This page is in English. The English version is the official legal text.
Legal
Privacy Policy
We built Everchat so you can talk about a page without handing us an inbox. This policy describes what the system stores today. It is not a warranty, certification, or marketing slogan.
The short version. No email. No phone. No legal name required. No ads. No trackers. No analytics pixels. No sale of personal data for advertising. Your public handle and what you post are public on purpose. “Anonymous” here means we do not ask for an inbox identity - not that posts are private or untraceable in every technical sense.
1. Who we are
Everchat is a small indie project: a Chrome side-panel extension and the site at everch.at. The site exists so passkeys can bind to a real domain, and so these policies have a stable public URL. The operator of Everchat is the publisher named on the Chrome Web Store listing. We are not claiming SOC 2, ISO, or “GDPR certified” status - those are audits and programs we have not obtained.
Questions about this policy: the contact email on that listing, or legal@everch.at.
2. What this product is not
Everchat is not a private messenger. It is a public comment layer on URLs.
- Identity privacy means we do not ask for, store, or require email, phone, legal name, government ID, or a social login to use the product.
- Speech privacy is not on offer. Comments, handles, avatars, votes that affect public score, and the page URL you commented on are visible to anyone who opens that thread.
If you would not put a sentence on a public noticeboard, do not post it here. We will not pretend otherwise.
3. What we refuse to collect (product design)
By design, Everchat’s product surfaces do not collect the following. If that ever changes in a material way, we will update this policy and the effective date before shipping the change - we will not bury a new identity pipeline in a silent “minor update.”
- Email addresses (as an account field or recovery channel)
- Phone numbers
- Legal names or postal addresses of users (as account fields)
- Passwords (there are none - authentication is a passkey on your device)
- Google, Apple, or other OAuth identities as Everchat login
- Payment card details in the extension (the product is free to use; see support below)
- Precise GPS geolocation
- Advertising identifiers, cohorts, or lookalike audiences
- A cross-site browsing dossier - we do not build “users who visited X also visited Y” for ads or profiling
- Keystrokes, screenshots, or the contents of the host page beyond what is listed in §4
We do not run ads in the product. We do not load advertising or product-analytics pixels (no Google Analytics, Meta Pixel, Mixpanel, PostHog, or equivalent). This website is intended to load first-party assets; fonts are hosted here, not on Google Fonts. Infrastructure vendors may still see ordinary network requests as described in §7.
We do not sell, rent, or “share for targeted advertising” personal data. There is no advertising partner list because there are no advertising partners.
Support. Voluntary support goes through Buy Me a Coffee. Payment details are processed by Buy Me a Coffee and its payment partners under their own policies; Everchat does not receive card numbers. Support records held by those providers are subject to their terms and privacy notices. Support does not buy preferential ranking, viewpoint protection, or special treatment.
4. What we do store, and why
Storage exists to run a public forum attached to URLs. If a field is not required for that, it should not exist.
Account (only if you sign in anonymously)
- Handle - the public
@nameyou claim (3-20 characters,a-z,0-9, underscore). - Passkey / WebAuthn material - credential ID, public key, sign counter, optional device label, last used time, and related ceremony state needed to verify assertions. The private key never leaves your authenticator. We cannot reset an account by email because we do not have an email.
- Optional avatar - an image you upload, stored so others can see it next to your handle.
- Karma - a public integer derived from other people’s votes on your posts (your votes on yourself do not count toward karma).
- Account created time and similar account metadata needed to operate the profile.
- Session tokens - short-lived credentials that keep you signed in after a successful passkey assertion.
While you use the extension
- Canonical page URL - host + path (and meaningful query params), with tracking parameters stripped (utm_*, fbclid, gclid, and similar noise). That string is the room ID. We keep title, short description, and favicon when available so the thread can show which page it belongs to. Opening Chat can refresh that page metadata.
- Messages - body text (up to 300 characters), optional GIF URL, parent message if it is a reply, timestamps, vote totals. If you delete your own post we remove that content from live systems; a content-empty structural placeholder may remain only so replies can keep their place in the thread.
- Votes - which handle voted +1 or −1 on which message (needed to prevent double-voting and to compute score).
- Notifications - if someone replies to you: actor, message ids, page URL, a short preview. Chrome may also show a local OS notification on your machine; that notification is not a channel we use to email you.
- Reports - if you flag a message, we store reporter, message, optional reason. We review stored reports on a monthly basis for illegal abuse, Terms violations, and other legal-floor patterns - not for ideology or opinion policing. Reports are not a backdoor to viewpoint moderation.
- Rate-limit counters - per handle, per action, per short time window, to slow floods. This is plumbing, not a reputation score we sell.
- Ephemeral WebAuthn challenges and short-lived handle reservations - they expire. They are not a durable user profile by themselves.
On your device only
The extension uses Chrome storage for a session so you stay signed in
in the side panel. That session lives in the browser. We do not sync it to
a marketing CRM. There is none.
5. What the extension can see
Everchat is a side panel. It does not inject a content script into the page you are reading. It does not scrape the article body.
Chrome permissions, used as declared in the extension manifest:
- sidePanel - to open the panel.
- tabs / activeTab - to know the active tab’s URL, title, and favicon so we can open the matching thread. We canonicalize that URL and drop tracking parameters before it becomes a room.
- storage - session and local extension state.
- notifications - optional OS alerts for replies.
- https://*.supabase.co/* - the API that holds threads, auth ceremonies, and avatars. Not a license to roam the web.
Reading a thread does not require an account. Writing, voting, and Profile do. Lurking does not create a handle.
6. Tracking we strip, tracking we will not add
Share links are full of surveillance leftovers. Everchat’s canonical URL algorithm deletes them so “the same article” stays one conversation, and so we are not storing campaign IDs that point at a person as room identity.
We do not intentionally:
- Fingerprint your browser for advertising
- Drop advertising cookies from Everchat
- Follow you across sites to retarget you with ads
- Feed your comments into a model we train on user content for ads or surveillance (we don’t run that business)
- Use “legitimate interest” as a euphemism for advertising profiling
This website and API will still send normal HTTPS requests to our hosts when you load a page or use the extension. That is how the web works. Those requests are not an advertising tracker we score into a behavioral profile, but they may create ordinary operational logs (see §7). Marketing lines like “no trackers” mean we do not track users with advertising or product analytics - not zero network metadata for all time.
7. Processors (people who see packets, not a product we are)
To run at all we use infrastructure. They process data on our instructions (or as needed to provide their service). They are not given a license to mine Everchat users for ads on our behalf.
- Supabase (Postgres, Auth-adjacent Edge Functions, Storage, Realtime) - application database and files.
-
Vercel - hosts this website and
/.well-known/webauthn. - Google / Chrome Web Store - distributes the extension. Their store, account, and review systems are Google’s, not ours. Install-time identity (your Google account) is between you and Google. Everchat does not receive that Google account as an Everchat login field.
- Giphy - only if you search for a GIF. The query goes through our Edge Function so the Giphy API key is not shipped in the extension. Giphy then sees the search string. If you do not search GIFs, this does not run. GIF files you insert are third-party URLs displayed in the thread.
- Buy Me a Coffee - if you support Everchat; payment details are processed by Buy Me a Coffee and its payment partners under their own policies. Everchat does not receive card numbers.
Passkeys may sync through Apple, Google, or a password manager on your side. That is your authenticator vendor, not an Everchat account field. We receive a public key and related WebAuthn fields. We do not receive the email those companies associate with your vault.
Hosts and CDNs typically keep short-lived access logs (IP address, user-agent, timestamp, request path) for abuse prevention, security, billing, and uptime. We do not treat those logs as a substitute for an email account, and we do not use them to build advertising profiles. We may use them, for a limited time, to debug outages, rate-limit abuse, or respond to security incidents. Retention depends on the vendor’s defaults and our operational needs; we aim to keep such logs only as long as reasonably necessary for those purposes.
Processors may store or process data in countries other than where you live. By using Everchat you understand that data may move across borders as needed to run the service through those vendors.
8. Retention
We do not promise a single fixed deletion clock for every row, because this is a public forum and a small project without a dedicated compliance team. In practice:
- Public posts, votes, handles, avatars, page metadata, and karma remain while the account/thread exists and the service is operating, unless you delete your own message, we delete data after a valid request we can authenticate, or we remove material under the Terms.
- Deleted messages - we remove post content (body and media) from our live database when you delete. If replies still need the row for thread structure, a content-empty placeholder may remain until those replies are gone; it does not keep a recoverable copy of what you wrote. Ephemeral backups and rare legal holds may lag live deletion until rotated or released.
- Ephemeral challenges, handle reservations, and rate-limit counters expire on short windows.
- Backups may lag live deletions until rotated.
- Operational / access logs - as described in §7; not retained as a commenter identity store.
9. Legal demands
We do not volunteer user data to random requesters. We do not run a “trust and safety identity team.”
If a binding court order, warrant, or other compulsory legal process that applies to us validly requires production, we will produce what we actually have - which is not an email, not a phone, and not a legal name as account fields. Typically that is a handle, public posts, WebAuthn/account technical records listed in §4, and whatever limited operational logs still exist.
We do not intend to expand collection solely to make future fishing easier, or to build a real-name pipeline because a third party wishes we had one.
10. Your rights and how to exercise them
You can, in the product:
- Read without an account
- Delete your own messages (content removed from live systems)
- Change or remove an avatar
- Add or revoke passkeys on the account (keep at least one while the account exists)
If you want the handle and remaining records deleted, contact legal@everch.at from a place we can reasonably tie to the account (for example by completing a passkey assertion we challenge, not by sending a screenshot of a @handle). We will not invent an email-based recovery flow to “help.” As a small project we will respond in good faith and within a reasonable time; response times are not guaranteed.
Public replies other people wrote, and copies that already left our servers (screenshots, scrapers, archives), are outside what we can unsay. Deletion on Everchat is deletion of our hosted copy, not a worldwide memory hole.
If you are in a region with statutory access, correction, deletion, or portability rights, tell us which rights you are exercising and how we can verify the account. We will try to honour applicable rights for the data we hold, subject to exceptions (for example legal retention, security, or freedom of expression of others’ public replies). We do not use your data for automated decision-making that produces legal effects about you. There is no ad auction.
11. Children
Everchat is not directed at children under 13, and we do not knowingly collect personal information from them. Do not create a handle if you are under 13. If you believe a child under 13 has an account, write legal@everch.at and we will delete it when we can reasonably confirm the issue. Where local law sets a higher digital-consent age, do not use Everchat below that age.
12. Changes
If we collect a new class of personal data, or introduce ads or product analytics, this page will say so with a new effective date before (or as) the product ships that change. We will not treat a tracking SDK as a silent “minor update.”
A future analytics tool, email gate, or advertising SDK would be a material product change. It is not something we currently intend to flip on without saying so here - but this policy describes the present design, not an eternal covenant that the project can never evolve.
13. Chrome Web Store disclosures
For store review: the extension’s single purpose is public commentary on the URL you already have open. User data we handle is limited to §4 and ordinary operational processing in §7. Use is limited to providing that commentary feature, security (passkeys, rate limits, abuse defense), and displaying the thread. We do not use or transfer user data for purposes unrelated to the item’s single purpose, and we do not sell it.