Skip to content
00%
Get Started

01 / Navigate

Product overviewProduct overview01SolutionsSolutions02PricingPricing03

02 / Work surfaces

01Creative DirectorCreative DirectorDirection held in context02BrainBrainOne memory per client03CanvasCanvasCreate, review, and finish04CollaborationCollaborationField and studio, in sync05Model ControlsModel ControlsRoute every creative model
SystemLocal-first / Apple Silicon
Get Started

Document 01 / Privacy Policy

Privacy, stated plainly.

What Etch collects across the local-first desktop app, the hosted sync service, and this website — and the choices you have.

DraftUpdated July 19, 2026Public build
●
DRAFT — pending counsel review. Not yet in force.

This policy was prepared against the current product but has not been reviewed by legal counsel. Items marked “[TODO: counsel]” are open. It takes effect only after attorney sign-off and an effective date are set.

On this page

  1. Scope
  2. Short version
  3. What we collect
  4. Purposes
  5. Sub-processors
  6. Cookies & DNT
  7. Retention
  8. Your rights
  9. Security
  10. Changes
Read the Terms of Service ↗

01

Scope

This policy explains what Informal Content Agency, a Nevada C corporation (“Informal”, “we”) collects when you use the Etch desktop app, the Etch hosted sync service at sync.etchstudios.ai, and this website, and the choices you have.

For data on our hosted service, Informal is the data controller; for business customers’ workspace content we act as a processor/service provider on their behalf. If your organization runs its own self-hosted etch-server, that organization — not Informal — controls the data on it.

02

Short version

  • Etch is local-first: with sync off, your work stays on your Mac.
  • With sync on, workspace content is stored on the sync server so your team can collaborate. You own it; we host it.
  • Bring-your-own-key provider keys entered on your device never leave your client, except to the provider you configured.
  • Crash reports go to a self-hosted GlitchTip instance we operate — not a third-party SaaS. Multiplayer runs on a self-hosted y-sweet server we operate.
  • Product analytics use Amplitude and can be turned off in Settings.
  • Payments are processed by Stripe through Stripe-hosted Checkout and billing portal; we never see or store full card numbers.
  • We do not sell personal data and do not use your content to train AI models.

03

What we collect

Account data. Name, email, avatar (from Google sign-in or signup), hashed password (Argon2 — never plaintext), verification and reset tokens, and session/refresh tokens (short-lived access tokens; rotating, revocable refresh tokens).

Sync data (only when team sync is on). Workspace records your team creates: clients, projects, talent, board items, planner entries, project-channel messages, media uploads, canvas documents and periodic canvas checkpoints, membership and invite records, and the append-only change log (the workspace audit trail visible to your team). While a shared canvas is open, the multiplayer server processes ephemeral presence data (cursor, selection, display name).

Workspace secrets. Provider API keys saved at the workspace level are encrypted at rest with a dedicated AEAD key and decrypted only to serve authorized workspace requests. Personal BYOK keys entered in the desktop app stay on your device and never leave your client except to call the provider you chose.

Crash data. If enabled (default on), the app sends stack traces, app version, OS version, device model, and an anonymous installation id to our self-hosted GlitchTip instance. Opt out in Settings → Privacy → Crash reporting.

Analytics. If enabled (default on), the app sends product events (e.g. app.launched, project.created, billing.checkout_started) to Amplitude with a pseudonymous id and coarse properties — no project content, media, prompts, or secrets. Opt out in Settings → Privacy → Usage analytics.

Billing data. Plan, seats, trial and subscription status, invoices, and a Stripe customer id. Card details are collected and stored by Stripe, not by Informal — including the payment method collected when a 10-day trial starts.

Server and website logs. Standard operational logs (IP address, request path, timestamps, rate-limit counters) kept for a limited period for security and debugging. This website does not currently declare a marketing analytics service.

Early access requests. When you submit the early-access form on this website, we store the time of the request, your work email, the optional name and company you provide, the page the request came from, your browser identification string, and a one-way hash of your network address. The raw network address is not stored. These fields are written to an append-only file on Etch infrastructure and used only to review and respond to your request. If the form is not configured, the access link opens your email client instead, and your email provider processes that message under its own terms.

We do not collect: your local-only projects when sync is off, personal BYOK keys, or full payment card numbers.

04

Purposes

Where GDPR or similar laws apply, our legal bases are:

  • Contract performance — providing sync, collaboration, storage, authentication, billing, trials, and transactional email (verification, reset, invites).
  • Legitimate interests — securing the Service (abuse prevention, rate limiting), fixing crashes, and understanding aggregate product usage (with opt-outs for crash reporting and analytics). [TODO: counsel — confirm legitimate interests vs consent for analytics in the EU/UK.]
  • Legal obligation — tax, accounting, and lawful requests.

05

Sub-processors

Members and admins of a workspace see the content and activity in that workspace. Beyond that, we share personal data only with service providers acting on our instructions:

  • Stripe — payments: hosted checkout, billing portal, subscriptions. Receives name, email, and card data you enter directly with Stripe; card data never touches Etch servers.
  • Amplitude — product analytics: pseudonymous usage events with coarse device and app properties. Opt-out in Settings.
  • Transactional email (SMTP) provider — email address and the contents of transactional mail. [TODO: owner — name the SMTP provider.]
  • Website hosting provider — standard request logs for this marketing site. [TODO: owner — confirm the hosting provider.]

Crash reporting (GlitchTip), multiplayer (y-sweet), and the sync service itself run on infrastructure operated by Informal in the United States — not third-party SaaS. We may disclose data if required by law or to protect rights, safety, or the Service, and personal data may transfer as part of a merger or acquisition subject to this policy. We do not sell personal data.

06

Cookies & DNT

The desktop app does not use cookies. The hosted service uses authentication tokens (equivalent to strictly-necessary cookies) to keep you signed in. This website does not intentionally set advertising cookies.

Because we do not track you across third-party sites or apps, there is no cross-site tracking to disable; we treat Global Privacy Control and Do-Not-Track signals as consistent with our existing practice of not selling or sharing personal data.

07

Retention

  • Account and workspace data — while your account or workspace is active; deleted on verified request.
  • Backups — fixed rotation schedule; deleted data ages out as backups rotate.
  • Crash reports — rolling window (target ~90 days). [TODO: ops/counsel — confirm.]
  • Analytics — rolling window (target ~12 months aggregated). [TODO: ops/counsel — confirm.]
  • Billing records — as required by tax and accounting law.

After deletion requests, data is removed from live systems promptly and from backups as they rotate.

08

Your rights

Everyone can toggle crash reporting and analytics in Settings, keep sync off to stay fully local, export workspace data at any time, and request access, correction, or deletion at the contact below. We verify requests before acting on them.

EEA, UK, Switzerland (GDPR/UK GDPR): you may request access, rectification, erasure, restriction, portability, and objection to legitimate-interest processing, withdraw consent where processing is based on consent, and lodge a complaint with your supervisory authority. [TODO: counsel — finalize the international transfer mechanism (SCCs and/or DPF) for US processing.]

California (CCPA/CPRA):you have the rights to know/access, correct, and delete personal information, to opt out of “sale” or “sharing” (we do neither), to limit use of sensitive personal information (we use none beyond providing the Service), and to non-discrimination. You may use an authorized agent; we verify agent authority.

The Service is not directed to children and is not intended for anyone under 16; if you believe a child has provided us data, contact us and we will delete it. Business customers can request a Data Processing Agreement. [TODO: counsel — prepare the DPA.]

09

Security

TLS in transit; Argon2 password hashing; short-lived access tokens with rotating refresh tokens revoked on password change; AEAD encryption at rest for workspace secrets; role-based workspace access with tenant-isolation checks on every scoped request; rate limiting on authentication endpoints.

Data is processed in the United States; if you use the Service from elsewhere, your data is transferred to the US. No system is perfectly secure — report vulnerabilities to the contact below.

10

Changes

We will post updates here and notify you in-app or by email of material changes at least 14 days before they take effect. The “Updated” date above reflects the current version.

Contact: gerald@weareinformal.com. [TODO: counsel/owner — add a physical mailing address and confirm role aliases before the draft banner is removed.]

01Product02Creative Director03Brain04Canvas05Solutions06Pricing
ETCH
Etch by Informal Content AgencymacOS · Apple SiliconLocal-first · Team sync by choice
PrivacyTerms