Privacy Policy
Your pod is yours. Everything on it (your agent’s memory, files, conversations, and any keys or tokens you give your agent) lives on the pod, not in our systems: we don’t collect it, and we don’t read it. It stays for as long as you subscribe, and when you leave it is permanently deleted, backups included. Outside the pod we hold only what it takes to run your account: your email address, sign-in and subscription records, and any mail you send us. No ad trackers, no selling data, no training AI on your content.
1. Who we are
Everpod is operated by DEH Technologies LLC, a Wyoming limited liability company, doing business as Everpod. For privacy questions or requests, contact privacy@everpod.ai. For security reports, use security@everpod.ai; for anything else, support@everpod.ai. The Terms of Service are the binding agreement; this policy explains how we handle personal information under it.
2. What we hold, and what we don’t collect
Account Data (we hold this): your email address, sign-in records, your pod’s basic details (such as its name and status), subscription records, and support correspondence. If you contact us or fill in a form on our site, we keep what you send us. Payment details are different: checkout is run by Paddle as Merchant of Record under its own privacy policy, and we never see your card number; we receive only transaction metadata (what was bought, when, receipt identifiers).
Pod Content (we host this, we don’t collect it): what you tell your agent, what it remembers, and the files it makes live on your pod: a machine we operate for you, whose contents you control. Pod Content is not part of our systems: we don’t collect, inspect, index, or analyze it. Section 5 covers how long it lives; section 7 covers the narrow, founder-approved circumstances in which we can access it.
Site and app usage (analytics): we use analytics to understand how our website and app are used. This covers only our site and app. It never touches your pod; your agent and your conversations with it are not part of it.
What we don’t do: no advertising trackers on our site; no selling or sharing of personal information for advertising; no use of your content to train AI models. Credentials you give your agent (your own model keys, channel tokens) live on your pod, not in our systems. We use cookies to keep you signed in and for the analytics above.
3. Our role
For Account Data, we are the controller: we decide what’s needed to run your account, and section 10 lists your rights over it. For Pod Content, our role is that of a hosting provider (in data-protection terms, closer to a processor): you decide what your agent knows and does, and we supply and operate the machine it lives on, acting on your instructions (chiefly: keep it secure, keep it running, back it up, and delete it when you leave).
4. Where your data lives
- Your pod and everything on it: data centers in Germany or Finland (EU/EEA-adjacent) operated by Hetzner, with backups in the same region. Pods are hosted in Europe today; if that ever changes, we’ll update this policy first.
- Account Data: the United States (our account/auth database, our website hosting, and analytics).
- Network edge: traffic to our site and to your pod’s sign-in page passes through Cloudflare’s global network.
- Model traffic: see section 6.
5. How long we keep things
Persistence is the product: Pod Content lives for the life of your subscription; that’s the point of a pod. Backups are made daily and rotate over roughly 7 days, so anything you delete on your pod ages out of backups on that cycle too.
When you cancel, your pod stops at the end of the paid period, and 7 days later we permanently delete the machine, its contents, and its backups, and revoke its credentials. The grace window exists so an accidental cancellation isn’t a catastrophe; past it, the deletion is permanent and we can’t undo it.
Account Data is kept while you have an account and deleted on request when no longer needed (email privacy@everpod.ai), except records we must keep for tax, accounting, or legal reasons.
6. Model providers (your agent’s thinking)
When your agent thinks, the conversation context is sent to an AI model provider; that’s how AI agents work. For Included Usage (and any additional usage you buy from us), that traffic is routed through OpenRouter under our account. Here is how it is handled:
- OpenRouter does not store your prompts or your agent’s responses.
- We enforce, at the routing layer, that Included Usage is never sent to model providers that use API traffic to train their models, whichever model your pod is set to.
- The default model is served by OpenAI and Microsoft Azure. Like most major providers, they may retain API traffic briefly (up to about 30 days) for abuse monitoring; they do not train on it.
If you bring your own key or connect your own model subscription (BYOK), your model traffic runs under your own agreement with that provider, and their policies, not this section, govern it.
7. When we can access your pod
We do not access or read your pod’s content (conversations, memory, files) except with your permission during support, or where required for security, abuse investigation, or by law. The machine your pod runs on does need maintaining, and that is what our access is for: setting your pod up, approving device pairings, running security checks, applying managed updates, helping when you ask for support, and investigating security or abuse problems. That access is tightly held, not open to staff at large: machine sign-in is by cryptographic key, password login is disabled, and every use is approved personally by Everpod’s founder, only for the purposes above.
8. Who we share data with
We use a small set of providers to run Everpod. They process data only to provide their service to us:
| Provider | What for | What it touches | Where |
|---|---|---|---|
| Hetzner | Pod hosting and backups | Pod Content (as host) | EU (Germany/Finland) |
| Cloudflare | Network edge, private pod access | Sign-in email, traffic routing | Global |
| Supabase | Accounts and sign-in | Account Data | US |
| Render | Website hosting | Site traffic | US |
| OpenRouter | Model routing for Included Usage and top-ups | Agent model traffic (see §6) | US routing; providers per §6 |
| Postmark | Sign-in and service email | Your email address | US |
| PostHog | Site and app analytics | Site and app usage data (never Pod Content) | US |
| Google Workspace | Our support mailbox | Mail you send us | US |
Paddle (checkout, taxes, receipts) is our Merchant of Record and an independent controller of buyer and payment data, not a subprocessor. Messaging platforms you connect (Telegram, WhatsApp, and similar) are your own accounts, not our vendors. We’ll post at least 15 days’ notice here before materially changing this list. Beyond the table: we disclose personal information only with your consent, to comply with law or valid legal process, to protect our rights or users’ safety, or as part of a merger or acquisition (in which case this policy continues to apply to it).
9. International transfers
Pods are hosted in Europe (section 4). Account Data is processed in the United States, and model traffic is processed where the provider runs (section 6). Where EU/UK law requires safeguards for a transfer, we rely on our providers’ data-processing agreements, including Standard Contractual Clauses where applicable.
10. Your rights
Depending on where you live (the EU/UK under GDPR, several U.S. states, and elsewhere), you may have rights to access, correct, delete, or export personal information we hold about you, to object to or restrict processing, and to complain to your local supervisory authority. Email privacy@everpod.ai and we’ll respond within a month (or sooner where your law requires); if we deny a request, we’ll say why, and you can appeal by replying. We’ll verify requests against the email on the account, and we never discriminate for exercising rights.
For Pod Content, the fastest path is usually direct: it’s your machine, and your agent can show you, send you, or delete anything on it when you ask. If you’d like a full copy of your Pod Content, email support@everpod.ai and we’ll provide one in a common archive format. Cancelling deletes everything on the schedule in section 5.
11. Security
Security is a core part of what you pay us for. Each pod is a separate machine serving one customer, and every pod is security-checked before you get the keys. Your pod accepts no incoming connections from the open internet, which is the route attacks on an ordinary server take. Your agent can still browse and use the internet normally; its connections start from inside the pod, not from outside. You reach your pod through a private, authenticated path tied to your email.
Traffic is encrypted in transit; software versions are pinned and updates are tested before we apply them; backups are made daily and we test restores. No one can promise absolute security, and we don’t. If we confirm a security incident affecting your data in our systems, we’ll notify you without undue delay and no later than 48 hours after confirming it. Report vulnerabilities or suspected incidents to security@everpod.ai.
12. Age, changes, contact
Everpod is for adults: you must be at least 18 to use it, and we don’t knowingly collect personal information from anyone younger. When this policy changes materially, we’ll note it here with a new date (prior versions stay available from this page’s archive links) and tell you by email or with a notice on our site if the change affects you. Questions: privacy@everpod.ai.