Privacy policy
1. Scope
This Privacy Policy describes how Everesteer, Inc. and its affiliates ("Everesteer") collect, use, disclose and retain information in connection with the Everesteer platform, tournaments, interfaces, datasets and related services (the "Platform"). It forms part of, and is incorporated into, the Terms for Entrants, and capitalised terms not defined here have the meaning given there. By accessing the Platform you consent to the practices described in this Policy.
2. Information we collect
Everesteer collects, and you consent to Everesteer collecting:
- Account and identity information: email address, display name, authentication credentials and their derivatives, verification status, organisation affiliation where provided, and any information you supply in support or verification correspondence;
- Participation data: Submissions, predictions, model artefacts and metadata, uploads, standings, scores, diagnostics, entitlements, and the full history of the foregoing;
- Transaction and settlement data: wallet and contract addresses, on-chain transaction identifiers and signatures, stake, settlement and payout records, and any information required to meet sanctions, anti-money-laundering or reporting obligations;
- Session and interaction records for hosted services: where you use hosted agent, model-training, inference or artificial-intelligence compute provided through the Platform, Everesteer records and retains the requests, prompts, completions, tool invocations, parameters, outputs, errors and associated metadata transmitted through or generated by those services;
- Device and usage data: IP address, device and browser characteristics, user agent, request paths, timestamps, interface and API usage, telemetry, diagnostic and performance data, and server, application and security logs;
- Communications: correspondence with us, including support, security and event-related messages, and email delivery and engagement events such as delivery, bounce, open and click.
3. How we use information
Everesteer uses information to:
- operate, provide, maintain, secure, debug and improve the Platform;
- evaluate Submissions, compute scores, standings, entitlements and settlements, and construct composite, aggregate, ensemble and derivative models;
- conduct research and analysis, including investment and commercial research by Everesteer and its affiliates;
- detect, investigate and prevent fraud, abuse, collusion, multiple accounts, de-anonymisation attempts, security incidents and breaches of the Terms for Entrants;
- administer accounts, events and prizes, and communicate with you;
- comply with legal, regulatory, sanctions, tax and audit obligations, and establish, exercise or defend legal claims.
Everesteer may create and retain indefinitely aggregated, de-identified, derived or statistical information, which is not personal data and which Everesteer may use and disclose for any purpose without restriction.
4. Analytics and session replay
We use PostHog (US) to understand how the Platform is used. Analytics run at two levels, and the second happens only if you accept the banner.
- Without your consent we record page views with the query string removed, using no cookies and no persistent identifier. We keep this to see which pages are used at all.
- Only if you accept we additionally record interactions (clicks and form submissions, never the values you type) and session replay: a reconstruction of what the page looked like and how you moved through it.
Session replay is the most detailed of these, so it is worth being explicit about the limits. Every input is masked before it leaves your browser, so passwords, API keys and anything you type are never captured. Account, administrative, password-reset and key-claim pages are excluded entirely, with no replay and no page view. We identify you to PostHog by a pseudonymous account identifier only, never by email address or wallet address.
You can withdraw consent at any time by clearing the eiq_ph_consent cookie for this site, which returns you to the first level above. Rejecting the banner is not a barrier to using the Platform.
5. Disclosure
Everesteer may disclose information:
- to service providers and processors acting on its instructions, including hosting, content-delivery, authentication, email delivery, managed-compute, model-inference, analytics and monitoring providers;
- to its affiliates, and to professional advisers, auditors and insurers;
- to a counterparty in connection with any merger, acquisition, financing, reorganisation, insolvency or sale of assets;
- where required by law, regulation, legal process or governmental request, or where necessary to protect the rights, property or safety of Everesteer, its Users or the public, or to enforce the Terms for Entrants;
- publicly, in the case of display name, standings, scores and related competitive information published through the Platform;
- on a public blockchain, in the case of on-chain transactions, which are by their nature permanent, public and outside Everesteer's control.
Everesteer does not sell personal information, and does not use advertising trackers or advertising third parties.
6. International transfer
Everesteer operates internationally, and information may be stored and processed in the United States, the United Kingdom, the European Economic Area and other jurisdictions whose data protection laws may differ from those of your own. Where required, Everesteer relies on appropriate safeguards for such transfers. By using the Platform you consent to such transfer, storage and processing.
7. Retention
Everesteer keeps each category of information for the period below, and deletes or de-identifies it when that period ends.
- Account and identity information: while your account is open. After a verified deletion request it is deleted or de-identified within one month, except for the records listed below that must be kept.
- Submissions, scores, standings and settlement records: for the life of the Platform, because rounds, leaderboards and payouts are historical records that other participants rely on. After a deletion request they are de-identified rather than deleted. Model files you upload are deleted within one month of a deletion request.
- Information on a public blockchain: permanently. Everesteer cannot delete or amend it.
- Request and tool-call records (including requests from connected AI assistants, see section 12): 90 days, removed by a weekly job, so no record is kept longer than 97 days. Rate-limit records: 30 days.
- Server, security and access logs: application logs 30 days; firewall, sign-in and load balancer logs 90 days; content delivery access logs 365 days.
- Session and interaction records for hosted services (prompts, completions and transcripts of hosted agent and model sessions): 365 days.
- Session recordings (section 4): 30 days.
- Email delivery records: while your account is open.
- Backups: database backups are kept for 7 days and replaced files for 30 days, so deleted information can persist in them for up to that long.
Information may be kept longer where the law requires it, or where it is needed to establish, exercise or defend a legal claim, and only for as long as that need lasts.
8. Security
Everesteer maintains organisational, physical and engineering safeguards intended to protect information, including encryption of data at rest and in transit and access controls over sensitive stores. No system is secure against every threat, and Everesteer does not warrant the security of any information. You are responsible for safeguarding your own credentials, keys and wallets, and for the security of the systems and agents you operate.
9. Your rights
Depending on your jurisdiction you may have rights to request access to, correction of, deletion of, restriction of or objection to the processing of your personal information, or to request portability, and where processing is based on consent, to withdraw that consent without affecting prior processing. Requests may be sent to [email protected]. Everesteer will respond as required by applicable law. Rights are not absolute: Everesteer may decline or limit a request where an exemption applies, where it must retain information for legal, regulatory, security, audit or dispute purposes, or where the information is irreversibly aggregated, de-identified or recorded on a public blockchain.
Browser product analytics are optional. A previously recorded choice can be cleared here; that removes the stored decision and returns you to anonymous page views only, and the banner will ask again on the next visit. Session recording does not run on pages concerning money or credentials.
Your current analytics choice: Analytics: no choice recorded
10. Children
The Platform is not directed to, and may not be used by, persons under the age of eighteen. Everesteer does not knowingly collect information from such persons and will delete it upon becoming aware.
11. Changes
Everesteer may amend this Policy at any time. Amendments take effect upon posting unless stated otherwise, and continued use of the Platform constitutes acceptance. The date above indicates when this Policy was last revised.
12. AI assistants and connectors
When you connect Everesteer to Claude, ChatGPT or another MCP client, Everesteer receives only the requests and tool arguments that the assistant sends on your behalf. It does not receive your conversation with the assistant, and it does not receive anything the assistant does not put into a tool call.
For each request Everesteer logs the HTTP method, the route (without the query string), the response status, latency, the identifiers of the API key and account used, your IP address and country, your client's user agent and a correlation identifier. For each tool call it additionally logs the tool name, the arguments sent to it, whether it succeeded and how large the result was; the result itself is not stored. Tool arguments are stored with prediction values reduced to their shape, model source code reduced to a size and digest, and credential-like values removed, and long values are truncated. Any other argument the assistant sends, including free text such as a model name, is stored as sent.
These request and tool-call records are deleted after 90 days by a weekly job, so none is kept longer than 97 days, and server logs held in our hosting provider's log service are deleted after 30 days. Records of Submissions, scores and settlements that the connector creates are retained as described in section 7.
13. Contact
Privacy enquiries and rights requests: [email protected]. Security reports: [email protected].