Privacy Policy for Evercore API and Site
Learn how Evercore handles personal data, logs, support records, cookies, and blockchain permanence across the site, API, and trust resources.
Data uploaded through Evercore is written to the Arweave permaweb — a public, immutable blockchain. Once confirmed on-chain, data cannot be deleted. Encrypt all sensitive content before uploading.
1. Overview
Evercore ("we", "us", or "our") operates as a stateless microservice intermediary for encrypted file storage on the Arweave permaweb. This Privacy Policy explains how we handle information in connection with the Evercore API and any associated interfaces.
Because Evercore is a stateless service with no internal database, we do not persist user data on our infrastructure. All stored artifacts are encrypted by the client before reaching our service and are subsequently written to the Arweave blockchain — a public, immutable, decentralized network.
2. Data We Collect
2.1 Data You Provide
When you interact with the Evercore API, you may transmit:
• Encrypted file payloads (AES-256-GCM ciphertext) — never stored on Evercore infrastructure • Arweave transaction metadata and tags you supply • Authentication credentials (API keys or wallet signatures) used solely for request validation
2.2 Operational Data
We may collect transient operational data, including:
• API request logs (IP address, endpoint, HTTP status, latency) — retained for up to 30 days • Error traces for debugging — anonymized and purged automatically • Arweave transaction IDs returned by upstream nodes — no content association is stored
2.3 Data We Do Not Collect
We do not collect, store, or process:
• Plaintext file contents — all data is encrypted client-side before submission • Encryption keys or derived key material • Personally identifiable information beyond what is technically required for API operation • Payment card data or financial account information
3. Blockchain Permanence Notice
By uploading data through Evercore, you acknowledge that:
• Data written to the Arweave network is permanent and immutable by protocol design — it cannot be deleted, modified, or removed by Evercore or any other party. • Transaction IDs and associated on-chain metadata are publicly visible on the Arweave network, regardless of whether the underlying payload is encrypted. • Evercore has no technical ability to remove or modify data after it has been confirmed on-chain. • It is your sole responsibility to ensure you hold the appropriate rights to any data you upload and that encryption is applied before submission for sensitive or regulated content.
4. How We Use Information
Transient operational data is used exclusively to:
• Operate and maintain the reliability of the Evercore service • Investigate and resolve API errors or anomalies • Detect and mitigate abuse, rate-limit violations, or malicious activity • Comply with applicable legal obligations
We do not sell, license, or share operational data with third parties for advertising or marketing purposes.
5. Third-Party Services
Evercore interfaces with the following external networks:
• Arweave Network — the decentralized storage layer. Data you upload becomes part of the public Arweave permaweb. Arweave's own network behavior is outside Evercore's control. • Bundlr / Irys — optional batching network for efficient uploads. Subject to their own terms. • Encore.dev — the underlying infrastructure platform. Encore may process request metadata per their privacy policy.
We encourage you to review the privacy policies of these third-party services.
6. Security
Evercore enforces the following security measures:
• TLS 1.3 for all API communications in transit • AES-256-GCM encryption enforced at the service layer before any upstream transmission • API keys are hashed and never stored in plaintext • Access to operational logs is restricted to authorized personnel
For details on our technical security architecture, see our Security page.
7. Your Rights
Depending on your jurisdiction, you may have rights regarding personal data we hold about you (e.g., GDPR, CCPA). Because Evercore is stateless and holds minimal data, most requests can be fulfilled quickly.
Note: We cannot fulfill requests to delete data that has been permanently written to the Arweave blockchain, as this is technically impossible by protocol design. We can, however, delete any transient operational data we hold (request logs, error traces) upon verified request.
To exercise your rights, contact us at the address below.
8. Cookies & Tracking
The Evercore API does not use cookies. The Evercore web interface may set strictly necessary session cookies for authentication. We do not use third-party tracking cookies, advertising pixels, or behavioral analytics.