Privacy policy
Your information, in your control
Effective October 5, 2026. Everyday Paper is operated by SVK Foundry LLC.
The short version
- The native apps keep your library on your devices. Optional iCloud and Web sync keep additional copies in the services you enable.
- The website stores account information, notes and attached files on servers operated for Everyday Paper. Cloud features process the information needed to provide the feature you use.
- Google mail access and Google Calendar are optional connections, separate from Google website sign-in. Drive backup is excluded from the public launch and is unavailable in native build 215 and later.
- We do not sell your Google user data, use it for advertising, or use it to train general-purpose AI models.
Who we are and how to contact us
SVK Foundry LLC operates Everyday Paper. For privacy, access, deletion or support requests, email support@everydaypaper.app. Please do not send passwords, verification codes, API keys or confidential note contents.
Your library and Web sync
The native apps store notes, recordings, transcripts, tasks and attachments in their device library. If iCloud is enabled, eligible library data is also stored in your Apple iCloud account through CloudKit. Apple operates that service under its own terms.
If you use the web app or connect Web sync, we store eligible notes and related account data in Neon Postgres and attached files in private Vercel storage. Signing out of Web sync stops that connection; it does not delete the server copy. Locked notes and notes excluded by the native app's On device or Never folder policies are not uploaded through Web sync.
The optional web vault encrypts supported content at rest. When you unlock it, the server can decrypt content while processing your authorized requests. This is not a promise that the service can never access unlocked content. Native note locking is a separate feature; keep your passphrase and any recovery information safe.
Google user data: access and use
The following disclosures cover information received through Google sign-in, Gmail, Google Calendar and Google Drive APIs, including copies of that information saved into Everyday notes. Each connection is optional; we access only the Google services you authorize.
- Account identity. Your Google email address and whether Google has verified it, using
openidand/oruserinfo.email, identify your connected account or sign you into Everyday. We do not request your Google password. - Gmail data. With
gmail.readonly, we access message and thread identifiers, labels, sender and recipient addresses, subject lines, dates, and snippets. For Standard accounts, we also fetch message text and attachment metadata and contents when needed to open correspondence or save a thread as a note. We use these data to show related correspondence, support permitted on-device mail assistance, and create the copies you request. Privileged accounts have the stricter limits described below. - Google Drive data. Earlier native builds used
drive.filefor identifiers, names, modification dates, sizes and contents of Everyday backup files. Drive backup is excluded from launch; build 215 and later do not request Drive authorization or send Drive API requests. Existing files in your Drive are not removed. - Google Calendar data (website). With
calendar.calendarlist.readonlyandcalendar.events.readonly, we read the list of your calendars and their events: titles, times, places, conferencing links and invitees' names and email addresses. We use them to show upcoming meetings, start a meeting note, prepare a meeting brief and suggest writing up notes afterwards. We never create, change or delete events. - Connection credentials. Google issues access tokens and, for ongoing native Gmail or Drive connections, refresh tokens. These authorize the connection without giving Everyday your Google password. Website Google Calendar tokens are stored encrypted on our server.
Read more about who receives Google user data, how we protect it, and retention and deletion.
Everyday Paper's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Gmail: optional, read-only access
When you connect Gmail in the native app, we request your Google email address and read-only Gmail permission. This lets you find correspondence related to notes, people and meetings, open messages, and deliberately save a thread and its attachments as a note. Everyday does not use this connection to send, modify or delete messages in Gmail.
For a Standard account, Everyday keeps message headers and snippets in a separate mail cache on your device. A message body is fetched when needed for a feature you invoke, such as opening a message or saving a thread. Direct mail evidence is restricted to on-device intelligence rather than sent to your configured cloud AI provider.
For a Privileged account, the automatic cache retains headers such as sender, recipient, subject and date, without snippets or message bodies. These messages are excluded from AI evidence and cannot be saved as notes through the mail integration.
The separate mail cache does not use the app's CloudKit or Web-sync note store. If you choose to save a Standard-account thread as a note, however, that creates a separate copy in your library. The copied text and attachments follow that note's folder, sync, export and AI settings. They may therefore reach your iCloud, the Everyday Paper web service, a backup destination, or an AI provider when you use an eligible cloud feature. Choose an On device or Never folder to restrict external processing through the app's policy controls.
Google Drive: legacy backups
Drive backup is not offered in the public launch. Earlier beta builds could create backups containing notes, history and attachment bytes. Existing copies remain under your control in Google Drive; you can download them there and use Everyday's ordinary file import, or delete them in Drive. File import/export does not require Everyday to connect to the Drive API.
Google sign-in on the website
Continue with Google requests basic sign-in identity and your verified email address to find or create your Everyday account. It does not request Gmail or Drive access. We use a Google access token during sign-in to verify your email; that flow does not retain a Google refresh token for ongoing mail or Drive access.
Google Calendar on the website
Connecting Google Calendar in the web app is optional and separate from signing in with Google. The access and refresh tokens, and a short-lived copy of the coming week's events, are stored encrypted on our server. A meeting note you start from a Google Calendar event is marked as holding Google user data, and so is a brief or Ask answer you save that drew on such data. Invitees' names and organisations help choose which of your notes go into a meeting brief; they are not sent to an AI provider. Disconnecting deletes the tokens and cached events and revokes the access with Google; deleting your account does the same.
Google user data: sharing, transfers and disclosure
We share Google user data only as needed for the Everyday features you enable, a destination you choose, or the limited support, security and legal purposes described here. The recipients and purposes are:
- Everyday Paper, Vercel and Neon. SVK Foundry LLC operates the service. Vercel hosts the web application and private attachment storage; Neon provides its database. They process your account email and service requests. If you save Gmail content as a note and enable Web sync, they also process that eligible copied text, metadata and attachments to store and synchronize your library. If you connect Google Calendar on the website, they store its encrypted tokens and short-lived event copy. The separate native Gmail cache and native Gmail/Drive refresh tokens are not uploaded through Web sync.
- Apple and Google. If iCloud is enabled, Apple CloudKit receives eligible library copies, including mail you chose to save as notes. Google retains any Drive backups you created using earlier beta builds until you manage those copies in Drive. Connecting Gmail by itself does not upload your mail cache to iCloud or create a Drive backup.
- Your selected AI service. Direct mail evidence stays with on-device intelligence. After you deliberately save Standard-account mail as a note, eligible copied text may be sent when you use a cloud note feature to a verified direct OpenAI or Anthropic API endpoint. The current website and native build 215 and later block Gemini, DeepSeek and unverified custom gateways for note-text AI. Older installed native builds must be updated to receive this enforcement. Optional Typesafe/Jev classification and ranking can receive eligible note text when enabled; on the website, only notes known not to hold Google user data are eligible, and others are left unchecked. These services receive the context needed for the requested feature; native Gmail/Drive connection tokens are not sent to them. Local modes and folder restrictions remain available.
- Your export recipients. When you export or share a note or backup, including one containing Google-derived content, the destination you select receives that copy. Examples include Notion, Google Drive, a file location or a recipient you choose. Their own access and retention settings apply.
- Transactional email and support. Postmark delivers our sign-in emails and receives the destination email address and sign-in message, not your Gmail mailbox contents. If you contact support, we receive the information you choose to send. Authorized people may access Google user data only under the Limited Use exceptions described below, such as your affirmative agreement for a specific support request or necessary security or legal compliance.
We do not sell Google user data or disclose it to advertisers, data brokers or information resellers. We do not use or transfer it for personalized advertising, creditworthiness or lending decisions. Google Workspace API data is not used to develop, improve or train generalized or non-personalized AI or machine-learning models. Optional YouTube playback and its advertising do not authorize use of your Gmail, Drive or Google sign-in data for advertising.
Google user data: protection of sensitive information
- Encrypted service connections. Connections to Google OAuth, Gmail and Drive APIs and the Everyday production web service use HTTPS/TLS to protect data in transit.
- Protected credentials. Native Gmail and Drive access and refresh tokens are stored in Apple Keychain. OAuth sign-in uses state validation and PKCE to protect the authorization flow. Web sessions use Secure, HttpOnly cookies in production, and the server stores hashes of session tokens.
- Account access controls. Authenticated web requests are scoped to the signed-in account. Attachment files use private storage and are served through account-authorized requests rather than public file links.
- Optional content encryption. The web vault uses AES-256-GCM encryption for supported stored content, including eligible Google-derived note text and attachments. When you unlock the vault, the server can decrypt content to fulfill authorized requests. This protection is optional and does not mean all metadata is encrypted or that the service is end-to-end encrypted. Native note locking is separate.
- Processing limits. The separate Gmail cache stays on the device; Privileged mail excludes snippets, message bodies, AI evidence and conversion into notes. Native locked notes and notes excluded by On device or Never folder policies are not uploaded through Web sync. Direct mail assistance is limited to on-device processing.
No system can guarantee absolute security. Device access controls, the destinations you choose, and keeping your account credentials and vault passphrase private also matter. We do not claim that Google has certified the app or that a security assessment has been completed.
Google user data: retention, deletion and permitted use
Native Google connection tokens are stored in the device Keychain. Disconnecting a Gmail account removes its local connection and cached mail from that device. It does not delete the original Gmail messages or notes you already chose to create from them. Earlier builds also stored a Drive connection in Keychain. Build 215 and later do not use those credentials. Existing Drive backups remain until you delete them in Google Drive; revoking access does not delete those files. You can also revoke Everyday's access in your Google Account connections.
We use Google data to provide and improve the user-facing features described here. We do not use it for advertising, credit decisions, sale to data brokers, or generalized AI model training. We do not permit people to read Google user data except with your affirmative agreement for a specific purpose, as necessary for security or legal compliance, or for permitted internal operations on aggregated, anonymized data, consistent with Google's Limited Use requirements.
Google data and AI processing
Our use of raw and derived data received from Google Workspace APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements. This applies to copied messages, attachments, extracted text, summaries and other derived content, not just the original mailbox cache. Google data must not be used or transferred to create, train or improve generalized AI or machine-learning models.
Local processing. Direct mail assistance uses local rules and, on supported devices, Apple's on-device Foundation Models framework. When you use a locally hosted model through an Ollama server on your own device, inference runs there. Those local processing modes do not send that content to the model developer for training. A remote or custom endpoint is a separate external service and is not covered by this local-processing description.
Cloud processing and provider settings. Our server-provided writing features use the OpenAI API. Optional integrations include the Anthropic API, Google Gemini API, DeepSeek API, user-configured compatible endpoints, Typesafe/Jev for classification and ranking, and ElevenLabs for transcription. Basic API access is not a promise of zero data retention. Some providers distinguish paid from unpaid services or require a training opt-out. Google-derived content must not be sent to a provider or account configuration that permits generalized model training. Your choice of provider does not override these Limited Use obligations.
Verified-provider enforcement. The current website and native build 215 and later restrict note-text AI to direct OpenAI and Anthropic APIs or local processing; optional Typesafe/Jev classification uses its fixed API. Unknown legacy note sources receive the same restriction. On the website, related notes and search by meaning use OpenAI's embeddings API, which is not on that reviewed list, so only notes known not to hold Google user data are indexed, and a Google Calendar meeting's title and place are never used to search by meaning. Google/unknown imported audio cannot be sent to ElevenLabs; fresh microphone or system-audio capture remains separately available with consent, without sending library text or vocabulary. Earlier native versions offered other providers and must be updated. These safeguards do not promise zero retention and do not override folder or account restrictions.
Visual Library organization
In native build 232 and later, organization analysis starts only when you request it. It uses eligible note titles, excerpts, folder labels and image evidence to suggest folders and moves. Image text recognition runs locally first. If no readable text is found and your configured, permitted OpenAI API service supports image descriptions, Everyday can send a reduced JPEG to the direct OpenAI API to obtain a short description for filing. The image is limited to 512 pixels on its longest side and 1 MB, with source metadata removed. Browsing folders or cards does not start this cloud analysis or download full-size originals for it.
Locally recognized image text and provider-generated descriptions can be included with other eligible evidence in the organization request. Local recognition does not mean that the resulting text stays on the device when you request cloud organization. Optional Typesafe/Jev can receive eligible text for fixed-choice classification; native build 232 excludes Google-derived and unknown-origin note content from that route, including mixed-source folder choices. Locked, device-only and AI-restricted content remains excluded. Provider access, adult eligibility and applicable content permissions are checked before sending.
You review proposed folders and moves before applying them. Provider processing and retention terms apply; basic API access is not a promise of zero data retention. The Google-data Limited Use and model-training restrictions above also apply to extracted text, images and derived descriptions.
Other services you choose
- AI and transcription. Local modes process content on your device where supported. Optional cloud modes send the selected text, recording or live audio to the provider you choose, such as ElevenLabs or an OpenAI-compatible service. Optional Typesafe/Jev features send text for classification or ranking. Provider retention and processing terms apply. Folder and account restrictions determine eligible context.
- Web Ask and Enhance. Your question and selected eligible context are processed by the configured AI provider through our server. Answers and generated content may be stored with your account. Provider keys saved in the web app are encrypted on our server; native provider credentials use device storage.
- Earlier Calling access. Outbound calling is unavailable in the initial public release. Earlier pre-release versions offered separately provisioned calling through Twilio, which processed call destinations, status and any enabled recordings. This change does not delete existing call notes or recordings. Recordings kept in Twilio are separate from copies saved to Everyday; deleting one copy does not necessarily delete the other. Earlier installed versions may still use their existing Calling access.
- Video notes. Features using Supadata send the video reference and the information needed for the requested transcript or analysis to that service. Opening an embedded YouTube player also connects to Google/YouTube, which receives information needed to deliver the video, such as your IP address and the video requested, and may display advertising. Native app builds 186 and later use YouTube's Privacy Enhanced Mode in a non-persistent web view. Google states that views in this mode do not personalize YouTube viewing or advertising, and any ads are non-personalized; this does not mean that playback sends no data. Google's privacy policy and YouTube's terms apply. Opening YouTube externally uses that browser or app's own settings.
- Notion and other export destinations. Content you choose to send is handled by the destination under its terms and access settings.
- Calendar. Device calendar access supports meeting selection and linking; write-back requires your action. Web calendar subscriptions are fetched by our server and cached briefly so upcoming events can be displayed. If you connect a Microsoft (Outlook) calendar in the web app, we read your calendars and events through Microsoft Graph with read-only permission, store the tokens and a short-lived copy of the coming week's events encrypted, and delete them when you disconnect. Microsoft does not offer per-app revocation, so also remove Everyday at account.microsoft.com if you want to end access there.
- Web transcription. Recordings made in the web app, and recordings you choose to transcribe, are sent to OpenAI to produce a transcript that separates speakers. The audio is not kept by Everyday after transcription. If you add a browser tab's audio to a recording, that tab's sound is included in what is sent.
- Related notes and search by meaning. If your account uses Everyday's AI or your own OpenAI key, the text of a note known not to hold Google user data is sent to OpenAI to compute a numerical representation (an embedding) used to find related notes and to search by meaning. We store that representation and a fingerprint of the text, not another copy of it. Nothing is computed for a sealed library, turning sealing on deletes them, and they are deleted with the note. Accounts using another AI provider are not included.
- Email to Paper. If you create a private Email to Paper address, messages sent to it are received through Postmark and saved as notes with their attachments. They are not sent to an AI provider automatically. Messages are refused, and nothing is stored, while your library is sealed. Resetting the address stops the old one from working.
- Link previews. When you click a web link in a note, our server visits that page to read its title, description, image and site name, as your browser would if you opened it. Only the link you click is visited, never the rest of the note, and only public web addresses on the usual ports. The preview is kept briefly in our server's memory, not stored with your account. The page's image and icon then load from that site in your browser.
- Recaps and exports. A recap or exported note is prepared in your browser. Nothing is sent until you copy, save or send it yourself.
- Sign in with Apple. We retain an Apple account identifier and, when provided, a verified email address that may be a private relay address. The authorization token is encrypted on our server so access can be revoked when the account is deleted.
Device permissions
Microphone access records audio you start; camera and photo access import or scan content you choose. Calendar and reminder permissions support the features you enable. Face ID or Touch ID can authorize protected actions. Mac system-audio recording requires permission and captures audio for a recording you initiate. Apple Notes import reads the content you select; it does not edit the source notes.
Retention and deletion
Library and account data remain while you keep them in the service. Moving a note to Recently Deleted is reversible and is not permanent erasure. Use the app's permanent-delete or account-deletion controls when you want to remove the corresponding service data. Copies in device backups, exports, Google Drive, iCloud or other providers may need to be managed separately. Limited copies may remain in operational backups or records needed for security or legal obligations until those records are retired.
You can export your library and manage connections in Settings. For help with data access, correction or deletion, contact us at the address above. Do not include sensitive content unless it is needed and you have agreed to share it.
Website sessions and operational information
The website uses necessary cookies for sign-in, authentication checks and an unlocked vault session, and browser storage for preferences and cached library data. Hosting, database and email providers process operational information needed to deliver and secure the service. We do not use advertising identifiers or third-party advertising trackers in the apps.
Sign-in emails use our transactional email provider. If you send a support request or export diagnostics, we receive what you send. Review diagnostic exports before sharing them. Apple may provide crash reports if you enable sharing with developers. We do not intentionally include note contents in diagnostic exports.
Children and changes
Everyday Paper is not directed at children under 13, and we do not knowingly collect their information. We update this page when our practices change and show the effective date above.