Draft — pending legal review.

EverHandled is in early beta — we're still refining the product and our policies.

Privacy Policy

Last updated: August 2026

Introduction

This Privacy Policy explains what information EverHandled collects, how we use it, and how we protect it. It applies to everyone who uses EverHandled. By using the service, you agree to the practices described here.

This is an early, plain-language draft of our policy, written to reflect how EverHandled actually works today. It has not yet been reviewed by a lawyer — see the note at the top of this page.

What we collect

We collect four kinds of information:

  • Account information. When you sign up, we collect your email address. If you sign in with Google, we also receive the name associated with your Google account.
  • Vault data. The information you choose to store in your vault — for example bank account details, investment details, loan details, passwords, and notes. Nothing here is required; you decide what to add.
  • Nominee details. If you add a nominee (someone who can access your vault under conditions you set), we collect their name, email address, and their relationship to you, so we can invite them and contact them if access is ever granted.
  • Technical & usage data. Like most web services, our hosting and infrastructure providers (Vercel, Supabase) automatically log basic technical information — such as IP address, browser type, and request timestamps — for security, debugging, and abuse prevention. We do not run any analytics or tracking tools (no Google Analytics, ad trackers, or similar) — we don't collect data about how you use the app beyond what's needed to operate it.

We also use your browser's local storage to keep you signed in between visits. This is not a tracking cookie, and it does not contain any vault data.

How your vault is protected — zero-knowledge encryption

Your vault — bank accounts, investments, loans, passwords, and notes — is encrypted on your own device with a key derived from a passphrase only you know, before anything is ever sent to our servers. That passphrase never leaves your device and is never transmitted to us in any form. We only ever receive and store ciphertext.

Because of this, we cannot read the contents of your vault. There is no master key, no admin override, and nothing in our systems that lets us — or anyone with access to our database — see your entries in plain form. This is a genuine zero-knowledge design: even if compelled, we have nothing readable to hand over. It depends on you keeping your own device and passphrase safe (for example, from malware or phishing) — that part is outside what encryption alone can protect.

This cuts both ways: if you forget your passphrase and haven't set up a nominee, your vault data is unrecoverable — permanently, even by us. We consider that a feature, not a limitation. It's what makes "even we can't read it" actually true, rather than a line in a privacy policy.

A nominee you've granted access to decrypts the entries you've shared with them using their own key — never a copy of yours, and never ours. When you share entries with a nominee, we create a separate encrypted copy of each entry's key addressed specifically to them, so they can unlock only what you've chosen to share.

One scope note, so this claim isn't broader than it should be: the protection above covers your vault contents. A nominee's email address is stored unencrypted, because we need it in plain form to send invitation and status emails, and a nominee's name and relationship to you are currently encrypted using a different method that is not zero-knowledge in the same way — a known gap we intend to close in a future update.

Legal basis for processing

We process your account information and the (encrypted) vault and nominee data you provide based on your consent — you create an account and choose to store information voluntarily, and you can withdraw that consent at any time by deleting your data or your account (see "Data retention" below). Where India's Digital Personal Data Protection Act, 2023 applies, we intend for this to qualify as lawful processing on the basis of your consent; this has not yet been confirmed by a lawyer.

Third parties we use

We rely on a small number of service providers to run EverHandled. Each only processes the data needed for its function:

  • Supabase — our database and user authentication provider.
  • Resend — sends transactional emails (invitations, verification codes, access notifications).
  • Vercel — hosts the application.
  • Google — if you choose to sign in with Google, Google processes that sign-in on our behalf.

We do not sell your data, and we do not share your vault contents with any third party other than as described above to operate the service, or a nominee you've explicitly chosen to share entries with.

These providers may process and store data outside India as part of operating their services. Each has its own privacy policy governing how they handle data on our behalf.

Your rights

Under India's Digital Personal Data Protection Act, 2023 (where applicable) and as a matter of policy everywhere else, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or outdated information.
  • Erase your data, including your full account.
  • Withdraw consent at any time, which you can do by deleting your data as described below.

You can exercise most of these rights directly in the app, without waiting on us: delete individual vault entries, remove a nominee, or use Reset vault (available from the vault-locked screen's "Account management" option) to immediately and permanently erase all of your vault data, nominees, and encryption keys. For anything Reset vault doesn't cover — including full account deletion — email us at everhandled@gmail.com.

Data retention & account deletion

We keep your account and vault data for as long as your account is active. If you delete a vault entry or remove a nominee, it's removed from active use immediately.

Reset vault is a self-service option (reachable even without your passphrase, from the unlock screen's "Account management" link) that immediately and permanently deletes all of your vault entries, nominees, and encryption keys, and starts you fresh with a new passphrase. It does not delete your login — your email or Google account stays registered with us.

Full account deletion — removing your login entirely — isn't yet a self-service action. Email us and we'll delete your account and any remaining data within a reasonable time of your request. As this is a draft policy, we're not yet committing to an exact number of days — that will be finalized after legal review.

Children's data

EverHandled is not directed at, or intended for use by, children under 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, contact us and we'll delete it.

Where your data is hosted

EverHandled runs on infrastructure operated by our third-party providers (Vercel for hosting, Supabase for our database). We have not yet finalized a specific data-residency commitment — your data may be stored and processed in India or in other countries where these providers operate. This will be addressed more precisely as part of legal review.

Changes to this policy

We may update this policy as EverHandled changes or as we complete legal review. We'll update the "Last updated" date above when we do. Continued use of EverHandled after a change means you accept the updated policy.

Contact

Questions about this policy or your data? Email everhandled@gmail.com.