04 Everview / governance
Privacy Policy
Effective date: August 9, 2026
1. Overview
E-paper Control operates Everview, a personal media center that connects supported data sources to user-owned e-paper devices. Current supported sources include YouTube, Instagram, Etsy, Home Energy, and Stocks. This Privacy Policy explains what information we collect, how we use it, and the choices available to you.
2. Information we collect
- Account information: your email address and account credentials. Passwords are stored using Django's password hashing system and are not stored as plain text.
- Device information: device identifiers, ownership, service configuration, connection records, and generated display images.
- YouTube information: when you authorize YouTube, we receive the channels owned by your Google account, the selected channel ID, title, URL or handle, subscriber count, daily snapshots used to calculate growth, daily views, estimated revenue when available, and the count of future scheduled videos.
- Instagram information: when you configure an Instagram username, we receive the public profile URL, the profile's displayed username and name when available, follower counts, device binding, and daily follower snapshots. If you choose account connection, we also store an encrypted access token, account identifier, granted scope, and token expiry so we can read the connected professional account. A public profile lookup remains available when an account is not connected or is not a professional account.
- Commerce, energy, and finance information: depending on the sources you connect, we may receive read-only Etsy store operations, home energy and Powerwall data, and stock or portfolio values needed to render the view you selected.
- Store orders: when you buy a product, we store the order number, product and variation details, payment status, email address, and the billing or delivery address you provide during checkout.
- Affiliate information: when you join the Affiliate Program, we store your referral link, coupon history, referral clicks, attributed orders, commission records, and the PayPal email you provide for payouts.
- Affiliate cookies: when you follow a creator link, we use a strictly limited referral cookie for up to 60 days to attribute a later eligible order. A coupon entered at checkout takes priority over link attribution.
- OAuth credentials: access and refresh tokens required to synchronize the selected channel. These credentials are encrypted before storage and are not sent to the browser.
3. How we use information
We use this information to authenticate your account, associate your devices with you, synchronize the sources you select, calculate or format the values needed for your chosen views, show them in the media center, render the selected result for your e-paper display, fulfill store orders, attribute affiliate referrals, calculate commission, prevent self-referral, and prepare monthly payouts. We do not use connected source data for advertising, unrelated profiling, or training artificial intelligence models.
4. Google API data
Our YouTube integration requests these read-only permissions only after you choose to connect YouTube:
https://www.googleapis.com/auth/youtube.readonlyis used to list channels owned by the authorizing account, read the selected channel's subscriber count, and identify future scheduled videos.https://www.googleapis.com/auth/yt-analytics.readonlyis used to read the selected channel's daily views report.https://www.googleapis.com/auth/yt-analytics-monetary.readonlyis used to read the selected channel's estimated revenue report when monetization data is available.
We do not sell Google user data. Google API data is handled in accordance with the Google API Services User Data Policy.
5. Instagram public-profile data
Instagram follower data can come from either an account connection for a Creator or Business account, or from the public profile URL configured for the device. Public profile data is not an owner-authenticated view and may be delayed or differ from the count shown to an account owner. You can continue using public synchronization if you do not convert a personal account or do not complete authorization.
6. Storage and security
Third-party access credentials, when a supported integration requires them, are encrypted before being stored and are not sent to the browser. We use HTTPS for the public production website and apply access controls so a user can access only devices assigned to that account. No internet transmission or storage method can be guaranteed to be completely secure.
7. Sharing and service providers
We do not sell or rent personal information. Information may be processed by hosting, database, email, security, and infrastructure providers only as needed to operate Everview. Connected source data is exchanged with the provider you choose only as required for the authorized synchronization. Third-party names and services remain subject to their own policies.
8. Retention and deletion
You may disconnect a source at any time and revoke Everview's access from the provider's account settings. You may also request deletion of your Everview account, source credentials, device associations, and stored snapshots by contacting [email protected]. We may retain limited records where required for security, fraud prevention, accounting, or legal compliance.
9. Children
Everview is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
10. Changes and contact
We may update this Policy when the service or legal requirements change. The effective date above will be updated when material changes are published. Questions or privacy requests can be sent to [email protected].