounts for children or to collect children’s personal information without an appropriate legal basis and safeguards.

International processing

Evidof and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws than your location. Where required, applicable contractual or legal safeguards will govern transfers.

Changes and contact

We may update this policy as the Services or legal requirements change. We will revise the effective date and provide additional notice when required. Questions may be sent to [email protected], or by mail to BasimDigital Lab. Co., 2451 West Grapevine Mills Circle, Suite 154, Grapevine, Texas 76051, USA.