Skip to content
eu/jev.
PlaygroundEU hostingDocs
Log inGet an API key
EU/JEV / LEGAL
LegalImpressumPrivacy policyTerms of ServiceData Processing AgreementSubprocessors

Privacy policy

Last updated: 1 October 2026

This notice covers the eu/jev website, playground, accounts, and API.

1. Who is responsible

Bevelites GmbH
Schleißheimer Str. 188, App. 520
80797 München, Germany

We are the controller for account, service, and security data. Contact juan@bevel.software for privacy questions or to exercise your rights.

2. Accounts and usage

We store your name, email address and account creation date. Where email authentication is enabled, new accounts require email verification. Passwords are stored as salted Argon2id hashes, never plaintext. Legacy scrypt hashes are upgraded when the password is next used successfully. Google sign-in is an alternative: Google provides your name, verified email address and stable account identifier. We never receive your Google password or request access to other Google data. Personal and work email addresses are welcome.

Google Workspace sends verification and password-reset emails on Bevel’s behalf. It processes your email address, message content (including the single-use link) and delivery metadata. Bevel is the controller. These emails contain no passwords, API prompts or outputs. Your email provider also handles delivery.

Google’s published Workspace contracting entity for German customers is Google Cloud EMEA Limited in Ireland. Email processing can occur outside the EEA, including in the United States. Google’s processing terms describe applicable adequacy mechanisms and standard contractual clauses. Contact juan@bevel.software for copies of the applicable transfer safeguards.

Verification links expire after 24 hours; recovery links expire after 30 minutes. Our database stores only a hash of the link token. Your browser temporarily keeps the token in that page’s history state so you can refresh; it is cleared when you complete the action. Pending signup records also contain your name and password hash. They are deleted when used, replaced, or during hourly cleanup after expiry while the application is running. Password recovery signs out existing browser sessions without changing API keys or credit balances. These messages are necessary account communications, not marketing.

Access is limited. Applications are reviewed as capacity opens. Waitlist and extra-usage requests use a separate Google Form. If you submit it, we receive your email address, request type, project description, expected usage, and reason for choosing eu/jev. We use your answers to review and respond to your request. Submitting the form does not create an account, API key, or credit balance. We do not automatically add you to the waitlist when registration is unavailable.

The request form belongs to Bevel’s Google Workspace. Bevel is the controller for the submitted answers; Google processes stored form responses on our behalf under the Google Workspace processing terms. Google also processes interaction and technical data under its privacy policy. The form opens only when you follow its link; it is not embedded in eu/jev. Waitlist entries collected through our previous signup flow contain a name, email, Google account identifier, and joining date. These existing entries are removed when an account is created, or you can contact us to request removal.

Google sign-in is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you choose it, your browser connects to Google, which processes your sign-in under its own privacy policy. A short-lived eujev_oauth cookie links your browser to the sign-in and is removed when it completes or after ten minutes.

We store hashed session tokens and API keys, key names and prefixes, and creation, last-use, and revocation dates. Raw API keys and session tokens are not stored in our database.

We record credit grants, balances, and request metadata: account and key identifiers where applicable, time, request source, model mode, status, question count, latency, token count, and cost. This provides your usage history and credit accounting. Anonymous playground requests have no account identifier.

For individual customers, these data are necessary to provide the service under Article 6(1)(b) GDPR. Where you represent an organisation, our account administration relies on Article 6(1)(f): our legitimate interest in providing and securing that organisation’s service. Without the required account details, we cannot create an account. You can try the public playground without signing up.

For account support, service operation and capacity planning, Bevel staff can view aggregate account counts and recorded calls, errors, input tokens, credit charges, and latency over the last 7, 30, or 90 days. Per-account totals include the account ID and email address already stored for your account. These are personal data, not anonymous statistics. No names, prompts, responses, IP addresses or credentials are included in this view. This view uses no additional browser tracking or analytics cookies.

This limited operational analysis relies on our legitimate interest in supporting accounts, managing capacity and maintaining service reliability under Article 6(1)(f) GDPR. Access requires a Google-verified Bevel Workspace identity and expires after 12 hours unless the staff member signs in again. We record this permission expiry in the existing session. The view uses existing account and usage records; its 90-day maximum window does not delete older billing or account history. You can object to this processing by contacting us.

If you use an invitation, we record the inviter and new account IDs, admission date and credit grants to provide the referral bonuses and apply the programme limit. Inviters see their completed referral count and earned credits. Bevel staff can review the linked account emails and reward records for support and programme administration. We use the same account-administration legal bases described above. Referral records contain no prompts or responses, and no referral-tracking provider receives this data.

3. Prompts and model responses

Your context, questions, and answer criteria are processed to produce a response. The application does not save prompts or responses in its database or application logs, or use them to train models. They remain in the browser while the playground is open and are processed in server memory for inference. To accelerate repeated input, the model worker can retain tokens and intermediate calculations in a temporary memory cache across requests. These can relate to personal data; completing a request does not immediately erase this cache. It is replaced or cleared as the worker runs and is lost when it restarts. The application does not write this cache to disk.

We operate eu/jev on a Hetzner server in Germany. Your inference content is processed there and is not sent to TypeSafe, another external model API, or any provider outside the EU. The public playground uses the same real model as the API.

For your own use, processing is necessary to answer your request under Article 6(1)(b) GDPR. If you submit personal data on behalf of your business, you determine its purpose and legal basis. Complete the self-serve Article 28 Data Processing Agreement before submitting personal data on behalf of a controller. A processor customer must have its controller’s authorisation. This privacy notice does not replace that agreement. Use non-personal or synthetic data in the anonymous playground.

4. Hosting and security

Our application, database, and model worker run on our Hetzner deployment in Germany, managed with self-hosted Coolify. Our infrastructure provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We have accepted Hetzner’s data processing agreement. This describes our origin server and model execution; it does not mean every provider processes data only in Germany or the EU.

Website and API HTTPS traffic connects directly to our Hetzner deployment. DNS for eu-jev.com is provided by STRATO GmbH in Germany. Our earlier address, jev.bevel.software, still works; Cloudflare provides DNS only for that name and does not proxy its traffic or receive API inputs and outputs, but DNS queries and resolver connection metadata for it can be processed on Cloudflare’s international network. Application API responses carry Cache-Control: no-store. See Cloudflare’s privacy policy.

Google handles optional sign-in and the separate request form described in section 2; it does not receive API prompts or outputs for inference. Those interactions can involve processing outside the EEA. Google’s privacy policy and Workspace processing terms describe its international processing and applicable transfer safeguards. We do not promise EU-only processing for Google services or DNS metadata. The account-email data and transfer arrangements are also described in section 2.

Our subprocessor and provider list describes recipients, their roles, processing locations and how to obtain the applicable processing terms. A provider’s published policy alone does not prove that a transfer mechanism covers every account or configuration.

Connections require processing an IP address and technical request information. The application hashes IP addresses and authentication email addresses for abuse-prevention counters. These identifiers remain pseudonymous personal data; hashing does not make them anonymous. Application error logs contain technical metadata such as request ID, time, HTTP method, and error type, without request bodies, credentials, or responses.

Security processing relies on Article 6(1)(f) GDPR: our legitimate interest in preventing misuse and maintaining a reliable service. Access is limited to personnel and service providers who need it to operate and support eu/jev. Data may also be disclosed where legally required under Article 6(1)(c) GDPR.

See Hetzner’s data-protection information for its processing arrangements.

5. Cookies and browser storage

The necessary eujev_session cookie keeps you signed in for up to 30 days and is removed on logout. The necessary eujev_oauth cookie lasts at most ten minutes during Google sign-in. We temporarily use session storage to pass a newly created API key to your dashboard; it is removed when the dashboard reads it or the browser tab closes.

If you start sign-in from the DPA page, session storage holds only a return-page marker so you can continue there. It is removed after successful sign-in or when the tab closes.

When you explicitly start signup or Google sign-in with an invitation, the tab retains its code for signup retries. It is valid for 24 hours, removed on the next check after expiry, and cleared when sign-in completes or the tab closes. The existing short-lived Google sign-in cookie carries the code through that sign-in attempt. For email signup, the code is attached to the pending verification record so verification works on another device. A temporary success notice is removed when the dashboard displays it. We do not record referral link clicks or send invitations on your behalf.

The eu/jev application sets no advertising cookies or analytics trackers. Google’s own pages have separate cookie practices. Fonts are served by eu/jev. Our necessary sign-in storage supports the service you request (§ 25(2)(2) TDDDG); associated personal-data processing relies on Article 6(1)(b) GDPR.

6. Retention and contact

We retain account, key, credit, and usage records while your account is active so you can use the service and inspect your history. Request account closure or deletion at juan@bevel.software. Records needed for a legal obligation or an unresolved claim are retained only for that purpose until it ends.

Account and usage history currently have no automatic age-based deletion job. The dashboard’s reporting windows do not determine retention. Deletion requests are handled by us after identity verification, including any records we must retain for a specific legal obligation.

On deletion of an invited account, its link to the referral record is removed. The inviter’s completed-referral count remains while their account is active so deleting an invitee does not reopen a claimed bonus. Referral records are removed when the inviter’s account is deleted, subject to any specific legal-retention obligation.

If you accept a DPA, we store the customer legal name and address, representative name, account contact email, stated processing scope, agreement version, acceptance time and complete agreed text with its hash. No IP address, browser fingerprint or signature image is added to this record. We use it to perform and evidence the agreement under Article 6(1)(b), and Article 6(1)(f) for our legitimate interest in maintaining contract evidence and resolving claims where you act as an organisation’s representative. Necessary statutory retention relies on Article 6(1)(c).

Agreement evidence is retained during the contract and applicable limitation period, normally three years from the end of the year in which it ends, subject to an applicable longer legal requirement or unresolved claim. Account closure does not automatically erase this evidence. We review and delete it manually when no retention basis remains; there is no automatic agreement-purge job. You can request a copy or correction at juan@bevel.software. An accepted agreement is preserved as evidence rather than silently overwritten by amended details.

Sessions expire after 30 days, are removed on logout, and expired session records are cleaned on subsequent sign-ins. Rate-limit counters stop enforcing a window within one hour, except the playground’s daily counter, which lasts 24 hours. Expired counter records are cleaned on subsequent rate-limited requests, so their identifiers may remain longer during inactivity. Application logs use size-based rotation configured for three 10 MiB files per container; there is no fixed time-based log deletion period.

If you email us or submit the request form, we process your contact details and answers to respond to the inquiry, under Article 6(1)(b) GDPR for service requests or Article 6(1)(f) for other correspondence. Email delivery also involves mail providers. We retain correspondence while needed to resolve the inquiry and any associated contractual or legal obligations. Please do not send API keys or sensitive prompt content through email or the form.

7. Your rights

Subject to the GDPR’s conditions, you may request access, correction, deletion, restriction, and portability. You may object to processing based on legitimate interests for reasons relating to your situation. Where processing relies on consent, you can withdraw it for future processing. Contact juan@bevel.software; we may need to verify your identity.

We respond without undue delay and normally within one month. Where the GDPR permits an extension because of complexity or the number of requests, we explain the reason within that first month. Necessary rights requests are not made conditional on buying more usage.

You may complain to a supervisory authority, including the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).

We do not use model predictions to make decisions about you with legal or similarly significant effects. Customers determine how to use API results and are responsible for their own data-protection obligations.

eu/jev.
ImpressumDocumentationFAQLegal
by BevelNot affiliated with TypeSafe AI.