Legal
Privacy Policy
Last updated June 11, 2026
The short version
Eudicot is a desktop GIS. Your geospatial data stays on your computer. We never upload your files, layers, or databases to our servers. The only content that leaves your machine is what the AI copilot needs to answer you: your chat messages and a compact description of the data you are working with. We do not sell data, we do not run ads, and we do not use your content to train AI models.
What we collect
Account information. Your email address and a salted hash of your password. We never store the password itself. If you sign in with Google, we receive your email address and a Google account identifier; we never see your Google password.
Billing information. Payments are handled by Stripe. Card numbers go directly to Stripe and never touch our servers. We store your plan and a Stripe customer reference so your subscription maps to your account.
Usage records. For each AI message we record counts: how many messages you have sent this month and how many tokens they used, so plans, limits, and the usage page in your dashboard work. These are numbers, not the content of your conversations, and they are kept for about a year.
Copilot messages and data context. When you ask the copilot something, your message plus a compact technical summary of the data you are working with (descriptive metadata, not the data itself) is sent to our server and relayed to our AI provider to generate the response. Under the terms we use, our AI provider does not train models on this content. We do not store your conversations on our servers; chat history lives on your computer.
What we never collect
- Your geospatial files, layers, rasters, or databases
- Card numbers or bank details (Stripe holds those)
- Advertising identifiers or cross-site tracking data
The website sets no tracking cookies. Signing in stores a session token in your browser's local storage; the desktop app stores its session token encrypted in your operating system's keychain.
Where your information goes
We rely on a small set of service providers, each receiving only what its job requires: Stripe for payments, an AI provider that generates copilot responses from your messages and data context, and infrastructure providers for hosting, storage, and email delivery. Like most internet services, these providers keep standard server logs (such as IP addresses and request timestamps) to operate and secure their systems.
How long we keep things
Account records are kept while your account exists, and usage records for about a year. If you delete your account, we remove your account records from our systems; Stripe retains payment records as required by financial regulations.
Your choices
- You can use the full GIS without an account; only the copilot requires one.
- You can change your password or email preferences from your dashboard.
- You can ask us to delete your account and its data by writing to hello@eudicot.app.
Security
Everything moves over TLS. Passwords are stored only as salted hashes. The desktop app encrypts its session token with your operating system's secure storage. Builds are signed and notarized so your computer can verify they came from us.
Children
Eudicot is not directed to children under 13, and we do not knowingly collect personal information from them.
Changes and contact
If this policy changes in a way that matters, we will update this page and the date above. Questions, requests, or concerns: hello@eudicot.app.