Data & Security
EverCore is designed to minimize unnecessary infrastructure and give users direct control over the services that power their business.
Local credential storage
Supported AI keys and GitHub access tokens are intended to be stored using secure device storage. Credentials should never be shared through email, chat, screenshots, or support tickets.
User-owned publishing
Mini Shops are published to a GitHub repository controlled by the user. Users are responsible for repository permissions, token expiration, recovery, and public content.
Token permissions
Use the least access necessary. Fine-grained GitHub tokens should be limited to the specific repository used for EverCore publishing and renewed or revoked as appropriate.
Third-party providers
Requests sent to AI, search, affiliate, merchant, or publishing providers are subject to those providers’ security, privacy, retention, billing, and availability practices.
Recommended user practices
- Use a device passcode and current iOS version.
- Protect provider accounts with strong passwords and multi-factor authentication.
- Do not reuse or publicly expose API keys or tokens.
- Revoke credentials immediately if compromised.
- Review all content before publishing.
Report a security concern
Email 7vncustoms@gmail.com with a clear description. Do not include live credentials or sensitive personal information.