PRE-LAUNCH POLICY DRAFT
Privacy Policy.
Last updated: .
EveryGen AI is available as a public preview. Real purchases remain closed, and generation requires funded production credits. These prepared policies describe the current release and the confirmed refund rule. Commercial effectiveness awaits final operating details, a working support mailbox and payment readiness.
Operator and contact
Named operator: 李靖 (Li Jing).
Country/region: China.
Website: https://everygenai.live. Service, billing, refund, security and privacy contact: support@everygenai.live (mailbox setup and receiving verification pending).
Controller and scope
This policy describes personal data processed by EveryGen AI for its public-preview website, sign-in, media workspace and billing. The confirmed operator name and country, together with the designated contact, appear below. Commercial purchases remain closed while the support mailbox and commercial prerequisites are completed. Third-party websites and sign-in providers also have their own policies.
Account and security information
Google sign-in supplies your account identifier, verified email, name and avatar. Auth.js stores user records, linked provider accounts, authentication tokens and database sessions in Cloudflare D1. We use them to sign you in and associate media, jobs and orders with your account. GitHub and email sign-in are not configured in the current release. We do not collect an EveryGen password. Rate-limit records and operational errors support abuse prevention and troubleshooting; hosting providers may process network and request metadata.
Creative work and task information
The application stores prompts, model choices, output settings, reference media metadata, media ownership, task identifiers and statuses, provider references, assistant plans and results, generation errors and content-check decisions. Uploaded and retained generated files use Cloudflare R2. These records provide your media library, generation workflow, task recovery and content controls. Do not upload sensitive personal data or another person's likeness or voice without the necessary authority.
Billing and customer communication
EveryGen stores account and order references, plan or pack identifiers, amounts, currency, payment and refund status, provider event references, credit balances, reservations and credit transactions. Waffo Pancake receives your buyer email, account identifier and order information to process checkout, payment and refunds. Full card details are handled by Waffo Pancake and are not stored by EveryGen. Current transactions are sandbox tests. Support correspondence will be processed when the designated mailbox is operational and you contact it; it is not a currently verified support system.
Purposes and applicable legal bases
We use account and creative data to provide the service you request, and billing data to deliver and reconcile purchased entitlements. Security and fraud controls protect accounts and the service. Where applicable law uses these concepts, the bases are performance of the requested service, legitimate interests in security and resolving errors, and legal obligations for payment records or lawful requests. Consent applies where required for optional processing. There is no active marketing or advertising-data sale integration. A sign-in or upload does not authorize an unrelated marketing purpose.
Service providers and international processing
Google provides sign-in. Cloudflare Workers hosts the website, D1 stores account and task records, and a private R2 bucket stores uploaded or retained media. Waffo Pancake processes separate sandbox payments and would process enabled commercial payments; real checkout is currently closed. A funded AI request sends API Mart the prompts, reference media and settings needed for the chosen video or assistant request, as well as required moderation inputs. Insufficient credits prevent submission. API Mart and its underlying model providers may process inputs under their own terms. Providers can operate outside your country. Provider transfer safeguards must be assessed before commercial launch; no unverified regional restriction or contractual safeguard is promised here.
Cookies and browser storage
Necessary cookies maintain authenticated sessions and OAuth security. Browser storage remembers theme preferences and local draft prompts, selected generation settings and assistant drafts. Local storage is on the device and is not the same as a server account record. Clearing browser storage can remove local drafts and preferences; it does not delete uploaded media, jobs or billing data. This release has no third-party analytics, advertising pixels or marketing-email integration. You can manage browser cookies and storage, but disabling necessary cookies can prevent sign-in.
Retention and expiry
Generated video files, retained thumbnails and final frames are available for 24 hours after completion. Download files you want to keep. Access stops at the displayed expiry time; a scheduled task runs every two minutes to delete expired R2 objects and retries failed deletions. A one-day R2 lifecycle rule also removes generated objects, including interrupted copies; lifecycle processing can lag the expiry time. Prompts, settings, task history and credit/payment records remain after video files expire. Uploaded source references have a separate lifecycle and are not covered by this generated-file deadline. Database sessions expire after 30 days and email verification links after 10 minutes when email sign-in is enabled. Signed reference links stop access at their encoded expiry; this does not delete source files. Account, source-media, content-check and billing records currently have no scheduled retention cleanup. A complete deletion/export workflow and commercial record-retention schedule are not yet available.
Security and disclosure
Account ownership checks restrict private tasks and uploads. External AI media references use time-limited signed links; anyone holding a valid link can access the referenced file until it expires. Merchant signing keys stay server-side. Payment status is checked with the provider, and signed events are processed idempotently. Avoid sharing signed links, passwords, verification links or API keys. No system is entirely secure. Security notifications and legally required disclosures will follow applicable law; we do not claim an unverified certification or fixed incident-response deadline.
Your rights and requests
Depending on applicable law, you may request access, correction, deletion, a portable copy, restriction or objection to processing, or withdrawal of consent where consent is the basis. Legal payment-record obligations can limit deletion of some records. Use the verified privacy contact once it is operational and identify your registered account without sending credentials or card numbers. Account ownership may need verification. You may also complain to the relevant data protection authority. Self-service account deletion and export are not currently implemented.
Age threshold and policy changes
EveryGen is intended for people aged 18 or older. It is not intended to collect children's information. If you believe a child has submitted personal data, contact the verified channel when available. We update the date on this page when practices change, and material changes will be displayed on the website. This draft does not establish that commercial launch or a Waffo account review has been completed.
Provider privacy policies
Google · Cloudflare · Waffo Pancake · API Mart (when enabled)
API Mart processing must be enabled and its applicable provider terms reviewed before real AI requests are opened.