Privacy Policy
Last updated: August 16, 2026
Everly ("Everly", "we", "us") is an AI assistant for small businesses, provided at get-everly.com. This policy explains what information we collect, how we use it, and the choices you have. It applies to the Everly application and website.
Information we collect
- Account information — your email address (used to sign in via a magic link) and your name if you provide it.
- Business information you give Everly — details about your business shared during onboarding and in conversation (for example your services, hours, policies, and team), documents you upload, and the content of your chats with Everly.
- Website content you ask Everly to read — when you share a URL, Everly reads the publicly available content of that page to help you.
- Google user data — only if you connect your Google account, and only the scopes described below.
- Usage information — basic product analytics (for example which features are used and whether actions succeed) tied to your account, used to operate and improve the service.
Google user data
Connecting Google is optional. If you connect, Everly requests the following permissions, each for a specific user-facing feature:
- Gmail (read) — so Everly can summarize your inbox, find threads you ask about, and tell you what needs a reply.
- Gmail (compose and send) — so Everly can save drafts to your Gmail drafts folder and send emails you have explicitly approved. Nothing is ever sent without your approval in the app.
- Calendar events — so Everly can tell you what is on your schedule and, with your approval, book, move, or cancel events. This permission covers events only, not your calendar settings or sharing.
Those four permissions are the complete set Everly requests. We do not request access to Google Drive, Docs, or Sheets.
Access tokens are stored encrypted on our servers, and every Google API call is made by our backend — tokens are never exposed to your browser, to other users, or to third parties. You can disconnect Google at any time in Settings, which deletes our stored tokens, or revoke Everly's access from your Google Account permissions page.
Limited Use disclosure
Everly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the user-facing features described above.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not use Google user data for advertising.
- We do not allow humans to read your Google user data, except with your explicit permission, where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
How we use information
- To provide the service — answering you, drafting emails, managing your calendar, and remembering your business context so you do not have to repeat yourself.
- To process content with AI models. Everly uses large language models to generate responses and drafts. Content needed for a given feature (for example an email thread you asked about) is processed by our AI infrastructure solely to provide that feature. Our AI providers are bound by terms that prohibit using this data to train their models.
- To operate, secure, and improve Everly.
- To communicate with you about the service.
We do not sell your personal information, and we do not use your information for third-party advertising.
Who we share data with
We do not sell your data and we do not share it for advertising. We share it only with the service providers listed below, who process it on our instructions, only to provide their service to us, and only to the extent each one needs. This is the complete list.
- Railway — cloud hosting and our PostgreSQL database. Everything Everly stores lives here: your account, your business context, your conversation history, and content derived from connected accounts.
- Bonito AI Enterprise Inc. — the AI gateway that routes our requests to language models. Content needed for a given request passes through it.
- Anthropic, OpenAI and Google (Vertex AI)— the language model providers that generate Everly's responses and drafts, reached through the gateway above. Each is bound by terms that prohibit using this content to train their models.
- Resend — delivery of sign-in links and service emails. Receives your email address and the message being sent, nothing else.
- Sentry — error monitoring, so we can find and fix failures. Receives technical diagnostic data, which can incidentally include fragments of content present when an error occurred.
- Cloudflare — serves and protects get-everly.com. Processes requests in transit; it does not store your content.
Google user data specifically
Data obtained from Google APIs (your Gmail messages and calendar events) is shared only with the providers above that are strictly necessary to deliver the feature you asked for:
- Railway, where content derived from those APIs is stored (for example a summary or a draft awaiting your approval).
- Bonito AI Enterprise Inc. and the language model provider it routes to (Anthropic, OpenAI or Google Vertex AI), when a request requires that content — for example summarizing your inbox or drafting a reply grounded in a real thread.
Google user data is not shared with Resend, is not used for advertising, is not sold, and is not used to train any generalized AI or machine learning model. We do not transfer it to any other third party except to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
Data retention and deletion
- Your business content and conversation history are retained while your account is active so Everly can keep serving you.
- Disconnecting Google deletes our stored tokens immediately; content previously derived from Google data can be removed on request.
- You can request deletion of your account and associated data at any time by emailing us; we will complete deletion within 30 days.
Security
Data is encrypted in transit (TLS) and at rest. OAuth tokens are additionally encrypted at the application layer. Access to production systems is limited to the small Everly team and protected by authentication. No method of storage is 100% secure, but we take protecting your business data seriously — it is the core of the product.
Children
Everly is a business tool and is not directed to children under 13. We do not knowingly collect information from children.
Changes to this policy
If we make material changes, we will update this page and note the new date above. Continued use of Everly after changes take effect means you accept the updated policy.
Contact
Questions or requests (including data deletion): hello@helloeverly.ai.