EveryPath.AI

Privacy Policy

Last updated: June 21, 2026

This Privacy Policy explains how EveryPath.Ai (“EveryPath”, “we”, “us”) collects, uses, shares, and protects information when you use everypath.ai and related services (the “Service”). It is maintained by EveryPath.Ai and is intended to address rights of users in the EU/UK (GDPR), California (CCPA/CPRA), and Canada (PIPEDA).

1. Information We Collect

We collect the following categories of information:

  • Account information: name, email address, authentication identifiers, and password hashes when you create an account or sign in with a third-party provider (e.g. Google).
  • Profile and preference data: the role, industry, company size, goals, and tool preferences you provide to power recommendations and AI comparisons.
  • Subscription and billing data: plan tier, subscription status, and billing identifiers. Payment card details are processed by Stripe and are not stored on our servers.
  • Usage data: pages viewed, tools compared, searches, clicks, device and browser information, IP address, approximate location, and timestamps.
  • AI inputs and outputs: prompts you submit and responses generated, used to provide and improve the Service.
  • Communications: support requests, feedback, and messages you send to us.
  • Cookies and similar technologies: see Section 7.

2. How We Use Information

  • Provide, operate, and maintain the Service.
  • Personalize recommendations, AI matches, comparisons, and content.
  • Process subscriptions, payments, refunds, and renewals.
  • Authenticate users, prevent fraud and abuse, and enforce our Terms.
  • Send transactional emails, security notices, and service updates.
  • With your consent or where permitted by law, send marketing communications. You can opt out at any time.
  • Analyze usage to improve features, performance, and reliability.
  • Comply with legal obligations and respond to lawful requests.

3. Legal Bases (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service), legitimate interests (to improve and secure the Service, prevent fraud), consent (for optional cookies and marketing), and legal obligation (tax, accounting, lawful requests).

4. How We Share Information

We do not sell your personal information. We share data with:

  • Service providers (subprocessors) that help us run the Service, including hosting and database (Lovable Cloud / Supabase), payment processing (Stripe), AI model providers (such as Google and other gateway-routed providers), email delivery, and analytics.
  • Marketing and social platforms you choose to connect (Instagram, TikTok, LinkedIn, Facebook) to publish or measure content on your behalf.
  • Legal and safety: when required by law, to enforce our Terms, or to protect rights, property, or safety.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with notice where required.

5. International Data Transfers

Our subprocessors may process data in countries other than your own, including the United States, Canada, and the EU. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

6. Data Retention

We retain personal information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion at any time (see Section 8). Backups are deleted on a rolling schedule.

7. Cookies and Tracking

We use strictly necessary cookies to operate the Service (e.g. authentication) and, where permitted, analytics cookies to understand usage. You can control cookies through your browser settings. Disabling required cookies may break parts of the Service.

8. Your Rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent. Specifically:

  • EU / UK (GDPR): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority.
  • California (CCPA / CPRA): right to know, delete, correct, opt out of sale or sharing (we do not sell), and limit use of sensitive personal information. We do not discriminate against you for exercising these rights.
  • Canada (PIPEDA): access and correction of your personal information and the right to withdraw consent, subject to legal and contractual restrictions.

To exercise any of these rights, email us at info@skillscouncil.ca. We will respond within the timeframes required by applicable law.

9. Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, access controls, and row-level security on our database. No method of transmission or storage is 100% secure.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.

11. Third-Party Links and Tools

The Service references and links to third-party AI tools and websites. We are not responsible for their content or privacy practices. Review their policies before use.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated through the Service or by email. Continued use after changes take effect constitutes acceptance.

13. Contact Us

Questions or requests? Contact EveryPath.Ai at info@skillscouncil.ca.