This Privacy Policy explains how Pranav Wadnere, trading as Aevum ("Aevum", "we", "us") collects, uses, and shares personal data when you use the Aevum desktop application, the aevumwriter.com website, and associated online services (together, the "Service").
The short version: Aevum is local-first. Your manuscripts live on your device. We run no analytics or tracking inside the app. Data reaches our servers only for accounts, licensing, payments, and - if you choose to use it - cloud AI.
1. Data We Collect
In short: your account, your licence, payment metadata, and only the AI requests you deliberately make.
Account data. When you create an account: your email address and a password (stored only as a secure hash). When you subscribe: your tier and subscription status.
Licensing and device data. To enforce licensing, the app exchanges license tokens with our server bound to a device identifier (a machine fingerprint). We store the device identifier, license tier, activation timestamps, and token validity data.
Payment data. Payments are handled by our payment processors, Razorpay and Stripe. They collect your payment details under their own privacy policies; we receive only transaction metadata (what was purchased, when, payment status) - never your full card number.
Cloud AI content. Only if you use Aevum's cloud AI features: the prompts you write and the portions of your manuscript the feature needs are sent to our gateway (api.aevumwriter.com) and forwarded to a third-party AI model provider to generate the response. We also record metering data (request counts and token usage per billing window) to enforce usage limits.
Support communications. If you email us, we keep the correspondence.
What we do NOT collect. The app contains no analytics, telemetry, or advertising SDKs. We do not collect your manuscripts, notes, or writing behaviour outside of the cloud AI requests you explicitly make. Spell-checking, semantic indexing, and local AI models run entirely on your device.
2. Data That Never Reaches Us
In short: your manuscripts, your BYOK traffic, and anything a local model touches.
- Manuscripts and project files are stored on your device. We have no copy and no access, except for the specific excerpts you send through cloud AI requests, which are processed transiently (see Section 4).
- Bring-your-own-key (BYOK) AI: content goes directly from your device to the provider you configured, under their privacy policy. It does not pass through our servers.
- Local model AI (e.g. Ollama) and on-device embeddings: processing happens entirely on your device.
3. How We Use Data
In short: to run accounts, licences, payments and cloud AI - never for advertising or model training.
We use personal data to: provide and secure accounts and sign-in; validate licenses and entitlements; process subscriptions and payments; provide cloud AI features and enforce usage limits; respond to support requests; prevent fraud and license abuse; and comply with legal obligations.
Legal bases (GDPR): performance of our contract with you (accounts, licensing, cloud AI, payments); legitimate interests (fraud and abuse prevention, service security); legal obligation (tax and accounting records); consent, where we ask for it (e.g. marketing emails, if any - you can withdraw at any time).
We do not sell personal data, and we do not use your content or personal data for advertising or to train AI models.
4. AI Processing and Subprocessors
In short: the full list of companies your data can touch, and how long anything is kept.
Cloud AI requests are forwarded to third-party AI model providers (currently Anthropic, OpenAI, and OpenRouter) solely to generate the response you requested. Under our arrangements with these providers, your content is not used to train their models. Request content is processed transiently; we retain metering metadata (counts and token totals), not the text of your prompts or manuscript excerpts, beyond what is needed for abuse prevention and debugging, and any such logs are retained no longer than 30 days.
Other processors we use: Razorpay and Stripe (payments), Hostinger (the server running api.aevumwriter.com), BigRock (hosting for the aevumwriter.com website and the mail service behind our support address), and Cloudflare (DNS, content delivery, and TLS termination for both domains - traffic to us passes through it). We will update this list as it changes.
5. Data Sharing
In short: processors, the law, and a buyer if the business is ever sold. Never sold or rented.
We share personal data only with: the processors listed in Section 4, bound by data-processing agreements; authorities where required by law; and a successor entity in a merger, acquisition, or asset sale (in which case this Policy continues to apply until amended with notice). We never sell or rent personal data.
6. International Transfers
In short: our providers may sit outside your country, and transfers are covered by standard legal safeguards.
Our servers and processors may be located outside your country, including outside the EEA/UK. Where GDPR applies, we rely on adequacy decisions or Standard Contractual Clauses for such transfers.
7. Retention
In short: how long each kind of record survives.
- Account data: for the life of your account, then deleted or anonymized within 90 days of account deletion.
- Licensing/device records: while the license is active, plus a reasonable period for fraud prevention.
- Payment/transaction records: as required by tax and accounting law (typically 7–10 years depending on jurisdiction).
- Cloud AI logs: see Section 4.
- Support emails: up to 2 years after the matter is closed.
8. Security
In short: hashed passwords, signed tokens, TLS - and your device security is the other half.
Passwords are stored hashed. License tokens are cryptographically signed and short-lived. Transport to our servers uses TLS. Access to production systems is restricted. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you and regulators as required by law.
Because your manuscripts are stored locally, their security also depends on your device - use disk encryption and backups.
9. Your Rights
In short: access, correct, delete, export, object - one email away.
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, to restrict or object to processing, and to withdraw consent.
- EEA/UK (GDPR): all of the above, plus the right to lodge a complaint with your supervisory authority.
- California (CCPA/CPRA): right to know, delete, correct, and opt out of "sale"/"sharing" (we do neither), and to non-discrimination for exercising rights.
- India (DPDP Act): right to access, correction, erasure, grievance redressal, and nomination.
To exercise any right, email [email protected] from your account email address. We respond within the timeframe required by applicable law (30 days under GDPR, extendable as permitted). You can delete your account from the account page or by emailing us; deleting the app or your account does not delete manuscripts stored on your device - those are under your control.
10. Children
In short: not for under-16s.
The Service is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
11. Cookies and Website
In short: only the cookies sign-in and checkout cannot work without. No analytics.
The aevumwriter.com website uses only cookies strictly necessary for sign-in and checkout. It runs no analytics, advertising, or tracking scripts, so no cookie-consent banner is required.
12. Changes to This Policy
In short: material changes come with at least 14 days' notice.
We may update this Policy. Material changes will be announced in-app, by email, or on the website at least 14 days before taking effect. The "Last updated" date above reflects the current version.
13. Contact
In short: who is responsible, and where to write.
Data controller: Pranav Wadnere, trading as Aevum Nehru Chowk, Jalgaon – 425001 Maharashtra, India Email: [email protected]
These documents also ship inside the app - open preferences → the fine print to read them offline.