DocsSecurity & TrustSecurity & Privacy

Security & Privacy

Evelant applies standard security practices across the extension, dashboard, and API.

Data handling — Your chat history and profile data are stored in Evelant's database with row-level security, so accounts can only ever read their own data. Extension authentication tokens are stored as hashes, never in plain text.

Extension permissions — Evelant requests broad page access so it can work on any site you visit. It only reads page content when you actively open the assistant — it does not run in the background monitoring what you browse.

Abuse protection — Every chat request passes through rate limiting, sanitization, and prompt-injection checks before reaching any AI provider, protecting both your account and the service as a whole from misuse.

You're always in control of your own data: clear chat history or delete individual sessions at any time from Dashboard → Settings.