Privacy Policy

Last updated: 9 October 2026

This policy describes how the public EvalSprint demo at evalsprint.vercel.app handles data. It is based on what the application's source code actually does, which you can inspect in the public repository. EvalSprint is an open-source project maintained by the GitHub user bhargavthaparbusiness (“the maintainer”, “we”).

In short: your suites are saved in your own browser. When you press Run or Compare, the suite is sent to the demo's server, evaluated in memory, and returned. The app keeps no copy, sets no cookies, and includes no analytics or tracking. The public demo never calls an AI provider.

1. Data stored in your browser

The web app stores the following in your browser's localStorage for this site only:

This data stays on your device. It is not synced between browsers or devices and is not sent anywhere unless you run an evaluation (see below). Evaluation results are kept in the page's memory only and disappear when you reload or close it.

2. Data sent to the server

The app talks only to its own server (same origin). It makes these requests:

WhenRequestWhat is sent
Opening the demoGET /api/providersNothing beyond the request itself.
Pressing Run evaluationsPOST /api/runThe full current suite (name, description, prompts, test cases with their variables, assertions and mock fixtures, settings), the selected prompt version and the selected provider.
Pressing Run comparisonPOST /api/compareThe same suite data plus the two selected prompt versions.

The server validates the suite, runs the evaluation in memory, and returns the results to your browser. The application does not write suites or results to a database, file or log. If an unexpected internal error occurs, the server logs the error itself, not your request body.

Please don't put personal data, secrets or confidential information in suites you run on the public demo. Use a self-hosted instance for anything sensitive.

3. AI providers

On the public demo, the Anthropic provider is disabled. This is enforced in the server code regardless of configuration, and only the mock provider runs. Mock outputs come from fixtures in your suite; no AI model is involved and no data is sent to any AI provider.

On a self-hosted instance where the operator has set ANTHROPIC_API_KEY, choosing the Anthropic provider sends each rendered prompt (system prompt and user message built from your test case variables) to Anthropic's API. Anthropic's own terms and privacy policy then apply, and the operator of that instance is responsible for it.

4. Hosting and logs

The demo is hosted on Vercel, which runs the server functions in the United States (region iad1). Like any web host, Vercel receives standard request information such as your IP address, user agent, the requested path and timestamps, and keeps platform logs under its own policies. See the Vercel Privacy Policy. The maintainer can view these platform logs for operating and debugging the demo.

5. Cookies, analytics and third parties

6. Retention and deletion

7. Public demo versus self-hosted instances

This policy covers only the public demo operated by the maintainer at evalsprint.vercel.app. EvalSprint is open-source software, and anyone can run their own copy. A self-hosted instance may be configured differently, for example with real AI providers enabled. Its operator, not the maintainer, is responsible for how it handles data.

8. Changes

If the app's data handling changes, this page will be updated along with the date above. Its full history is in the repository.

9. Contact

For privacy questions, see the Contact page. Issues on GitHub are public, so please don't include personal or sensitive details in them.