EverBird.ai is a product of Kinsei Lab. This policy sets out what personal data we handle, why, on what legal basis, who else sees it, and what you can do about it.
It covers two very different groups of people: customers, who have an account and send documents, and recipients, who open, sign or pay a link a customer sent them and never signed up for anything. What we hold about each, and who is answerable for it, differs — so the two are addressed separately throughout. Recipients who want the short route can go straight to Section 51.
This policy explains what personal data EverBird.ai handles, why, on what legal footing, who else sees it, and what you can do about it. It applies from 4 August 2026 and replaces any earlier version.
It is written to be read by two very different people. One has an account, creates invoices and sends documents — we call them the customer. The other has no account at all: they received a link, opened it, and perhaps signed or paid — we call them the recipient. Almost everything about data protection differs between them, including who is answerable for the data. Section 4 sets that split out, and Section 51 is written for recipients specifically.
Section 5 is a summary. Everything after it is the detail, and the detail governs. Each clause is numbered and separately linkable — /privacy#19 goes straight to the retention clause — so you can point us, or a regulator, at an exact sentence.
EverBird.ai is a product of Kinsei Lab. In this policy, “we”, “us” and “our” mean Kinsei Lab, which is the controller for the processing described in Section 4 as ours.
This policy covers:
It does not cover:
Data protection law distinguishes the party who decides why data is processed (the controller) from the party who processes it on someone else’s instructions (the processor). We are both, depending on the data, and it matters because it decides who you should go to.
In practice: if you are a recipient asking why a business sent you a document, or asking for it to be corrected or deleted, the business is the right first stop — they control it, we only store it for them. If they do not respond, contact us at hello@everbird.ai and we will help (Section 51). If you are asking about your own EverBird.ai account, or about what was recorded when you signed something, that is us.
A short version. It is not a substitute for the clauses it points at.
While you are signed in, the following is recorded about your own use of the product. Measurement of your recipients is a different thing and is described in Section 11.
This clause is about people who never signed up for EverBird.ai. We did not get their data from them — we got it from a customer who uses us to invoice or send documents. Under Article 14 GDPR that requires its own disclosure, which is this.
Documents you build in the editor are stored as structured content — headings, line items, amounts, addresses, images — with each saved version kept so you can look back at what a document said at a point in time. Files you upload for tracking are stored whole: PDFs, Word, PowerPoint and Excel files, and images. Images you place inside a document are extracted and stored as files too.
We hold this for you, as processor. We do not read it for our own purposes, do not sell it, do not use it for advertising, and do not train any model on it (Section 24). Access is scoped to your workspace and to the roles and folder restrictions you set — with one consequence worth knowing about, described in Section 50.
Two technical points that affect your data directly:
You can delete a document, unpublish a link, or delete a workspace at any time. Deleting a workspace removes its documents, files, clients, threads, shares and comments. The deliberate exceptions — signature records, and financial and moderation records — are set out in Section 19.
When a customer sends a document as a link, the recipient’s visit is measured so the sender can tell whether it arrived and was read. This is the feature people buy the product for, and it is also the processing recipients are most entitled to know about, so here is the complete field list rather than a summary.
One thing measurement opt-out does not stop. The first time a shared document is opened, a single timestamp is written against that document so the sender can see it has been seen. That timestamp carries no visitor information — no identifier, no location, no device — and it is recorded even where a recipient has objected to measurement. Everything described in the table above stops immediately on objection (Section 38).
We never receive your card number. Card details are entered into a payment form served and controlled by Stripe, or on Stripe’s own hosted checkout page. They do not pass through our systems and we cannot see them.
This is separate from measurement, it is not optional, and it is disclosed to a signer before they sign. When someone signs a document electronically we record:
Why we collect it. That record is the signature’s legal weight. Electronic signature law — ESIGN and UETA in the United States, eIDAS in the EU and UK — attributes a signature to a person on the strength of evidence like this, and the fingerprint is what demonstrates the document has not been altered since. The lawful basis is performance of a contract and the establishment, exercise and defence of legal claims. It is not consent and not legitimate interest, so there is no opt-out: the way to decline is to not sign.
Why the IP address is taken the way it is. It is observed by our own infrastructure at the moment of signing and passed to our backend over an authenticated internal channel. It is never taken from what the browser claims about itself, because a self-reported address would be trivial to falsify and worth nothing as evidence.
Retention and erasure. Audit records are kept for as long as the signed document has legal effect, and are kept even where the surrounding document is deleted. Under Article 17(3)(e) GDPR they are exempt from erasure requests, because they exist to establish and defend legal claims. This is the one place we may refuse a deletion request, and if it applies we will say so explicitly rather than quietly decline (Section 42). Both sides can obtain a copy: senders can download a Certificate of Completion from the document’s audit trail, and signers can request one from hello@everbird.ai.
There are exactly two connections you can make, and neither reads your mail.
We do not connect to, read, import or send from your mailbox. There is no Gmail or Outlook integration. Every email the product sends — including automated follow-ups — leaves from our own sending address through our email provider, showing your workspace name in the message. Your own address is not used as the sender or the reply-to address (Section 22, Section 31).
We do not ask for, and do not want, special-category data as Article 9 GDPR defines it — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data used to identify someone, health data, sex life or sexual orientation. Nor do we collect government identifiers, precise location, or the sensitive-information categories defined by California law.
Two things deserve a straight answer rather than a blanket denial:
Stated plainly, because “we may collect” language usually hides these:
Each purpose below maps to something the product actually does.
We do not use any of it for advertising, and we do not use your documents or your clients’ data to build products for anyone else.
If you are in the EEA or the UK, we must have a lawful basis for each purpose. Ours are:
The balancing test for link measurement, because it is the one that touches people who never chose us. Someone who sends a business document has a real and obvious interest in knowing whether it was delivered and read — that is what the product is for, and a recipient of a business document would reasonably expect it. The data is deliberately kept coarse: no name, no email, no raw IP, location no finer than a city, and an identifier that is one-way, scoped to a single document and rotated every 30 days, so it cannot follow anyone anywhere. Nothing is written to the recipient’s device. And the objection is one click, on the document itself. Against that, the intrusion is slight and the interest is substantial.
You can object to anything we do on legitimate interests. For link measurement the fastest route is the Privacy control at the foot of the document (Section 38); for everything else, Section 45 explains how.
We keep personal data only as long as it is needed for the purpose it was collected for. Rather than publish durations we cannot guarantee, the criteria below are what actually determine how long something lives — with the two fixed periods our systems enforce automatically called out as fixed.
Where a retention criterion has expired but a record is caught up in an active dispute, investigation or legal hold, we keep it until that ends. Backups roll over on their own cycle, so a deleted record can persist in a backup for a short period before being overwritten.
This is the notice at collection required by the CCPA as amended by the CPRA. It summarises, for California residents, what we collect and why. The detail is in Section 6–Section 16.
EverBird.ai can write and send the follow-up when a client goes quiet. It watches what happens on a thread and, when the pattern calls for it, composes a message chasing the outstanding signature or payment.
What it looks at. Two things, and nothing else:
What it does not look at. The contents of your document are not an input. Line items, amounts, attachments, the body of what you wrote, uploaded files — none of it is read to generate a follow-up.
Generation happens on our own infrastructure (Section 25).
No decision we automate produces legal effects concerning you, or similarly significantly affects you, within the meaning of Article 22 GDPR.
The one automated decision the product makes is when to send a reminder about a document you are already expecting — and whether to send it at all, or hand it to a person to review. Sending a chaser is not a decision of the kind Article 22 governs: it decides nothing about you, grants or denies you nothing, and changes no legal position.
Specifically, we do not:
The engagement signals in Section 21 are used to time a message and to show a sender what happened to their document. They are not used to draw conclusions about a person’s character, reliability or worth.
We do not train, fine-tune or otherwise improve any model on your documents, your uploaded files, your clients’ data, or the contents of anything you send. Not for you, and not for anyone else.
Nor do we use one customer’s data to produce output for another. A follow-up written for your thread is generated from your thread’s own signals and nothing else.
If we ever want to change this, it will require a change to this policy, notice to you before it takes effect, and — where consent is the right basis — your consent rather than your silence.
Follow-up generation runs on our own infrastructure. No third-party model provider receives your content, your documents, your clients’ details, or the signals described in Section 21.
Accordingly there is no AI or model vendor in our subprocessor list (Section 29). If that changes, we will name the provider there, state what would be sent to it and under what terms, and update this policy before the change takes effect — not after.
You choose, per thread, whether a person sees each follow-up before it leaves.
If you believe a follow-up was sent in error, or a recipient asks you to stop, turn the thread off and tell us at hello@everbird.ai if you would like us to look into it.
There are five circumstances, and no others. Personal data is not disclosed for advertising, not traded, and not made available to data brokers.
A subprocessor is a company we engage that may handle personal data on our behalf. We keep the list short deliberately — every addition is another party holding your customers’ data.
Each one is:
If we add or replace a subprocessor we will update Section 29 and, where the change is material, tell affected customers before it takes effect. Customers who need advance notice in writing can ask at hello@everbird.ai.
Current as of the effective date at the top of this page. The last three are conditional: they are only involved if a specific thing happens, noted in each row.
Two separate payment flows, with different parties in each.
All email is delivered through Resend. Our sending address is the From address on every message — including messages about your documents, and automated follow-ups. Your own email address is never used as the sender or the reply-to.
Our transactional email carries no advertising or profiling pixels, and we do not use it to build a picture of your reading habits. We do not enable open or click tracking on it.
We may disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims — for example in response to a valid court order, subpoena, or a lawful demand from a regulator or law enforcement agency.
Our practice:
We may also disclose data where necessary to prevent fraud, abuse or an imminent threat to someone’s safety.
If Kinsei Lab is involved in a merger, acquisition, restructuring, financing or sale of assets, personal data may be transferred as part of that transaction or disclosed under confidentiality to a party evaluating it. Any acquirer remains bound by this policy in respect of data transferred to it, or must adopt a policy offering equivalent protection, until it gives you notice of a change and — where the law requires it — obtains your consent. We will tell you before your data becomes subject to a materially different policy, and where you have a right to object or delete, you will be able to exercise it first.
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months — and we do not do so now. This applies to the specific meanings those terms carry under California law and the equivalent US state laws in Section 44, including disclosures for money and for other valuable consideration.
We also do not sell or share the personal information of anyone under 16.
There is nothing to opt out of because the product contains no mechanism that would make it possible: no advertising networks, no retargeting pixels, no tag managers, no data-broker integrations, no third-party analytics scripts, and no advertising identifiers (Section 40). Section 39 explains what that means for a Global Privacy Control signal.
EverBird.ai sets no advertising cookies and no tracking cookies, and shows no cookie consent banner — because it does not set the kind of storage that would legally require one.
The reason is architectural rather than a matter of policy. Consent banners exist because of the ePrivacy rule on storing or reading information on a person’s device. Our measurement of shared links does neither: nothing is written to a recipient’s browser, and nothing is read from it. The identifier used to tell one viewer from another is derived from the request itself, at our edge, and never leaves our systems (Section 37).
What we do store on a device is either strictly necessary to run the service, or a preference you set yourself. Section 36 lists every item, including the ones a shorter policy would leave out.
Cookies. Five, in two groups.
Local storage. Held in your browser, not sent with every request:
IndexedDB. Signature, logo and seal images you have saved for reuse, and document drafts, are kept in your browser’s database because they are too large for ordinary storage. Cleared on sign-out.
Session storage. Nothing is written to it.
Two different things, often confused, so taken separately.
Product usage — how signed-in customers use the app: feature events, daily-active counts, funnel steps and internal rollups. Tied to a workspace and an opaque account identifier (Section 7).
Recipient measurement — how someone engaged with a document you sent them (Section 11). This is the one that touches people who never chose us, so here is exactly how the visitor identifier works:
Approximate country, region and city come from the same edge lookup. Device type, operating system and browser are derived from the user-agent and reduced to broad families before anything is recorded — we keep “mobile, iOS, Safari”, not the full string.
A Global Privacy Control signal tells a website you are opting out of the sale or sharing of your personal information. We do not sell or share personal information in the first place (Section 34), so there is no sale or sharing for such a signal to stop.
To be straightforward rather than merely compliant: we do not currently read the Global Privacy Control or Do Not Track header, and we will not claim to honour a signal we do not process. If we ever introduce anything that would constitute a sale or share, we will implement GPC handling before doing so and update this clause.
The effective control today is the Privacy control on the document itself (Section 38), which is honoured immediately and remembered.
There are none. EverBird.ai contains no advertising or ad-measurement technology of any kind:
Marketing email, where we send it, is separate from the transactional email in Section 31: it goes only to people who asked for it, every message carries an unsubscribe link, and unsubscribing never affects the service you receive.
Which rights you have depends on where you live, and the next three clauses set them out by regime. In practice we apply the same operational baseline to everyone who asks, wherever they are:
Exercising any of them is free, and never costs you access to the service (Section 48). Two limits apply throughout, and we would rather state them up-front than in a footnote:
If you are in the EEA, the UK or Switzerland, you have the following rights in respect of data for which we are controller (Section 4):
We respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.
California residents have the following rights under the CCPA as amended by the CPRA. Section 20 is the notice at collection.
We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island — have broadly equivalent rights: to confirm and access, to correct, to delete, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects.
Three points specific to those laws:
We respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.
In the product, immediately. These need no request and take effect at once:
By email, for everything else. Write to hello@everbird.ai from the address on your account where you can, and tell us what you want. To be straightforward about it: there is currently no self-serve export button — access, correction of records you cannot edit, portability and erasure-with-confirmation are handled by us by hand. That is slower than a button, and it is what we have today.
Recipients and signers who have no account can write to the same address. Say which document or link it concerns so we can find the record (Section 51). If the request concerns data inside a customer’s workspace, Section 9 explains what happens next.
We verify before we act, because handing someone else’s data to the wrong person is itself a breach. How much verification depends on how sensitive the request is.
Information you give us purely to verify a request is used only for that, and is not retained afterwards beyond the record that the request was made and answered.
You may use an authorised agent to make a request on your behalf. We will ask for written permission signed by you, and we may contact you directly to confirm both that you gave permission and that you want the request made. We will also verify the agent’s own identity. Where an agent holds a valid power of attorney, we will accept that instead of the above. An agent acting without demonstrable authority will be refused, and we will tell them why.
Exercising a privacy right will not get you worse treatment. We will not deny you the service, charge you a different price, give you a lower quality of service, or suggest that any of those might happen, because you asked us to access, correct, delete or stop processing your data. We operate no financial incentive or loyalty programme tied to personal information.
One honest caveat, which is a consequence rather than a penalty: if you ask us to delete data the service needs to function — your account, or the documents in your workspace — that data is gone and the parts of EverBird.ai that depended on it will no longer work for you. We will tell you what will be lost before we act on an irreversible request.
If we refuse a request in whole or in part, we will tell you which parts we refused and the specific reason. You can appeal that decision.
You never have to appeal to us first. You may go straight to a supervisory authority or Attorney General at any point.
A workspace is shared, and that has consequences worth stating plainly rather than burying in a permissions table.
Our own support access. A small number of named staff can enter a customer workspace to investigate a problem — typically a support request or a suspected abuse report. We disclose it because it is real access to real data, and the safeguards are:
If you would like to know whether your workspace has been accessed this way, ask at hello@everbird.ai and we will check the log and tell you.
This clause is for you if you received a link. You do not have an account with us, you did not choose us, and you are entitled to know what happens when you open it. This is our Article 14 notice.
Your controls. Use the Privacy control at the foot of the document to stop measurement immediately (Section 38). To have the underlying details corrected or removed, contact the business that sent it — they can do it directly. If you cannot identify or reach them, write to hello@everbird.ai naming the link, and we will identify them and pass it on, or act ourselves where the duty is ours (Section 9). The one thing we may be unable to erase is a signature audit record, and we will tell you if that is the case.
Two kinds of code can bring you to EverBird.ai: a workspace invitation, and a founder referral link. Both work the same way and neither is used to track you.
Kinsei Lab is established in the United Arab Emirates. The infrastructure that runs EverBird.ai is not — so if you are in the EEA, the UK or elsewhere, your data is transferred internationally as a matter of course, and you should know where it goes.
The United Arab Emirates is not the subject of an adequacy decision by the European Commission, and neither is the United States except under the EU–US Data Privacy Framework for certified organisations. We state that rather than leave it to be inferred. Section 54 explains what we rely on instead.
Where data leaves the EEA or the UK, we rely on the following:
Where we are today, stated honestly. We are a small company at the start of our life. The clauses above describe the mechanisms we rely on and are putting formally in place with each subprocessor; we are not going to claim a completed set of signed agreements as a marketing point. If you need our current transfer documentation for your own compliance file — a data processing agreement, a subprocessor list, or the transfer mechanism for a specific provider — ask at hello@everbird.ai and we will give you what we have, plainly. An Article 27 representative has not yet been appointed (Section 2).
The measures below are the ones actually in place, not a best-practice list we aspire to.
What we will not claim. No system is completely secure, and we are a small team. We do not hold an ISO 27001 or SOC 2 certification, and we will not imply one. If you need our current security documentation for a vendor review, ask at hello@everbird.ai and we will tell you exactly where we stand.
Your part matters too: use a strong, unique password, keep your email account secure since it can reset your password, review your active sessions occasionally, and think about who is in your workspace before you put something sensitive in it (Section 50).
If personal data we hold is subject to a breach, we will investigate immediately, take steps to contain it, and notify as follows:
A notice will describe what happened, the categories and approximate number of records involved, the likely consequences, what we have done about it, what we recommend you do, and how to reach us for more. We will not delay a notification to make it look better.
EverBird.ai is a business tool for invoicing and document workflow. It is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children, and we do not knowingly sell or share the personal information of anyone under 16 (Section 34).
We do not currently verify age at sign-up, so this rests on the service being what it is rather than on a gate. If you believe a child has given us personal data, write to hello@everbird.ai and we will delete the account and its data promptly. Parents and guardians may make that request on the child’s behalf.
A separate point worth making to customers: if you send a document to, or collect a signature from, someone under 18, that is your processing and your responsibility as controller (Section 4).
Parts of the product take you to, or load content from, someone else’s service. Once you are there, their privacy policy governs, not ours.
EEA, United Kingdom and Switzerland. Your legal bases are at Section 18, your rights at Section 42, retention criteria at Section 19, and transfers at Section 53–Section 54. Where we obtained your data from a customer rather than from you, Section 9 and Section 51 are the Article 14 notice. We have not yet appointed an Article 27 representative (Section 2). You may complain to your national supervisory authority (Section 62).
California. Section 20 is the notice at collection, Section 43 sets out your rights, and Section 34 is our statement that we neither sell nor share personal information. We do not offer financial incentives for personal information. California residents may also request information under the “Shine the Light” law using the contact details at Section 61.
Other US states. Section 44 lists the rights and Section 49 the appeal process. We do not conduct targeted advertising, sell personal data, or profile in furtherance of decisions producing legal or similarly significant effects, so no opt-out is required for those activities. We have not conducted a data protection assessment because none of the triggering processing occurs.
United Arab Emirates. As a UAE-established business, Kinsei Lab processes personal data in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. UAE residents have rights of access, correction, erasure, restriction, portability and objection broadly equivalent to those at Section 42, and may complain to the UAE Data Office (Section 62). Cross-border transfers are made on the bases at Section 54.
Canada and Australia. Canadian residents have rights of access and correction under PIPEDA and may complain to the Office of the Privacy Commissioner of Canada. Australian residents have rights of access and correction under the Privacy Act 1988 and may complain to the Office of the Australian Information Commissioner. In both cases the routes at Section 45 apply, and we handle requests to the same standard as everyone else’s.
The effective date at the top of this page is authoritative. We update this policy when what we do changes — not to reword it into something vaguer.
One commitment specifically: if we ever begin sending your content to a third-party model provider, or begin anything that would count as a sale or share, this policy will say so before it starts (Section 25, Section 34).
This policy is effective 4 August 2026 and applies to EverBird.ai, operated by Kinsei Lab.
You can complain to a regulator at any time. You do not have to come to us first, and doing so does not affect any other remedy. We would rather you raised it with us so we can fix it — but the choice is yours.
If you would like to raise something with us first, hello@everbird.ai — and Section 49 explains how to appeal if we get it wrong.
Everbird spots who’s stalling, decides when to follow up, and writes the message that closes the deal — automated client follow up software with one link for all client documents.
Our community is built into EverBird, and yes, we answer every email ourselves, always.
Contact us →