1. Data we collect
- Account data: email address, name (optional), hashed password or OAuth identity.
- Content data: topics, scripts, generated images, voiceovers, and videos you create.
- Platform connections: if you connect TikTok or YouTube, we store OAuth access/refresh tokens and basic channel/account metadata (channel ID, name) solely to publish videos you schedule and to show publishing status.
- Payment data: handled by Stripe; we never store card numbers. We keep subscription status and invoice history.
- Usage data: render counts, feature usage, and privacy-friendly analytics (Umami, self-hosted on our own servers, cookieless, no cross-site tracking), server logs (IP, user agent) for security.
2. How we use it
To provide the Service (generate and render videos, publish to platforms you authorize), bill subscriptions, prevent abuse and enforce quotas, send transactional email (via Brevo), and improve the product. We do not sell personal data or use it for third-party advertising.
3. Google/YouTube API Services
Evershorts uses YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
Evershorts' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access YouTube data only to upload/schedule videos on your channel at your direction and display publishing status. The same applies to Google sign-in, where we receive only your email address, name and profile picture.
You can disconnect the channel in Evershorts at any time, which deletes the access tokens we store. You can additionally revoke Evershorts' access from your own Google account at https://myaccount.google.com/permissions.
4. TikTok
We access the TikTok Content Posting API only to publish content you explicitly create and schedule. We do not read your TikTok inbox, followers, or analytics beyond post status. You can disconnect TikTok in Settings at any time, which deletes the access tokens we store; you can additionally revoke Evershorts' access from TikTok's own security settings.
5. Sub-processors
These are the third parties that process personal data on our behalf, under our instructions. Each receives only what is necessary to perform its function.
| Sub-processor | What it does for us | Location |
|---|---|---|
| Hetzner | Hosting of the application, database and workers | Germany (EU) |
| Cloudflare R2 | Storage of your generated videos, images and voiceovers | EU |
| Stripe | Payment processing, subscriptions and invoices | EU / US |
| Brevo | Transactional email (verification, password reset, invites) | EU |
| OpenRouter | Routes script and image generation requests to the model providers below; receives the topics and scripts you submit | US |
| Anthropic (via OpenRouter) | Model provider for script generation; receives your topics and scripts | US |
| Google (via OpenRouter) | Model provider for scene image generation; receives your scripts and scene prompts | US |
| ElevenLabs | Voiceover synthesis; receives the text of your script | US |
Separately from the above, the platforms you choose to connect — Google sign-in, YouTube and TikTok — are not our sub-processors. They are independent controllers: when you sign in with Google or publish to YouTube or TikTok, those companies process your data under their own terms and privacy policies, over which we have no control. See the Google Privacy Policy and the TikTok Privacy Policy.
6. Legal bases & international transfers (GDPR)
Servicio LTD is established in Cyprus (EU); the GDPR applies directly. We process data under contract performance (Art. 6(1)(b)), legitimate interest (security, product analytics), and consent (platform connections, marketing email). Data may be processed in the EU and the US under standard contractual clauses or adequacy decisions (e.g. the EU-US Data Privacy Framework, where processors are certified).
7. Storage & deletion
Your account data and the videos, images and voiceovers you generate are stored for as long as your account is active. We do not delete your content on a schedule and we do not impose a per-plan storage limit. You can delete any individual video at any time, which removes its database record and its files from storage.
Deleting your account is immediate and permanent. It removes your account and content records and the access tokens we store for connected platforms, and then deletes your generated files from storage. There is no grace period and nothing can be restored afterwards — download anything you want to keep first. Deleting stored tokens is not the same as revoking the grant at the platform: you can additionally remove Evershorts' access from your own Google or TikTok security settings.
Three things outlive the deletion, each because the law, fraud prevention or accountability requires it: invoices and the payment records Stripe and we must keep for statutory accounting periods; a one-way hash of the email address used to claim free signup credits, which we keep indefinitely so the same mailbox cannot claim them repeatedly (legitimate interest in fraud prevention); and the narrow set of activity-log entries described in §8 — billing entries, which keep your account reference and the financial facts but not your device data, and actions taken by our administrators, which are a record of what we did rather than of what you did. The hash is not a record of who signed up, only that someone did.
8. Activity logging
We keep an internal activity log of actions taken in your account: signing in and out (including failed sign-in attempts), password changes and resets, email verification, creating, editing, rendering and deleting videos and series, connecting and disconnecting publishing platforms, purchases, and changes made by our administrators. Each entry records what happened, when, which account did it, and — where the action came from a browser request — the IP address and browser user agent. It records which fields an edit changed, never their contents: your scripts, video titles, series names and display name are not copied into these entries.
We do this for security, fraud prevention, and accountability: to investigate incidents, to answer "who changed this?", and to meet our own accountability obligations under Art. 5(2) GDPR. The basis is our legitimate interest (Art. 6(1)(f) GDPR). These logs are never shown to other users — only to our administrators.
Activity log entries are deleted after 12 months. If you delete your account, we go further and do it sooner:
- Ordinary activity — content, publishing, profile and sign-in entries — is stripped of everything identifying you. Your account reference, IP address and browser user agent are removed, leaving only the fact that an action of that type happened at that time.
- Billing entries keep your account reference and the financial facts, because we may need them to answer a payment dispute or a tax question after your account is gone. The device data — IP address and user agent — is removed from these too.
- Actions taken by an administrator are kept in full. They are a record of what we did, not of what you did.
Where you appear inside somebody else's entry — for example as the person who invited them — your account reference is removed from that entry as well.
9. Invite and referral emails
If an existing user enters your address in our invite form, we send you oneemail, at that user's initiative, telling you they invited you and carrying their invite link. Your address is processed for that single send on the basis of our legitimate interest in letting users refer people they know (Art. 6(1)(f) GDPR); it is not added to any mailing list and is never used for marketing. The inviting user's email address is disclosed to you in that message, so that you can see who invited you — invite someone only if you are content for them to have your address, and for them to see yours. Write to us and we will delete your address on request.
10. Your rights
Access, rectification, deletion, portability, objection. Contact hello@evershorts.com. EU/Swiss users may lodge complaints with their supervisory authority.
11. Cookies
Strictly necessary session cookies; analytics as described in §1. No third-party ad cookies.
12. Changes & contact
We'll notify account holders of material changes by email. Contact: hello@evershorts.com.