Privacy Policy
This policy explains what information EveAgents handles through Google and GitHub sign-in, why we use it, and the choices available to you.
Last updated: July 22, 2026
1. Who controls your information
Bergside LLC is the controller of personal information handled through EveAgents. Our registered address is Constantin Titel Petrescu Nr. 7, Timisoara, Timis 300103, Romania. This policy applies to eveagents.dev and the public source-viewing, account, and download features available there.
2. Information we collect
Google OAuth sign-in
If you choose Continue with Google, EveAgents uses Google OAuth and OpenID Connect through Supabase Auth. We request only the openid, email, and profile scopes needed for sign-in. Google may provide a stable account identifier, email address and verification status, display name, and profile picture. We use this information to create and secure your EveAgents account, display your account identity, and provide authenticated download features.
EveAgents does not request Google Workspace scopes and does not use Google sign-in to access Gmail, Drive, Calendar, Contacts, or other Google content, or to take actions in your Google account.
GitHub OAuth sign-in
If you choose Continue with GitHub, EveAgents uses GitHub OAuth through Supabase Auth. GitHub may provide a stable account identifier, email address when available, username, display name, avatar, and public profile information needed for authentication. We use this information for the same account, identity, security, and download purposes described above.
Regular website sign-in does not request repository access. EveAgents does not use this sign-in to list, create, read, change, or delete your repositories. Website authentication is separate from any GitHub channel or connection you configure for an agent.
Passwords
Google or GitHub authenticates you directly. EveAgents does not receive or store your Google or GitHub password.
Session and technical information
We process session cookies, request information, IP address, browser and device details, timestamps, and security logs as needed to keep you signed in, deliver the service, prevent abuse, and diagnose failures.
API keys and bundle requests
If you create an EveAgents API key, we show the complete key once and store only its one-way SHA-256 hash, a short identifying prefix and suffix, your label for the key, creation and last-use timestamps, and request counters used to enforce rate limits. Registry requests may also appear in our infrastructure and security logs. You can revoke an active key at any time from the API Keys page.
Usage analytics
We use Fathom Analytics to understand aggregate traffic, such as page views and referrers. Fathom states that its website analytics does not use cookies and briefly processes information such as IP address and user agent to produce privacy-focused aggregate measurements.
Communications
If you contact Bergside about EveAgents, we receive the information you choose to provide, such as your name, email address, and message.
3. Why we use information
- To create and administer your account and authenticated session.
- To provide public agent source previews and authenticated ZIP downloads.
- To authenticate, rate-limit, and deliver agent bundles to deployment services.
- To secure, maintain, troubleshoot, and improve EveAgents.
- To measure aggregate site use and understand which pages are useful.
- To respond to requests and enforce our terms.
- To comply with legal obligations and protect legal rights.
Where applicable, our legal bases are performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent when the law requires it.
We do not use Google or GitHub account information for advertising, behavioral profiling, or training artificial intelligence models. EveAgents' use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
4. OAuth authorization and your controls
Supabase completes the provider exchange and creates the EveAgents session. EveAgents does not store Google or GitHub provider access or refresh tokens in its application database.
You can revoke EveAgents' authorization from your Google Account connections or GitHub application settings. Revoking provider authorization prevents future use of that authorization, but it does not by itself delete the EveAgents account information already created. To delete that information, use the account-deletion control described in Section 10.
5. Cookies
EveAgents uses essential Supabase authentication cookies to establish, refresh, and protect your login session. Disabling them prevents authenticated features from working. We do not use advertising cookies. Fathom Analytics does not set cookies through its analytics script.
6. How information is shared
We disclose information only as needed to operate the service:
- Supabase provides authentication, database, and file storage.
- GitHub or Google processes the OAuth flow you select.
- Vercel hosts and delivers the application.
- Fathom Analytics provides aggregate website analytics.
- Professional advisers, authorities, or other parties may receive information when reasonably necessary to comply with law, enforce agreements, or protect rights and safety.
- A successor may receive relevant information as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law.
We do not sell personal information or share it for cross-context behavioral advertising.
7. Third-party policies
These providers explain their own practices in their policies:
8. Retention
We retain account information while your account is active and for a limited period afterward when needed for security, backup integrity, dispute resolution, or legal compliance. Security and infrastructure logs are retained according to our providers' configured retention periods. Communications are kept only as long as reasonably necessary to answer the request and maintain appropriate records.
When information is no longer required, we delete or anonymize it, subject to technical backup cycles and mandatory legal retention.
When you delete your account from My Account, we remove the active Supabase authentication record, account profile, and API-key records linked to it. Limited information may remain temporarily in security logs, provider backups, or records we must retain by law until the applicable retention period expires.
9. International transfers and security
Our providers may process information in countries outside your own. Where required, we rely on lawful transfer mechanisms and provider safeguards. We use access controls, encrypted transport, and database Row Level Security, but no online service can guarantee absolute security.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, or obtain a portable copy of your personal information. You may also withdraw consent where processing relies on consent and complain to your local data protection authority. We will not discriminate against you for exercising a privacy right.
You can delete your account directly from My Account. For other privacy requests, or if you cannot access your account, use the Bergside contact page. We may need to verify your identity before completing a request.
11. Children
EveAgents is not directed to children under 16, and we do not knowingly collect their personal information. Contact us if you believe a child has provided personal information so we can investigate and delete it where appropriate.
12. Changes to this policy
We may update this policy as EveAgents or applicable requirements change. The last-updated date identifies the current version. We will provide reasonable notice of material changes through the site or available account contact information.