This Privacy Policy explains what information Everburn AI (“Everburn,” “we,” “us”) collects when you use the site, why we collect it, who we share it with, and the choices you have. It applies to everything at everburnai.com and any subdomains.
Everburn AI is an uncensored AI companion platform intended exclusively for adults aged 18 and over. By using the service, you confirm you are an adult and agree to this policy and our Terms of Service.
1. Information we collect
1.1 Information you give us
- Account information. Email address, username, password (stored hashed), date of birth, and optional profile data (nickname, avatar, bio).
- Content you create. Companions you build, chat messages, generated images, comments, likes, favorites, follows, reports, and notification preferences.
- Communications. Anything you send to us by email or through a contact form, including the contents and any attachments.
1.2 Information collected automatically
- Device and connection. IP address, browser user-agent, approximate country, referrer, language. Used for security, abuse prevention, and aggregate analytics.
- Usage. Pages visited, features used, timestamps. If you have granted analytics consent, this is collected via Google Analytics. Otherwise, only anonymous cookieless pings are sent (see Section 5).
- Cookies. See Section 5 for the full list.
1.3 Information from third parties
- OAuth providers. If you sign in with a third-party provider, we receive your email and any profile information you authorize.
- Payment processor. [Placeholder: To be added once payment processing is integrated. We will receive billing metadata and the last four digits of your card; full card numbers will not be stored by us.]
2. How we use information
- To provide the service: authentication, hosting chats, generating images, applying tier limits.
- To enforce safety and our policies: detecting prohibited content, banning abusive accounts, responding to reports.
- To improve the product: aggregate analytics, error monitoring, A/B testing (if/when used).
- To communicate with you: account notifications, security alerts, optional marketing (only if you opt in).
- To comply with law: responding to lawful requests, preserving evidence in serious-harm cases.
3. Legal bases (EEA / UK users)
Where the GDPR or UK GDPR applies, we rely on the following bases:
- Contract — to provide the service you signed up for.
- Legitimate interests — to keep the service safe, prevent fraud, and run essential analytics that have minimal privacy impact.
- Consent — for analytics and marketing cookies, marketing emails, and any optional features you turn on.
- Legal obligation — to meet recordkeeping, safety reporting, and law-enforcement requirements.
4. Who we share information with
We do not sell your personal information. We share it only with the subprocessors that operate the service, with the categories listed below. A full current list is on our Subprocessors page.
- Cloud infrastructure and database — hosts our application and data.
- AI model providers — receive the messages you send in chat in order to generate responses.
- Image-generation compute — receives prompts you submit and returns generated images.
- Email delivery — sends transactional and (if you opt in) marketing email.
- Analytics — measures aggregate usage; only enabled if you grant analytics consent.
- Payment processor — [Placeholder] processes payments when the billing system goes live.
- Law enforcement — when required by valid legal process or to prevent serious harm.
5. Cookies and similar technologies
We use cookies and similar storage in three categories. You can change your choices anytime via the “Cookie preferences” link in the footer or in your account settings.
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary (always on) | Authentication, security, remembering your consent choice. The service cannot run without these. | everburn-auth, eb_consent |
| Analytics (opt-in) | Anonymous and pseudonymous usage measurement so we can see what features are used. | Google Analytics (_ga, _ga_*) |
Everburn AI does not currently deploy any marketing, advertising, or remarketing cookies. If that ever changes, we will add a Marketing category to the cookie banner and re-prompt for consent before any such cookie is set.
When analytics consent has not been granted, Google Analytics is loaded in Consent Mode v2 with all storage flags set to “denied,” and only cookieless pings are sent — these contain no identifiers and are used to model aggregate traffic.
If your browser sends the Global Privacy Control signal, we automatically treat that as an opt-out for marketing cookies in addition to whatever choice you make in the banner.
6. International transfers
Some of our subprocessors are located in the United States or other jurisdictions outside the EEA / UK. Where required, transfers rely on Standard Contractual Clauses or other safeguards approved under applicable law. The subprocessors page lists the location of each provider.
7. How long we keep your data
- Account data: while your account is active.
- Chat content: while your account is active, or until you delete it from the chats screen.
- Generated images: while your account is active, or until you delete them from the gallery.
- Consent log: 24 months from the date of the decision, for compliance recordkeeping.
- Server access logs: typically 30 days.
- Backups: rotated on a 30-day cycle. Deletion takes effect in primary stores immediately and propagates through backups as they rotate.
When you delete your account, we delete personal data tied to it within 30 days, except where we are required by law to retain it (e.g. financial records, abuse evidence).
8. Your rights
You can exercise these rights from your account settings or by contacting us:
- Access & export — Settings → Privacy → “Export my data.” We send a JSON archive to your verified email.
- Correction — Edit your profile and account information directly.
- Deletion — Settings → Privacy → “Delete my account.”
- Opt out of analytics / marketing — Footer → “Cookie preferences” or Settings → Privacy.
- Object / restrict processing (EEA/UK) — Contact us.
- Lodge a complaint — You may complain to your local supervisory authority.
9. California residents (CCPA / CPRA)
Categories of personal information we collect are listed in Section 1. We do not “sell” personal information as defined by the CCPA, and we do not knowingly “share” it for cross-context behavioral advertising. California residents may exercise access, deletion, and correction rights as described in Section 8. We honor the Global Privacy Control signal as a valid opt-out request.
10. Children
Everburn AI is for adults only. The service is not directed to anyone under 18, and we do not knowingly collect personal information from minors. Accounts found to belong to anyone under 18 are removed.
11. Security
Passwords are hashed; transport is HTTPS; row-level security is enforced in our database. No system is perfectly secure, and we will notify affected users in the event of a material breach as required by law.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced in-app and via email where appropriate, and the “Last updated” date above will change. If a material change affects what we collect or share, we will prompt you to review the new policy.
13. Contact
Questions or requests: support@everburnai.com.