This Privacy Policy explains how Everpop ("Everpop", "we", "us", or "our") collects, uses, shares, and protects information about you when you use our website and services (the "Service"). By using the Service, you agree to the practices described here. If you do not agree with this Policy, please do not use the Service.
Everpop is operated by Very - Fast Ltd. (Вери - Фаст ЕООД), an EOOD (single-member limited liability company) registered in Bulgaria under EIK 206337186, with registered seat at 29 Georgi Benkovski Str., 3000 Vratsa, Bulgaria (ул. Георги Бенковски №29, 3000 Враца). You can contact us at privacy@everpop.app for any data protection matter, or at support@everpop.app for general support. Our supervisory authority is the Commission for Personal Data Protection of the Republic of Bulgaria (kzld@cpdp.bg, cpdp.bg).
1. Information We Collect
We collect the following categories of information:
- Account information: name, email address, and password (stored hashed) when you register.
- Connected platform data: when you connect a YouTube channel or social account, we receive identifiers, channel/video metadata, and authorization tokens needed to provide the Service. Tokens are encrypted at rest. If you connect an optional Google Drive folder, we also receive the names, sizes, and IDs of video files in that one folder (see Section 5a).
- Content: videos, clips, captions, transcripts, and related metadata processed to deliver clipping and publishing features.
- Prompts & generated content: text prompts you submit in the Create studio, and the scripts, voiceovers, and videos generated from them.
- Clip ratings & notes: the thumbs-up/down and written comments you leave on your own clips. These are shown back to you and included in internal product-quality reviews; they are not used to train ranking models.
- Clip performance data: aggregate per-clip and per-channel metrics retrieved from platform analytics APIs you authorize (see Section 5). Never viewer-level data.
- Billing information: processed by our payment provider (Stripe). We do not store full card numbers.
- Usage data: log data, device/browser information, IP address, and product analytics about how you interact with the Service.
- Communications: messages you send to support.
2. How We Use Information
- To provide, operate, maintain, and improve the Service;
- To detect new uploads, generate clips, and publish content to platforms you authorize;
- To process payments, manage subscriptions, and prevent fraud;
- To communicate with you about your account, security, and updates;
- To monitor, secure, and troubleshoot the Service;
- To comply with legal obligations and enforce our Terms.
3. Legal Bases for Processing (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the bases of: performance of a contract (to provide the Service), legitimate interests (to operate and improve the Service and prevent abuse), consent (where required, e.g. certain cookies), and compliance with legal obligations. As the controller is established in Bulgaria, our lead supervisory authority is the Bulgarian Commission for Personal Data Protection (cpdp.bg).
4. How We Share Information
We do not sell your personal information. We share information only with service providers ("subprocessors") that help us run the Service, under contractual confidentiality and data-protection obligations. We may also disclose information to comply with law, enforce our Terms, or protect our rights, users, or the public.
5. YouTube / Google API Services
When you connect your YouTube channel, Google initially provides us with access limited to: youtube.readonly (to detect new uploads on the channel you authenticate), and yt-analytics.readonly (to retrieve aggregate performance metrics for your own channel and for the Shorts we publish on it). We request youtube.upload only when you explicitly choose to publish your first clip to that channel. Granting that permission does not publish anything; you still review and confirm the clip. We store your channel_id, channel title, recent video metadata (titles, video_ids, thumbnails) for clip generation, OAuth tokens (encrypted at rest), and the video_ids of Shorts we publish.
Receipts & performance measurement. Using the analytics scope, we retrieve a fixed, limited set of aggregate metrics per published clip and per channel: views, estimated minutes watched, average view duration, average view percentage, subscribers gained, likes, shares, and comments. These are channel-level aggregates only — we never receive or store any information about individual viewers. We use these metrics to (a) show you your clips' real performance ("receipts"), and (b) improve clip selection for your own channel: each channel's model is trained solely on that channel's own clip features and aggregate results. You can exclude any published clip from future model fitting at any time (Receipts → "Learning off"). Its measured outcome remains in your receipt and account history until you delete it or your account, but Everpop does not use that excluded outcome in later channel-model fits. Disconnecting your channel stops new collection.
Public receipt pages. If — and only if — you generate and share a receipt link, the aggregate metrics above for that one clip become viewable by anyone holding the link. You control whether such links are created and where they are shared; they contain no account, email, or viewer information.
Limited Use. Everpop's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data; we do not use Google user data for serving advertisements (including retargeting, personalized, or interest-based advertising); we do not use Google user data to train generalized machine-learning models; and we do not allow humans to read Google user data unless we have your explicit consent for specific data, or it is necessary for security purposes or to comply with applicable law.
The Service uses YouTube API Services to provide its YouTube features. Your use of the Service's YouTube features is also subject to the YouTube Terms of Service and Google Privacy Policy. You can revoke our access at any time at myaccount.google.com/permissions.
5a. Google Drive Ingestion (Optional)
If you connect a Google Drive folder, you share that one folder with our service account (read-only). We access only files in that folder: we read file names, sizes, and IDs, and copy new video files into our storage (Cloudflare R2) to generate clips. We never see the rest of your Drive. Disconnecting the folder in Settings (or un-sharing it in Drive) stops all access immediately; videos already imported stay in your library until you delete them. Our use of information received from Google APIs — including Drive — adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Meta Platform Data (Facebook + Instagram)
When you connect your Facebook account and/or Instagram Business or Creator account, Meta Platforms, Inc. provides us with limited information necessary to operate the connection: your Facebook user ID and name; the IDs and names of Facebook Pages you administer; your Instagram user_id, username, and account_type; and OAuth access tokens (including long-lived Page access tokens) used to publish content on your behalf when you explicitly initiate a publish action.
We use this data exclusively to (a) display the connected account in your dashboard, (b) publish the specific clips you select to your chosen destinations, and (c) honor your request to disconnect. We do not use this data for advertising, profiling, machine-learning training, or any purpose other than the publishing function you opt into.
Stored fields: Facebook user_id; Page IDs and names you select; Instagram user_id, username, account_type; OAuth tokens (encrypted at rest); video_ids of clips we publish. Disconnect: removes publishing authority and scrubs cached credentials and active account identifiers, normally within minutes. If the connection has publishing history, a non-sensitive disconnected record, provider post IDs, and per-clip history remain so your receipts continue to work. A verified platform data-deletion request removes the matching Meta connection data and associated local publishing history. You can request that deletion at privacy@everpop.app. You can also revoke our access directly at facebook.com/settings → Apps and Websites.
We support Meta's Data Deletion Callback. Our callback endpoint is hosted at https://everpop.app/api/meta/data-deletion, and our user-facing deletion instructions are at everpop.app/data-deletion.
7. TikTok Data
When you connect your TikTok account, TikTok provides us with your open_id, display name, avatar URL, and OAuth access + refresh tokens, used solely to publish clips you explicitly select via the dashboard.
We do not read your TikTok feed, your followers, your comments, or any content other than what you produce through Everpop. We do not perform any growth automation, fake engagement, or bulk-posting from one account to many accounts. Each connection is single-creator, opt-in, and revocable at any time at Settings → Connections.
We honor TikTok's content removal: if a post is deleted on TikTok's side, we do not re-publish it. We comply with TikTok's Music Usage Confirmation and Branded Content Policy where applicable; commercial-content disclosure is surfaced in the publish dialog before the post is sent. Clips published to TikTok through Everpop are automatically labeled as AI-generated content (TikTok's is_aigc flag), as required by TikTok's rules for AI-assisted media.
Stored fields: open_id, display name, avatar URL, OAuth tokens (encrypted at rest), video_id of each published clip, your selected privacy_level and interaction settings per clip. Disconnect: removes publishing authority, OAuth tokens, and active account identifiers. If posts exist, we retain a scrubbed destination record and per-clip publishing history so receipts remain available. To request deletion of the locally retained connection history, write to privacy@everpop.app.
8. Subprocessors
We use the following service providers and subprocessors to operate Everpop. Optional providers receive data only when their integration is configured or you use the relevant feature. Where data-protection law requires it, the applicable contractual and international-transfer safeguards govern the processing; business customers can request the current details and DPA.
- Vercel Inc. (USA) — application hosting, AI model gateway, and cookieless Web Analytics when enabled for the production project (pageview and request metadata)
- Neon, Inc. (USA) — database hosting
- Upstash, Inc. (USA) — rate limiting and QStash job-queue infrastructure; depending on the operation, may process IP addresses, email addresses, internal user/source/clip/post/destination/Drive-file identifiers, and queued publishing metadata such as reviewed title, description, and visibility
- Cloudflare, Inc. (USA/EU) — CDN and R2 object storage for source videos, generated media, fonts, and related request metadata; Zero Trust Tunnel proxying of render-engine requests, which may carry source-media URLs, prompts, render settings, internal job identifiers, callback URLs, and ordinary request metadata; and, when Turnstile is configured, anti-bot verification using a challenge token plus IP and browser/device request data
- Hetzner Online GmbH — infrastructure hosting for an Everpop render-engine node and fallback capacity. When a render is routed to that node, it may process source video and extracted audio, transcripts, creator prompts, clip timing/title directives, caption and brand settings, referenced hook audio or custom fonts, generated clips and thumbnails, plan tier, and internal job identifiers
- Configured external uptime/cron monitoring service — optional dead-man's-switch monitoring used only when an external heartbeat endpoint is configured; receives the cron identifier in the ping URL, ping time, and ordinary connection/request metadata such as the service IP. The application does not include Everpop account identifiers, creator media, transcripts, or prompts in this heartbeat ping
- Stripe, Inc. (USA / Ireland) — payment processing; card data is sent directly to Stripe, while Everpop stores customer/subscription identifiers and subscription, billing-period, payment-state, dispute, and transactional metadata
- AI service providers — currently Anthropic, PBC; Groq, Inc.; OpenAI, Inc.; AssemblyAI, Inc.; xAI; Google LLC; Fireworks AI, Inc.; and Together Computer, Inc. (primarily USA) — audio transcription, moment selection, script and metadata writing, text-to-speech, content-safety screening, and visual analysis. Depending on the feature and configured route, the inputs can include prompts, source audio, video transcripts, titles/descriptions, clip opening hooks, thumbnail images, and candidate clip video. Provider routing varies by feature; we send the inputs needed for that requested operation.
- Pexels — stock b-roll search; receives visual search keywords derived from generated scripts or words in source speech/transcripts. Queries can therefore contain contextual words or names, but this integration does not send your Everpop account identifier or source-media file
- Resend, Inc. (USA) — transactional and opted-in engagement email delivery; receives recipient email address and message content
- Crisp IM SAS (France) — support chat messages and browser/session metadata; its widget loads only when you separately enable support chat
- PostHog, Inc. — optional product analytics. Browser funnel events run only when you separately enable product analytics and use a random browser identifier. Separately, when server-side analytics is configured, service events such as signup, billing, render, and publish state may use an internal account identifier and event metadata without browser storage, for service operation, measurement, and improvement
- Functional Software, Inc. (Sentry) — optional error monitoring; when configured, may receive exception messages/stacks, URLs, internal identifiers, and diagnostic context. We redact secret-shaped context keys, request headers/cookies, and similar credential fields before sending, but diagnostics are not represented as anonymous
- Discord Inc. — optional operational alerts; when a webhook is configured, may receive service-failure details, internal user/subscription/platform/post identifiers, creator-provided video or clip titles, and moderation reasoning. Control characters and message markup are sanitized before sending; these alerts are limited to operational response
- Outstand — retired historical publishing integration. New connections and publishing are disabled. A temporary legacy-drain configuration may receive signed status callbacks and query historical provider post identifiers only until old records are settled.
We update this list when service-provider use changes. Any advance-notice and objection rights in a signed DPA continue to govern; otherwise, we provide notice of material changes as required by applicable law. Business customers and compliance teams can request current provider, transfer-mechanism, and retention details at privacy@everpop.app. See also our dedicated Subprocessors page and DPA summary.
9. Data Retention
We keep personal data only as long as necessary for the purposes described in this Policy, then delete or anonymize it. The periods below are indicative and may be extended where a longer period is required by law or to resolve a dispute or enforce our agreements:
- Account & profile data: kept for the life of your account and deleted promptly when you delete your account — normally immediately and no later than 30 days. The limited records expressly described below, storage-deletion records, and portions of records belonging to other users are handled separately; our Data deletion page lists exactly what remains.
- Connected-platform tokens & identifiers: kept until you disconnect or delete your account; removed within 24 hours of a disconnect or platform deletion request (in practice within minutes for an in-app disconnect).
- Content (source videos, clips, posts) & receipts: for the life of your account, and deleted with it. Shorts published to your own channel remain there unless you remove them.
- Aggregate clip/channel analytics (receipts & learning): for the life of your account. Turning learning off excludes that outcome from future channel-model fits; it does not delete the receipt or its stored metrics.
- Billing & tax records: retained after account deletion only where an applicable law requires the specific record, for the period set by that law (accounting and tax rules can reach 10 years). Those records are access-restricted and are not used for marketing or for promotion eligibility. Stripe holds payment-instrument and invoice data under its own retention obligations. Everpop does not store full card numbers; while your account exists we store Stripe customer/subscription identifiers and subscription, plan, price, billing-period, dunning, dispute, guarantee, and delivery/audit metadata needed to operate billing and reconstruct transactions.
- Legal-claim records: records necessary for an actual, threatened, or reasonably anticipated legal claim are access-restricted until the hold ends, and are deleted once the matter closes and any related legally required period has run.
- Audit & security logs: kept for fraud-prevention and security no longer than necessary for those purposes (up to 12 months), then deleted. They are deleted with your account, apart from the narrow case where an applicable law requires the specific record or it falls under a legal-claim hold as described above.
- Promotion & trial eligibility checks: before granting the free first video or a free trial, we compare your account against other accounts that still exist — email aliases (including Gmail dot and plus variants) and any YouTube channel you have connected. These checks read only data belonging to accounts that still exist. We do not keep an email-derived eligibility record after your account is deleted, and deleting your account removes the data these checks would otherwise have matched against. Basis: our legitimate interest in enforcing promotional limits.
- Support communications: handled through our support processors (the Crisp chat widget and our email provider) and retained, per their settings and our policy, for up to 24 months after your last interaction.
- Data-deletion request records: retained as needed to evidence our compliance.
You may request deletion of your account and associated personal data at any time — see our Data deletion page.
10. Security
We implement technical and organizational measures designed to protect your information, including encryption of sensitive tokens, access controls, and signed webhooks. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Breach notification. In the event of a personal-data breach, we will notify the competent supervisory authority (in Bulgaria, the Commission for Personal Data Protection) without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will also notify you without undue delay, as required by GDPR Article 34.
11. Your Rights
Depending on your location, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing or withdraw consent. To exercise these rights, contact us at privacy@everpop.app. You may also revoke connected-platform access at any time from your account or the relevant platform's settings. EU residents have the right to lodge a complaint with their local supervisory authority; in Bulgaria this is the Commission for Personal Data Protection (cpdp.bg).
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and not be discriminated against for exercising your rights. We do not sell or share personal information as defined by the CCPA/CPRA.
13. Cookies & Tracking
We use cookies and similar technologies for authentication, consent preferences, optional product analytics, marketing attribution, and support chat. Strictly necessary storage is always on. Each optional purpose is off by default and has its own control. Product analytics, the short-lived attribution cookie, and Crisp load or run only when you enable the matching purpose, and that purpose's accessible browser state is cleared when you withdraw it. You can change any selection at any time without affecting the others. For full details — categories, providers, and durations — see our Cookie Policy.
14. International Transfers
Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers outside the EEA.
15. Children
The Service is intended for adults: it is not directed to anyone under 18, and we do not knowingly collect personal data from individuals under 18. If you believe someone under 18 has provided us data, contact us and we will delete it.
16. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted on this page with a revised "Last updated" date. Your continued use of the Service after changes take effect constitutes acceptance.
17. Contact
Questions about this Policy? Contact us at privacy@everpop.app. Mailing address: Very - Fast Ltd., 29 Georgi Benkovski Str., 3000 Vratsa, Bulgaria.