Privacy Policy
Contents
1. Who we are
This Privacy Policy describes how Blue Horizon Ventures ("Everest", "we", "us", or "our") collects, uses, stores, and shares information when you use the Everest application, website, APIs, integrations, and related services (the "Service"), accessible at everest.ag and cal.everest.ag (and the legacy alias app.everest.ag).
Everest is operated from Newark, Delaware, USA. For data protection purposes, the data controller is Blue Horizon Ventures, contactable at privacy@everest.ag.
2. Data we collect
2.1 Account information
- Email address, display name, and authentication identifier provided when you sign up
- Profile data you choose to add (e.g. timezone, working hours, role)
- Channel identifiers if you link a messaging channel — currently Telegram (your Telegram chat ID)
- The scheduling address Everest issues you (
your-handle@ai.everest.ag), which is how you CC Everest into an email thread
2.2 Connected-service data
When you authorise Everest to access third-party services on your behalf — such as Google or Microsoft — we receive data from those services through their official APIs. The specific data depends on the scopes you grant; see Section 3 for Google in detail.
2.3 Conversation and usage data
- Messages you send to Everest through any channel and the responses we generate
- Email threads you CC Everest into, including the message bodies, headers, participants, and attachments of those threads
- Voice notes you send Everest, and the text transcription we produce from them
- Scheduling outputs Everest produces on your behalf — proposed times, calendar events, and the emails it sends
- Bug reports you submit from the dashboard, including any screenshot or diagnostic context you choose to attach
- Technical logs (IP address, user agent, timestamps, error traces) needed to operate, secure, and debug the Service
- Aggregate usage metrics (feature counts, latency) used to operate and improve the Service
2.4 Waitlist data
If you join the waitlist before you have an account, we collect the email address, name, role, and calendar provider you submit, plus the page you signed up from, so we can contact you when we open access.
3. Google user data
If you connect a Google account, Everest accesses Google user data only with your explicit OAuth consent and only for the scopes you grant. Everest's Google access is focused on one job: scheduling — checking availability, resolving the people you mention by name, and managing calendar events on your instruction. The current scope set, and what each is used for, is:
| Scope | What we do with it |
|---|---|
| openid, userinfo.email, userinfo.profile | Identify you and link your Google identity to your Everest account |
| calendar.events | Read events on your calendars to answer scheduling questions, and create, update, or cancel events on your instruction |
| calendar.freebusy | Check when you — or a colleague whose calendar is visible to you — are free or busy before proposing or booking a time |
| calendar.calendarlist.readonly | List the calendars you subscribe to, so your schedule view covers all of them |
| calendar.settings.readonly | Read your calendar settings (e.g. timezone) so events are booked at the right local time |
| directory.readonly | Look up colleagues in your organisation's Google Workspace directory when you mention them by name (e.g. "is Sam free at 3pm?"), so you don't have to paste an email address |
| contacts.readonly | Look up people in your saved contacts by name for the same purpose |
| contacts.other.readonly | Look up people in your "Other contacts" (contacts Google saves automatically from your interactions) by name for the same purpose |
Scopes we no longer request. Before July 2026, Everest requested broader Google scopes (including Gmail, Drive, Docs, Sheets, Tasks, Google Analytics, and Google Ads). We no longer request any of these. If you granted them previously, you can narrow your grant by disconnecting and reconnecting Google in Everest, or revoke access entirely at any time (see below). Data previously obtained under those scopes is retained only as part of your conversation history and derived notes, per the retention schedule, and you can delete it at any time.
You can revoke Everest's access to your Google account at any time from the Integrations settings in Everest or via your Google Account permissions page. Revocation takes effect immediately for new requests; cached data is deleted per the retention schedule.
4. People you schedule with
Everest's core feature is scheduling with other people. When you CC your Everest address into an email thread, or ask Everest to arrange a meeting, we necessarily process personal data about the other participants — people who are not Everest users and have not signed up with us.
For those participants we process: their name and email address as they appear in the thread or as you provide them, the content of the messages they send to the thread Everest is on, the availability and scheduling preferences they state, and the calendar invitations Everest sends them.
- We process this data on your instruction, for the sole purpose of arranging the meeting you asked for. We do not build profiles of participants, market to them, or use their data for any other customer.
- Participant data is subject to the same subprocessors, security, and retention rules as the rest of your conversation history — including being sent to our LLM providers so Everest can understand the thread.
- Everest's messages are sent from an address on the
ai.everest.agdomain, so recipients can see that an assistant is handling the scheduling. - You are responsible for having a proper basis to share a participant's contact details with us, and for using Everest's email sending in line with the acceptable-use rules in our Terms — in particular, not for unsolicited bulk outreach.
- A participant can ask us to delete their data, or to stop being contacted, by emailing privacy@everest.ag. We honour those requests regardless of whether they hold an Everest account.
5. How we use data
- Provide the Service — answer your messages, negotiate and propose meeting times, and create, update, or cancel events on the calendars you connect
- Operate, secure, and maintain the Service — authentication, abuse prevention, fraud detection, debugging
- Communicate with you about your account, security, and material changes to the Service
- Comply with legal obligations and respond to lawful requests from authorities
We do not use your data, including Google user data, to train, fine-tune, or evaluate generalised AI models. We do not sell your personal data. We do not use it for targeted advertising.
6. AI processing
Everest is an AI-driven product. To understand your messages and schedule on your behalf, we send relevant context (your messages, the email thread Everest is CC'd on, calendar entries, contact lookups) to large-language-model (LLM) providers acting as our subprocessors. These providers process the data on our instruction under their standard API terms, which exclude using API data to train their models.
We currently use OpenAI as the primary provider, with Fireworks AI and Anthropic as automatic fallbacks when the primary provider is unavailable. Because a request can fail over, you should assume any of the three may process a given message. The current set is reflected in Section 7.
Because LLM outputs are probabilistic, Everest may occasionally make mistakes. You remain responsible for reviewing material actions Everest is about to take on your behalf, and for the consequences of actions you authorise.
7. Sharing & subprocessors
We share data only with subprocessors who help us operate the Service, and only as needed for them to perform their function. Each is bound by a data processing agreement, or by data-protection terms in their standard API terms, that restricts their use of your data to providing services to us.
7.1 Infrastructure
| Subprocessor | Purpose | Region |
|---|---|---|
| OVH | Application servers and network | EU (France) |
| Supabase | Database, authentication, backups | EU |
| Porkbun | Domain registration and DNS | US |
7.2 AI processing
| Subprocessor | Purpose | Region |
|---|---|---|
| OpenAI | LLM inference — primary provider for the scheduling assistant | US |
| Fireworks AI | LLM inference — automatic fallback | US |
| Anthropic | LLM inference — automatic fallback | US |
| ElevenLabs | Speech-to-text, only for voice notes you send | US |
7.3 Communications
| Subprocessor | Purpose | Region |
|---|---|---|
| Brevo | Sending and receiving the scheduling emails Everest handles on your behalf. Brevo processes the content of threads you CC Everest into. | EU (France) |
| Resend | Account and waitlist email (sign-up confirmations, invitations) | US |
| Telegram | Message delivery, only if you link a Telegram account | Various |
| Google (Calendar, People APIs) | Reading and writing your Google calendar and resolving contacts, under the scopes you grant | Global |
| Microsoft (Graph API) | Reading and writing your Outlook calendar, under the scopes you grant | Global |
7.4 Operations
| Subprocessor | Purpose | Region |
|---|---|---|
| Linear | Issue tracking — a bug report you submit becomes a Linear issue, including what you attach to it | US |
| Google (Sheets / Apps Script) | Recording waitlist sign-ups before you have an account | Global |
Our public website and dashboard also load web fonts from Google Fonts and images from Unsplash, and our home page displays a listing badge served by There's An AI For That. These providers receive your IP address and browser user-agent as a normal consequence of serving those files. They receive no account or calendar data. See Section 12.
Services we no longer use. Earlier versions of this policy listed Composio, Nango, Discord, WhatsApp (Meta), and Google Gemini. Composio and Discord have been retired from the Service; Nango was evaluated but never integrated; WhatsApp is not currently available as a channel; and Gemini is used only in our internal offline test suite, which never receives customer data. None of them process your data today.
We do not share your data with advertisers, data brokers, or for marketing purposes.
We may disclose data when legally required (e.g. valid subpoena, court order), to enforce our Terms of Service, or to protect the rights, safety, or property of Everest, our users, or others. Where lawful, we will notify you of any government request for your data before disclosing it.
8. Storage & security
Everest's application servers run on OVH infrastructure in France. Account data, conversation history, and backups are stored in our Supabase database, hosted in the European Union.
OAuth refresh tokens for connected services are stored encrypted at rest. Backups are encrypted in transit and at rest.
We use industry-standard administrative, technical, and physical safeguards designed to protect your data against unauthorised access, disclosure, alteration, and destruction. No system can be perfectly secure; in the event of a personal data breach, we will notify affected users and competent authorities within the timeframes required by applicable law.
9. Retention & deletion
- Account data — for the life of your account, plus 30 days after deletion to allow recovery from accidental deletion
- Conversation history — for the life of your account, unless you delete individual conversations sooner
- Cached Google and Microsoft calendar data — only as long as needed to fulfil your active request, typically minutes; durable results (scheduling notes, booked events) are stored as your conversation history above
- Email threads Everest is CC'd into — for the life of your account, as part of your conversation history
- Logs — 30 days for application logs, 12 months for security/audit logs
- Backups — 30 days rolling
- Legal-hold data — for as long as required to comply with applicable law or to assert/defend legal claims
You can ask us to delete your Everest account at any time by emailing privacy@everest.ag. We action deletion requests within 30 days: your data is removed from our active systems within that window, and from backups within 90 days. A self-service deletion control in the dashboard is planned; until it ships, email is the route and we will confirm to you in writing when the deletion is done.
10. Your rights
Subject to applicable law (including the EU General Data Protection Regulation where it applies to you), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data ("right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a structured, machine-readable format (data portability)
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email privacy@everest.ag. We respond within 30 days of receipt.
11. International transfers
We are a US-based company and our primary data storage is in the European Union, but several of our subprocessors — including our LLM providers — are in the United States, so personal data of EEA and UK users is transferred outside those regions.
For those transfers we rely on: the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum; the EU–US Data Privacy Framework for subprocessors certified under it; and supplementary technical measures, including encryption in transit and at rest, where required.
12. Cookies and similar technologies
The Everest dashboard uses a small number of strictly necessary cookies for authentication and session management. On the public Everest website, we also offer optional Google Analytics cookies to understand aggregate landing-page traffic. We load Google Analytics only after you allow analytics in the cookie banner, and we do not use third-party advertising cookies.
If you decline analytics, Everest stores that preference in your browser and does not load Google Analytics. You can later change your preference by clearing site data for everest.ag in your browser.
Separately from cookies, our pages load some assets from third parties — web fonts from Google Fonts, images from Unsplash, and a listing badge from There's An AI For That on our home page. These requests disclose your IP address and browser user-agent to those providers. They do not set advertising cookies for us and receive no account or calendar data.
13. Children
Everest is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, please contact privacy@everest.ag and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will provide additional notice — for example, by emailing the address associated with your account or by displaying a prominent notice in the Service — at least 14 days before the change takes effect.
15. Contact
For privacy questions, data subject requests, or any concern about this policy, contact:
Blue Horizon Ventures
Newark, Delaware, USA
Email: privacy@everest.ag