Privacy & data handling
Last updated: 23 June 2026
EvalSmart helps program teams turn plain-language descriptions into review-ready evaluation plans. This page explains what we collect, how we use it, and — just as important — what we ask you not to send. It's written in plain English on purpose.
The short version
- EvalSmart only needs a plain-language description of your program — not your raw data. Please don't submit raw datasets, identifiable student records, patient information, client case notes, employee records, or other protected data.
- Program descriptions may be processed by Anthropic's Claude API to generate evaluation-planning drafts. EvalSmart does not sell your information, does not use advertising trackers, and does not use your content to train models of its own.
- Netlify hosts the site and form submissions. Our fonts are self-hosted, so loading the site doesn't send your browser's request information to third-party font servers.
- You may ask what information we hold, request correction, or ask us to delete the active working files associated with your submission.
What we collect
- When you contact us: your name, email, and message (and, for nonprofit inquiries, your organization). Form submissions are handled by Netlify.
- When you request a preview: your email (where we send the reports), an optional name or organization, and the program description you paste or upload.
- Basic technical logs: our host (Netlify) records standard request data such as IP address and browser type for security and troubleshooting. These logs are kept only as long as needed for those purposes.
How we use your program description
We use it only to generate your evaluation-planning drafts. To do that, your description is processed by Anthropic's Claude API, which our pipeline uses to draft and review the plan.
- Anthropic states that data submitted through its commercial API is not used to train Anthropic's models, and that API inputs and outputs are retained only for a limited period for trust-and-safety purposes. Some API features or models may have specific retention requirements.
- EvalSmart does not use your content to train any models of its own.
- We retain preview submissions and the generated reports for up to 60 days after delivery, unless you ask us to delete them sooner or we need to keep limited records for tax, legal, or dispute-resolution purposes. Contact-form messages may be kept for up to 12 months for follow-up and service records.
- Deletion applies to our active EvalSmart working files. We can't guarantee removal from third-party systems (such as Netlify or Anthropic), backups, or email logs, which keep their own records under their own policies.
Please do not submit identifiable student, patient, client, or employee records.
Who we share it with
We use a small number of service providers, and only to operate EvalSmart:
- Netlify — website hosting and form submissions.
- Anthropic — AI processing of your program description.
We email reports and replies to the address you provide. We don't sell or rent your information, and we don't share it for advertising.
Cookies & analytics
- We don't use third-party analytics or advertising / tracking cookies.
- The site's fonts are self-hosted on evalsmart.io, so your browser doesn't contact third-party font servers (such as Google Fonts) to display the page.
Data security
We limit who can access your information and rely on established providers (Netlify, Anthropic). No method of transmission or storage is ever completely secure, but we take reasonable steps to protect what you share — and you can help by not sending identifiable records.
The preview is not a compliance service
The preview is not a HIPAA, FERPA, IRB, or institutional data-governance service. Please do not submit protected health information, education-record PII, student IDs, patient details, personnel records, case notes, or raw datasets. Standards references (LCME, ACGME, ACRL, ESSA / state frameworks) are contextual prompts to verify with your institution before any compliance use. Projects that involve protected or sensitive data require a separate written agreement before any data is shared.
Your choices
You can ask what we hold about you, ask us to correct it, or ask us to delete the active working files associated with your submission — just email contact@evalsmart.io. We aim to respond within 30 days. Depending on where you live, you may also have rights under laws such as the GDPR or CCPA.
Changes to this page
We may update this page from time to time. When we do, we'll change the "last updated" date above.
Contact
Questions about privacy or your data? Email contact@evalsmart.io.
EvalSmart is operated by Fangning Wang.