Privacy Policy
Effective August 14, 2026
EverestPass provides owner-controlled credential and task access for AI agents. This policy explains what information the EverestPass Chrome extension and service collect, why it is used, and when it is shared.
Information we collect
- Account information: your email address and workspace identifiers.
- Authentication information: one-time sign-in challenge data, session credentials, and API credentials that you choose to add. Provider API credentials are encrypted in your browser before upload.
- Agent and Task information: agent names, descriptions, runtimes, purposes, approved actions, policies, budgets, expiration times, and access status.
- Usage and security information: provider, action, model, token or credit counts, cost amounts, request status, access decisions, alerts, and audit events. EverestPass does not store agent prompts or provider response bodies as part of its standard activity records.
- Network security information: an IP address is processed for abuse prevention and rate limiting. Rate-limit identifiers are stored as one-way hashes and expire after the applicable security window.
The extension does not collect browsing history, the content of pages you visit, browser clicks, keystrokes, health information, personal communications, or precise GPS location.
How we use information
EverestPass uses the information described above only to:
- authenticate you and maintain your signed-in session;
- encrypt, store, rotate, and use credentials for actions you approve;
- create and enforce Agent and Task permissions, budgets, and expiration;
- show activity, usage, alerts, and audit history;
- prevent fraud, abuse, unauthorized access, and service disruption; and
- maintain and improve the reliability and security of EverestPass.
How information is shared
EverestPass does not sell user data or use it for advertising, lending, or creditworthiness decisions.
Information is shared only when necessary to provide or secure the service:
- with infrastructure and email service providers that host EverestPass, store encrypted data, deliver sign-in codes, or protect the service;
- with the external provider selected by the user, such as OpenRouter or Apollo, when executing an expressly approved Agent action; and
- when required by law or necessary to investigate abuse or a security incident.
Security
EverestPass uses HTTPS for network transmission. Provider credentials are encrypted in the browser using AES-256-GCM, and the encryption key is wrapped using RSA-OAEP-256 before encrypted material is uploaded. The extension stores its signed-in session in Chrome local storage and removes it on logout or expiration.
Retention and deletion
Information is retained only while needed to provide the service, enforce security controls, meet legal obligations, and resolve disputes. Deleting a credential revokes its EverestPass access and schedules its stored encrypted material for deletion. Users can pause or revoke Agents, Tasks, connections, and entitlements from the extension.
Limited Use
EverestPass's use and transfer of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this policy
This policy may be updated when EverestPass features or data practices change. The effective date at the top of this page will be updated when changes are published.
Contact
Privacy questions can be sent to support@everestpass.com or through the EverestPass support page.