DRAFT — Under Legal Review. Do not rely on this document until this banner is removed.

Privacy Policy

Last updated: April 2, 2026

Everyday AI Services ("EAI," "we," "us," or "our") is committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use and share it, and your rights. This policy applies to all interactions with everydayaiapp.com (the "Site") and our programs and services.

1. Privacy Officer

Our Privacy Officer is responsible for overseeing compliance with this policy and applicable privacy legislation:

Milind Bhat, Privacy Officer
Everyday AI Services
Email: privacy@everydayaiapp.com

2. Information We Collect

2.1 Information You Provide

  • Name and email address when you contact us, book a consultation, or enroll in a program
  • Organization name, job title, and professional role
  • Payment information (processed by Stripe; we do not store card numbers)
  • Information about your professional situation shared in messages, forms, or during sessions
  • Program submissions, exercises, and feedback
  • Communications with us (email, form submissions, scheduling)

2.2 Information Collected Automatically

  • IP address and approximate geographic location
  • Browser type and version, operating system, and device type
  • Pages visited, time spent on pages, and referral source
  • Interaction data collected through analytics tools (see Section 6)

3. How We Use Your Information

We use the information we collect to:

  • Deliver and administer our programs and services
  • Process payments and manage enrollment
  • Respond to inquiries and determine program fit
  • Communicate about schedules, program details, and follow-up
  • Send program-related materials and resources
  • Improve our programs based on aggregate feedback and usage patterns
  • Maintain the security and functionality of the Site
  • Comply with legal obligations

We do not sell, rent, or trade your personal information.

4. Legal Basis for Processing

We operate under Canadian federal and provincial privacy legislation, including:

  • PIPEDA — Personal Information Protection and Electronic Documents Act (federal)
  • PIPA — Personal Information Protection Act (British Columbia)

We collect and process personal information with your knowledge and consent. By providing your information and using our Services, you consent to the collection, use, and disclosure of your information as described in this policy. You may withdraw consent at any time, subject to legal or contractual restrictions, by contacting our Privacy Officer.

5. Data Sharing

We share personal information only with service providers who help us operate, under appropriate data processing agreements. We do not sell your data. The following table describes our third-party service providers:

Provider Purpose Data Shared Location
Stripe Payment processing Name, email, payment details USA
Cal.com Scheduling Name, email USA
PostHog Product analytics Anonymized usage data, IP address USA/EU
Anthropic AI tools used in programs Prompts and inputs during exercises USA
Cloudflare CDN and security IP address, request metadata Global
Senja Testimonials Name, role, testimonial text (with consent) USA

We will also disclose personal information if required by law, regulation, or court order.

6. Cross-Border Data Transfers

Some of our service providers are located outside Canada, primarily in the United States. When your personal information is transferred to another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to law enforcement and regulatory authorities in accordance with those laws. By using our Services, you consent to the transfer of your information to jurisdictions outside Canada as described in the data sharing table above.

7. Cookies and Tracking

The Site uses cookies and similar technologies for:

  • Essential cookies: Required for Site functionality (session management, security).
  • Analytics cookies: Used by PostHog to understand how visitors use the Site. These collect anonymized usage data.

We do not use advertising or marketing cookies. You can control cookies through your browser settings. Disabling essential cookies may affect Site functionality.

8. Your Privacy Rights

Under PIPEDA and PIPA, you have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Withdrawal of consent: Withdraw consent to the collection, use, or disclosure of your information, subject to legal or contractual restrictions.
  • Deletion: Request deletion of your personal information, subject to our retention obligations.
  • Complaint: File a complaint with our Privacy Officer or the applicable privacy commissioner (see Section 14).

To exercise any of these rights, contact our Privacy Officer at privacy@everydayaiapp.com. We will respond to requests within 30 days.

9. Data Retention

We retain personal information only as long as necessary for the purposes described in this policy or as required by law. The following table outlines our retention schedule:

Data Type Retention Period
Contact and inquiry data 3 years after last interaction
Program enrollment records 7 years (tax/legal requirements)
Payment records 7 years (tax/legal requirements)
Program materials and submissions Duration of program + 1 year
Analytics data 24 months (anonymized)
Testimonials Until consent is withdrawn

You may request deletion of your data at any time by contacting our Privacy Officer. Certain data may be retained as required by law.

10. Security

We implement reasonable administrative, technical, and physical safeguards to protect your personal information, including encryption in transit (TLS/SSL), secure hosting, and access controls. However, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your information.

11. Breach Notification

In the event of a breach of security safeguards involving personal information that creates a real risk of significant harm, we will: (a) notify affected individuals as soon as feasible, and in any case within 72 hours of becoming aware of the breach; (b) notify the Office of the Privacy Commissioner of Canada as required under PIPEDA; and (c) keep records of the breach as required by law.

12. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on the Site with a revised "Last updated" date. We encourage you to review this page periodically. For participants enrolled in active programs, material changes will be communicated directly via email.

14. Complaints

If you are not satisfied with our response to a privacy concern, you have the right to file a complaint with the applicable privacy commissioner:

  • Office of the Information and Privacy Commissioner of British Columbia (BC OIPC)
    www.oipc.bc.ca
  • Office of the Privacy Commissioner of Canada (OPC)
    www.priv.gc.ca

15. Contact

For privacy-related questions, to exercise your rights, or to file a complaint, contact us at:

Milind Bhat, Privacy Officer
Everyday AI Services
Email: privacy@everydayaiapp.com
Web: everydayaiapp.com/contact