Everwhen

Legal

Privacy Policy

Last updated: July 14, 2026

Everwhen helps families turn spoken or written answers into a keepsake storybook. This policy explains what information we collect to do that, who else touches it, and the choices you have over it. It applies to everwhen.app and the accounts, gift links, invite links, and QR playback pages that make up the product.

1. Information we collect

Account information. When you sign in, we store your email address, display name, and which sign-in method you used (Google, or a one-time email code) through our authentication provider, Supabase.

Onboarding and preview answers. If you try the free preview before creating an account, the sample questions and answers you enter are used to generate the demo storybook shown to you.

Book content. Once you create or join a storybook, we store the prompts and questions asked, your typed or transcribed answers, any photos you upload, and the story pages generated from your answers.

Audio recordings. If you answer by voice, we store the recording itself as well as its text transcript.

Support submissions. If you contact us through a support or contact form, we store your message, the email you provide, the category you select, and basic context such as the page you submitted from, your locale, and your browser’s user agent.

Usage and device information. We collect standard product-analytics events (e.g. which screens were viewed) and basic device/browser information, described further in the Analytics section below.

2. How we use AI to process your information

We use OpenAI’s API to (a) transcribe voice recordings into text, and (b) generate a draft storybook page from a transcribed or typed answer. This processing happens on our servers; your raw answers and audio are sent to OpenAI only to produce that output, and we do not log the content of your recordings, transcripts, or generated pages. Under OpenAI’s API terms, content submitted this way is not used to train their models.

AI-generated story pages are a starting draft. We recommend reviewing them for accuracy before treating them as a final record, since AI transcription and writing can occasionally misinterpret names, dates, or details.

3. How we store your information

Book data, audio recordings, and photos are stored with our infrastructure provider, Supabase, in private storage that is not publicly browsable. Files are served to your browser only through short-lived, signed links generated by our servers — the app never exposes a permanent public URL to your raw recordings or photos.

Alongside the providers named in this policy, we use a small number of other service providers (for example, email delivery) that process only the data needed to perform their function for us.

International transfers. Some providers, such as OpenAI, process data in the United States. Where personal data leaves the EEA or UK, the transfer is covered by recognized safeguards such as the EU–US Data Privacy Framework or Standard Contractual Clauses.

4. QR codes and audio playback links

Each printed storybook can include a QR code that links to a page playing back one of your recordings. Anyone who has that link or scans that code can play the recording — access is based on possession of the link, not on being signed in. Treat a printed book and its QR codes the same way you’d treat the recordings themselves: share the book only with people you trust with that recording.

5. Invite and share links

A helper invite link lets someone join a storybook as a helper, but they must sign in first — an invite link alone does not grant access to book content.

A read-only share link lets family members view a storybook without an account. These links can be turned off at any time by the purchaser or storyteller; once revoked or expired, the link no longer shows any content.

6. Analytics and session replay

We use Mixpanel, hosted in the EU, to understand how the product is used. We do not send Mixpanel your story content, transcripts, audio, photos, invite or share tokens, one-time codes, or other private family details.

We use Mixpanel’s session-replay feature to see how the interface itself is used. Story content and anything marked private is masked before it leaves your browser, all form inputs are masked, and images, video, and audio players are excluded from replay entirely. Replay is recorded for only a sample of sessions in production.

7. Cookies and local storage

We use cookies and browser storage for two purposes. Functional cookies remember your signed-in session, your language and country preferences, and your reading text-size setting — the service doesn’t work without them. Analytics cookies support the product-usage measurement described in the previous section.

We do not use advertising cookies. A settings control for managing analytics preferences is planned; in the meantime, you can limit analytics cookies through your browser settings, or contact us to have your analytics data removed.

8. Payment data

Purchases are processed by Lemon Squeezy, which acts as the merchant of record for every Everwhen sale. When you buy, you are taken to a checkout page hosted by Lemon Squeezy, and your card details are entered there — they are handled by Lemon Squeezy and its payment processors, and are never sent to or stored on Everwhen’s servers. Lemon Squeezy also collects and remits any applicable sales tax or VAT, and is the party named on your card statement and receipt.

Lemon Squeezy processes the billing information you give it (such as your name, email, billing address, country, and card details) under its own privacy policy. What we receive back from them, and store, is limited to what we need to give you the storybook you paid for and to support the purchase: an order identifier, the amount and currency charged, the email used at checkout, and the payment status.

9. Data retention, export, and deletion

We keep your account and storybook content for as long as your account is active — a storybook is a keepsake, and deleting it on a timer would defeat its purpose. If you delete your account, we remove your content from our systems within a reasonable period, except where a copy must be kept for legal, security, or backup-integrity reasons; residual backup copies are purged on our normal backup cycle.

You can export a read-only copy of a storybook’s content from within the app. If you’d like a full account export, or want us to delete your account and associated content, contact us at hello@everwhen.app and we will handle the request. We are still building a self-serve deletion flow; until then, deletion requests are handled manually.

10. Legal bases and your rights

Where GDPR applies, we process your data on these legal bases: performance of a contract (storing and processing your storybook content is the service you signed up for), legitimate interests (product analytics, security, and support), and consent where we ask for it explicitly.

If you are located in the EEA, UK, or a jurisdiction with similar data-protection law, you have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You also have the right to lodge a complaint with your local data-protection supervisory authority. To exercise any of these rights, contact hello@everwhen.app.

11. Children's privacy

Everwhen is intended for use by adults collecting stories from family members. It is not directed at children, and we do not knowingly collect account information from children.

12. Changes to this policy

We may update this policy as the product changes. We’ll update the “last updated” date above when we do, and material changes will be communicated through the app or by email where practical.

13. Contact and data controller

Questions about this policy or your data can be sent to hello@everwhen.app, or through our contact form.

The data controller for Everwhen is Yauheni Haiduk, Warsaw, Poland, reachable at hello@everwhen.app.