Privacy Notice

Version: 2026-09-24 · Effective date: 2026-09-24

1. Scope and roles

Eva Core Inc. operates Anti Sandbox. For customer conversations and knowledge that a business places in its workspace, the business normally decides why and how to use that data, and we process it to provide the service on its behalf. For our own account administration, security, support, and billing records, we determine the necessary processing. A signed agreement may specify the roles more precisely. Contact support@antisandbox.com for privacy requests; we may ask for information needed to verify identity and route a customer request to the relevant workspace.

2. Data we receive and why

We process workspace and user information (name, work email, role, authentication and security records); customer contact or channel identifiers (which may include name, email, phone number, and provider ID); conversation text, replies, attachments and delivery records; uploaded knowledge, learned rules and connected-system responses; support requests; and subscription, wallet, usage and transaction metadata. Passwords are stored in hashed form. Stripe handles payment-card entry; Anti Sandbox receives billing and transaction metadata, not full card numbers through its billing flow. The business and its authorized providers supply customer data; users supply their account and support information; connected systems supply the data needed for enabled functions.

We use this information to authenticate users; receive, route and answer support requests; operate human support and optional AI; connect authorized channels and systems; protect the service; investigate failures; keep audit and billing records; provide support; and meet applicable obligations. Optional AI sends the relevant request context to the configured model provider when that feature is enabled. For workspace customer data, we normally act on the business's instructions. For our own account and billing data, processing is based on providing the contracted service, security and other legitimate interests where permitted, legal obligations, and consent where a function such as optional marketing analytics requires it.

3. Providers and locations

The application and primary database run on Alibaba Cloud SCCC in Riyadh, Saudi Arabia. Depending on features used, data may go to Zernio for connected social or messaging channels, Resend for transactional or support email, Google Gemini for enabled AI inference, and Stripe for Checkout, subscriptions and card payments. Connected stores and other integrations receive the data needed for their enabled actions. Sentry receives error reports only if enabled. Some external providers may process data outside Saudi Arabia; the service is not wholly Saudi-resident.

The separate public marketing website may use Google Analytics for page and demo-use measurement only after a visitor opts in. Its choice record lasts up to 180 days; visitors can decline or change the choice. The product app uses authentication and other essential session storage needed to sign in and operate the workspace. Marketing analytics is not shared as a default product-app measurement feature.

4. Retention, export, and deletion

The workspace's default retention setting for closed conversations is 24 months, configurable by the organization from 1 to 120 months. A periodic sweep removes qualifying conversations and related messages and records. Open conversations are not deleted merely because they reach that age. Knowledge documents, audit records, billing evidence, provider receipts and other operational records have separate lifecycles; we do not promise that every record or file is automatically deleted at 24 months. Backup copies may remain until their normal rotation completes. We retain information as needed for the service, security, accounting, disputes, and applicable requirements, then delete or de-identify it under the relevant process.

Depending on the applicable law, individuals may request access to or a copy of their data, correction, or deletion; withdraw consent where processing relies on it; or complain to the relevant data-protection authority. Authorized workspace staff can request a customer's export or correction and initiate deletion through the service. A deletion removes the person's customer record, conversations, messages and identified related database data; billing amounts may remain without the conversation link, and audit references may be replaced by a hash. Archived media deletion can remain pending or unverified while storage work is reconciled; the service reports that state for review. For a privacy request, contact support@antisandbox.com. We may verify identity and coordinate with the business responsible for the workspace before acting. Rights and response duties depend on the applicable law and relationship.

5. Security and questions

The service uses organization separation, role and queue permissions, audit records, and protected handling of integration credentials. Contact support@antisandbox.com with privacy or security questions.

Sign in