Privacy Policy
Last updated: 7 July 2026
This policy explains what personal data antevel collects, why, and your rights over it. The data controller is Pierre Natiez, operating antevel.com; full identification is in our Legal Notice. Contact: antevel.api@gmail.com.
1. Data we collect
- Account: your email address and a securely hashed password.
- Your content: the topics, filters, and preferences you create.
- Technical: limited logs and your IP address, used to keep the Service secure and to enforce rate limits.
- Billing: handled by our payment processor; we do not store your card details.
2. What we do NOT do
We do not sell your personal data. We do not use advertising or third-party analytics trackers, and we do not store data in your browser beyond the essential session and CSRF cookies needed to keep you signed in securely.
3. How we use your data and legal bases
We process your data to provide the Service (authentication, your topics, dashboards and alerts) - performance of our contract with you; to keep the Service secure and prevent abuse - our legitimate interest; and to send transactional emails such as password resets - performance of the contract. Where we ever rely on consent, you can withdraw it at any time.
4. The research data in antevel
antevel aggregates public research metadata about grants, trials, preprints, datasets, and publications. This may include the names of investigators, institutions, and funders that are already publicly published by the original sources. We obtain it only from public sources and links; it is professional, already-public information and is not collected from you.
5. Service providers
We rely on a small set of processors to run antevel:
- Railway (hosting) - Railway Corporation, United States.
- Resend (transactional email) - United States.
- Creem (payments, as merchant of record).
- Google (the LLM that generates the AI summaries and briefing) - United States.
They process data only to provide their service to us, under their own agreements. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as the European Commission standard contractual clauses (see section 10). The public data APIs listed in our Terms are separate public sources, not processors of your account data.
6. Cookies
We use strictly necessary, first-party cookies only (a sign-in cookie and a CSRF cookie); no marketing or analytics cookies are set, and no consent banner is required. Each cookie is listed with its purpose and duration in our Cookie Policy.
7. Retention
We keep your account data for as long as your account is active. To close your account and have your data erased, email antevel.api@gmail.com; we delete or anonymize it within 30 days, except where a longer period is required by law (for example, billing records kept for the legal accounting period). Security logs and IP addresses are kept for up to 12 months.
8. Your rights
Under the GDPR you have the right to access, correct, delete, port, restrict, or object to the processing of your personal data. Email antevel.api@gmail.com to exercise them. You also have the right to lodge a complaint with a supervisory authority - in France, the CNIL.
9. Security
We protect data in transit with HTTPS, store passwords only as salted hashes, and follow a least-data approach - we collect only what the Service needs.
10. International transfers
Some providers may process data outside the EEA. Where that happens, we rely on appropriate safeguards such as the European Commission standard contractual clauses.
11. Children
antevel is intended for professional and research use and is not directed at children under the age of majority.
12. Changes
We may update this policy as the Service evolves; the date above reflects the latest version.
13. Contact
Privacy questions or requests: antevel.api@gmail.com.