Overview
ClassEve operates the classeve.com website and related software applications. This Privacy Policy explains how we collect, use, store, and protect information when you use our services.
Use of our services is governed by our Terms of Service. Where we rely on your consent to process personal data, we ask for it separately through a clear, purpose-specific action — such as the age and Terms confirmation shown when you create an account, or the cookie choice on your first visit. This policy explains how we handle data; it is not, by itself, a substitute for that consent, and simply browsing the site is not treated as consent to anything beyond the essential cookies needed to run it.
Data controller and privacy contact
ClassEve is the data controller for the personal data described in this policy.
Privacy contact: [email protected] (the ClassEve privacy team). We acknowledge privacy requests and complaints within 24 hours and target resolution within 30 days of receipt.
You may contact the privacy team in writing at the email above.
Information we collect
Account information: When you create an account, we collect your email address and authentication credentials. If you sign in through a third-party provider such as Google or GitHub, we receive your name and email address from that provider.
Waitlist emails: If you join a pre-launch waitlist for one of our products, we store the email address you enter, the product you queued for, and timestamps, and we use that email only to notify you about your access. Waitlist entries that are never linked to an account are deleted automatically after 180 days; entries linked to an account are deleted when that account is deleted.
Subscription and account status: We record subscription state (trial / active / canceled / past-due), plan tier, and account-management events for billing and access control. For Lven Cloud subscribers we additionally record daily transcription counts to enforce plan limits; for Lven Instant subscribers no transcription metering occurs because transcription runs entirely on your device and never reaches our infrastructure.
Audio data — Lven Instant (flagship, on-device): Your microphone audio is processed entirely on your machine by a speech model downloaded during setup. The audio never leaves the device, is never uploaded to ClassEve or any subprocessor, and is discarded as soon as the local transcription completes. We physically cannot read, store, or share it because we never receive it.
Audio data — Lven Cloud (the server-side product): Audio recordings you submit for transcription are captured when you hold the Lven hotkey, transmitted over TLS to our transcription subprocessor (Groq), processed in real time, and discarded — they are not persisted on our servers or by Groq. The returned transcription text is delivered to your device and stored only there — ClassEve keeps no Cloud transcript text on its servers.
Audio data — earslate (live translation): earslate is a free, standalone app with no ClassEve account or subscription. When a session starts, our Cloudflare Worker receives an anonymous installation UUID, provider preference, target language, and IP address for credential minting and abuse prevention. It returns a short-lived Gemini or OpenAI credential. Ambient audio and translated transcripts then stream directly between your device and the selected provider; ClassEve does not proxy, receive, or store them. Provider processing is governed by our provider agreements and the provider terms identified in our subprocessor list. earslate is not for confidential or sensitive conversations.
Transcription text storage: ClassEve does not store transcription text on its servers for either product. Lven Instant transcribes entirely on-device; for Lven Cloud the returned text is delivered to your device and kept only there. Because nothing is stored server-side, Cloud history does not sync across devices through us — it lives on each device.
Device and technical data: We may collect device identifiers, operating system versions, application versions, and IP addresses for security, debugging, and fraud prevention purposes.
Payment data: Payment processing is handled entirely by Paddle.com Market Limited. We do not store credit card numbers, CVV codes, or other raw payment credentials on our systems. We retain only the customer identifier necessary to manage your subscription.
Microphone and voice data
The Lven applications request access to your device microphone. The microphone is activated only while you hold the transcription hotkey (or equivalent gesture). The application does not listen ambiently, does not record continuously, and does not retain audio between transcription sessions.
On Lven Instant — the flagship on-device build — your microphone audio is processed and discarded entirely on your machine. Nothing leaves your device. There is no recovery scenario in which an attacker compromising our servers can read what you dictated, because we never had the audio.
On Lven Cloud — the server-side product — audio is captured locally and sent to our transcription subprocessor (Groq) via TLS for the duration of the request only. Groq returns the text and discards the audio.
Audio data constitutes sensitive personal data. You may revoke microphone permission at any time via your operating system's privacy settings. Revoking permission disables transcription. On Lven Instant you may also delete the local transcription history at any time from the app's history panel. On Lven Cloud, transcript text is stored only on your own device — deleting your local history removes it completely, because there is no server-side copy.
ClassEve does not use your voice data to train machine-learning models, and we do not share it with advertisers or data brokers. For Lven transcription, audio either never leaves your device (Instant) or is processed and then discarded by our transcription provider for the duration of the request only (Cloud). Earslate audio is sent directly from your device to the selected translation subprocessor, Gemini or OpenAI; ClassEve never receives or stores that audio.
How we use your information
To provide, maintain, and improve our services, including account management, transcription processing, and subscription enforcement.
To communicate with you regarding your account, billing, service updates, and support requests.
To detect, prevent, and address fraud, abuse, and security incidents.
To comply with applicable legal obligations.
Information sharing and disclosure
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
We share information with a small set of named subprocessors, each bound by contract to process data solely on our behalf and under security obligations consistent with the EU GDPR and, where applicable, the California CCPA. The full list is maintained at /legal/subprocessors and includes Cloudflare, Supabase, Groq, ElevenLabs, Google, OpenAI, Paddle, and Spacemail. Lven Instant transcription never crosses a subprocessor. Earslate audio streams directly from the device to Google or OpenAI, while ClassEve supplies only the short-lived session credential.
We may disclose information when required by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of ClassEve, its users, or the public.
International data transfers (GDPR Chapter V)
ClassEve delivers its services through subprocessors located in several countries. The personal data flows are itemised below.
Cloudflare, Inc. (United States — globally distributed edge network): API request routing, rate-limiting, edge caching of public marketing pages, and failover transcription inference (Workers AI) for Lven Cloud when the primary provider is saturated — audio is processed in real time and never retained.
Supabase, Inc. (United States — primary region us-east): authentication credentials (hashed), profile metadata, paired-device records, daily usage counters, comp-code redemptions, audit log. No transcript text and no audio — the database has no table for transcript content.
Groq, Inc. (United States): in-flight transcription of audio — Lven Cloud sessions only. Audio is processed and discarded by Groq within seconds; we do not store the audio at our end either. Lven Instant transcription never reaches Groq because it runs entirely on the user's device.
ElevenLabs, Inc. (United States): in-flight realtime transcription of audio — Lven Cloud Premium Realtime sessions only. Audio is streamed for the duration of the session and not stored by ClassEve.
Google LLC (United States): in-flight live translation of Earslate audio when Gemini is selected. Audio streams directly from the device; ClassEve does not proxy or retain it.
OpenAI, L.L.C. (United States): in-flight live translation of Earslate audio when OpenAI is selected. Audio streams directly from the device; ClassEve does not proxy or retain it.
Paddle.com Market Limited (United Kingdom; merchant data co-processed in the EU): payment processing, subscription management, VAT/GST invoicing, customer self-service portal.
Spaceship, Inc. / Spacemail (United States and EU/EEA): transactional and customer-support email delivery from [email protected] and [email protected].
Transfers are protected by industry-standard TLS in transit, encryption at rest, contractual data-processing terms with each subprocessor, and limitation of access to the minimum personnel and minimum data scope required for service delivery. The full subprocessor list is maintained at /legal/subprocessors and updated in advance of any change.
Data retention
We retain personal data only for the period necessary for the purpose for which it was collected, in line with GDPR Article 5(1)(e) (storage limitation). The table below summarises retention by category.
Account email + profile metadata: while the account is active. The active database record is removed when automated deletion completes; verified operational backups may retain a historical copy for up to 30 days before expiry.
Transcription text: not retained on our servers for either product. Lven Instant and Lven Cloud both keep transcript history only on your device; ClassEve stores no transcript content, so there is none to expire or delete server-side.
Paired-device records (refresh tokens, device kind, last-seen timestamp): until you revoke the device, or 180 days after last activity, whichever is sooner.
Contact-form submissions (email, subject, message body, hashed IP): up to 180 days after the support team marks the ticket handled. Honeypot-flagged spam submissions are deleted within 30 days.
Trial-eligibility hash (canonicalized email, one-way): retained indefinitely after a free trial is used, to prevent trial farming. You can request its removal — note that removal allows a fresh trial.
Consent records (which Terms/age version you accepted, the timestamp, a hashed IP and user-agent): kept as legally-required proof of consent. On account deletion the link to your identity is severed and the remaining record is pseudonymous — retained only as consent evidence, not tied to you.
Paddle webhook event log: signed event payloads can contain Paddle customer, subscription, transaction, and billing-email metadata. They are retained for replay protection and reconciliation, then removed 30 days after processing.
Paddle reconciliation queue: up to 90 days after the entry is resolved.
Audit log entries (admin actions): retained indefinitely; user references are redacted (NULLed) within 30 days of account deletion. The integrity of the audit trail is preserved as a security control.
Cloudflare access logs and Supabase platform logs: retained per provider policy (typically 30 days) and outside our direct deletion mechanism.
Personal-data breach notification
In the event of a personal-data breach as defined under GDPR Article 4(12), we will notify affected users and, where required, the competent supervisory authority within 72 hours of becoming aware of the breach, in line with GDPR Articles 33 and 34.
Each notification will describe the nature of the breach, the categories and approximate number of affected data subjects, the contact for further information, the likely consequences, and the measures taken or proposed to address the breach.
If you suspect a breach of your data, please email [email protected] immediately.
Data security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS), encrypted storage of authentication credentials, and access controls on internal systems.
No method of electronic transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.
Your rights
Depending on where you live, you may have some or all of the following rights over your personal data: to access a copy of it, to have it corrected or completed, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time. We honour these rights for all users regardless of jurisdiction, subject to the narrow legal exceptions that apply in each region (for example, records we must keep as proof of consent).
To exercise any of these rights, contact the privacy team at [email protected]. You may also withdraw your consent at any time by deleting your account; note that withdrawal does not affect the lawfulness of processing carried out before the withdrawal. If you are in the EEA or the UK, you additionally have the right to lodge a complaint with your local data-protection supervisory authority.
California residents — CCPA
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights regarding your personal information.
Right to know (§1798.100, §1798.110, §1798.115): you may request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and any third parties we share it with.
Right to delete (§1798.105): you may request deletion of personal information we have collected, subject to certain statutory exceptions (e.g., complete a transaction, comply with law).
Right to correct (§1798.106): you may request correction of inaccurate personal information.
Right to opt out of sale or sharing (§1798.120): we do not sell or share personal information as those terms are defined under the CCPA. You nonetheless have the right to direct us not to do so in the future.
Right to non-discrimination (§1798.125): we will not discriminate against you for exercising any CCPA right.
To exercise these rights, email [email protected] with subject line "CCPA Request." We respond within 45 days as required by §1798.130.
Children
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. The signup form requires you to attest that you are 18 or older before an account can be created.
If we discover or are notified that a minor has created an account, we will delete the account and any associated personal data without undue delay. To report a minor's account, email [email protected].
We do not undertake age-gating beyond a self-attestation checkbox. Parents and guardians are encouraged to monitor minors' use of the internet generally.
Changes to this policy
We may update this Privacy Policy from time to time. The revised version will be indicated by an updated date at the top of this page. Continued use of our services after changes are posted constitutes acceptance of those changes.
Contact
For privacy-related inquiries, contact us at [email protected].
ClassEve · https://classeve.com