The important boundaries: what each product sends, and what it does not.
Connections and web security
All ClassEve web and app traffic is encrypted in transit, behind strict browser security headers, rate limits and abuse controls.
Self-hosted developer tools listen on your own machine only. Put your own authenticated boundary in front before exposing one to a network.
Build integrity and code signing
Android builds from this site are signed with ClassEve’s release key, so Android verifies the publisher and refuses an update signed by anyone else. Google Play signs the builds it distributes with its own key, so a Play install updates from Play and a direct install from this site.
On Windows, SmartScreen can show a publisher prompt the first time a new build runs — choose More info, then Run anyway, and check the file against its published SHA-256.
Every desktop artifact is published with its exact version, byte size and SHA-256 in the public products.json registry, so a downloaded file can be checked against what we published.
Authentication and devices
Signed-in sessions are short-lived. Each linked device has its own revocable credential; review and revoke devices in the dashboard. One account covers five active devices.
A device’s credential is only as safe as the device. Protect it and its operating-system account.
Lven Instant
The speech model processes microphone audio on the device. Sign-in, access and model-download requests carry no audio and no text. Local history is controlled by the app and operating system.
On Android, the Accessibility permission lets the app type into other apps. It is used to find the field that has focus and deliver text there; revoke it if you prefer to paste from the clipboard.
Lven Cloud
Lven Cloud sends your audio encrypted, transcribes it and returns the text. Nothing is kept after delivery.
REX
REX works through the AI model provider you connect with your own key: your prompts and the work go to that provider, not to ClassEve. The key stays on your PC.
Unless you turn it off in REX’s settings, a crash sends us a report: the PC’s system build, memory and language, the REX build and its install folder, the error, and REX’s own recent log lines. Never your chats, prompts, files, keys or account.
earslate and Folio PDF
earslate has no ClassEve account. Your AI provider key is stored securely on the phone, and session audio goes directly from the device to that provider; ClassEve does not receive it.
Folio PDF renders supported documents locally and does not require a ClassEve account. It declares no Internet permission, so it cannot open a network connection; files leave the app only through an action you choose, such as Android sharing or printing.
Payments
Checkout is handled by our payment partner, which sells to you on our behalf. Card details never reach ClassEve.
Credential Airlock boundary
Credential Airlock keeps real credentials out of ordinary prompts for cooperative clients by injecting them in a local proxy. It is a credential boundary, not an operating-system sandbox: it protects your keys from the agent, not the machine from a process running under your own account.
Data requests and deletion
The dashboard provides account, device, access, usage and deletion controls. A broader access or deletion request goes to security@classeve.com. Records held by our payment partner and by providers you select yourself remain subject to their controls.
Report a vulnerability
Send a private report to security@classeve.com rather than opening a public issue. Include the affected URL or product, impact, reproduction steps, and a safe proof of concept. We read every report sent there and respond once we have assessed it.
The machine-readable disclosure record is at /.well-known/security.txt.