← Back to Everscope

Privacy notice

What data does Everscope process?

Everscope processes Microsoft account information, Power BI/Fabric metadata, scan results, aggregated usage statistics, and user-provided governance and workflow information. This can include owner or validator names, KPI definitions, strategic objectives, team names, deadlines, decisions, notes, data classifications, SLA information, and links to external tickets. Everscope does not read or store underlying semantic-model rows and never removes Power BI objects automatically.

Launch control can also store support contacts, readiness attestations, pilot feedback, incident messages, subscription entitlements and billing-provider references. Everscope does not store payment card data. Provider references are excluded from normal exports.

Purposes

Data is used only for authentication, technical analysis, history, governance workflow, security, and service support.

Microsoft tokens

The MSAL token cache is encrypted at rest with AES-256-GCM. Tokens and secrets are not included in application logs.

Activity Events

User identities from Microsoft Activity Events are used only temporarily in memory to count unique users. Only aggregated counts per asset are stored.

Retention

Completed and failed scans are retained for 90 days by default. The administrator can adjust the configured retention period.

Export and deletion

In Settings, a user can export stored data or permanently delete the connection and its associated data. A user can also create tenant-scoped, read-only API keys for governance integrations. Only key hashes are stored; keys can expire and be revoked. API responses do not contain underlying semantic-model rows or KPI business values. Tenant archives include launch evidence, feedback, incident history and operational alerts; billing-provider identifiers are redacted.

Subprocessors and region

The intended production infrastructure uses Fly.io in Amsterdam and a Supabase project in an EU region. Review contracts, DPAs, and current subprocessor lists before public launch.

Contact

Privacy questions and data-subject requests can be sent to privacy@everscope.app. Security reports can be sent to security@everscope.app.