Skip to main content
EverPacket
Product Terms Privacy Refunds
Scheduled policy. This policy has an effective date of August 15, 2026 and is scheduled to govern sales beginning on or after that date. Purchases are not currently open.

Privacy Policy

Source version: privacy-2026-08-15-v2

Effective date: August 15, 2026

1. Who we are and how to contact us

This Privacy Policy explains how Kimi Chen, a California sole proprietor doing business as EverPacket (EverPacket, we, us, or our) handles personal information in connection with the EverPacket website, progressive web application, account, purchase activation, support, and related services (the Service).

EverPacket's business address is 8843 Villa La Jolla Drive Apt 2, La Jolla, CA, 92037. The privacy contact is privacy@everpacket.com.

For data-protection law purposes, EverPacket is generally the controller or business responsible for the account, purchase administration, consent, support, security, product analytics, first-party marketing measurement, and unsupported-country aggregate interest information described below. The Payment Merchant—the legal entity identified by Stripe or Link at checkout and on the receipt—is the merchant of record for that transaction and independently determines how it handles payment, billing, tax, transaction-fraud, dispute, receipt, and merchant-support information under its own privacy notice.

The separate Consumer Health Data Privacy Notice explains how EverPacket handles health-related information that a user chooses to process locally in a packet, including categories, sources, purposes, sharing, deletion, and consumer-health-data rights. That Notice is supplemental and does not mean that every consumer-health-data law applies to every EverPacket user or activity.

2. The most important privacy boundary

Through ordinary product operation, the editable contents of an EverPacket packet are designed to stay in the browser profile and device storage you use and in project files, PDFs, contact cards, QR codes, printouts, or other files you choose to create.

Except for one permitted, content-free support image that you intentionally submit as described in Section 4.4, EverPacket’s servers are not designed to receive:

  • packet fields, household notes, checklist text, or search text;

  • packet titles, names, phone numbers, addresses, household locations, or healthcare locations entered in a packet;

  • .EverPacket project-file contents;

  • generated PDF contents, contact-card contents, QR payloads, filenames, or output contents; or

  • passwords, account numbers, medical records, household information, or other sensitive information you may nevertheless choose to enter locally contrary to product guidance.

The application necessarily processes local packet information—including any health-related information you choose to enter—in your browser to save, search, review, import, export, and generate outputs at your direction. That local processing does not by itself send the content to EverPacket. To the extent a law treats EverPacket as determining aspects of that on-device processing, we limit the purpose to providing the functions you request and do not use the content for advertising, profiling, product analytics, model training, or server-side storage. See the Consumer Health Data Privacy Notice for additional disclosures and controls.

A permitted support attachment is a deliberate, limited exception to this local-only boundary. Submitting a support image does not upload the related packet, project file, generated output, or other local information.

Signing in restores account and purchase access; it does not upload, synchronize, transfer, back up, or recover packet contents. An account-data export does not include local packets.

3. Scope

This Policy applies to personal information handled by EverPacket through:

  • the public website and application;

  • account creation, authentication, linked identities, sessions, and recovery;

  • purchase review, activation, entitlement, refund, dispute, and transaction administration;

  • product support, privacy requests, account export, and account deletion;

  • security, fraud prevention, reliability, and legal-compliance operations;

  • consent and browser-privacy choices; and

  • optional, content-blind product analytics and first-party campaign attribution or text-slot experiments when enabled and permitted, together with content-free country-interest counts for unsupported markets.

It does not govern information handled independently by the Payment Merchant, an identity provider, your browser or operating-system provider, a cloud drive, email or messaging provider, printer, device backup service, recipient, or another service you choose to use.

4. Personal information we collect or receive

4.1 Account and identity information

Depending on the sign-in method and features you use, we may receive or create:

  • email address and account identifier;

  • account creation, status, and update timestamps;

  • identity-provider name, provider-linked identifier, and provider-supplied basic identity metadata such as a display name or profile-image URL when the provider includes it;

  • linked-identity, sign-in, and last-used timestamps;

  • recovery email and verification status;

  • authentication session identifiers, session summaries, and recent-authentication status; and

  • account setup, consolidation, transfer, deletion, and recovery records.

We do not ask for a separate EverPacket password when email-code or supported identity-provider authentication is used. The sign-in flow is used only to authenticate and link the selected identity. EverPacket does not use sign-in authorization to read the contents of a Gmail or Outlook mailbox, Google Drive or OneDrive files, contacts, calendars, or social-media posts. Advertising-account reporting uses separate operator credentials and is not derived from a customer’s Google, Meta/Facebook, or Microsoft sign-in. The identity provider may process additional information under its own notice.

4.2 Purchase and entitlement information

We may collect or receive:

  • checkout email and normalized email used to prevent duplicate purchases;

  • product, offer, promotion, price, discount, amount, currency, and quote information;

  • purchase-intent, checkout-session, customer, order, payment, refund, dispute, and provider reference identifiers;

  • transaction status, payment verification, activation, entitlement, paid-output evidence, refund-window, recovery, and transfer status;

  • billing country, tax information, payment-method category, or other transaction details the Payment Merchant makes available to us;

  • receipt, invoice, promotion-redemption, refund, chargeback, and dispute events; and

  • timestamps and records needed to reconcile the transaction.

EverPacket does not receive or store your complete card number, card security code, online-banking password, or complete payment credential. Those details are entered with and handled by the Payment Merchant and its payment partners.

4.3 Legal acceptance and consent records

We may keep append-only or otherwise integrity-protected records of:

  • the document type and exact version presented;

  • acceptance method and timestamp;

  • the purchase intent or account to which the acceptance relates;

  • separate immediate-supply, withdrawal-right, or digital-content acknowledgments required by local law;

  • analytics category, allowed, denied, Global Privacy Control, or Do Not Track decision;

  • policy version and an anonymous installation identifier for a browser-level decision; and

  • durable-copy or confirmation-delivery status.

A privacy-policy acknowledgment is not treated as consent for processing that is necessary to perform a contract or comply with law. We ask for consent only when consent is the appropriate legal basis.

4.4 Support, privacy, and account-service information

When you contact us or use account controls, we may process:

  • your name, email address, case reference, subject, message, category, status, and timestamps;

  • transaction or account references needed to verify and resolve the request;

  • one optional permitted support attachment, when the support form displays an attachment control;

  • the verification level and steps used to protect the account;

  • support replies, provider-delivery results, and resolution notes;

  • privacy-request type, applicable deadline, status, and response record; and

  • account-export or account-deletion status.

A permitted support attachment is limited to one PNG or JPEG image no larger than 15 MiB. It may show only a redacted application-shell view, generic error state, or another content-free interface, browser, payment, or support problem.

Do not submit an .EverPacket project file, generated packet PDF, vCard or contact card, QR output, screenshot containing a QR payload, screenshot showing packet entries, password, credential, authentication code, recovery link, payment information, government identification, medical information, household information, or other unnecessary sensitive information.

You are responsible for reviewing and redacting the complete visible image before submitting it. The Service checks the file’s size, declared media type, and file signature; decodes the image within dimension and pixel limits; and re-encodes the decoded pixels into a new PNG. The original submitted file is not retained. Re-encoding removes source-file metadata and appended non-image data, but technical validation does not inspect or guarantee that the visible pixels contain no sensitive information.

Submitting a permitted support attachment is an intentional exception to the normal local-only product boundary. The sanitized PNG is stored under a generated case-bound name in a private Supabase storage bucket, associated with the applicable support case, and recorded with content type, byte size, and a SHA-256 integrity hash. Access is restricted to authorized EverPacket personnel and service providers whose responsibilities require access for support, security, legal compliance, or protection of the Service. Operator access is delivered through an authenticated, no-store download route and is recorded as support-file access evidence.

We use a permitted support attachment only to investigate and resolve the request, maintain security, comply with law, or establish, exercise, or defend legal claims. We do not use it for advertising, behavioral profiling, unrelated product analytics, or model training.

If we discover prohibited or unnecessary information in an attachment, we may stop viewing it, restrict access, contain it, and delete it under our privacy and security procedures. We may retain it temporarily when a documented legal hold or other legal obligation prevents deletion.

4.5 Device, request, security, and reliability information

When your device connects to EverPacket or a service provider, ordinary network and security systems may process:

  • IP address, request time, requested host and route, response status, and network headers;

  • browser family, operating-system or device category, language, time zone, and app version;

  • cookie and session identifiers, authentication claims, and anti-forgery or rate-limit signals;

  • origin and redirect validation, webhook signatures, and provider event identifiers;

  • error category, availability, delivery, incident, risk-hold, or security event; and

  • administrative access and action logs.

The public application is designed not to place packet contents, filenames, free text, or output contents into server logs or analytics. Infrastructure providers may maintain limited request logs for delivery, abuse prevention, and security under their service terms.

4.6 Optional content-blind product analytics

When optional analytics is enabled in production and your current choice permits it, the browser may send a randomly generated installation identifier and a strictly allowlisted product event such as packet created, section opened, free sheet generated, full PDF generated, project exported, checkout started, sign-in completed, or account deletion completed. Some events contain only a predefined section, preset, error code, or sign-in-provider value. The same optional analytics choice also governs the first-party marketing measurement described in Section 4.7.

The analytics contract is designed to reject unknown properties and exclude packet values, names, phone numbers, notes, titles, filenames, output contents, URLs, arbitrary referrers, exception messages, clipboard data, keystrokes, DOM capture, session replay, console capture, and free text.

A Global Privacy Control or Do Not Track signal forces optional product analytics, first-party marketing attribution, and experiment assignment off in the current design. Denying or withdrawing analytics permission does not block editing, output generation, checkout, account access, recovery, or support.

Aggregate public-site traffic or performance measurement may be provided through an approved Cloudflare configuration. We will update this Policy and the Cookie and Device-Storage Notice before introducing any materially different analytics, advertising, session-replay, or tracking technology.

4.7 First-party marketing attribution and experiments

The browser parses recognized campaign parameters and immediately removes them from the visible address bar and navigation history. While your analytics choice is undecided, the parsed closed values may be held only in the current page’s memory; EverPacket does not create persistent marketing identifiers or send those values to the server unless analytics is allowed, and denial discards the pending values.

When optional analytics is allowed and no GPC or DNT override applies, EverPacket may create random browser visitor and session UUIDs and send closed, same-origin marketing records. Those records may include a bounded page pathname without its query string; landing-page version; normalized source, medium, campaign, content, and paid-search-term values; an affiliate identifier when that channel is enabled; opaque tracking-link, campaign, creative, attribution, landing-page, experiment, and variant identifiers; coarse referrer, device, and browser categories; CTA category and placement; and a closed route, surface, slot, manifest, or experiment-exposure record.

The marketing schema is designed to reject account email, account ID, packet fields, packet or output contents, names, contact details, notes, search text, filenames, full URLs, raw referrer URLs, DOM capture, session replay, console or exception text, and other arbitrary or free-text properties. Browser-supplied marketing identifiers are treated as pointers and are resolved against server-controlled records before they are used for reporting.

First-party attribution ordinarily uses a 30-day window and may preserve first-touch and last-non-direct-touch context. A reviewed checkout may freeze the applicable attribution and in-window experiment context so later retries, refunds, disputes, and aggregate campaign reporting remain consistent. A signed text-slot experiment assignment may remain in an HttpOnly cookie for up to 30 days, but it must be revalidated against the active route, experiment, and variant before it can render. Raw first-party marketing attribution, exposure, checkout-context, and experiment records may be retained for up to 13 months so a configured experiment, conversion window, and refund or dispute guardrail can mature; the production configuration must not permit those combined horizons to exceed that period. Completed aggregate metrics and experiment-decision snapshots may be retained for up to 25 months, or longer only after verification that they are truly anonymous.

EverPacket may connect its own Meta and Google advertising accounts to import aggregate campaign or advertisement identifiers, spend, impressions, clicks, and provider-reported conversion totals. At initial launch, that reporting sync does not upload EverPacket account email, account identifiers, visitor identifiers, purchase identities, or packet information to Meta or Google. EverPacket does not place a Meta pixel, Google advertising tag, customer-list audience, or cross-site behavioral-advertising cookie on EverPacket-controlled pages at initial launch. We will update this Policy and the relevant controls before introducing a materially different advertising-data flow.

4.8 Country-interest counts and external social links

At initial launch, EverPacket does not operate a non-U.S. email availability list and does not collect a non-U.S. email address, name, account identifier, or contact preference merely because paid access is unavailable. An unsupported-country page may use a Cloudflare-provided approximate country signal to route or prefill the page and may allow a visitor to register interest in that country or region.

When the country-interest control is submitted, EverPacket records only the country code and a coarse aggregate time bucket needed to increment a country-level demand count. The application does not intentionally attach that count to an email address, account, cookie, marketing visitor or session identifier, packet, support case, or full IP address. At initial launch, this unsupported-country flow does not create optional marketing identifiers, assign experiments, or send optional product or marketing analytics. Ordinary infrastructure and short-lived abuse-prevention systems may still process request information as described in Section 4.5.

The page may provide ordinary outbound links to EverPacket social profiles. EverPacket does not embed social-media pixels, login widgets, feeds, or tracking SDKs in that unsupported-country flow at initial launch. Following a social profile occurs on the social platform under that platform’s notice. This feature does not reserve a price, create an account, authorize marketing email, or promise a launch date. Country-interest aggregates may be retained for up to 25 months and may be retained longer only after verification that they are truly anonymous. No availability confirmation, launch notice, or product-news email is sent through this feature.

4.9 Local browser and file information

The Service stores packet contents and operational data locally through IndexedDB, local storage, session storage, cookies, service-worker Cache Storage, and downloaded files as described in the Cookie and Device-Storage Notice.

Local browser storage may include packet records, revisions, output history, project backup history, preferences, free-use acceptance, analytics choice, anonymous installation identifier, optional marketing visitor and session identifiers, closed attribution context, a signed experiment assignment, feedback and layout preferences, offline entitlement receipt, and short-lived writer-lease information. Those items remain on the device unless a separate section of this Policy expressly says a value is sent to us. Denial or withdrawal of analytics stops future optional requests and removes or disables the local marketing visitor, session, context, permission-cookie, and assignment-cookie state.

Packet records and exported .EverPacket project files are not currently encrypted by EverPacket. Protect the device, browser profile, downloaded file, cloud-drive copy, removable media, and printed output accordingly.

5. Sources of personal information

We obtain personal information:

  • directly from you when you provide an email, create an account, accept documents, buy, contact support, or make a privacy request;

  • automatically from your device and browser when they communicate with the Service;

  • from the Payment Merchant and payment ecosystem for transaction administration;

  • from an identity provider you choose for sign-in;

  • from email-delivery, hosting, security, authentication, approximate-country, and aggregate advertising-report providers;

  • from an administrator acting on a verified case, such as a refund, account-recovery, transfer, or security operation; and

  • from public or government sources only where reasonably necessary for legal compliance, sanctions screening, fraud prevention, or dispute handling.

We do not buy packet-content profiles or append advertising-broker data to EverPacket accounts.

6. Why we use personal information and legal bases

PurposeTypical informationLegal basis where required
Provide free and paid product functionsDevice state, account, entitlement, requested local operationsPerformance of a contract; steps requested before contract; legitimate interests for basic service operation
Create and secure accountsEmail, identity provider, sessions, recovery, security eventsContract; legitimate interests in authentication and security; legal obligation where applicable
Review, process, activate, and reconcile purchasesEmail, offer, transaction references, amount, currency, status, legal versionsContract; legal obligations for records, tax cooperation, fraud, and consumer law; legitimate interests in reconciliation
Deliver receipts, codes, recovery, support, and legal messagesEmail, delivery status, and case dataContract; legal obligation; legitimate interests in communication and support
Administer refunds, disputes, and consumer remediesTransaction status, paid-output completion, case and risk recordsContract; legal obligation; legitimate interests in preventing fraud and resolving claims
Keep legal acceptance and consent evidenceDocument version, method, timestamp, account or anonymous IDLegal obligation; establishment, exercise, or defense of legal claims; legitimate interests in demonstrating compliance
Protect the Service and usersIP/network data, sessions, rate limits, audit and incident recordsLegitimate interests in security, fraud prevention, and service integrity; legal obligation
Respond to privacy requests and account deletionIdentity verification, request and response recordsLegal obligation; legitimate interests in preventing unauthorized disclosure or deletion
Optional product and first-party marketing analyticsRandom installation, visitor, and session IDs; allowlisted product, attribution, CTA, and experiment eventsConsent where required; otherwise legitimate interests only where local law permits and after honoring opt-out signals
Comply with law and enforce rightsRelevant account, transaction, security, support, and legal recordsLegal obligation; public interest where applicable; establishment, exercise, or defense of legal claims

Where we rely on legitimate interests, we consider the local-first design, data minimization, user expectations, sensitivity, opt-outs, security, and potential impact. You may object where applicable. Where we rely on consent, you may withdraw it without affecting processing already lawfully completed.

7. How we disclose personal information

We may disclose personal information to the following categories of recipients for the stated purpose:

Recipient categoryCurrent or expected providerPurpose and role
Merchant of record and payment servicesStripe, Sold through Link, LLC or the entity named at checkout, and payment partnersCheckout, payment, billing, tax, fraud, receipts, refunds, disputes, and transaction support; often an independent controller for its functions
Hosting, delivery, and securityCloudflareWebsite and application delivery, edge security, request handling, approximate-country market gating, connectivity, and approved aggregate public-site analytics
Authentication and application databaseSupabaseAccount authentication, sessions, account records, purchase administration, consent, support cases, permitted support attachments, first-party analytics and marketing records, unlinked country-interest aggregates, and server-side operational data.
Transactional emailResend and underlying delivery infrastructureAuthentication codes, purchase, recovery, support, security, and legal email; delivery status
Identity providers selected by the userGoogle, Meta/Facebook, MicrosoftSign-in and linked identity when the selected provider is enabled and chosen; independent processing under provider notices
Professional advisers and service providersLawyers, accountants, security specialists, insurers, and contractors subject to dutiesLegal compliance, tax, security, operations, claims, and professional advice
Authorities and counterpartiesCourts, regulators, law enforcement, tax authorities, banks, card networks, and dispute bodiesValid legal process, consumer complaints, payment disputes, fraud, sanctions, safety, and protection of rights
Successor organizationA buyer, investor, lender, or successor in a bona fide transactionDue diligence and transfer of the business, subject to confidentiality, notice, and applicable law

7.1 Advertising-platform reporting

Meta and Google may act as independent controllers for activity occurring on their own advertising, account, authorization, or dashboard services. EverPacket’s initial reporting integration reads aggregate advertising-account data for campaign measurement; it does not send EverPacket account, visitor, purchase, or packet data to those platforms. A person who interacts with an advertisement may separately be subject to the advertising platform’s own collection and notice before reaching EverPacket.

We require service providers acting on our behalf to process personal information only for authorized purposes and with appropriate confidentiality, security, retention, deletion, assistance, and transfer commitments. We do not receive local packet contents through ordinary product operation. A permitted support attachment that you intentionally submit under Section 4.4 is a limited exception and may be processed by Supabase and authorized EverPacket personnel or service providers solely for the purposes described in this Policy. The support-attachment exception does not authorize the submission of packet contents or other prohibited information.

8. No sale, behavioral advertising, or packet-content profiling

EverPacket does not sell personal information for money and does not share personal information for cross-context behavioral advertising. EverPacket’s optional product analytics, first-party attribution, and text-slot experiments operate on EverPacket-controlled systems after the applicable choice and are not used to build third-party advertising audiences. At initial launch, EverPacket does not upload account email, account identifiers, visitor identifiers, purchase identities, or packet information to Meta or Google; does not use a Meta pixel or Google advertising tag on EverPacket-controlled pages; and does not use packet content for advertising because ordinary product operation does not send packet content to us.

We do not use sensitive personal information to infer characteristics or to advertise. We do not use session replay, keystroke capture, clipboard capture, or packet-derived customer segmentation in the current product. EverPacket does not sell consumer health data, use packet health information for advertising or behavioral profiling, or implement health-care geofencing, as further described in the Consumer Health Data Privacy Notice.

If a future practice would constitute a sale, sharing, targeted advertising, or profiling under applicable law, we will update this Policy, provide required notices and controls, and honor recognized opt-out signals before the practice begins.

9. Cookies and similar technologies

EverPacket uses strictly necessary cookies and device storage for authentication, security, purchase setup, session preferences, local packet storage, offline operation, entitlement, concurrency, and legal acceptance. Optional product analytics, first-party attribution, and text-slot experiment storage and requests are controlled by one analytics choice and recognized privacy signals. Optional marketing storage includes random visitor and session IDs, closed attribution context, a server-readable allowed-state cookie, and a signed experiment-assignment cookie, as listed in the Cookie and Device-Storage Notice.

The Cookie and Device-Storage Notice identifies the current storage names, purposes, typical durations, and management options. The Payment Merchant and identity providers may set their own cookies when you use their hosted services.

Clearing cookies or local storage may sign you out, remove purchase-setup proof, reset preferences, disable offline entitlement, or delete the only local packet copy. Export a current project file before clearing browser data.

10. International processing and transfers

EverPacket is based in California, United States. Our providers may process account and operational information in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where you live.

If an approved market or applicable law requires a specific international-transfer mechanism, EverPacket will put the required mechanism in place before offering the covered Service in that market. Depending on the provider, destination, and law, that mechanism may include:

  • an adequacy decision;

  • the European Commission's Standard Contractual Clauses, with supplementary measures where appropriate;

  • the UK International Data Transfer Addendum or another UK-approved mechanism;

  • contractual clauses or comparable protection required by Canadian, Quebec, Brazilian, Swiss, New Zealand, Singaporean, South African, or other law; or

  • a limited statutory exception that is valid for the specific transfer.

EverPacket’s vendor-governance process records each active provider’s role, relevant processing locations, contract, and any required transfer mechanism or provider attestation. EverPacket will not launch in a market requiring a representative, registration, assessment, or transfer document until the required measure is documented and operational.

10.1 EEA representative

EverPacket Full and the account/application experience are not currently available for purchase or directed to people in the European Economic Area. Public information and legal pages may remain technically accessible, but the initial unsupported-country flow does not invite EEA residents to create an account, use the packet application, submit support content, join an EverPacket email waitlist, or participate in optional product or marketing analytics. It may route a request using an approximate country signal, accept an unlinked country-interest count, and provide ordinary outbound social links. EverPacket has not appointed an EEA representative for the initial U.S.-directed launch. Before intentionally targeting or regularly offering the covered Service in the EEA—or sooner if actual processing makes Article 27 applicable—EverPacket will complete the representative assessment, make any required appointment, and update this Policy.

10.2 United Kingdom representative

EverPacket Full and the account/application experience are not currently available for purchase or directed to people in the United Kingdom. Public information and legal pages may remain technically accessible, but the initial unsupported-country flow does not invite UK residents to create an account, use the packet application, submit support content, join an EverPacket email waitlist, or participate in optional product or marketing analytics. It may route a request using an approximate country signal, accept an unlinked country-interest count, and provide ordinary outbound social links. EverPacket has not appointed a UK representative for the initial U.S.-directed launch. Before intentionally targeting or regularly offering the covered Service in the UK—or sooner if actual processing makes the UK representative requirement applicable—EverPacket will complete the assessment, make any required appointment, and update this Policy.

10.3 Other local contacts

A Brazilian data-protection contact, Canadian/Quebec privacy officer, South African Information Officer, Swiss representative, or other local contact will be identified in the market-specific notice where required. A market remains unavailable until a mandatory appointment, registration, impact assessment, or notice is completed.

11. Retention

We retain personal information only for as long as reasonably necessary for the purposes described, including to provide the Service, maintain transaction integrity, comply with law, resolve disputes, prevent fraud, enforce agreements, and protect security.

The following retention schedule applies to the records described below. Raw first-party marketing attribution, exposure, checkout-context, and experiment records are retained for up to 13 months, while raw optional product analytics remain subject to the 90-day table period. A production experiment’s configured duration, conversion window, and refund or dispute guardrail follow-up must fit within the 13-month raw-marketing period. Country-interest aggregates contain no email address or EverPacket account identifier and are retained for up to 25 months, or longer only after an explicit verification that they are truly anonymous. Provider-held records may follow a provider’s own legally required period; EverPacket records deletion or retention attestations where a provider does not expose direct deletion control.

RecordPlanned retention after the relevant eventNotes
Active account profile and linked-identity metadataFor the life of the account; deletion or de-linking generally within 30 days after a valid deletion requestProvider and legally retained records may remain independently
Authentication sessionsUntil expiration, revocation, or account deletionRemember preference must not extend a compromised session beyond provider controls
Routine authentication and security logs12 monthsShorter where feasible; longer only for an incident, abuse pattern, or legal hold
Purchase, entitlement, payment, tax, refund, and dispute records7 years after the end of the transaction or longer where a specific law or open dispute requiresMay be de-linked from a deleted account; Payment Merchant retains its own records
Legal-acceptance and withdrawal-consent records7 years after the related transaction or account closureExact version and method preserved for legal proof
Browser analytics-consent records5 years after replacement or withdrawalAnonymous browser ID may remain until the retention job removes it
Raw optional product analytics records90 daysContent-blind; deletion or irreversible aggregation after the period
Aggregated product and marketing metricsUp to 25 months, or longer only if truly anonymizedMust not permit user or packet reconstruction
Support cases3 years after closure7 years for refund, dispute, fraud, legal, or financial cases
Transactional email-delivery records12 monthsMessage content retained only as needed for the underlying record
Privacy requests and responses5 years after closureTo demonstrate compliance and prevent unauthorized repeat action
Incident and breach recordsAt least 5 years after closureLonger if law, litigation, insurance, or regulator direction requires
Administrative audit and risk-hold records7 yearsAccess restricted; user identifiers de-linked where feasible and lawful
Unfinished purchase intents and checkout attempts90 days after expiration, unless needed for fraud, support, or reconciliationMinimize email and provider references after expiration
Permitted support-attachment file90 days after the associated support case is closed, unless the attachment is deleted earlier because it is prohibited, unnecessary, or no longer needed.An attachment may be retained longer only while a documented legal hold, security incident, payment dispute, fraud investigation, legal claim, or other legal obligation requires preservation.

The support-attachment file follows the separate period above even when the support case’s messages, metadata, transaction records, or legal records are retained for a longer period.

A legal hold affecting a support attachment must identify the reason and scope of the hold, the responsible person, the date the hold began, the review schedule, and the date the hold is released. After release, the attachment returns to its ordinary deletion schedule and is deleted promptly if that period has already expired.

Packet contents ordinarily have no EverPacket server-retention period because the normal product is not designed to collect them. A permitted support attachment is the limited exception and follows the separate attachment-retention schedule above.

12. Account deletion and local data

A verified account-deletion request deletes the authentication account and active profile as implemented, signs out sessions, and de-links retained immutable records where feasible. Transaction, legal-acceptance, consent, fraud, audit, refund, dispute, tax, and security evidence may remain without the active account identifier for the periods above.

Deleting an EverPacket account does not:

  • delete packet contents in browser IndexedDB;

  • delete downloaded .EverPacket files, PDFs, contact cards, QR images, or printouts;

  • delete information held independently by the Payment Merchant, identity provider, email provider, browser, operating system, cloud drive, or recipient; or

  • necessarily cancel or refund a completed purchase.

Delete local packets and files separately. Export any copy you need before deleting the browser profile or device data.

13. Your privacy rights

Depending on where you live and whether a particular law applies to EverPacket, you may have rights to:

  • know whether we process your personal information and obtain access or a copy;

  • obtain information about categories, purposes, sources, recipients, and retention;

  • correct inaccurate personal information;

  • delete personal information, subject to legal exceptions;

  • restrict or object to processing;

  • withdraw consent;

  • obtain portable account information in a commonly used format;

  • opt out of sale, sharing, targeted advertising, or qualifying profiling;

  • appeal a refusal where local law provides an appeal;

  • receive equal service and price without unlawful discrimination for exercising a right;

  • lodge a complaint with a data-protection, privacy, or consumer authority; and

  • give instructions concerning information after death where local law recognizes that right.

An account export currently includes account, profile, purchase, linked-identity, session-summary, legal-acceptance, consent, and attachment-history information. It expressly does not include local packets.

13.1 How to make a request

Send a request to privacy@everpacket.com or use available account controls. Include the right you wish to exercise and the email associated with the account or purchase. Do not send a password, complete payment credential, or unnecessary identification document.

We will verify the request proportionately. Recent authentication may be required for account export or deletion. For an agent request, we may require proof of authority and direct confirmation where allowed. We will respond within the deadline required by applicable law and explain any lawful denial, extension, or appeal route.

13.2 California and other U.S. state rights

EverPacket provides the disclosures in this Policy to comply with the California Online Privacy Protection Act and, to the extent applicable, the California Consumer Privacy Act as amended by the CPRA and other U.S. state privacy laws. EverPacket does not currently sell or share personal information for cross-context behavioral advertising.

We honor Global Privacy Control as an overriding instruction to disable optional product analytics, first-party marketing attribution, and experiment assignment in the current implementation. Because EverPacket may be below statutory coverage thresholds, a particular state-law right may not legally apply; we will nevertheless make reasonable efforts to honor access, correction, deletion, consent-withdrawal, communication opt-out, and other privacy requests unless doing so would impair security, legal obligations, another person’s rights, or transaction integrity.

The Consumer Health Data Privacy Notice describes additional access, deletion, consent-withdrawal, appeal, and related rights for health-related information where applicable. Because ordinary packet content remains under the user’s local control and is not available to EverPacket, local deletion is performed through packet, site-data, and file controls; EverPacket cannot access or delete a local packet from its servers.

13.3 EEA, UK, and Switzerland

You may have the rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint under the GDPR, UK GDPR, or Swiss Federal Act on Data Protection. You may object to processing based on legitimate interests. You may complain to the supervisory authority where you live, work, or believe a violation occurred.

No solely automated decision is intended to produce a legal or similarly significant effect without a review route. Fraud, duplicate-purchase, risk-hold, or entitlement rules may temporarily restrict an online transaction; contact support for human review.

13.4 Canada and Quebec

You may request access and correction and challenge compliance through the designated privacy contact. We remain accountable for information transferred to service providers. Quebec residents may have additional rights concerning information, consent, de-indexation, portability when in force and applicable, and automated decisions. The required French privacy notice and local assessment must be available before the Service is offered to Quebec residents.

13.5 Brazil

Brazilian users may exercise rights under the LGPD, including confirmation, access, correction, anonymization, blocking or deletion of unnecessary or unlawfully processed data, portability subject to regulation, information about sharing, withdrawal of consent, review of certain automated decisions, and complaint to the ANPD. The Brazilian-language notice, data-protection channel, transfer documentation, and consumer disclosures must be active before launch in Brazil.

13.6 Australia and New Zealand

Where the Australian Privacy Act or New Zealand Privacy Act applies, you may request access and correction and complain to the relevant privacy authority after giving us an opportunity to respond. Mandatory consumer guarantees and privacy rights are not limited by this Policy.

13.7 Other regions

The Global Consumer Rights Addendum and market-specific privacy notices describe additional rights for India, Japan, South Korea, Taiwan, Singapore, Hong Kong, South Africa, Mexico, and other approved markets. A technically available payment method does not mean a market has been approved.

14. California notice at collection

At or before collection, California residents may use this table as a summary of the categories EverPacket may collect and the purposes for which they are used. The more detailed sections above control.

California categoryExamples in EverPacketBusiness or commercial purposesTypical disclosures
IdentifiersEmail, account or provider ID, anonymous installation or marketing visitor/session ID, IP address, tracking identifiers, transaction referencesAccount, purchase, security, support, analytics consent, and first-party attribution and experimentsHosting, authentication, payment, email, professional advisers
Customer recordsContact and transaction-administration informationContract, receipt, support, consent, and legal recordsPayment Merchant, database, email, advisers
Commercial informationProduct, price, currency, purchase, activation, refund, dispute, promotionFulfill and administer purchase; fraud; accountingPayment Merchant, hosting/database, advisers, authorities
Internet or electronic activityRequest and security logs, bounded landing path, browser or device category, allowlisted product and marketing events, CTA and experiment exposure, consent choiceDeliver and secure the Service, troubleshoot, measure first-party campaigns and experiments, and provide optional analyticsHosting/security, database, approved analytics
GeolocationApproximate region or country inferred or supplied for security, tax, or market gatingLegal availability, fraud, localization, transactionPayment Merchant, hosting/security
Professional or employment informationOnly if voluntarily included in a support messageResolve requestSupport providers and advisers
Sensitive personal informationNot intentionally collected through ordinary product operation or authorized support attachments. Submission through a support attachment is prohibited. If sensitive personal information is received inadvertently, it is processed only as necessary for containment, deletion, security, legal compliance, or the establishment, exercise, or defense of legal claims.Resolve the specific request, security, legal complianceRestricted providers or advisers only as necessary
InferencesLimited fraud or risk signals; no packet-content profilingSecurity, fraud prevention, transaction integrityPayment and security providers

Retention follows Section 11. We do not use sensitive personal information to infer characteristics. We do not offer a financial incentive for personal information.

15. Security

We use administrative, technical, and organizational safeguards appropriate to the information we receive, including separation of customer and administrative systems, access controls, least-privilege roles, authentication, recent-authentication checks for sensitive account actions, rate limits, signed provider webhooks, content-blind event schemas, audit records, and transport security.

No system is completely secure. Email, browsers, devices, downloaded files, and third-party services have their own risks. The local-first design reduces server collection of packet contents but places responsibility for device and file security on the user.

EverPacket does not currently encrypt local packet records or exported .EverPacket project files. Use operating-system disk encryption, strong device authentication, a locked browser profile, careful backups, and protected sharing. Do not treat EverPacket as a vault.

Report a suspected account or service security issue to security@everpacket.com or support@everpacket.com. Do not email packet contents or exploit data.

16. Data incidents

We maintain an incident-response process for personal information we control. If an incident creates a notification duty, we will notify affected people and authorities in the manner and time required by applicable law. Notification timing differs by jurisdiction; our internal process uses the shortest applicable deadline and preserves a documented incident record.

A loss of a user's device or unencrypted project file that never reached EverPacket may not be a breach of EverPacket's server systems, but it can still create serious risk. Use device or file protections and notify affected people or authorities where you are responsible for the information.

17. Children

The Service is not directed to children under 13. Accounts and purchases require the age of legal majority. We do not knowingly collect an account from a child in a manner subject to the U.S. Children's Online Privacy Protection Act without required parental authorization. Contact us if you believe a child supplied account information improperly.

Information about dependents or other household members remains local unless the adult user chooses to disclose it through a generated output or another service. Do not include dependent, household, medical, contact, or other personal information in a support attachment.

18. Automated rules and fraud prevention

The Service uses rules to validate legal-document versions, check country and purchase eligibility, prevent duplicate checkout, verify provider events, authorize entitlements, apply risk holds, assign or revalidate consented text-slot experiments, and assess the voluntary refund criteria. These rules use closed transaction, consent, marketing, and security data—not packet contents—and do not make a solely automated legal or similarly significant decision without an available review route where one is required.

A rule may pause or deny an online action when data is stale, inconsistent, duplicated, disputed, refunded, unverified, or risky. Contact support for review. Where law grants a right to human intervention, explanation, or contest, we will provide it.

19. Changes to this Policy

We may update this Policy prospectively and will post the current version and effective date. For minor, administrative, clarifying, formatting, or other non-material changes that do not materially expand the categories of personal information we collect, the purposes for which we use it, or the parties with whom we disclose it, posting the updated Policy is ordinarily sufficient and we do not ordinarily send an individual email or in-product notice. Material changes will receive additional notice or consent where required. The version accepted or acknowledged for a transaction will remain available in the legal archive.

A cached offline copy may be older than the live Policy. The live version presented in a purchase or account flow controls. We will not materially expand packet-content collection without a new privacy and product review, prominent notice, and any required consent.

20. Complaints and supervisory authorities

Please contact privacy@everpacket.com first so we can investigate. You may also complain to the privacy or data-protection authority with jurisdiction over you, including the California Privacy Protection Agency or California Attorney General where applicable, an EEA supervisory authority, the UK Information Commissioner's Office, the Office of the Privacy Commissioner of Canada or a provincial authority, Quebec's Commission d'acces a l'information, Brazil's ANPD, the Office of the Australian Information Commissioner, New Zealand's Privacy Commissioner, Singapore's PDPC, Hong Kong's PCPD, South Africa's Information Regulator, Switzerland's FDPIC, or another competent authority.

21. Contact and required regional representatives

Controller / business Kimi Chen, a California sole proprietor doing business as EverPacket 8843 Villa La Jolla Drive Apt 2, La Jolla, CA, 92037 San Diego, California, USA Privacy: privacy@everpacket.com Support: support@everpacket.com

EEA representative No representative is currently appointed for the initial U.S.-directed launch. See Section 10.1.

UK representative No representative is currently appointed for the initial U.S.-directed launch. See Section 10.2.

Other market-specific privacy contacts See the localized notice for each approved market.

EverPacket

Kimi Chen, a California sole proprietor doing business as EverPacket

Support

support@everpacket.com

Terms Privacy Refunds