Skip to main content
Legal

Privacy Policy

Last updated 4 August 2026

EverBird.ai is a product of Kinsei Lab. This policy sets out what personal data we handle, why, on what legal basis, who else sees it, and what you can do about it.

It covers two very different groups of people: customers, who have an account and send documents, and recipients, who open, sign or pay a link a customer sent them and never signed up for anything. What we hold about each, and who is answerable for it, differs — so the two are addressed separately throughout. Recipients who want the short route can go straight to Section 51.

Opening

1.About This Policy

This policy explains what personal data EverBird.ai handles, why, on what legal footing, who else sees it, and what you can do about it. It applies from 4 August 2026 and replaces any earlier version.

It is written to be read by two very different people. One has an account, creates invoices and sends documents — we call them the customer. The other has no account at all: they received a link, opened it, and perhaps signed or paid — we call them the recipient. Almost everything about data protection differs between them, including who is answerable for the data. Section 4 sets that split out, and Section 51 is written for recipients specifically.

Section 5 is a summary. Everything after it is the detail, and the detail governs. Each clause is numbered and separately linkable — /privacy#19 goes straight to the retention clause — so you can point us, or a regulator, at an exact sentence.

2.Who We Are and How to Contact Us

EverBird.ai is a product of Kinsei Lab. In this policy, “we”, “us” and “our” mean Kinsei Lab, which is the controller for the processing described in Section 4 as ours.

Postal address
Kinsei LabSharjah Media CitySharjahUnited Arab Emirates
Privacy contact
hello@everbird.ai — the same address handles data-protection requests, questions about this policy, and complaints. Put “Privacy” in the subject line and it will be routed accordingly.
Data Protection Officer
We have not appointed one. We are not a public authority, and neither large-scale processing of special-category data nor large-scale systematic monitoring is a core activity of ours, so Article 37 GDPR does not require an appointment. Requests go to the address above and are handled by us directly.
EEA representative (Art 27)
Not yet appointed. We are established in the United Arab Emirates and have no establishment in the EEA. If you are in the EEA you can contact us directly at the address above, and you may complain to your national supervisory authority without going through us first (Section 62).
UK representative (Art 27 UK GDPR)
Not yet appointed. UK users can contact us directly, and may complain to the Information Commissioner’s Office (Section 62).

3.Scope — What This Policy Covers and What It Doesn’t

This policy covers:

  • the EverBird.ai website, including the marketing, pricing and free-tool pages;
  • the application itself — accounts, workspaces, the invoice editor, uploads, threads, billing and the dashboards;
  • the recipient-facing surfaces a customer’s link points at: shared documents, thread pages, and hosted upload viewers, together with signing, commenting and payment-claim actions on them;
  • the transactional and automated email we send about all of the above.

It does not cover:

  • what a customer puts inside their own documents, or what they do with the data they collect through us. For that the customer is the controller and their own privacy notice applies (Section 4);
  • Stripe’s hosted checkout and account-onboarding pages. When you enter card details or complete payout onboarding you are on Stripe’s own page under Stripe’s own policy — we never see those details (Section 12, Section 30);
  • third-party viewers and embeds reached from our pages: Microsoft Office Online for legacy Office file previews, and YouTube or Vimeo where a workspace has set an intro video on its client portal (Section 58);
  • any website a customer links to from inside a document they send.

4.Our Two Roles: Your Data vs. Your Clients’ Data

Data protection law distinguishes the party who decides why data is processed (the controller) from the party who processes it on someone else’s instructions (the processor). We are both, depending on the data, and it matters because it decides who you should go to.

We are the controller for
Account and identity data; workspace and brand profile; billing and subscription records; product usage measurement; measurement of shared links, which exists so the sender can see whether a document was opened; e-signature audit records, which exist as evidence and are ours to keep; marketing enquiries; support and moderation records.
We are the processor for
The contents of documents a customer creates, uploads or sends; files stored in their workspace; the client records they keep about their own customers; the recipient details they send to; and comments or payment claims those recipients leave. The customer decides what goes in, who receives it and how long it stays. We act on their instructions and do not use any of it for our own purposes.

In practice: if you are a recipient asking why a business sent you a document, or asking for it to be corrected or deleted, the business is the right first stop — they control it, we only store it for them. If they do not respond, contact us at hello@everbird.ai and we will help (Section 51). If you are asking about your own EverBird.ai account, or about what was recorded when you signed something, that is us.

5.Summary at a Glance

A short version. It is not a substitute for the clauses it points at.

Your documents
Stored on our infrastructure and scoped to your workspace. We do not read them for our own purposes, do not sell them, and do not train any model on them. Section 10
Link measurement
When you send a document, the recipient’s visit is measured for you: opens, pages, time, coarse location, device. It is cookieless — nothing is written to the recipient’s device — and every shared document carries a control that turns it off. Section 11, Section 38
Signatures
Signing records name, supplied email, time, IP address, browser, coarse location and a fingerprint of the exact document signed. This is the signature’s evidential value, it is disclosed before signing, and it is not optional. Section 13
Payments
We never receive card numbers. Subscription billing and client-invoice payments both run through Stripe. Section 12
Follow-up automation
Runs on our own infrastructure, sees engagement signals and contact details only — never your document’s contents — and never trains on your data. Section 21Section 26
Selling data
We do not sell or share personal information, and there is no advertising technology anywhere in the product. Section 34, Section 40
Who else sees it
A short list of named subprocessors, each for one job. Section 29
Your rights
Access, correction, deletion, portability, objection — plus the one documented exception, for signature audit records. Section 41Section 49
Where it is processed
We are in the UAE; most processing happens in the United States. Section 53

What is collected

6.Information You Give Us Directly

Creating an account
Your name, email address, and either a password (stored only as a hash, never in readable form) or a Google sign-in. Email verification uses a six-digit code sent to the address you gave.
Setting up a workspace
Workspace name, logo, website, contact email and phone, and postal address (street, city and state, postal code, country) — these appear on the invoices you issue, which is why we ask for them. Optionally an accent colour, a profile role and headline, a short bio, social links, a booking link, and an intro video URL for your client portal.
Onboarding answers
Business type (agency, freelancer, consultancy or other, with free text if other) and team size. Self-reported, used to set defaults and to understand who uses the product.
Invoice and document settings
Currency, numbering patterns and their timezone, saved line items, payment terms, and bank or payment details you choose to print on an invoice.
Founding-member listing
If you opt in, a short tagline and a pull-quote you write, shown publicly on your founding-member page together with your workspace name, logo and website. Opt-in is off unless you turn it on, and turning it off removes the listing.
Contacting us
Our enquiry forms collect your name, email and company, plus a website, team size, timeline, or a free-text message depending on which form you use. Sales and white-label enquiries also create an internal activity record containing your name and email.
Support correspondence
Whatever you put in an email to us, kept with the thread so we can answer it.

7.Information We Collect Automatically

While you are signed in, the following is recorded about your own use of the product. Measurement of your recipients is a different thing and is described in Section 11.

Sessions
Each sign-in creates a session record holding the session token, its expiry, and the IP address and browser user-agent of the device that signed in. You can see and revoke your own sessions from your account settings.
Activity records
Sign-ins, sign-ups, workspace creation, enquiries, onboarding completion and purchases are written to an internal activity log that includes the acting account’s email and name. It is how we investigate abuse and reconstruct what happened to an account.
Product events
Coarse feature-usage events tied to a workspace and an opaque account identifier — for example that a thread was created or a document was sent. No document contents and no contact details.
Daily activity
One row per account per day, so we can count weekly and monthly active users. It records that you were active, not what you did. These rows are deleted automatically after 40 days.
First-touch attribution
On your very first visit we record, in your browser, where you arrived from: campaign source, medium and campaign name from the link, the referring site’s hostname, and the landing path. It is written once, never overwritten, and copied onto your workspace record when you create an account, so we can tell which channels bring people in.
Pre-launch funnel measurement
During our pre-launch period, steps through the sign-up and plan selection funnel are measured. Country, device, browser, referrer and campaign parameters are included; email addresses, names, workspace identifiers and referral codes deliberately are not.

8.Information We Receive From Third Parties

Google
If you sign in with Google we receive your name, email address, whether that address is verified, and your profile picture, together with the tokens needed to keep the connection working. We ask for nothing beyond basic profile and email, and we do not read your Gmail, Drive or calendar.
Stripe
Subscription status, plan, price, billing interval, period end and trial end. Card brand, last four digits and expiry are fetched from Stripe when we need to show them and are not stored by us. For payouts, whether your connected account can accept charges and receive payouts, whether onboarding is complete, its country and default currency — the identity documents you give Stripe stay with Stripe.
Our edge network
When a page is requested, our hosting provider tells us the request’s approximate country, region and city, and we derive a short-lived pseudonymous visitor identifier from the request itself. Section 37 explains exactly how, and why the raw IP address is never kept.
People who referred you
If you arrived on an invite or referral link, we learn which workspace or member’s code you used, so they can be credited. Section 52

9.Information About Your Clients and Document Recipients

This clause is about people who never signed up for EverBird.ai. We did not get their data from them — we got it from a customer who uses us to invoice or send documents. Under Article 14 GDPR that requires its own disclosure, which is this.

Categories held
Client records a customer chooses to keep: name, contact name, email address, phone number, postal address, company, job title, a social handle, free-text notes, a lifetime-value figure, and any additional columns that customer defines for themselves. Separately, the email addresses a document was sent to, and the name and details a recipient supplies when they sign, comment or report a payment.
Source
The EverBird.ai customer who holds the relationship — usually typed in by them or imported from their own records — and, for signatures and comments, from the recipient at the moment they act.
Our role
Processor. The customer decides what to store, why, and for how long. We store it for them, keep it inside their workspace, and do not use it for anything of our own.
How to exercise rights
Ask the business that holds the relationship first — they can correct or delete the record directly. If you cannot identify them, or they do not respond, write to hello@everbird.ai and we will identify the customer and pass it on, or act ourselves where the law puts the duty on us. The one thing we may be unable to erase is a signature audit record (Section 13, Section 42).

10.Document Content and Uploaded Files

Documents you build in the editor are stored as structured content — headings, line items, amounts, addresses, images — with each saved version kept so you can look back at what a document said at a point in time. Files you upload for tracking are stored whole: PDFs, Word, PowerPoint and Excel files, and images. Images you place inside a document are extracted and stored as files too.

We hold this for you, as processor. We do not read it for our own purposes, do not sell it, do not use it for advertising, and do not train any model on it (Section 24). Access is scoped to your workspace and to the roles and folder restrictions you set — with one consequence worth knowing about, described in Section 50.

Two technical points that affect your data directly:

  • Link and upload passwords are never stored readable. If you password-protect a share, we keep a salted PBKDF2 hash. We cannot recover the password and cannot tell you what it was.
  • Every version is fingerprinted with SHA-256. That fingerprint is what a signature attests to, and it is what proves a signed document has not been altered since (Section 13).

You can delete a document, unpublish a link, or delete a workspace at any time. Deleting a workspace removes its documents, files, clients, threads, shares and comments. The deliberate exceptions — signature records, and financial and moderation records — are set out in Section 19.

11.Document Activity and Engagement Data

When a customer sends a document as a link, the recipient’s visit is measured so the sender can tell whether it arrived and was read. This is the feature people buy the product for, and it is also the processing recipients are most entitled to know about, so here is the complete field list rather than a summary.

Events recorded
Opening the document, viewing a page, ending a session, downloading the PDF, unlocking a password-protected link (successfully or not), saving an edit where editing is permitted, signing, and the sender copying the link.
Fields on each event
Time; which event; which document; the pseudonymous visitor identifier described in Section 37; approximate country, region and city; the referring site’s hostname; campaign source, medium and campaign name if the link carried them; device type (mobile, tablet or desktop); operating system family; browser family; browser language; timezone offset; page number; time spent on the page and in total; and a per-visit session identifier.
On a signature event
Only the label of the field signed and a yes-or-no flag for whether an email was supplied. The signer’s name and email are never sent to our measurement system — they live only in the audit record (Section 13).
Hosted upload viewers
The same, minus browser language and the signature fields.
What is never included
The document’s contents, the recipient’s name or email address, their raw IP address, or any identifier that works on another website.

One thing measurement opt-out does not stop. The first time a shared document is opened, a single timestamp is written against that document so the sender can see it has been seen. That timestamp carries no visitor information — no identifier, no location, no device — and it is recorded even where a recipient has objected to measurement. Everything described in the table above stops immediately on objection (Section 38).

12.Payment and Billing Information

We never receive your card number. Card details are entered into a payment form served and controlled by Stripe, or on Stripe’s own hosted checkout page. They do not pass through our systems and we cannot see them.

Your subscription
We store your Stripe customer and subscription identifiers, the price and plan, billing interval, status, current period end, trial end and any add-ons. Your name and email are given to Stripe so it can bill you and issue receipts.
Getting paid by your clients
If you connect a payout account, you are the merchant of record for invoices your clients pay — the money moves from your client to you. Your client enters their own email and billing address on Stripe’s page; those details are not passed through us. What we record is the client name and document name as they appear on your invoice, the amount, currency, the Stripe session and payment identifiers, and whether it succeeded, so your revenue dashboard works and so refunds and disputes reconcile.
Payment claims
If a recipient tells you they have paid by bank transfer instead, we store the name they type, the method they picked and any note they leave, and show it to you.
Our own ledgers
Subscription changes, invoice outcomes, refunds and disputes are recorded against the workspace. These are financial records and they outlive the workspace (Section 19).

13.E-Signature Records and Audit Trail Data

This is separate from measurement, it is not optional, and it is disclosed to a signer before they sign. When someone signs a document electronically we record:

  • the name they sign under;
  • the email address they supply, if any, which is stored exactly as typed and is not verified by us;
  • the exact time of signing;
  • which field or role was signed;
  • the signature image itself, drawn, typed or uploaded by the signer;
  • the IP address the signature was submitted from;
  • the browser user-agent string;
  • an approximate location, at city and country level; and
  • a SHA-256 fingerprint of the exact document content at the moment of signing.

Why we collect it. That record is the signature’s legal weight. Electronic signature law — ESIGN and UETA in the United States, eIDAS in the EU and UK — attributes a signature to a person on the strength of evidence like this, and the fingerprint is what demonstrates the document has not been altered since. The lawful basis is performance of a contract and the establishment, exercise and defence of legal claims. It is not consent and not legitimate interest, so there is no opt-out: the way to decline is to not sign.

Why the IP address is taken the way it is. It is observed by our own infrastructure at the moment of signing and passed to our backend over an authenticated internal channel. It is never taken from what the browser claims about itself, because a self-reported address would be trivial to falsify and worth nothing as evidence.

Retention and erasure. Audit records are kept for as long as the signed document has legal effect, and are kept even where the surrounding document is deleted. Under Article 17(3)(e) GDPR they are exempt from erasure requests, because they exist to establish and defend legal claims. This is the one place we may refuse a deletion request, and if it applies we will say so explicitly rather than quietly decline (Section 42). Both sides can obtain a copy: senders can download a Certificate of Completion from the document’s audit trail, and signers can request one from hello@everbird.ai.

14.Connected Accounts and Email Integration Data

There are exactly two connections you can make, and neither reads your mail.

Google sign-in
Optional. Linking stores the tokens Google issues so the connection keeps working, alongside the profile fields in Section 8. You can unlink it from your account settings, as long as you have another way to sign in.
Stripe payouts
Optional. Connecting lets your clients pay your invoices directly to you. We hold the account identifier and its capability flags — nothing else about it (Section 12).

We do not connect to, read, import or send from your mailbox. There is no Gmail or Outlook integration. Every email the product sends — including automated follow-ups — leaves from our own sending address through our email provider, showing your workspace name in the message. Your own address is not used as the sender or the reply-to address (Section 22, Section 31).

15.Sensitive Personal Information

We do not ask for, and do not want, special-category data as Article 9 GDPR defines it — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data used to identify someone, health data, sex life or sexual orientation. Nor do we collect government identifiers, precise location, or the sensitive-information categories defined by California law.

Two things deserve a straight answer rather than a blanket denial:

  • The signature image. A drawn signature is an image of your handwriting. We do not analyse it, do not extract features from it, and do not use it to identify anyone — it is stored as evidence of what was signed, and matched to nothing. On that basis it is not biometric data within the meaning of Article 9. We still treat it as sensitive in practice: it is only ever shown on the document it belongs to and in that document’s audit trail.
  • Uploaded documents can contain anything. We cannot police what a customer puts in a file. If you upload or send material containing special-category data, you are the controller of it and you need your own lawful basis; our agreement with you requires that. We ask customers not to use EverBird.ai as a store for medical records, identity documents or similar material.

16.Information We Do Not Collect

Stated plainly, because “we may collect” language usually hides these:

  • Card numbers. Never received, never stored.
  • Precise or GPS location. Location is derived from the network request and is city-level at best.
  • Raw IP addresses for measurement. The visitor identifier is derived from the IP address by a one-way function and the address itself is neither stored nor logged. Signature audit records are the deliberate exception, and are disclosed as such (Section 13).
  • Advertising or cross-site identifiers. No ad networks, no pixels, no tag managers, no third-party analytics scripts.
  • Device fingerprints. We do not probe fonts, canvas, hardware or any similar signal.
  • Mailbox contents. No mail is read or imported.
  • Biometric templates. No face, fingerprint or handwriting-analysis data.
  • Data knowingly collected from children. Section 57
  • Profiles or inferences sold to anyone. Section 34

Why and on what basis

17.How We Use Your Information

Each purpose below maps to something the product actually does.

  • Run your account and workspace — authenticate you, keep you signed in, apply roles and folder permissions, switch between workspaces, and let teammates in by invitation.
  • Create, store and render documents — save your invoices and uploads, keep version history, generate the PDF in your browser, and produce merged downloads.
  • Deliver and measure shared links — resolve a share link, enforce any password or expiry you set, and show you who opened it, when, and how far they read (Section 11).
  • Produce e-signature evidence — capture and retain the audit record that gives a signature its weight (Section 13).
  • Take payment and help you get paid — run your subscription, and process invoice payments from your clients through your connected account (Section 12).
  • Send transactional email — sign-in and verification links, invitations, signature and payment notifications, and account notices, subject to your notification preferences (Section 31).
  • Generate and send follow-ups — compose a follow-up message when a thread goes quiet, and send it or offer it to you as a draft (Section 21).
  • Support, moderation and safety — answer your questions, investigate reported problems, and act on abuse of the service.
  • Prevent fraud and abuse — rate-limit public forms, signing attempts and checkout, and block addresses that have abused the service.
  • Understand and improve the product — aggregate usage counts, funnel measurement, and internal metrics.
  • Meet legal and accounting duties — retain financial records and respond to lawful requests.

We do not use any of it for advertising, and we do not use your documents or your clients’ data to build products for anyone else.

18.Legal Bases for Processing (EEA/UK)

If you are in the EEA or the UK, we must have a lawful basis for each purpose. Ours are:

Performance of a contract — Art 6(1)(b)
Creating and running your account; storing and rendering your documents; sharing links and enforcing their protections; capturing e-signatures; billing you; processing an invoice payment a recipient chooses to make; sending the transactional email needed to operate all of it.
Legitimate interests — Art 6(1)(f)
Measuring shared links so a sender knows whether a document arrived; generating and sending follow-ups on a customer’s instruction; aggregate product analytics; security, rate limiting and abuse prevention; keeping internal activity and support records; direct communication with business contacts who enquire.
Legal obligation — Art 6(1)(c)
Retaining accounting and tax records for payments; responding to valid legal process; complying with sanctions and anti-fraud duties.
Legal claims — Art 6(1)(f) and Art 17(3)(e)
Retaining e-signature audit records, and records of disputes, refunds and moderation actions.
Consent — Art 6(1)(a)
Used only where it is genuinely optional: opting in to the public founding-member listing, and any marketing email you choose to receive. You can withdraw it at any time without affecting the service.

The balancing test for link measurement, because it is the one that touches people who never chose us. Someone who sends a business document has a real and obvious interest in knowing whether it was delivered and read — that is what the product is for, and a recipient of a business document would reasonably expect it. The data is deliberately kept coarse: no name, no email, no raw IP, location no finer than a city, and an identifier that is one-way, scoped to a single document and rotated every 30 days, so it cannot follow anyone anywhere. Nothing is written to the recipient’s device. And the objection is one click, on the document itself. Against that, the intrusion is slight and the interest is substantial.

You can object to anything we do on legitimate interests. For link measurement the fastest route is the Privacy control at the foot of the document (Section 38); for everything else, Section 45 explains how.

19.Retention Periods by Data Category

We keep personal data only as long as it is needed for the purpose it was collected for. Rather than publish durations we cannot guarantee, the criteria below are what actually determine how long something lives — with the two fixed periods our systems enforce automatically called out as fixed.

Account and identity data
Kept while your account exists. Deleting your account removes it.
Workspace and brand profile
Kept while the workspace exists. Deleting the workspace removes it.
Documents, versions and uploaded files
Kept until you delete them, or until the workspace holding them is deleted — whichever comes first. We do not impose a lifetime on your own content.
Client records
Controlled by the customer who created them; kept until they delete the record or the workspace.
Shared links and their measurement
Kept while the link exists and for as long as the resulting analysis is useful to the sender. Unpublishing a link stops further measurement.
E-signature audit records
Kept for as long as the signed document has legal effect, and deliberately outlive deletion of the document they relate to. Article 17(3)(e) applies (Section 13).
Billing, payment and dispute records
Kept for as long as needed to meet accounting and tax obligations and to defend claims. These survive deletion of the workspace.
Moderation and staff-action records
Kept for as long as needed to enforce our terms and defend claims, including records of accounts blocked for abuse.
Session records
Kept until the session expires or you revoke it.
Support and enquiry correspondence
Kept for as long as needed to handle the matter and any follow-up.
Referral records — fixed, 30 days
A referral code carried against a new account but not yet used is deleted automatically 30 days after it was captured. The copy held in your own browser expires on the same schedule.
Measurement key — fixed, 30 days
The secret used to derive visitor identifiers is rotated every 30 days, which caps how long any identifier remains comparable to itself (Section 37).
Daily activity rows — fixed, 40 days
Deleted automatically after 40 days.

Where a retention criterion has expired but a record is caught up in an active dispute, investigation or legal hold, we keep it until that ends. Backups roll over on their own cycle, so a deleted record can persist in a backup for a short period before being overwritten.

20.Notice at Collection (California)

This is the notice at collection required by the CCPA as amended by the CPRA. It summarises, for California residents, what we collect and why. The detail is in Section 6Section 16.

Identifiers
Name, email address, postal address, phone number, account identifiers, IP address (in the limited circumstances at Section 13 and Section 7). Collected to create and run your account, to bill you, to send transactional email, and — for signers — to make a signature evidential.
Customer records / commercial information
Subscription and payment history, plan, invoices issued and paid. Collected to run billing and your revenue dashboard.
Internet or network activity
Pages viewed, time spent, events within the product, device, operating system, browser, referrer and campaign parameters. Collected to operate and measure the service.
Geolocation (coarse)
Approximate country, region and city derived from the network request. Collected to give senders context on a document view and to make signature evidence meaningful. Never precise.
Professional or employment information
Company, job title, business type and team size, where you or a customer supplies them. Collected to configure the product and for business communication.
Audio, electronic or visual information
Uploaded files, images placed in documents, profile pictures, and signature images. Collected to provide the core service.
Sensitive personal information
None collected. We do not collect the categories California treats as sensitive, so there is nothing to limit the use of (Section 15).
Sources
You; your workspace’s members; recipients who act on a link; Stripe; Google, if you sign in with it; and our own systems.
Disclosure
To the service providers named in Section 29, for the purposes stated there, under contract.
Retention
By the criteria in Section 19.
Sale or sharing
We do not sell personal information and do not share it for cross-context behavioural advertising (Section 34). EverBird.ai contains no advertising technology at all.

AI and automation

21.How Our AI Features Work

EverBird.ai can write and send the follow-up when a client goes quiet. It watches what happens on a thread and, when the pattern calls for it, composes a message chasing the outstanding signature or payment.

What it looks at. Two things, and nothing else:

  • Engagement signals — whether the document was sent, whether it was opened, which pages were read and for how long, whether it has been signed, whether it has been paid, and how long it has been since each of those; and
  • Contact details — the recipient’s name and email address, so the message can be addressed and delivered.

What it does not look at. The contents of your document are not an input. Line items, amounts, attachments, the body of what you wrote, uploaded files — none of it is read to generate a follow-up.

Generation happens on our own infrastructure (Section 25).

22.AI Follow-Ups and Automated Sending

Who it goes to
The address the document was sent to on that thread, or the email on the linked client record. Nobody else.
Who it comes from
Our own sending address, through our email provider, showing your workspace name in the message. Your mailbox is not connected and is not used to send (Section 14).
What is in it
A short message referring to the document and how long it has been outstanding, plus the link. It does not quote the document’s contents, because it never had them (Section 21).
On whose instruction
Yours. You enable follow-ups for a thread; we act on that instruction as processor for the message and its recipient data. You are responsible for having a lawful basis for contacting your own clients, as you would be for any email you send them.
Stopping it
You can pause or cancel a scheduled follow-up, or switch the thread to draft-only, at any time (Section 26). A recipient who wants them to stop can tell you, or write to hello@everbird.ai and we will act.

23.Automated Decision-Making and Profiling

No decision we automate produces legal effects concerning you, or similarly significantly affects you, within the meaning of Article 22 GDPR.

The one automated decision the product makes is when to send a reminder about a document you are already expecting — and whether to send it at all, or hand it to a person to review. Sending a chaser is not a decision of the kind Article 22 governs: it decides nothing about you, grants or denies you nothing, and changes no legal position.

Specifically, we do not:

  • score, rank or rate any person — not customers, not their clients, not recipients;
  • assess creditworthiness, ability to pay, or likelihood of default;
  • make eligibility, pricing or access decisions by automated means;
  • build behavioural profiles for advertising, or profiles that follow anyone across websites (Section 40); or
  • take any automated action against an account. Blocking or removing an account is always a human decision, logged and reversible.

The engagement signals in Section 21 are used to time a message and to show a sender what happened to their document. They are not used to draw conclusions about a person’s character, reliability or worth.

24.Model Training and Your Data

We do not train, fine-tune or otherwise improve any model on your documents, your uploaded files, your clients’ data, or the contents of anything you send. Not for you, and not for anyone else.

Nor do we use one customer’s data to produce output for another. A follow-up written for your thread is generated from your thread’s own signals and nothing else.

If we ever want to change this, it will require a change to this policy, notice to you before it takes effect, and — where consent is the right basis — your consent rather than your silence.

25.AI Subprocessors and Model Providers

Follow-up generation runs on our own infrastructure. No third-party model provider receives your content, your documents, your clients’ details, or the signals described in Section 21.

Accordingly there is no AI or model vendor in our subprocessor list (Section 29). If that changes, we will name the provider there, state what would be sent to it and under what terms, and update this policy before the change takes effect — not after.

26.Human Review and Oversight

You choose, per thread, whether a person sees each follow-up before it leaves.

Draft for review
The message is composed and held for you. Nothing is delivered until you read it and send it. You can edit it freely or discard it.
Automatic send
Once you enable it for a thread, messages go out on their own schedule. You can pause the thread, cancel a scheduled message before it sends, or switch the thread back to draft-only at any time.
Always true
Follow-ups are off until you turn them on. They stop when the thread is signed, paid or closed. And a person on your side can always intervene before a message is delivered.

If you believe a follow-up was sent in error, or a recipient asks you to stop, turn the thread off and tell us at hello@everbird.ai if you would like us to look into it.

Sharing

27.When We Share Your Information

There are five circumstances, and no others. Personal data is not disclosed for advertising, not traded, and not made available to data brokers.

  • To service providers who run part of the product for us, under contract and only for the purpose we engaged them for (Section 28, Section 29).
  • To the people you send to. Sending a document discloses whatever you put in it to the recipient you chose. That is the point of the product, and what you include is your decision.
  • Within your workspace. Teammates see what their role and your folder settings allow — with the caveat in Section 50.
  • Where the law requires it (Section 32).
  • On a business transfer (Section 33).

28.Service Providers and Subprocessors

A subprocessor is a company we engage that may handle personal data on our behalf. We keep the list short deliberately — every addition is another party holding your customers’ data.

Each one is:

  • engaged under a written contract with confidentiality and security obligations, and instructed to process only for the purpose we named;
  • prohibited from using the data for its own purposes, including advertising or model training;
  • assessed for the transfer safeguards described in Section 54 where data leaves the EEA or the UK; and
  • listed by name in Section 29, so you can check who they are.

If we add or replace a subprocessor we will update Section 29 and, where the change is material, tell affected customers before it takes effect. Customers who need advance notice in writing can ask at hello@everbird.ai.

29.Subprocessor List

Current as of the effective date at the top of this page. The last three are conditional: they are only involved if a specific thing happens, noted in each row.

Convex
Application database, backend and authentication. Holds accounts, workspaces, document content, clients, shares, comments and audit records, and the records describing uploaded files. The file contents themselves are stored by Cloudflare, below. United States.
Cloudflare
Website and application hosting, the edge network that serves requests, and object storage for uploaded files. Derives the approximate location and the pseudonymous visitor identifier (Section 37), and relays the observed IP address for signature audit records (Section 13). Globally distributed.
Tinybird
Shared-link and document-view measurement. Holds the event fields listed in Section 11 — no names, no email addresses, no document contents. United States.
Stripe
Subscription billing, and payments your clients make on your invoices. Receives your name and email for billing, and collects your payer’s own details directly (Section 12, Section 30). United States and Ireland.
Resend
Transactional and automated email delivery. Receives the recipient address and the message content (Section 31), and reports back whether a message bounced or was marked as spam. United States.
Google — only if you use Google sign-in
Authenticates you and returns the profile fields in Section 8. If you sign in with an email address and password, Google is not involved at all. United States.
Microsoft — only when a legacy Office file is previewed
Word, PowerPoint and Excel files cannot be rendered in the browser directly, so previewing one loads Microsoft’s Office Online viewer. To do that, a link to the file is passed to Microsoft, which fetches and renders the file. PDFs and images are rendered by us and never involve Microsoft. If you would rather Microsoft never see a document, upload it as a PDF.
YouTube / Vimeo — only if a workspace sets an intro video
A workspace can put a video on its client portal. Where it does, the visitor’s browser loads the player from YouTube or Vimeo, which sets its own storage and receives the visitor’s request under its own policy. No video, no involvement.
Zippopotam — only when you use postal-code autofill
Looks up a city and state from a postal code as you type an address. Receives a country code and a postal code and nothing else — no name, no account, no identifier.

30.Payment Processing

Two separate payment flows, with different parties in each.

You paying us
Your subscription. You give Stripe your card details on a form Stripe controls; we receive the identifiers and status in Section 12 and never the card number. Stripe processes your data as a controller in its own right for fraud prevention and regulatory purposes, under its own privacy policy.
Your clients paying you
If you connect a payout account, you are the merchant of record — your client pays you, not us, and we take no cut of it. Your client enters their email and billing address on Stripe’s hosted page. Those details never pass through us. We record only what we need to show you the payment and reconcile refunds and disputes.
Payout onboarding
Identity and bank verification is completed directly with Stripe on Stripe’s pages. The documents and identifiers you provide there are held by Stripe; we receive only whether your account can accept charges and receive payouts, its country and its currency.

31.Email Delivery and Sending on Your Behalf

All email is delivered through Resend. Our sending address is the From address on every message — including messages about your documents, and automated follow-ups. Your own email address is never used as the sender or the reply-to.

To you
Sign-in and verification links, welcome and onboarding messages, notifications when a document is signed, viewed-milestone and payment notices, invitation codes, billing and trial notices, and pre-launch updates.
To people you invite
An invitation naming your workspace and who invited them, with a link to accept.
To your clients
A notice that a document is ready for them, showing your workspace name — and automated follow-ups where you have enabled them (Section 22).
Your controls
Notification preferences let you choose, per category — signing, payments, comments, system — whether you are notified in the app, by email, or not at all, plus quiet hours during which email is held.
What preferences do not silence
Messages that are part of the service itself — sign-in and verification links, security notices, billing failures — and notices about the status of your account, such as a workspace being suspended or removed. Those are sent regardless of your notification settings, because you need to receive them.
Delivery failures
Our delivery provider tells us when a message could not be delivered, or when a recipient marked one as spam. We keep that record — the address, the reason, and the time — so that we stop sending to an address that permanently rejects our mail, or whose owner has told us to stop. It is not used for any other purpose.

Our transactional email carries no advertising or profiling pixels, and we do not use it to build a picture of your reading habits. We do not enable open or click tracking on it.

32.Legal Disclosures and Government Requests

We may disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims — for example in response to a valid court order, subpoena, or a lawful demand from a regulator or law enforcement agency.

Our practice:

  • we check that the request is valid, comes from an authority with jurisdiction over us, and is properly served;
  • we disclose the narrowest set of data that answers it, and push back on requests that are overbroad, vague or unsupported;
  • where a request covers a customer’s workspace and we can lawfully redirect it, we ask the requester to go to the customer, who controls that data; and
  • we tell the affected person that a request was made, unless we are legally prohibited from doing so or there is a genuine risk to someone’s safety or to an investigation.

We may also disclose data where necessary to prevent fraud, abuse or an imminent threat to someone’s safety.

33.Business Transfers

If Kinsei Lab is involved in a merger, acquisition, restructuring, financing or sale of assets, personal data may be transferred as part of that transaction or disclosed under confidentiality to a party evaluating it. Any acquirer remains bound by this policy in respect of data transferred to it, or must adopt a policy offering equivalent protection, until it gives you notice of a change and — where the law requires it — obtains your consent. We will tell you before your data becomes subject to a materially different policy, and where you have a right to object or delete, you will be able to exercise it first.

34.We Do Not Sell or Share Your Personal Information

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months — and we do not do so now. This applies to the specific meanings those terms carry under California law and the equivalent US state laws in Section 44, including disclosures for money and for other valuable consideration.

We also do not sell or share the personal information of anyone under 16.

There is nothing to opt out of because the product contains no mechanism that would make it possible: no advertising networks, no retargeting pixels, no tag managers, no data-broker integrations, no third-party analytics scripts, and no advertising identifiers (Section 40). Section 39 explains what that means for a Global Privacy Control signal.

Tracking

35.Cookies and Similar Technologies

EverBird.ai sets no advertising cookies and no tracking cookies, and shows no cookie consent banner — because it does not set the kind of storage that would legally require one.

The reason is architectural rather than a matter of policy. Consent banners exist because of the ePrivacy rule on storing or reading information on a person’s device. Our measurement of shared links does neither: nothing is written to a recipient’s browser, and nothing is read from it. The identifier used to tell one viewer from another is derived from the request itself, at our edge, and never leaves our systems (Section 37).

What we do store on a device is either strictly necessary to run the service, or a preference you set yourself. Section 36 lists every item, including the ones a shorter policy would leave out.

36.Categories of Cookies We Use

Cookies. Five, in two groups.

Sign-in — strictly necessary
Three cookies keep you signed in and let the server recognise your session. They are set on this site only, marked httpOnly so page scripts cannot read them, and cleared when you sign out. Without them an account is impossible.
Sidebar layout — preference, 1 year
Remembers whether you collapsed the sidebar, so the page does not jump on load. Set only after you change it.
Invite code — functional
If you arrived through someone’s invite link, the code from that link is kept so the person who invited you is still credited when you finish signing up, which may be days later. It is a public share code, not an identifier of you, and it is never read on any other site. Be aware of the mismatch between the two copies: the record we hold against your account is deleted after 30 days, while the copy in your browser has a much longer lifetime (up to 400 days) unless you clear your browser storage.

Local storage. Held in your browser, not sent with every request:

  • Measurement objection — if you use the Privacy control on a shared document, that choice is remembered on that device so we can honour it next time. It has no expiry and is removed if you opt back in.
  • Your brand kit — the business details you entered for your documents, including logo, contact details and any bank account, IBAN or routing details you chose to save for printing on invoices. It is kept on your device so the editor can fill a document without a round trip. Clearing site data removes it.
  • Draft send details — the recipient addresses and message you last typed into the Send dialog for a document, so reopening it does not lose your work. This is not cleared when you sign out — clear your browser’s site data to remove it, particularly on a shared computer.
  • First-touch attribution — where you first arrived from (Section 7). Written once, on your first visit.
  • Referral code — if you arrived on a founder referral link. Expires after 30 days and is deliberately not a cookie, so it is never sent with a request or readable by our edge network.
  • Interface state — a mirror of the sidebar preference, a dismissed sign-in prompt, and a cached copy of your onboarding checklist.
  • Account pin — the account that device-stored data belongs to, so another person signing in on the same browser never sees the previous account’s stored drafts or assets. Removed on sign-out.
  • Daily activity marker — a date, and nothing else, so we do not record the same active day twice. Only written while you are signed in.

IndexedDB. Signature, logo and seal images you have saved for reuse, and document drafts, are kept in your browser’s database because they are too large for ordinary storage. Cleared on sign-out.

Session storage. Nothing is written to it.

37.Analytics and Product Usage Measurement

Two different things, often confused, so taken separately.

Product usage — how signed-in customers use the app: feature events, daily-active counts, funnel steps and internal rollups. Tied to a workspace and an opaque account identifier (Section 7).

Recipient measurement — how someone engaged with a document you sent them (Section 11). This is the one that touches people who never chose us, so here is exactly how the visitor identifier works:

  • When a shared link is opened, our edge network takes the request’s IP address, the browser’s user-agent string, and the identifier of the document being opened.
  • It combines them with a secret key and passes them through a one-way keyed hash (HMAC-SHA256), then truncates the result. That short string is the visitor identifier.
  • The IP address is not stored, not logged, and never returned to the page. It exists only for the instant the hash is computed. The original address cannot be recovered from the identifier.
  • The key rotates every 30 days, so an identifier stops matching itself after a month.
  • The identifier is scoped to a single document. The same person opening two different documents produces two unrelated identifiers, so it cannot be used to follow anyone between documents, let alone across other websites.
  • If the secret key is not configured, no identifier is produced at all and views are counted without distinguishing visitors.

Approximate country, region and city come from the same edge lookup. Device type, operating system and browser are derived from the user-agent and reduced to broad families before anything is recorded — we keep “mobile, iOS, Safari”, not the full string.

38.Managing Cookie Preferences

Stop measurement of your visit
Every shared document and hosted upload carries a Privacy control at the foot of the page. It states whether the visit is being measured and turns it off immediately. The choice is remembered on that device, and applies to every document you open from us afterwards. It is an objection under Article 21 GDPR and we do not ask you to justify it.
What it stops, and what it does not
It stops everything in Section 11. It does not stop the single first-opened timestamp described at the end of that clause, and it does not affect a signature audit record, which is not measurement and not optional (Section 13).
Browser controls
You can clear cookies and site data, or block them, through your browser’s privacy settings. Clearing them will sign you out, and will reset preferences including a measurement objection — so you may want to set it again afterwards.
Everything else
Notification preferences and quiet hours are in your account settings; the public founding-member listing has its own toggle; and Section 45 covers requests we handle by email.

39.Global Privacy Control and Do Not Track

A Global Privacy Control signal tells a website you are opting out of the sale or sharing of your personal information. We do not sell or share personal information in the first place (Section 34), so there is no sale or sharing for such a signal to stop.

To be straightforward rather than merely compliant: we do not currently read the Global Privacy Control or Do Not Track header, and we will not claim to honour a signal we do not process. If we ever introduce anything that would constitute a sale or share, we will implement GPC handling before doing so and update this clause.

The effective control today is the Privacy control on the document itself (Section 38), which is honoured immediately and remembered.

40.Marketing and Advertising Technologies

There are none. EverBird.ai contains no advertising or ad-measurement technology of any kind:

  • no advertising networks or exchanges;
  • no conversion or retargeting pixels from any social or search platform;
  • no tag manager, and no third-party analytics scripts;
  • no audience-building, lookalike modelling or data-broker enrichment; and
  • no advertising identifiers, and no cross-site tracking.

Marketing email, where we send it, is separate from the transactional email in Section 31: it goes only to people who asked for it, every message carries an unsubscribe link, and unsubscribing never affects the service you receive.

Rights

41.Your Privacy Rights — Overview

Which rights you have depends on where you live, and the next three clauses set them out by regime. In practice we apply the same operational baseline to everyone who asks, wherever they are:

  • tell you what we hold about you and why;
  • correct it if it is wrong;
  • delete it, subject to the exceptions we state openly;
  • give you a copy in a portable format;
  • stop processing you have objected to; and
  • explain, in plain terms, any request we cannot fully grant, and why.

Exercising any of them is free, and never costs you access to the service (Section 48). Two limits apply throughout, and we would rather state them up-front than in a footnote:

  • If your data sits inside a customer’s workspace, we are the processor and the customer decides. We will identify them for you and pass your request on (Section 9, Section 51).
  • Signature audit records are retained even against a deletion request, because they exist as legal evidence (Section 13).

42.Rights Under GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland, you have the following rights in respect of data for which we are controller (Section 4):

Access — Art 15
Confirmation of whether we process your data, a copy of it, and the supporting information — purposes, categories, recipients, retention, and the source where we did not get it from you.
Rectification — Art 16
Correction of inaccurate data and completion of incomplete data. Most account and workspace fields you can edit yourself immediately.
Erasure — Art 17
Deletion where the data is no longer needed, where you withdraw consent that was the basis, or where you successfully object. The documented exception: signature audit records are retained under Article 17(3)(e), because they are necessary for the establishment, exercise and defence of legal claims. If your request touches one, we will tell you explicitly that it applies rather than silently keeping the record.
Restriction — Art 18
Suspension of processing while accuracy is contested, or while an objection is assessed.
Portability — Art 20
A copy of the data you gave us, in a structured, commonly used, machine-readable format, for processing based on consent or contract.
Objection — Art 21
You may object at any time to processing based on legitimate interests (Section 18). For shared-link measurement the Privacy control on the document is an immediate objection and needs no justification (Section 38). For anything else we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims.
Withdraw consent — Art 7(3)
Where consent is the basis, you can withdraw it at any time. This does not affect processing carried out before you withdrew.
Automated decisions — Art 22
Not applicable: we make no solely automated decision producing legal or similarly significant effects (Section 23).
Complaint — Art 77
You may complain to your supervisory authority at any time, without asking us first (Section 62).

We respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.

43.Rights Under California Law

California residents have the following rights under the CCPA as amended by the CPRA. Section 20 is the notice at collection.

Right to know
The categories and specific pieces of personal information we collected, the sources, the business purpose, and the categories of third parties it was disclosed to — for the 12-month period before your request, and beyond it where we can reasonably provide it.
Right to delete
Deletion of personal information we collected from you, subject to the statutory exceptions — including completing a transaction, detecting security incidents, complying with a legal obligation, and exercising or defending legal claims, which is what covers signature audit records (Section 13).
Right to correct
Correction of inaccurate personal information.
Right to opt out of sale or sharing
Nothing to opt out of. We do not sell personal information and do not share it for cross-context behavioural advertising (Section 34), and we have no “Do Not Sell or Share My Personal Information” link because there is no such processing to disable. Section 39 covers Global Privacy Control signals.
Right to limit use of sensitive information
Nothing to limit. We do not collect the categories California treats as sensitive personal information (Section 15).
Right to non-discrimination
Section 48.

We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.

44.Rights Under Other US State Laws

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island — have broadly equivalent rights: to confirm and access, to correct, to delete, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects.

Three points specific to those laws:

  • We do not conduct targeted advertising, sell personal data, or carry out profiling of that kind (Section 23, Section 34, Section 40), so those opt-outs have nothing to act on.
  • Where a law requires us to recognise a universal opt-out mechanism, Section 39 states our position honestly rather than claiming support we have not built.
  • Every one of these states gives you a right to appeal a refused request, which we set out at Section 49.

We respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.

45.How to Submit a Request

In the product, immediately. These need no request and take effect at once:

  • Delete your account — Account settings. Deleting requires your password, so if you only ever signed in with Google you will need to set a password first.
  • Delete or leave a workspace — deleting removes its documents, files, clients, threads, shares and comments, subject to Section 19.
  • Revoke sessions and devices, and sign out everywhere.
  • Change your email address or password, and link or unlink Google.
  • Edit your profile and workspace details — this is the fastest route to correction.
  • Set notification preferences and quiet hours.
  • Object to measurement — the Privacy control at the foot of any shared document (Section 38).
  • Remove your public founding-member listing.

By email, for everything else. Write to hello@everbird.ai from the address on your account where you can, and tell us what you want. To be straightforward about it: there is currently no self-serve export button — access, correction of records you cannot edit, portability and erasure-with-confirmation are handled by us by hand. That is slower than a button, and it is what we have today.

Recipients and signers who have no account can write to the same address. Say which document or link it concerns so we can find the record (Section 51). If the request concerns data inside a customer’s workspace, Section 9 explains what happens next.

46.How We Verify Requests

We verify before we act, because handing someone else’s data to the wrong person is itself a breach. How much verification depends on how sensitive the request is.

Signed-in actions
Already verified. Deleting your account, revoking a session or changing your email are authenticated actions, and the sensitive ones ask for your password again.
Email requests from account holders
We match the request to the address on the account, and may ask you to confirm details we already hold. We will not ask for identity documents for an ordinary request.
Requests from signers and recipients
Verified against the record itself — the link concerned, the name or address used at the time. If we cannot match you to a record with reasonable confidence we will say so rather than guess.
Deletion and access requests
Held to a higher standard than a correction, and we may ask one additional confirming question. If we still cannot verify you, we will tell you why and treat the request as an opt-out request where the law requires that fallback.

Information you give us purely to verify a request is used only for that, and is not retained afterwards beyond the record that the request was made and answered.

47.Authorized Agents

You may use an authorised agent to make a request on your behalf. We will ask for written permission signed by you, and we may contact you directly to confirm both that you gave permission and that you want the request made. We will also verify the agent’s own identity. Where an agent holds a valid power of attorney, we will accept that instead of the above. An agent acting without demonstrable authority will be refused, and we will tell them why.

48.Non-Discrimination for Exercising Rights

Exercising a privacy right will not get you worse treatment. We will not deny you the service, charge you a different price, give you a lower quality of service, or suggest that any of those might happen, because you asked us to access, correct, delete or stop processing your data. We operate no financial incentive or loyalty programme tied to personal information.

One honest caveat, which is a consequence rather than a penalty: if you ask us to delete data the service needs to function — your account, or the documents in your workspace — that data is gone and the parts of EverBird.ai that depended on it will no longer work for you. We will tell you what will be lost before we act on an irreversible request.

49.Right to Appeal a Denied Request

If we refuse a request in whole or in part, we will tell you which parts we refused and the specific reason. You can appeal that decision.

  • Reply to our decision, or write to hello@everbird.ai with “Appeal” in the subject line, within a reasonable time of the decision.
  • The appeal is reviewed by someone other than the person who made the original decision, wherever our size allows.
  • We respond within 45 days for US state-law appeals — the period those laws set — and within one month for GDPR and UK GDPR requests, with a written explanation of the outcome.
  • If we refuse the appeal, we will give you a means of contacting the relevant regulator, and Section 62 lists them.

You never have to appeal to us first. You may go straight to a supervisory authority or Attorney General at any point.

Team, portal and transfers

50.Team Accounts and Workspace Administrators

A workspace is shared, and that has consequences worth stating plainly rather than burying in a permissions table.

What administrators can see
Owners and administrators can see every document in the workspace, including documents a member created in a folder that member believed was private to them. Folder and library restrictions constrain ordinary members; they do not constrain owners and administrators. If you would not want your workspace owner to read it, do not put it in the workspace.
What they can see about members
Each member’s name, email address, role, and which folders and libraries they have been granted. They can change a member’s role, remove a member, and transfer ownership.
What they cannot do
They cannot see a member’s sign-in sessions or devices, cannot read a member’s password, cannot sign in as a member, and cannot see anything outside the workspace.
If you are invited to a workspace
Your name and email address are shown to that workspace’s owner and administrators. Work you do there belongs to the workspace, and stays with it if you leave.

Our own support access. A small number of named staff can enter a customer workspace to investigate a problem — typically a support request or a suspected abuse report. We disclose it because it is real access to real data, and the safeguards are:

  • access is limited to designated staff and cannot be granted from inside the product;
  • a banner is displayed in the workspace for the duration, so it is visible rather than silent;
  • a session expires automatically after 8 hours and must be started again;
  • every start and stop is written to a permanent audit log recording who did it, which workspace, and when; and
  • staff are bound by confidentiality obligations, and using access for anything other than the task at hand is a disciplinary matter.

If you would like to know whether your workspace has been accessed this way, ask at hello@everbird.ai and we will check the log and tell you.

51.Client Portal and Recipient Privacy

This clause is for you if you received a link. You do not have an account with us, you did not choose us, and you are entitled to know what happens when you open it. This is our Article 14 notice.

Where your data came from
The business that sent you the link. They typed your details in, or imported them from their own records. We did not obtain them from you or from any public source.
Who is responsible
That business controls the document and the details it holds about you. We store and deliver it for them (Section 4). For the measurement of your visit and for signature evidence, we are the controller.
Opening the link
Your visit is measured for the sender: pages, time spent, approximate location, device, browser, referring site (Section 11). No cookie is set and nothing is stored on your device. The basis is legitimate interest, and the balancing test is set out at Section 18.
Signing
Records your name, any email you supply, the time, your IP address, your browser, an approximate location, and a fingerprint of the document (Section 13). It is shown to you before you sign, it is not optional, and it is kept as legal evidence even if the document is later deleted.
Commenting
Stores what you wrote and the name you gave, and shows it to the sender. Optional, and no account is needed.
Reporting a payment
Stores the name you type, the method you chose and any note, and shows it to the sender. Optional.
Paying an invoice
Handled entirely by Stripe on Stripe’s own page. Your card details and the billing address you enter there do not pass through us (Section 30).
Automated follow-ups
If the sender has enabled them, you may receive reminder emails about an outstanding document. They are timed from whether you opened, signed or paid — never from the document’s contents (Section 21). Ask the sender to stop, or tell us.

Your controls. Use the Privacy control at the foot of the document to stop measurement immediately (Section 38). To have the underlying details corrected or removed, contact the business that sent it — they can do it directly. If you cannot identify or reach them, write to hello@everbird.ai naming the link, and we will identify them and pass it on, or act ourselves where the duty is ours (Section 9). The one thing we may be unable to erase is a signature audit record, and we will tell you if that is the case.

52.Referral and Invite Program

Two kinds of code can bring you to EverBird.ai: a workspace invitation, and a founder referral link. Both work the same way and neither is used to track you.

What the code is
A short public code printed on the link you clicked. It identifies the workspace or member who shared it — it is not an identifier of you, is not derived from anything about you, and is not read on any other website.
Why it is kept
Because signing up may happen days after you click. Keeping the code lets us credit the right person when you finish, rather than losing the connection the moment you close the tab.
Where it is kept, and for how long
In your browser, and — once you have an account — against that account until it is used. The account-side record is deleted automatically after 30 days if it is never used. The referral code in your browser expires on the same 30-day schedule; the invite code’s browser copy persists longer, as Section 36 explains.
What the referrer learns
That a referral was completed, and their running count. They do not receive your email address, your name, or anything about what you do in the product.
Founding-member listing
Separate and opt-in. If you turn it on, your workspace name, logo, website and the tagline you write appear on a public page. Turning it off removes the listing (Section 6).

53.International Data Transfers

Kinsei Lab is established in the United Arab Emirates. The infrastructure that runs EverBird.ai is not — so if you are in the EEA, the UK or elsewhere, your data is transferred internationally as a matter of course, and you should know where it goes.

United States
The database, backend and file storage that hold your account, documents and uploaded files; shared-link measurement; billing; email delivery; and Google sign-in if you use it. This is where the bulk of processing happens.
Globally distributed edge
Requests are served from the edge location nearest the visitor, which is also where the approximate location and the pseudonymous visitor identifier are derived (Section 37). The location depends on where the visitor is.
United Arab Emirates
Our own administration, support and business records.
Conditional
Microsoft receives a link to a file only when a legacy Office document is previewed; YouTube or Vimeo are contacted only where a workspace has set an intro video (Section 29).

The United Arab Emirates is not the subject of an adequacy decision by the European Commission, and neither is the United States except under the EU–US Data Privacy Framework for certified organisations. We state that rather than leave it to be inferred. Section 54 explains what we rely on instead.

54.Transfer Safeguards and Mechanisms

Where data leaves the EEA or the UK, we rely on the following:

  • Standard Contractual Clauses — the European Commission’s 2021 clauses, with the UK International Data Transfer Addendum where UK data is involved, incorporated into our agreements with subprocessors that offer them.
  • The EU–US Data Privacy Framework, where a subprocessor is certified under it.
  • Article 49(1)(b) — necessity for the contract. Where you ask us to store a document, send a link, take a payment or capture a signature, the transfer is necessary to perform the contract you asked for. This is what covers transfers to us in the UAE in the absence of an adequacy decision.
  • Supplementary measures — encryption in transit throughout, access limited to what a subprocessor needs, and the deliberate minimisation described in Section 11 and Section 37, which means our measurement provider never receives a name, an email address or a raw IP address in the first place.

Where we are today, stated honestly. We are a small company at the start of our life. The clauses above describe the mechanisms we rely on and are putting formally in place with each subprocessor; we are not going to claim a completed set of signed agreements as a marketing point. If you need our current transfer documentation for your own compliance file — a data processing agreement, a subprocessor list, or the transfer mechanism for a specific provider — ask at hello@everbird.ai and we will give you what we have, plainly. An Article 27 representative has not yet been appointed (Section 2).

Security and closing

55.How We Protect Your Information

The measures below are the ones actually in place, not a best-practice list we aspire to.

Transport
Everything is served over HTTPS. Our infrastructure providers encrypt data at rest on the storage they operate.
Sessions
Session cookies are marked httpOnly and are set only on this origin, so page scripts cannot read them and they are not mirrored into browser storage. You can revoke any session from your account settings, and changing your password revokes all other sessions.
Passwords
Account passwords are stored only as hashes. Passwords you set on a shared link or a hosted upload are stored as a salted PBKDF2 hash — we cannot recover them or tell you what they were.
Document integrity
Every saved version is fingerprinted with SHA-256, which is what proves a signed document has not been altered (Section 13).
Data minimisation by design
The visitor identifier is a one-way HMAC on a key that rotates every 30 days, so our measurement provider never receives a name, an email address or a raw IP address (Section 37).
Access control
Every read and write is authorised against the caller’s workspace and role. Staff access to customer workspaces is restricted, time-limited, visible to the customer and permanently logged (Section 50).
Payment integrity
Payment webhooks are cryptographically verified before their contents are read, so a forged payment notification cannot change your plan or mark an invoice paid.
Abuse limits
Public forms, signing attempts and checkout are rate-limited, and addresses that abuse the service can be blocked.

What we will not claim. No system is completely secure, and we are a small team. We do not hold an ISO 27001 or SOC 2 certification, and we will not imply one. If you need our current security documentation for a vendor review, ask at hello@everbird.ai and we will tell you exactly where we stand.

Your part matters too: use a strong, unique password, keep your email account secure since it can reset your password, review your active sessions occasionally, and think about who is in your workspace before you put something sensitive in it (Section 50).

56.Data Breach Notification

If personal data we hold is subject to a breach, we will investigate immediately, take steps to contain it, and notify as follows:

  • Supervisory authorities — where GDPR or UK GDPR applies, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people’s rights and freedoms.
  • The UAE Data Office — as required under Federal Decree-Law No. 45 of 2021.
  • Affected individuals — without undue delay where the breach is likely to result in a high risk to them, and in accordance with US state breach-notification laws where they apply.
  • Affected customers — where the breach concerns data we process on their behalf, so they can meet their own notification duties as controller (Section 4).

A notice will describe what happened, the categories and approximate number of records involved, the likely consequences, what we have done about it, what we recommend you do, and how to reach us for more. We will not delay a notification to make it look better.

57.Children’s Privacy

EverBird.ai is a business tool for invoicing and document workflow. It is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children, and we do not knowingly sell or share the personal information of anyone under 16 (Section 34).

We do not currently verify age at sign-up, so this rests on the service being what it is rather than on a gate. If you believe a child has given us personal data, write to hello@everbird.ai and we will delete the account and its data promptly. Parents and guardians may make that request on the child’s behalf.

A separate point worth making to customers: if you send a document to, or collect a signature from, someone under 18, that is your processing and your responsibility as controller (Section 4).

58.Third-Party Links and Integrations

Parts of the product take you to, or load content from, someone else’s service. Once you are there, their privacy policy governs, not ours.

Stripe
Card entry, hosted checkout and payout onboarding all happen on Stripe’s pages, which set their own cookies (Section 30).
Google
Signing in with Google takes you to Google’s consent screen (Section 8).
Microsoft Office Online
Previewing a legacy Word, PowerPoint or Excel file loads Microsoft’s viewer, which receives a link to the file in order to render it (Section 29). PDFs and images are rendered by us and do not involve Microsoft.
YouTube and Vimeo
If a workspace has set an intro video on its client portal, the player is loaded from YouTube or Vimeo and they receive the visitor’s request under their own terms.
Links inside documents
A customer can put any link in a document they send. We do not check or endorse them, and clicking one takes you outside our service entirely.

59.Region-Specific Disclosures

EEA, United Kingdom and Switzerland. Your legal bases are at Section 18, your rights at Section 42, retention criteria at Section 19, and transfers at Section 53Section 54. Where we obtained your data from a customer rather than from you, Section 9 and Section 51 are the Article 14 notice. We have not yet appointed an Article 27 representative (Section 2). You may complain to your national supervisory authority (Section 62).

California. Section 20 is the notice at collection, Section 43 sets out your rights, and Section 34 is our statement that we neither sell nor share personal information. We do not offer financial incentives for personal information. California residents may also request information under the “Shine the Light” law using the contact details at Section 61.

Other US states. Section 44 lists the rights and Section 49 the appeal process. We do not conduct targeted advertising, sell personal data, or profile in furtherance of decisions producing legal or similarly significant effects, so no opt-out is required for those activities. We have not conducted a data protection assessment because none of the triggering processing occurs.

United Arab Emirates. As a UAE-established business, Kinsei Lab processes personal data in line with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. UAE residents have rights of access, correction, erasure, restriction, portability and objection broadly equivalent to those at Section 42, and may complain to the UAE Data Office (Section 62). Cross-border transfers are made on the bases at Section 54.

Canada and Australia. Canadian residents have rights of access and correction under PIPEDA and may complain to the Office of the Privacy Commissioner of Canada. Australian residents have rights of access and correction under the Privacy Act 1988 and may complain to the Office of the Australian Information Commissioner. In both cases the routes at Section 45 apply, and we handle requests to the same standard as everyone else’s.

60.Changes to This Policy

The effective date at the top of this page is authoritative. We update this policy when what we do changes — not to reword it into something vaguer.

  • Material changes — a new category of data, a new purpose, a new subprocessor that handles your content, or a change that reduces your rights — are announced in the app and by email to account holders before they take effect. Where a change requires consent, we will ask for it rather than treat continued use as agreement.
  • Minor changes — clarifications, corrections, restructuring — take effect when posted, with the date updated.
  • We keep previous versions. Ask at hello@everbird.ai for the version in force on a particular date, or for a summary of what changed and why.

One commitment specifically: if we ever begin sending your content to a third-party model provider, or begin anything that would count as a sale or share, this policy will say so before it starts (Section 25, Section 34).

61.How to Contact Us

Email
hello@everbird.ai — for privacy requests, questions about this policy, and complaints. Put “Privacy” in the subject line.
Post
Kinsei LabSharjah Media CitySharjahUnited Arab Emirates
What to include
What you are asking for, and enough for us to find you — the email address on your account, or the link concerned if you are a recipient or a signer.
Response times
We acknowledge promptly and answer within one month for GDPR and UK GDPR requests, and within 45 days for US state-law requests, with the extensions described at Section 42, Section 43 and Section 44. If a request will take longer, we will tell you why before the deadline rather than after.

This policy is effective 4 August 2026 and applies to EverBird.ai, operated by Kinsei Lab.

62.How to Lodge a Complaint With a Supervisory Authority

You can complain to a regulator at any time. You do not have to come to us first, and doing so does not affect any other remedy. We would rather you raised it with us so we can fix it — but the choice is yours.

EEA
The supervisory authority of the member state where you live, work, or where the issue arose. A directory is maintained by the European Data Protection Board. We have not yet appointed an Article 27 representative (Section 2), so you may contact us directly in the meantime.
United Arab Emirates
The UAE Data Office, established under Federal Decree-Law No. 45 of 2021.
United States
Your state Attorney General. California residents may also contact the California Privacy Protection Agency.
Canada and Australia
The Office of the Privacy Commissioner of Canada, or the Office of the Australian Information Commissioner.

If you would like to raise something with us first, hello@everbird.ai — and Section 49 explains how to appeal if we get it wrong.

EverBird.ai

Everbird spots who’s stalling, decides when to follow up, and writes the message that closes the deal — automated client follow up software with one link for all client documents.

Pre-launch · Founders’ Circle open
Talk to the team

Our community is built into EverBird, and yes, we answer every email ourselves, always.

Contact us →
© 2026 Kinsei Lab. All rights reserved.