Privacy Policy
Last Update: August 4, 2026
Everythink Ltd (company number 14267762, registered office at 20-22 Wenlock Road, London, England, N1 7GU) (the Controller or we) operates the Everythink platform (the Service). This Privacy Policy explains what personal data we collect, how we use it, and the rights you have under the UK GDPR and the UK Data Protection Act 2018. By using the Service, you accept the practices described in this Policy.
1. Data Controller
The controller responsible for your personal data is Everythink Ltd. You can contact us at [email protected] with any question regarding your personal data or this Policy.
2. Data We Collect
Account data: when you create an account, we collect your name, email address, and age and, if you register via Google Sign-In, the name, email, and profile picture Google provides to us through your id_token. Passwords are stored only as an irreversible hash, never in plain text.
Authentication data: we record your IP address, user agent, and session history to issue and bind JWT sessions, detect unauthorized use, and protect your account.
Eye Keys: the API keys (Eye Keys) you issue are stored only as an HMAC and a fingerprint; the plaintext is shown once at creation and is never persisted to disk.
Usage and log data: we record IP addresses, timestamps, and request metadata in server logs for security, abuse and fraud prevention, and Service stability.
World Monitor: the geo-signals (flights, vessels, earthquakes, fires, conflict, weather, satellites) shown by the Service are aggregate public data obtained from external sources and do not constitute your personal data.
3. How We Use Your Data
To provide, maintain, and secure the Service and your account; to authenticate you and manage sessions; to send transactional emails (email verification and access recovery); to respond to your inquiries; to prevent fraud, abuse, and prohibited activities; and to meet applicable legal obligations.
4. Legal Basis (UK GDPR)
We process your personal data on the basis of: (a) performance of a contract or pre-contractual steps with you (providing the Service); (b) your consent (for example, Google Sign-In and optional communications); (c) our legitimate interests (security, fraud prevention, and Service improvement); and (d) legal obligations (regulatory compliance).
5. Cookies and Similar Technologies
We use strictly necessary httpOnly cookies to maintain your authentication session (access and refresh tokens); they are not accessible from JavaScript. For analytics we use Cloudflare Web Analytics, a service that does not use cookies or identify individuals. We do not share data with advertising networks or enable third-party tracking for commercial purposes.
6. Sharing Data with Third Parties
We do not sell your personal data. We share data only with the processors necessary to provide the Service: Google (Google Sign-In authentication), Brevo (transactional email delivery), Cloudflare (CDN and analytics), and hosting and database infrastructure providers. These providers are contractually bound to process data only on our behalf and in accordance with this Policy.
7. International Transfers
Your data may be processed by providers outside the United Kingdom (for example, the European Union or the United States). Where this occurs, we apply adequate safeguards under the UK GDPR, including the International Data Transfer Agreement (UK IDTA) or standard contractual clauses, and we require equivalent measures from our providers.
8. Data Retention
We retain your personal data while your account is active and, afterwards, for as long as reasonably necessary to meet legal obligations, resolve disputes, and enforce our agreements. Security logs are retained for the period necessary for abuse detection and prevention, in accordance with applicable law.
9. Security
We apply reasonable technical and organizational measures: password hashing, HMAC for Eye Keys, IP-bound sessions, short-lived JWT tokens with refresh rotation, encryption in transit (TLS), and restricted access to infrastructure. No method is completely infallible, but we work continuously to protect your data.
10. Your Rights (UK GDPR)
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, as well as rights regarding automated decision-making. To exercise them, write to [email protected]. If you believe we have not resolved your request, you may complain to the UK Information Commissioner Office (ICO) at ico.org.uk.
11. Children
The Service is intended for individuals aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, contact us at [email protected] so we can delete it.
12. Changes to This Policy
We may update this Privacy Policy. We will post the most recent version on the Service with its last-updated date. If changes are material, we will notify you by reasonable means. Continued use of the Service after changes take effect constitutes acceptance.
13. Contact Us
For any question about this Privacy Policy or your personal data, write to us at [email protected].
