This Privacy Policy explains how Everpop ("Everpop", "we", "us", or "our") collects, uses, shares, and protects information about you when you use our website and services (the "Service"), and the rights you have. It is a notice, not a contract: where we rely on your consent we ask for it separately, and you can withdraw it at any time.
Everpop is operated by Very - Fast Ltd. (Вери - Фаст ЕООД), an EOOD (single-member limited liability company) registered in Bulgaria under EIK 206337186, with registered seat at 29 Georgi Benkovski Str., 3000 Vratsa, Bulgaria (ул. Георги Бенковски №29, 3000 Враца). You can contact us at privacy@everpop.app for any data protection matter, or at support@everpop.app for general support. We have not designated a Data Protection Officer; the privacy contact above handles every request. Our supervisory authority is the Commission for Personal Data Protection of the Republic of Bulgaria (kzld@cpdp.bg, cpdp.bg).
1. Information We Collect
We collect the following categories of information:
- Account information: name, email address, and password (stored hashed) when you register. Providing them is necessary to open an account; without them we cannot provide the Service.
- Connected platform data: when you connect a YouTube channel or social account, we receive identifiers, channel/video metadata, and authorization tokens needed to provide the Service. Tokens are encrypted at rest. Section 5 lists exactly what we store for YouTube, Section 6 for Meta, and Section 7 for TikTok. If you connect an optional Google Drive folder, we also receive the names, sizes, and IDs of video files in that one folder (see Section 5a).
- Content: videos, clips, captions, transcripts, and related metadata processed to deliver clipping and publishing features. Transcripts are produced by speech-to-text from the video file you provide.
- Prompts & generated content: text prompts you submit in the Create studio, and the scripts, voiceovers, and videos generated from them, where that feature is available to you.
- Clip ratings & notes: the thumbs-up/down and written comments you leave on your own clips. These are shown back to you and included in internal product-quality reviews; they are not used to train ranking models.
- Clip performance data: aggregate per-clip and per-channel metrics retrieved from platform analytics APIs you authorize (see Section 5). Never viewer-level data.
- Billing information: processed by our payment provider (Stripe). We do not store full card numbers.
- Consent and preference records: when and under which version you accepted the Terms and this Policy, your optional-email choices, and your cookie choices.
- Usage data: log data, device/browser information, IP address, and — only if you enable it — product analytics about how you interact with the Service.
- Communications: messages you send to support, and the email address of a person a workspace owner invites (Section 4).
2. How We Use Information
- To provide, operate, maintain, and improve the Service;
- To detect new uploads, generate clips, and publish content to platforms you authorize;
- To screen clips and prompts for prohibited content before publishing, with a person reviewing anything the automated screen flags;
- To process payments, manage subscriptions, and prevent fraud;
- To communicate with you about your account, security, billing, and changes to the Service or these documents;
- With your consent, to send optional receipt, weekly-digest, and tips emails — unsubscribe via the link in every such email or in Settings;
- To monitor, secure, alert our team about, and troubleshoot the Service;
- To comply with legal obligations and enforce our Terms.
3. Legal Bases for Processing (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the following bases. As the controller is established in Bulgaria, our lead supervisory authority is the Bulgarian Commission for Personal Data Protection (cpdp.bg).
| Purpose | Legal basis |
|---|---|
| Providing the Service you signed up for: detecting your uploads, generating clips, publishing to the destinations you connect, receipts, workspaces, support | Performance of a contract — Art. 6(1)(b) |
| Billing, invoicing, and tax and accounting records | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Security, fraud and abuse prevention, rate limiting, enforcing promotional limits, keeping audit logs | Legitimate interest — Art. 6(1)(f): running a secure service that is not abused |
| Automated content-safety screening of clips and prompts before publishing, with human review of anything flagged | Legitimate interest — Art. 6(1)(f): keeping unlawful and harmful content off the platforms we publish to; legal obligation where the law requires it |
| Operational alerts to our team when a render, publish, or billing step fails | Legitimate interest — Art. 6(1)(f): operating and repairing the Service |
| Aggregate, server-side service measurement (how many sign-ups, renders, publishes succeed) | Legitimate interest — Art. 6(1)(f): measuring and improving the Service |
| Optional receipt, weekly-digest, and tips emails | Consent — Art. 6(1)(a); withdraw via the link in every such email or in Settings |
| Non-essential cookies and browser storage (support chat, product analytics, marketing attribution) | Consent — Art. 6(1)(a), asked for separately in the cookie banner |
| Responding to legal requests and defending claims | Legal obligation — Art. 6(1)(c); legitimate interest — Art. 6(1)(f) |
Automated processing. We use automated content-safety screening. A clip the screen flags is held for review by a person before any enforcement; we do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. The clip-selection model scores the content features of your own clips against your own results; it does not profile you or your viewers.
People who appear in our customers' videos. If you appear in a video that an Everpop customer processes, the customer is responsible for informing you. We process that content on the customer's instructions to make and publish clips, and for the security and content-safety purposes above. You can exercise your rights by writing to privacy@everpop.app.
4. How We Share Information
We do not sell your personal information. We share information with service providers ("subprocessors") that help us run the Service, under contractual confidentiality and data-protection obligations (Section 8). Inside a workspace, the owner and the members the owner invites can see the workspace's videos, clips, receipts, and an activity log naming who did what; an invitation stores the invited email address until it is accepted, revoked, or expires. We may also disclose information to comply with law, enforce our Terms, or protect our rights, users, or the public.
5. YouTube / Google API Services
When you connect your YouTube channel, Google initially provides us with access limited to: openid (the Google account identifier that ties the grant to your Everpop account), youtube.readonly (to detect new uploads on the channel you authenticate), and yt-analytics.readonly (to retrieve aggregate performance metrics for your own channel and for the Shorts we publish on it). We request youtube.upload only when you explicitly choose to publish your first clip to that channel. Granting that permission does not publish anything; you still review and confirm the clip.
What we store. Your channel_id, channel title, channel URL and thumbnail, the list of permissions you granted, the Google account identifier, OAuth tokens (encrypted at rest), recent video metadata (titles, descriptions, publish dates, video_ids, thumbnails) used to offer you each new upload for clipping, and the video_ids of Shorts we publish. Where a new upload has a caption track, we read it through the YouTube Captions API to propose clip moments; we do not keep the caption text. We never download your videos from YouTube: clips are made from the file you add or the Drive folder you share.
Receipts & performance measurement. Using the analytics scope, we retrieve a fixed, limited set of aggregate metrics per published clip and per channel: views, estimated minutes watched, average view duration, average view percentage, subscribers gained, likes, shares, and comments — and, for a video you are clipping, its aggregate audience-retention curve, so that the clip picker can favour the moments viewers stayed for. These are channel-level aggregates only — we never receive or store any information about individual viewers. We use these metrics to (a) show you your clips' real performance ("receipts"), and (b) improve clip selection for your own account: the model is trained solely on the clip features and aggregate results of the channels connected to your account, and data never crosses accounts. You can exclude any published clip from future model fitting at any time (Receipts → "Learning off"). Its measured outcome remains in your receipt and account history until you delete it or your account, but Everpop does not use that excluded outcome in later fits. Disconnecting your channel stops new collection.
After a disconnect or revocation. When you disconnect a channel in Everpop you choose whether to keep its receipts: "Disconnect" keeps them, and "Disconnect & delete YouTube data" removes that channel's receipts, its catalog of detected videos and its analytics baseline at once (your uploaded files, clips and posts stay). If you revoke Everpop's access in your Google account instead and do not reconnect, we email you about 23 days later with a one-click choice to keep your receipts; without that choice, we delete the same YouTube data 30 days after we detected the revocation. If you ask us to delete YouTube data we hold about you or your channel, we do so within 7 days. Everpop-computed figures shown next to YouTube numbers — the prediction, the percentile, and similar scores — are our own product metrics, not YouTube metrics.
Public receipt pages. If — and only if — you generate and share a receipt link, campaign proof link, or bundle link, the aggregate metrics above for the clips it covers (together with their titles and public URLs, and any payout figure you typed in) become viewable by anyone holding the link. You control whether such links are created and where they are shared; they contain no account, email, or viewer information.
Limited Use. Everpop's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data; we do not use Google user data for serving advertisements (including retargeting, personalized, or interest-based advertising); we do not use Google user data to train generalized machine-learning models; and we do not allow humans to read Google user data unless we have your explicit consent for specific data, or it is necessary for security purposes or to comply with applicable law.
The Service uses YouTube API Services to provide its YouTube features. Your use of the Service's YouTube features is also subject to the YouTube Terms of Service and Google Privacy Policy. You can revoke our access at any time at myaccount.google.com/permissions (also reachable at security.google.com/settings/security/permissions).
5a. Google Drive Ingestion (Optional)
If you connect a Google Drive folder, you share that one folder with our service account (read-only). We access only files in that folder: we read file names, sizes, and IDs, and copy new video files into our storage (Cloudflare R2) to generate clips. We never see the rest of your Drive. Disconnecting the folder in Settings (or un-sharing it in Drive) stops all access immediately; videos already imported stay in your library until you delete them. Our use and transfer to any other app of information received from Google APIs — including Drive — will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Meta Platform Data (Facebook + Instagram)
When you connect your Facebook account and/or Instagram Business or Creator account, Meta Platforms, Inc. (or Meta Platforms Ireland Limited for users in the EEA and the UK) provides us with limited information necessary to operate the connection: your Facebook user ID and name; the IDs and names of Facebook Pages you administer; your Instagram user_id and username; and OAuth access tokens (a long-lived user token and long-lived Page access tokens) used to publish content on your behalf when you explicitly initiate a publish action. We request the business_management permission only to list Pages held in your Business Portfolio.
We use this data exclusively to (a) display the connected account in your dashboard, (b) publish the specific clips you select to your chosen destinations, and (c) honor your request to disconnect. We do not use this data for advertising, profiling, machine-learning training, or any purpose other than the publishing function you opt into.
Stored fields: Facebook user_id; Page IDs and names you select; Instagram user_id and username; the permissions you granted; OAuth tokens (encrypted at rest — we keep your long-lived user token so that we can revoke our own access when you disconnect); video_ids of clips we publish. Disconnect: removes publishing authority and scrubs cached credentials and active account identifiers, normally within minutes. If the connection has publishing history, a non-sensitive disconnected record, provider post IDs, and per-clip history remain so your receipts continue to work. A verified platform data-deletion request removes the matching Meta connection data and associated local publishing history. You can request that deletion at privacy@everpop.app. You can also revoke our access directly at facebook.com/settings → Business Integrations.
We support Meta's Data Deletion Callback. Our callback endpoint is hosted at https://everpop.app/api/meta/data-deletion, and our user-facing deletion instructions are at everpop.app/data-deletion.
7. TikTok Data
When you connect your TikTok account, TikTok provides us with your open_id, display name, avatar URL, and OAuth access + refresh tokens, used solely to deliver the clips you choose — or, if you enable Autopilot for TikTok, the clips it picks — to your TikTok account.
How delivery works today. Clips are sent to TikTok as drafts in your TikTok inbox. You open the draft in the TikTok app, where TikTok itself asks you for the privacy level, interaction settings, commercial-content disclosure, and the AI-generated-content label, and you decide whether to post. TikTok's API does not accept the AI-generated label for inbox drafts, so for an AI-assisted clip you must switch on "AI-generated content" in the TikTok app before posting. Where Everpop posts directly to TikTok, the publish dialog collects those settings before the post is sent, and Everpop sets TikTok's AI-generated-content flag automatically.
We do not read your TikTok feed, your followers, your comments, or any content other than what you produce through Everpop. We do not perform any growth automation, fake engagement, or bulk-posting from one account to many accounts. Each connection is single-creator, opt-in, and revocable at any time from Publishing → Destinations & channels. We honor TikTok's content removal: if a post is deleted on TikTok's side, we do not re-publish it.
Stored fields: open_id, display name, avatar URL, OAuth tokens (encrypted at rest), the id of each delivered clip, and — for direct posts — the privacy and interaction settings you chose per clip. Disconnect: removes publishing authority, OAuth tokens, and active account identifiers. If posts exist, we retain a scrubbed destination record and per-clip publishing history so receipts remain available. To request deletion of the locally retained connection history, write to privacy@everpop.app.
8. Subprocessors
We use the following service providers and subprocessors to operate Everpop. Optional providers receive data only when their integration is configured or you use the relevant feature. Where data-protection law requires it, the applicable contractual and international-transfer safeguards govern the processing; business customers can request the current details and DPA.
- Vercel Inc. (USA) — application hosting, AI model gateway, and cookieless Web Analytics when enabled for the production project (pageview and request metadata)
- Product analytics and error monitoring — none currently. Browser funnel events you enable are received by Everpop's own endpoint and are not forwarded to any analytics vendor; application errors are written to our own logs. If we add a vendor for either purpose we will list it here first.
- Neon, Inc. (USA) — database hosting, including encrypted point-in-time backups
- Upstash, Inc. (USA) — rate limiting and QStash job-queue infrastructure; depending on the operation, may process IP addresses, email addresses, internal user/source/clip/post/destination/Drive-file identifiers, and queued publishing metadata such as reviewed title, description, and visibility
- Cloudflare, Inc. (USA/EU) — CDN and R2 object storage for source videos, generated media, fonts, and related request metadata; Zero Trust Tunnel proxying of render-engine requests, which may carry source-media URLs, prompts, render settings, internal job identifiers, callback URLs, and ordinary request metadata; and, when Turnstile is configured, anti-bot verification using a challenge token plus IP and browser/device request data
- Hetzner Online GmbH (Germany, EU) — infrastructure hosting for an Everpop render-engine node and fallback capacity. When a render is routed to that node, it may process source video and extracted audio, transcripts, creator prompts, clip timing/title directives, caption and brand settings, referenced hook audio or custom fonts, generated clips and thumbnails, plan tier, and internal job identifiers
- Everpop-operated render machines (Bulgaria, EU) — most renders run on machines we operate ourselves rather than on a cloud host; they process the same render inputs as the Hetzner node above and are not a third party
- Configured external uptime/cron monitoring service — optional dead-man's-switch monitoring used only when an external heartbeat endpoint is configured; receives the cron identifier in the ping URL, ping time, and ordinary connection/request metadata such as the service IP. The application does not include Everpop account identifiers, creator media, transcripts, or prompts in this heartbeat ping
- Stripe, Inc. (USA / Ireland) — payment processing; card data is sent directly to Stripe, while Everpop stores customer/subscription identifiers and subscription, billing-period, payment-state, dispute, and transactional metadata
- AI service providers — currently Anthropic, PBC; Groq, Inc.; OpenAI, Inc.; AssemblyAI, Inc.; xAI; Google LLC; Fireworks AI, Inc.; and Together Computer, Inc. (primarily USA) — audio transcription, moment selection, script and metadata writing, text-to-speech, content-safety screening, and visual analysis. Depending on the feature and configured route, the inputs can include prompts, source audio, video transcripts, titles/descriptions, clip opening hooks, thumbnail images, and candidate clip video. Provider routing varies by feature; we send the inputs needed for that requested operation.
- Pexels (USA) — stock b-roll search; receives visual search keywords derived from generated scripts or words in source speech/transcripts. Queries can therefore contain contextual words or names, but this integration does not send your Everpop account identifier or source-media file
- Resend, Inc. (USA) — transactional and opted-in engagement email delivery; receives recipient email address and message content
- ImprovMX (email forwarding) and Google LLC (mailbox hosting) — receive the messages, sender addresses, and attachments you send to our support@, privacy@, security@, and copyright@ mailboxes, and our replies
- Crisp IM SAS (France, EU) — support chat messages and browser/session metadata; its widget loads only when you separately enable support chat
- Discord Inc. (USA) — optional operational alerts; when a webhook is configured, may receive service-failure details, internal user/subscription/platform/post identifiers, creator-provided video or clip titles, and moderation reasoning. Control characters and message markup are sanitized before sending; these alerts are limited to operational response
- Outstand — retired historical publishing integration. New connections and publishing are disabled. A temporary legacy-drain configuration may receive signed status callbacks and query historical provider post identifiers only until old records are settled.
We update this list when service-provider use changes. Any advance-notice and objection rights in a signed DPA continue to govern; otherwise, we provide notice of material changes as required by applicable law. Business customers and compliance teams can request current provider, transfer-mechanism, and retention details at privacy@everpop.app. See also our dedicated Subprocessors page and DPA summary.
9. Data Retention
We keep personal data only as long as necessary for the purposes described in this Policy, then delete or anonymize it. The periods below are indicative and may be extended where a longer period is required by law or to resolve a dispute or enforce our agreements:
- Account & profile data: kept for the life of your account and deleted promptly when you delete your account — normally immediately and no later than 30 days. The limited records expressly described below, storage-deletion records, and portions of records belonging to other users are handled separately; our Data deletion page lists exactly what remains.
- Connected-platform tokens & identifiers: kept until you disconnect or delete your account; removed normally within 24 hours and no later than 30 days of a disconnect or platform deletion request (in practice within minutes for an in-app disconnect). A request we cannot complete automatically is reviewed by a person within that window.
- Content (source videos, clips, posts, transcripts, prompts, generated content) & receipts: for the life of your account, and deleted with it. Shorts published to your own channel remain there unless you remove them. YouTube data we hold is deleted within 7 days of your request (Section 5).
- Aggregate clip/channel analytics (receipts & learning): for the life of your account. Turning learning off excludes that outcome from future model fits; it does not delete the receipt or its stored metrics.
- Clip ratings & notes: for the life of your account, deleted with it.
- Billing & tax records: retained after account deletion only where an applicable law requires the specific record, for the period set by that law (accounting and tax rules can reach 10 years). Those records are access-restricted and are not used for marketing or for promotion eligibility. Stripe holds payment-instrument and invoice data under its own retention obligations. Everpop does not store full card numbers; while your account exists we store Stripe customer/subscription identifiers and subscription, plan, price, billing-period, dunning, dispute, guarantee, and delivery/audit metadata needed to operate billing and reconstruct transactions.
- Payment-dispute evidence: records of checkout attempts, subscription changes, and disputes from the 120 days before you delete your account are kept, pseudonymised (no longer linked to your account), for up to 120 days after deletion so that we can respond to a card-network chargeback. Basis: our legitimate interest in defending payment disputes.
- Legal-claim records: records necessary for an actual, threatened, or reasonably anticipated legal claim are access-restricted until the hold ends, and are deleted once the matter closes and any related legally required period has run.
- Audit & security logs, server logs, and IP addresses in them: kept for fraud-prevention and security no longer than necessary for those purposes (up to 12 months), then deleted. They are deleted with your account, apart from the narrow case where an applicable law requires the specific record or it falls under a legal-claim hold as described above. Aggregate web-analytics reporting is held by Vercel under its own retention and contains no account identifier.
- Promotion & trial eligibility checks: before granting the free first video or a free trial, we compare your account against other accounts that still exist — email aliases (including Gmail dot and plus variants) and any YouTube channel you have connected. These checks read only data belonging to accounts that still exist. We do not keep an email-derived eligibility record after your account is deleted, and deleting your account removes the data these checks would otherwise have matched against. Basis: our legitimate interest in enforcing promotional limits.
- Support communications: handled through our support processors (the Crisp chat widget, our mailboxes, and our email provider) and retained, per their settings and our policy, for up to 24 months after your last interaction.
- Workspace invitations: the invited email address is kept until the invitation is accepted, revoked, or expires.
- Data-deletion request records: retained as needed to evidence our compliance; the link between such a request and your former account is removed when the deletion completes.
- Backups: encrypted database backups and pre-release snapshots can contain deleted records until they are rotated. Backups are never used to restore an individual account.
You may request deletion of your account and associated personal data at any time — see our Data deletion page.
10. Security
We implement technical and organizational measures designed to protect your information, including encryption of sensitive tokens, access controls, and signed webhooks. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach notification. In the event of a personal-data breach, we will notify the competent supervisory authority (in Bulgaria, the Commission for Personal Data Protection) without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will also notify you without undue delay, as required by GDPR Article 34.
11. Your Rights
Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data. You may object at any time to processing based on our legitimate interests, and to direct marketing, and you may withdraw any consent you have given at any time without affecting the lawfulness of processing before the withdrawal. To exercise these rights, contact us at privacy@everpop.app; you can export your data and delete your account yourself from Settings. You may also revoke connected-platform access at any time from your account or the relevant platform's settings. You have the right to lodge a complaint with your local supervisory authority; in Bulgaria this is the Commission for Personal Data Protection (cpdp.bg), and if you are in the UK you may complain to the Information Commissioner's Office (ico.org.uk).
12. California Privacy Rights (CCPA/CPRA)
To the extent the CCPA/CPRA applies to Everpop, California residents have the rights to know what personal information we collect, to delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising those rights. Submit requests to privacy@everpop.app. We do not sell or share personal information as defined by the CCPA/CPRA.
13. Cookies & Tracking
We use cookies and similar technologies for authentication, consent preferences, optional product analytics, marketing attribution, and support chat. Strictly necessary storage is always on. Each optional purpose is off by default and has its own control. Product analytics, the short-lived attribution cookie, and Crisp load or run only when you enable the matching purpose, and that purpose's accessible browser state is cleared when you withdraw it. You can change any selection at any time without affecting the others. For full details — categories, providers, and durations — see our Cookie Policy.
14. International Transfers
Your information may be processed in countries other than your own, including the United States. For recipients outside the EEA and the UK we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) together with the UK International Data Transfer Addendum, or on the EU-US Data Privacy Framework (and its UK Extension) where the recipient is certified under it, or on an adequacy decision where one applies. You can obtain a copy of the safeguards that apply to a particular recipient by writing to privacy@everpop.app.
15. Children
The Service is intended for adults: it is not directed to anyone under 18, and we do not knowingly collect personal data from individuals under 18. If you believe someone under 18 has provided us data, contact us and we will delete it.
16. Changes to This Policy
We may update this Policy from time to time. If we make material changes we will notify you in advance by email or in-app notice, and, where a change relies on your consent, we will ask for it again. Every version is identified by the "Last updated" date on this page.
17. Contact
Questions about this Policy? Contact us at privacy@everpop.app. Mailing address: Very - Fast Ltd., 29 Georgi Benkovski Str., 3000 Vratsa, Bulgaria.