Privacy Policy

This policy explains what the EverythingAI website collects, why it is collected, who processes it, how long it is kept, and how to ask for access, correction, or deletion.

Last updated 15 September 2026.

At a glance

What the request form collects
Ten fields you type, the time the form was opened, the state of one decoy field, a challenge response verified by Cloudflare, and a keyed hash of the network your request arrived from.
Why
To qualify the inquiry, reply to you, arrange the call, and keep automated and abusive submissions out of the queue.
Where it is stored
A SQLite database on a server EverythingAI controls. It has no public interface: only the service that accepts submissions and operator tooling reach it.
Retention
Inquiries that do not become a client engagement are deleted automatically after 90 days.
Backups
Encrypted with AES-256-GCM using a key derived from a passphrase held outside the backup. The seven most recent backups are kept.
Analytics
Production pages load Google Analytics 4, which records page views and configured site interactions and may set first-party analytics cookies. EverythingAI sends it no contact-form field values or inquiry contents.
Rights
Email [email protected] to ask what is held, to have it corrected, or to have it deleted.

What you send through the request form

The form on the Contact page collects only what is needed to qualify an inquiry and reply to it:

  • Your name
  • Work email address
  • Organization
  • Your role or title
  • Organization-size range
  • The workflow or problem you describe
  • When you would like to start
  • Systems involved (optional)
  • Phone number (optional)
  • How you heard about EverythingAI (optional)

The form also asks you not to send anything sensitive. Do not include passwords, API keys, account credentials, records about people your organization serves, protected health information, confidential documents, or screenshots of production systems. If sensitive material reaches EverythingAI anyway, say so and it is deleted.

Information the service records about the request itself

Beyond the fields you type, the service that accepts submissions records:

  • When the form was opened and submitted. The service compares the two times to filter out submissions completed implausibly fast. A form left open for most of a day restarts that measurement when you next interact with it.
  • One decoy field. The form contains a field that is hidden from people and from assistive technology. Anything typed into it marks the submission as automated, and no visitor sees which signal was rejected.
  • A keyed hash of your network. Rate limits are applied per network to stop one source from filling the queue. The address itself is never stored with the inquiry: the service stores a salted hash, and the salt is discarded when the service restarts, so the stored value cannot be reversed or matched to an address later.
  • A challenge response. The form carries a Cloudflare Turnstile token. EverythingAI verifies that token server-side with Cloudflare before the submission is accepted. Client-side completion alone is never treated as proof.

How your request is used

EverythingAI uses an accepted request to read and qualify the inquiry, reply to you, arrange an AI Opportunity Call, and decide whether the work fits. It is not used for advertising or profiling, and inquiry information is not sold.

Who else processes it

  • Cloudflare serves the website, terminates TLS, filters hostile traffic, and carries requests to the origin server through Cloudflare Tunnel. Cloudflare also provides Turnstile, which processes browser and device signals to decide whether a visitor is a person. Cloudflare's own privacy terms govern what it processes for those services.
  • Google Analytics measures how the production site is used, under Google's own privacy terms. The measurement script is loaded only on production pages; development and preview pages do not load it.
  • Resend is the transactional email provider the service is built to use. When it is enabled it delivers the notification that tells Tanner a request arrived, and it receives the inquiry details so those details reach EverythingAI's mailbox. Delivery is retried with a stable key so a retry cannot send the same notification twice. No provider is configured or sending today: this page names Resend only so the processor is not a surprise, and it is updated again before delivery goes live.
  • A scheduling provider is offered only after a request is durably stored. If you follow the scheduling link, that provider's terms and privacy policy apply to the details you enter there.
  • Email and calendar providers receive information if you choose the email fallback on the Contact page or continue the conversation by email.

Storage and access

Accepted requests are stored in a SQLite database on a server EverythingAI controls. The service that writes to it runs as an unprivileged process with access to one data volume, and the server is not exposed directly to the internet: public traffic reaches it only through Cloudflare Tunnel. Records are read with restricted operational tooling or direct database access over the private management path. There is no browser dashboard and no public interface to the inquiry database.

Logging

The service writes structured operational logs, and every field in a log record is drawn from a fixed allowlist. A log record contains:

  • The event, its outcome, an internal inquiry identifier, and timings such as how long a request took.
  • No message bodies, names, email addresses, phone numbers, organization names, or request contents.
  • No verification tokens, no secrets, and no raw network addresses.

This operational logging is separate from website analytics and from the inquiry record itself: a log record never contains inquiry content, and analytics never receives it.

Website analytics

Production pages load Google Analytics 4 through the shared page layout, under measurement ID G-0QD8CXSWTP. Development and preview pages do not load the measurement script at all.

Analytics records:

  • Page views, with the page path and the referrer for each one.
  • Browser and device information, and the approximate geography that follows from the network a request arrives on.
  • The site interactions EverythingAI has configured as events.

Google Analytics may set its own first-party analytics cookies in your browser while it measures a visit. EverythingAI does not deliberately send the values you type into the request form, or the contents of an inquiry, to analytics: those stay in the service described above, and the inquiry record and its operational logging remain separate from analytics.

Retention and deletion

An accepted inquiry is treated as unqualified until it becomes a client engagement. Unqualified inquiries are deleted automatically once they are 90 days old; the deletion runs on the server and can be run on demand, including as a preview that reports what would be removed without removing it. When an inquiry becomes a client engagement, its record is marked as qualified and the relevant details move into the business system that holds client records, where the retention that applies to client work takes over.

The deletion job runs on the server several times a day and can also be run on demand, including as a preview that reports what would be removed without removing it.

Backups

The inquiry database is backed up on the server. Each backup is a consistent snapshot of the database, encrypted with AES-256-GCM under a key derived from a passphrase, and authenticated so that a modified or truncated file is refused rather than restored. The seven most recent backups are kept; older ones are removed as new ones are written, so information deleted from the live database does not survive indefinitely in a backup. The restore procedure is exercised, and a restored copy is verified before it replaces anything.

Security measures that affect your information

  • Server-side validation of every field, with request-size and field-length limits.
  • Server-side verification of the Cloudflare Turnstile token for every submission.
  • Honeypot and completion-time signals, plus per-network rate limits.
  • Parameterized database access and no visitor-supplied markup rendering.
  • Encrypted backups, a non-root service container, and secrets kept outside the code.

Your choices

You can ask what is held about you, ask for it to be corrected, or ask for it to be deleted. Email [email protected] and say what you want done; Tanner handles these requests directly and replies. If a request concerns a record that has already become part of a client engagement, EverythingAI explains what is retained and why before acting.

What this policy does not claim

This policy describes current practice for this website and nothing more. It has not been reviewed by a lawyer, it is not legal advice, and it is not a contract. It does not claim certification or compliance with any framework. Signed engagement terms take precedence for work delivered to a client.

Changes

When practice changes, this page changes with it, and the date at the top reflects the change. Material changes to how inquiry information is handled are reflected here before the new practice is used for new submissions.

Contact

Questions about this policy, or about any request you have sent, go to [email protected].