PRIVACY & CONTROL
Your information. Your decisions.
Updated September 20, 2026. EveryFavor is operated by Chang Yang. For privacy questions or requests, contact cyangprojects@gmail.com.
Customer onboarding is currently closed while launch checks are completed. The public sample uses fictional information. It does not connect to your accounts, and you should not enter private receipts, financial information or credentials into it.
Information you choose to provide
When account access opens, EveryFavor will process your email address and account profile, verification and session information, consent choices, uploaded receipts or documents, imported transactions, connected-source permissions, findings, feedback and reported recoveries. You decide which sources to add and when to start a scan.
Documents may contain information about other people. Upload only information you are authorized to provide, and avoid unrelated sensitive information. EveryFavor does not need your bank password or payment-card security code.
Why we process it
We use this information to authenticate you, operate your private account, inspect and read authorized files, identify potential economic opportunities, explain the supporting evidence, record your decisions, provide exports and handle deletion. Limited security and operational records help detect abuse, diagnose failures and maintain the service.
Findings and potential value are estimates that may be wrong or incomplete. Receipt text and your corrections do not establish payment or eligibility. Money you report recovering is labeled separately from potential value. V1 prepares recommendations and does not cancel services, file claims, transfer money or take consequential external action.
Connected email
Gmail is currently disabled. When available, connecting it requires Google's consent screen and read-only permission. Imports are started by you and limited to matching messages from the previous 90 days, with at most 50 retrieval attempts per import. This version reads bounded plain text, skips attachments and remote images, and does not send, modify or delete mail.
Disconnecting stops future ingestion immediately. Provider revocation can take longer; the app shows when confirmation is pending. Records already imported may remain available for your review and export until you delete your account. We do not sell Gmail data or use it for advertising or model training.
Service providers and processing
EveryFavor uses Vercel to host the application, Neon for its database and managed authentication, Cloudflare for private document storage and background coordination, OVHcloud for isolated malware inspection and document reading, and Resend for account and operational email. Google processes authorization and mailbox requests if you choose to connect Gmail. These providers process information needed for their functions, including network and security metadata.
Private content is encrypted in transit and at rest, with additional application encryption for sensitive records and files. Authorized application processes decrypt information when needed. Files are decrypted temporarily for inspection and reading in isolated processes. Access is limited by account membership and permissions. Founder diagnostics require an explicit permission and are audited.
The current release uses deterministic rules and a document reader, including OCR where needed. It does not send your private content to an LLM or use it to train models. Any future feature needing additional processing or permissions will be explained before it is enabled.
Measurements and logs
Account measurements count generated and displayed findings, your feedback, ingestion progress, processing failures and reported recovery. A displayed card does not prove you read it. These measurements stay linked to your retained account and are included in export and deletion. They are not anonymous historical tracking.
Application logs are designed to exclude raw email bodies, receipts, transaction descriptions, passwords and access tokens. Providers may retain their own service and security logs under their terms. No system can guarantee that every security risk or service interruption is prevented.
Export, retention and deletion
You can request a private export of retained structured records and original files that passed safety checks. Exports are split into numbered parts and expire after 24 hours. Access still requires your account; a download address alone is not permission. Your own downloaded copies remain under your control.
Deletion requests immediately stop account access and new ingestion. Cleanup removes live account records, original files and their recovery copies, and the managed sign-in identity. Pending provider revocation or an unresolved cleanup failure may delay completion. We do not label an unconfirmed provider deletion as complete.
Production database recovery history is configured for 24 hours. That period begins separately for each removed record and is not a promise that every provider copy disappears exactly 24 hours after your request. Cleanup records remain protected until recovery history and other retained copies have been checked. Minimal deletion and security markers remain to prevent deleted information from returning after recovery. Final retention procedures are still being verified before real customer data is accepted.
Security records and provider logs may have different retention requirements. Contact us if you need help with access, correction, export, disconnection or deletion, or if you believe your information was provided without permission. We may need to verify that a request concerns your account.
Changes and contact
We will update this notice when processing changes and request new consent where a feature requires it. This service is intended for adults. Questions can be sent to Chang Yang at cyangprojects@gmail.com.