01
Scope
This policy explains what Informal Content Agency, a Nevada C corporation (“Informal”, “we”) collects when you use the Etch desktop app, the Etch hosted sync service at sync.etchstudios.ai, and this website, and the choices you have.
For data on our hosted service, Informal is the data controller; for business customers’ workspace content we act as a processor/service provider on their behalf. If your organization runs its own self-hosted etch-server, that organization — not Informal — controls the data on it.
02
Short version
- Etch is local-first: with sync off, your work stays on your Mac.
- With sync on, workspace content is stored on the sync server so your team can collaborate. You own it; we host it.
- Bring-your-own-key provider keys entered on your device never leave your client, except to the provider you configured.
- Crash reports go to a self-hosted GlitchTip instance we operate — not a third-party SaaS. Multiplayer runs on a self-hosted y-sweet server we operate.
- Product analytics use Amplitude and can be turned off in Settings.
- Payments are processed by Stripe through Stripe-hosted Checkout and billing portal; we never see or store full card numbers.
- We do not sell personal data and do not use your content to train AI models.
03
What we collect
Account data. Name, email, avatar (from Google sign-in or signup), hashed password (Argon2 — never plaintext), verification and reset tokens, and session/refresh tokens (short-lived access tokens; rotating, revocable refresh tokens).
Sync data (only when team sync is on). Workspace records your team creates: clients, projects, talent, board items, planner entries, project-channel messages, media uploads, canvas documents and periodic canvas checkpoints, membership and invite records, and the append-only change log (the workspace audit trail visible to your team). While a shared canvas is open, the multiplayer server processes ephemeral presence data (cursor, selection, display name).
Workspace secrets. Provider API keys saved at the workspace level are encrypted at rest with a dedicated AEAD key and decrypted only to serve authorized workspace requests. Personal BYOK keys entered in the desktop app stay on your device and never leave your client except to call the provider you chose.
Crash data. If enabled (default on), the app sends stack traces, app version, OS version, device model, and an anonymous installation id to our self-hosted GlitchTip instance. Opt out in Settings → Privacy → Crash reporting.
Analytics. If enabled (default on), the app sends product events (e.g. app.launched, project.created, billing.checkout_started) to Amplitude with a pseudonymous id and coarse properties — no project content, media, prompts, or secrets. Opt out in Settings → Privacy → Usage analytics.
Billing data. Plan, seats, trial and subscription status, invoices, and a Stripe customer id. Card details are collected and stored by Stripe, not by Informal — including the payment method collected when a 10-day trial starts.
Server and website logs. Standard operational logs (IP address, request path, timestamps, rate-limit counters) kept for a limited period for security and debugging. This website does not currently declare a marketing analytics service.
Early access requests. When you submit the early-access form on this website, we store the time of the request, your work email, the optional name and company you provide, the page the request came from, your browser identification string, and a one-way hash of your network address. The raw network address is not stored. These fields are written to an append-only file on Etch infrastructure and used only to review and respond to your request. If the form is not configured, the access link opens your email client instead, and your email provider processes that message under its own terms.
We do not collect: your local-only projects when sync is off, personal BYOK keys, or full payment card numbers.
04
Purposes
Where GDPR or similar laws apply, our legal bases are:
- Contract performance — providing sync, collaboration, storage, authentication, billing, trials, and transactional email (verification, reset, invites).
- Legitimate interests — securing the Service (abuse prevention, rate limiting), fixing crashes, and understanding aggregate product usage (with opt-outs for crash reporting and analytics). [TODO: counsel — confirm legitimate interests vs consent for analytics in the EU/UK.]
- Legal obligation — tax, accounting, and lawful requests.
07
Retention
- Account and workspace data — while your account or workspace is active; deleted on verified request.
- Backups — fixed rotation schedule; deleted data ages out as backups rotate.
- Crash reports — rolling window (target ~90 days). [TODO: ops/counsel — confirm.]
- Analytics — rolling window (target ~12 months aggregated). [TODO: ops/counsel — confirm.]
- Billing records — as required by tax and accounting law.
After deletion requests, data is removed from live systems promptly and from backups as they rotate.
08
Your rights
Everyone can toggle crash reporting and analytics in Settings, keep sync off to stay fully local, export workspace data at any time, and request access, correction, or deletion at the contact below. We verify requests before acting on them.
EEA, UK, Switzerland (GDPR/UK GDPR): you may request access, rectification, erasure, restriction, portability, and objection to legitimate-interest processing, withdraw consent where processing is based on consent, and lodge a complaint with your supervisory authority. [TODO: counsel — finalize the international transfer mechanism (SCCs and/or DPF) for US processing.]
California (CCPA/CPRA):you have the rights to know/access, correct, and delete personal information, to opt out of “sale” or “sharing” (we do neither), to limit use of sensitive personal information (we use none beyond providing the Service), and to non-discrimination. You may use an authorized agent; we verify agent authority.
The Service is not directed to children and is not intended for anyone under 16; if you believe a child has provided us data, contact us and we will delete it. Business customers can request a Data Processing Agreement. [TODO: counsel — prepare the DPA.]
09
Security
TLS in transit; Argon2 password hashing; short-lived access tokens with rotating refresh tokens revoked on password change; AEAD encryption at rest for workspace secrets; role-based workspace access with tenant-isolation checks on every scoped request; rate limiting on authentication endpoints.
Data is processed in the United States; if you use the Service from elsewhere, your data is transferred to the US. No system is perfectly secure — report vulnerabilities to the contact below.
10
Changes
We will post updates here and notify you in-app or by email of material changes at least 14 days before they take effect. The “Updated” date above reflects the current version.
Contact: gerald@weareinformal.com. [TODO: counsel/owner — add a physical mailing address and confirm role aliases before the draft banner is removed.]

