BuildMyEvidence← Back

Privacy Policy

This document was last updated May 30, 2026. We recommend reviewing it periodically.

1 · What we collect

We collect only what you give us:

  • Account information: your email address and password (password is hashed — we cannot see it).
  • Case data: journal entries, photos, correspondence, contacts, and documents you create or forward to the service.

2 · How we store your data

Your data is stored in Supabase, a secure cloud database hosted in the United States (US East region). Each user's data is isolated using row-level security — no other user can see or access your records.

Photos and documents are stored in Supabase Storage with signed URLs that expire after one hour. Files are only accessible to the authenticated account that uploaded them.

3 · Who can access your data

Only you. We do not access your case data unless you explicitly request support that requires it, or we are compelled by law.

We will never sell, rent, or share your personal data with third parties for marketing purposes.

4 · Service providers

We use the following third-party services to operate buildmyevidence:

  • Supabase — database and file storage (US East)
  • Vercel — web hosting and serverless functions
  • Cloudflare — DNS, email routing, security, and encrypted backups
  • Stripe — payment processing (when available)
  • Resend — email delivery for account notices

Each provider has their own privacy policy.

5 · Cookies

We use cookies only for authentication (keeping you signed in) and the coming-soon bypass during private testing. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

6 · Your rights

You have the right to:

  • Access all of your data at any time through the app
  • Export your data using the Download Case Backup feature
  • Delete individual entries, photos, contacts, correspondence, or entire cases
  • Delete your account entirely (contact support@buildmyevidence.com)
  • Request a copy of all data we hold about you

7 · How long we keep things, and who else touches them

7.1 Your cases stay until you remove them, or the account goes

We don't put an expiry date on your records. A case stays for as long as the account it lives in stays.

An account ends only through going unused: cold at twelve months unopened, notices at eighteen, twenty-one and twenty-three months, deleted at twenty-four. Opening it resets that to zero. An account holding a paid case is never deleted for inactivity, and if a notice bounces nothing is deleted at all. The full wording is in section 6 of the Terms, and it means the same thing there as it does here.

7.2 What we actually remove

When an account is deleted, the records go and the files you uploaded go with them, out of storage. It isn't a flag on a row that hides things from you while we keep them.

Before any of that, you can take everything out — free, at any time, exactly as it reached us.

7.3 When you delete a case yourself

It goes when you press the button. There is no waiting period and no recycle bin. The one copy that outlives the button is the encrypted daily backup, which holds it for up to seven days and then does not — §7.4 says exactly what that is.

The files go out of storage first, then the records that point to them — that order, because doing it the other way would strand your files somewhere nothing could ever reach them again. Afterwards we look in the storage again and check that what should be gone is gone, rather than taking the first answer on trust.

Closing a case is a different thing entirely, and it removes nothing. A closed case is simply one you've finished with. There's no clock on it.

7.4 Backups, and how long a deleted thing stays in one

Every day we take a copy of the records and the files and keep it with Cloudflare, in the United States. It is encrypted before it leaves us, and Cloudflare cannot read it. The key that opens it is held by the account holder of this business and exists nowhere else — not on the servers that make the backup, and not with the company that stores it.

After you delete something, it can remain in those encrypted backups for up to seven days. Then it is gone. Backups older than seven days are deleted, so there is no copy of your record anywhere older than a week.

Separately, Supabase takes its own daily backups of the database and ages them out on their own cycle, also seven days. We cannot search those, and we cannot delete from them.

7.5 Who else handles your information

Running BuildMyEvidence means using a small number of other companies. These are all of them, and what each one holds:

Supabase
The database and the file storage. Your cases and the files you upload physically sit here.
Vercel
Serves the site and the app to your browser. Handles the request, not the contents of your case.
Cloudflare
Sits in front of the site, filtering traffic and blocking abuse, and holds the encrypted backups.
Stripe
Takes payments. Stripe sees the payment; your card details never reach us, and Stripe never sees what the case is about.
Resend
Sends the emails we have to send you — including the notices described in section 6 of the Terms. Resend receives your email address and the wording of the message. It never receives anything from inside a case, and we don't use it to send you anything you didn't ask for.

Those are the only companies that hold or handle anything from your account. We don't sell your information, we don't use it for advertising, and nothing in your case is used to train anything. There is no analytics or tracking on the app at all.

Nothing in your case is sent to any AI service. Not by us, and not in the background. If you choose to take your own record to an AI yourself, that is you doing it, in your own account with that company.

One smaller thing, for completeness: our pages load their typefaces from Google's font service, so your browser tells Google its IP address when a page loads — the same as on a great many websites. Google receives nothing from your account and nothing about your case.

7.6 Recordings

If you record audio into a case, the recording is a file like any other file. It is stored, and it is not transcribed. No audio is sent anywhere to be turned into text.

8 · Children

buildmyevidence is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors.

9 · Changes to this policy

We may update this policy from time to time. Significant changes will be communicated by email or through the app.

10 · Contact

For privacy questions or data requests, contact privacy@buildmyevidence.com.