Skip to content
00%
Check access

01 / Navigate

Product overviewProduct overview01SolutionsSolutions02PricingPricing03DocumentationDocumentation04

02 / Work surfaces

01ExploreExplorePull the refs02ChatChatSet the concept03WhiteboardWhiteboardPick the cut04ShotlistShotlistPlan the shoot05LooksLooksMake the frames06AssetsAssetsThe library07PlannerPlannerThe feed
SystemLocal-first / macOS desktop studio
Check access

Document 01 / Privacy Policy

Privacy, stated plainly.

What Etch collects across the local-first desktop app, the hosted sync service, and this website — and the choices you have.

In forceEffective July 21, 2026Updated September 3, 2026Public build

On this page

  1. Scope
  2. Short version
  3. What we collect
  4. Purposes
  5. Sub-processors
  6. Cookies & DNT
  7. Retention
  8. Your rights
  9. Security
  10. Changes
Read the Terms of Service ↗

01

Scope

This policy explains what Informal Content Agency, a Nevada C corporation (“Informal”, “we”) collects when you use the Etch desktop app, the Etch hosted sync service at sync.etchstudios.ai, and this website, and the choices you have.

For data on our hosted service, Informal is the data controller; for business customers’ workspace content we act as a processor/service provider on their behalf. If your organization runs its own self-hosted etch-server, that organization — not Informal — controls the data on it.

02

Short version

  • Etch is local-first: with sync off, your work stays on your own computer.
  • With sync on, workspace content is stored on the sync server so your team can collaborate. You own it; we host it.
  • Personal bring-your-own-key credentials stay on your device and go only to the provider you configured. Approved workspace provider keys are sent to Etch and stored encrypted at rest for authorized workspace requests.
  • Hosted AI is optional and uses Etch-managed credentials by default. The prompt and inputs selected for a request are sent to the disclosed provider; BYOK remains available.
  • Crash reports go to a self-hosted GlitchTip instance we operate — not a third-party SaaS. Multiplayer runs on a self-hosted y-sweet server we operate.
  • Product analytics use Amplitude in the desktop app (off in Settings) and, when configured, on this website — where they stay off until you accept in the consent banner, and honor Do Not Track and Global Privacy Control.
  • Payments are processed by Stripe through Stripe-hosted Checkout and billing portal; we never see or store full card numbers.
  • We do not sell personal data and do not use your content to train AI models.

03

What we collect

Account data. Name, email, avatar (from Google sign-in or signup), hashed password (Argon2 — never plaintext), verification and reset tokens, and session/refresh tokens (short-lived access tokens; rotating, revocable refresh tokens).

Sync data (only when team sync is on). Workspace records your team creates: clients, projects, talent, board items, planner entries, project-channel messages, media uploads, canvas documents and periodic canvas checkpoints, membership and invite records, and the append-only change log (the workspace audit trail visible to your team). While a shared canvas is open, the multiplayer server processes ephemeral presence data (cursor, selection, display name).

Workspace secrets. Provider API keys saved at the workspace level are encrypted at rest with a dedicated AEAD key and decrypted only to serve authorized workspace requests. Personal BYOK keys entered in the desktop app stay on your device and never leave your client except to call the provider you chose.

Crash data. If enabled (default on), the app sends stack traces, app version, OS version, device model, and an anonymous installation id to our self-hosted GlitchTip instance. Opt out in Settings → Privacy → Crash reporting.

Analytics. If enabled (default on), the app sends product events (e.g. app.launched, project.created, billing.checkout_started) to Amplitude with a pseudonymous id and coarse properties — no project content, media, prompts, or secrets. Opt out in Settings → Privacy → Usage analytics.

Billing data. Plan, seats, trial and subscription status, invoices, and a Stripe customer id, tied to the workspace billing account. Only a workspace admin can start checkout or change billing. Card details are collected and stored by Stripe, not by Informal — including the payment method collected when a workspace admin starts a paid plan or its 10-day trial. Free requires no payment method.

Hosted AI request and usage data. When you use an Etch-managed route, we process the prompt, project context and input media you select, provider and concrete model, generation settings, job id, status, timestamps, internal metering metadata, and output location. This operational metadata is not presented to workspace members as per-call or per-model pricing. Prompt and input content for image and video generation are sent to fal (Features & Labels, Inc.). Hosted text is sent to OpenRouter and the selected text-model provider. BYOK chat goes to the provider you configured. Etch stores the returned response or a provider-hosted output reference with the job. Inline generated images may be persisted in protected workspace media storage so an authenticated Etch client can retrieve them. They remain private to the generation job and are not automatically published to workspace sync or imported into any project; you choose whether to download or import them. fal generation is not eligible for Zero Data Retention. Informal intends to request fal Store-IO:0 and a 3600-second object lifecycle on submit; until that configuration is live, fal’s defaults apply. Save generated media you need.

Server and website logs. Standard operational logs (IP address, request path, timestamps, rate-limit counters) kept for a limited period for security and debugging. This marketing website may also send optional Amplitude product-analytics events when an Amplitude key is configured for the build. Those events use a pseudonymous id and coarse page or device properties. They do not include form field values, account passwords, payment details, or workspace content. The Amplitude browser SDK is not loaded when Do Not Track or Global Privacy Control is enabled. This is product analytics, not advertising, and it is separate from the in-app Amplitude opt-out in Settings.

Early access requests. When you submit the early-access form on this website, we store the time of the request, your work email, the optional name and company you provide, the page the request came from, your browser identification string, and a one-way hash of your network address. The raw network address is not stored. These fields are written to an append-only file on Etch infrastructure and used only to review and respond to your request. If the form is not configured, the access link opens your email client instead, and your email provider processes that message under its own terms.

Beta waitlist. New-customer checkout availability is determined at request time by Etch’s deployed runtime access gate; this policy does not assert the current launch state. The waitlist is closed and the application form has been removed, so no new applications are being taken. Applications already submitted are stored as follows. The record holds your first name, last name, and email, the phone number you gave if you gave one, your date of birth, the time you applied, a one-way hash of your network address, and a record of the consent you gave — including the exact sentence that was shown to you. The raw network address is not stored. The form also asked about your work, and we hold the answers you gave: whether you work on an Apple Silicon Mac, your role, the size of your team, how many clients you carry, which tools hold your client context today, how often work has to be redone, whether you run production shoots, what AI tooling you already use, what you would use Etch for in your first week, whether you are willing to give us feedback, and anything you wrote in the notes field.

Your date of birth is collected for one purpose: confirming that you are 18 or over, which is a condition of joining the beta. The check runs when you submit the form. If the date you give makes you under 18, the application is refused at that moment and no record of it is written — we keep neither the date nor the rest of your answers. If you are 18 or over, the date is held with your application for the period given under Retention below and is used for nothing else: not to profile you, not to rank or sort applications, and not to target anything at you.

We also generate a private link so you can check your place in line without an account. Your position itself is not stored: it is counted from the applications still ahead of yours each time it is shown. We use these fields to run the waitlist and to review your application — to tell you where you stand, to email you when your position changes meaningfully, and to write to you with the outcome either way. If we accept you, that email carries your invitation. If we decline you, it carries a single-use Stripe code for one free month of Etch Pro, as thanks for the time the application took. Applying does not put you on a marketing list.

We do not collect: your local-only projects when sync is off, personal BYOK keys, or full payment card numbers.

04

Purposes

Where GDPR or similar laws apply, our legal bases are:

  • Contract performance — providing sync, collaboration, storage, authentication, billing, trials, customer-directed hosted AI inference, and transactional email (verification, reset, invites). This also covers steps taken at your own request before any contract exists — reviewing a beta waitlist application, confirming we received it, and writing to you with the outcome. The outcome is one message either way: your invitation if we accept you, or, if we decline you, a note telling you so with a single-use Stripe code for one free month of Etch Pro. The code is part of that reply rather than a separate mailing, and sending it does not add you to a marketing list.
  • Legitimate interests — securing the Service (abuse prevention, rate limiting), fixing crashes, and understanding aggregate product usage (with opt-outs for crash reporting and analytics). In the United States we rely on legitimate interests for product analytics, with an opt-out in Settings; in the EEA, UK, and Switzerland we enable analytics only with consent. On this website the consent banner appears on your first visit and stays until you choose: Accept turns analytics on (with a granular “Ads & measurement” toggle, off by default, for ad measurement we do not otherwise use), Reject keeps them off. Your choice is stored in this browser, and Do Not Track and Global Privacy Control signals count as refusal whether or not the banner has been answered. We also rely on legitimate interests to confirm that beta applicants are 18 or over. The beta is open to adults only, a date of birth is the least we can ask to establish that, we use it for nothing else, and an application from someone under 18 is refused at submission with no record kept. No law requires this check of us, which is why it sits here rather than under legal obligation.
  • Consent — beta waitlist position updates, the optional emails telling you that you have moved up the queue. You give this consent on the waitlist form itself and can withdraw it at any time from the link at the foot of those emails. Withdrawing stops the position updates only: you keep your place in line, and we still write to you with the outcome — your invitation if you are accepted, or the decline and its free-month code if you are not — because that is the thing you asked us for.
  • Legal obligation — tax, accounting, and lawful requests.

05

Sub-processors

Members and admins of a workspace see the content and activity in that workspace. Beyond that, we share personal data only with service providers acting on our instructions:

  • Stripe — payments: hosted checkout, billing portal, subscriptions. Receives name, email, and card data you enter directly with Stripe; card data never touches Etch servers.
  • Amplitude — product analytics: pseudonymous usage events with coarse device, app, or page properties from the desktop app and, when configured, this website. Desktop opt-out is in Settings; the website SDK is not loaded when Do Not Track or Global Privacy Control is enabled.
  • Google Workspace (Google LLC) — transactional email via SMTP: email address and the contents of verification, password-reset, invite, and beta waitlist mail.
  • Hosted AI routing and model providers — fal (Features & Labels, Inc., San Francisco, California, US) receives the prompt, inputs, settings, and identifiers needed to perform Etch-managed image and video generation. OpenRouter receives the same class of data for hosted text routes only. The concrete route is recorded with the job. Current processors and purposes appear on the Subprocessor page.
  • Website hosting — this marketing site is served from Informal-operated infrastructure (same U.S. footprint as the sync service); standard reverse-proxy request logs may be created. It is not hosted on a third-party static platform.

Crash reporting (GlitchTip), multiplayer (y-sweet), and the sync service itself run on infrastructure operated by Informal in the United States — not third-party SaaS. We may disclose data if required by law or to protect rights, safety, or the Service, and personal data may transfer as part of a merger or acquisition subject to this policy. We do not sell personal data.

06

Cookies & DNT

The desktop app does not use cookies. The hosted service uses authentication tokens (equivalent to strictly-necessary cookies) to keep you signed in. This website does not intentionally set advertising cookies. When website Amplitude is configured and you have accepted analytics in the consent banner (and have not sent a Do Not Track or Global Privacy Control signal), the Amplitude browser SDK may store first-party identifiers in the browser so product events can be associated across page views. The banner itself stores one more item in the browser: your consent choice, so you are not asked on every visit. Clear this site’s browser data to reset it and be asked again.

Because we do not track you across third-party sites or apps, there is no cross-site tracking to disable; we treat Global Privacy Control and Do-Not-Track signals as consistent with our existing practice of not selling or sharing personal data.

07

Retention

  • Account and workspace data — while your account or workspace is active. Deleting your account is what starts the clock: when you ask us to delete it, in the app or by verified request to the contact below, erasure runs 30 days later. Nothing is removed before that date, you can cancel at any point in the 30 days, and we email you a reminder before the deadline. The date is fixed at the moment you ask, so a later change to the window never moves a deadline you were already given.
  • Workspace change-log detail — the change log keeps a lasting record of what happened in a workspace: what changed, when, and who did it. The detailed before-and-after payload attached to each entry is cleared after about 90 days; the entry itself stays. This runs automatically on active workspaces and is not tied to any deletion request.
  • Backups — a nightly Postgres dump is copied to a separate NAS host on the same private infrastructure. This is an off-host operational copy, not an independent or geographically separate backup, and full restoration from it has not yet been proven. Deleted data ages out as the copies rotate (target ≤ 30 days).
  • Crash reports — rolling ~90 days on self-hosted GlitchTip.
  • Analytics — rolling ~12 months aggregated in Amplitude (product events only).
  • Server logs — ~14 days for reverse-proxy and application security/debug logs.
  • Beta waitlist records — the waitlist is closed and the application form has been removed, so no new applications are being taken. Applications already submitted are still held: your contact details, the answers you gave about your work, and anything you wrote in the free-text fields. We delete them when the programme is wound up, and you can have yours deleted sooner — ask at the contact below, or delete your Etch account, which removes the matching application with it. Your date of birth goes first, and automatically: the age check runs at submission and nothing after it needs the date, so a daily job clears it within 30 days of your applying, leaving only the record that the check passed. The consent record is kept for as long as the application it belongs to, as evidence of the consent you gave. A single-use code we have already emailed you exists in Stripe; deleting your waitlist record does not cancel it.
  • Billing records — as required by tax and accounting law. Invoices and payment records are held by Stripe, which retains them on its own schedule to meet the same obligations. Deleting your Etch account does not remove them, and we cannot delete them on request.
  • AI usage and job records — while the workspace is active and as needed for billing, abuse prevention, provider reconciliation, and dispute handling. Prompt or media content retained in the workspace follows the workspace retention period; provider-side copies follow the applicable API terms. Etch-managed image and video generation is not eligible for Zero Data Retention: fal receives the prompt and selected inputs to perform the request. Informal intends to request fal Store-IO:0 (no dashboard payload retention) and a 3600-second object lifecycle on submit; until that configuration is live, fal’s defaults apply (request payloads retained about 30 days in fal’s dashboard; generated media on fal CDN URLs without a guaranteed expiry). Save generated media you need. Hosted text routed through OpenRouter follows the selected text provider’s API terms.

What erasure reaches. On the deadline we delete your account record and everything attached to it — memberships, sessions and tokens, email preferences, consent records, invites — together with any workspace where you were the only member, including its content, its uploaded files, and its change history. A workspace that other people are still working in is not deleted; your contributions stay in it and your name comes off. Messages, canvas checkpoints, shares, generated media, and audit entries are reassigned to “Deleted user”. That is anonymisation rather than deletion, and we would rather say so than call it erasure.

What outlives it, and why. Invoices and payment records stay at Stripe under tax and accounting law. If your address is on our do-not-email list because it bounced or you unsubscribed, that entry stays — dropping it would let us mail an address that asked us to stop, and it is the only record left holding your address. We also keep a receipt showing that the erasure happened, which stores a one-way hash of your email address and counts of what was removed, never the address itself. Backups are not instant: deleted data ages out of them as the copies rotate, on the schedule above.

08

Your rights

Everyone can toggle crash reporting and analytics in Settings, keep sync off to stay fully local, export workspace data at any time, and request access, correction, or deletion at the contact below. We verify requests before acting on them. Deleting your account is self-service and reversible for 30 days: ask, and erasure runs on the thirtieth day unless you cancel first. Retention above sets out what that removes and what it does not.

EEA, UK, Switzerland (GDPR/UK GDPR): you may request access, rectification, erasure, restriction, portability, and objection to legitimate-interest processing, withdraw consent where processing is based on consent, and lodge a complaint with your supervisory authority. Personal data is processed in the United States; where GDPR or UK GDPR requires a transfer mechanism, we rely on adequacy regulations where they apply and otherwise on the European Commission’s Standard Contractual Clauses (with the UK addendum where required) in our data processing terms.

California (CCPA/CPRA): you have the rights to know/access, correct, and delete personal information, to opt out of “sale” or “sharing” (we do neither), to limit use of sensitive personal information (we use none beyond providing the Service), and to non-discrimination. You may use an authorized agent; we verify agent authority.

The Service is not directed to children and is not intended for anyone under 18; if you believe a child has provided us data, contact us and we will delete it. Business customers can request a Data Processing Agreement; the current DPA, including its processing schedules and international transfer clauses, is published at /dpa.

09

Security

TLS in transit; Argon2 password hashing; short-lived access tokens with rotating refresh tokens revoked on password change; AEAD encryption at rest for workspace secrets; role-based workspace access with tenant-isolation checks on every scoped request; rate limiting on authentication endpoints.

Data is processed in the United States; if you use the Service from elsewhere, your data is transferred to the US. No system is perfectly secure — report vulnerabilities to the contact below.

10

Changes

We will post updates here and notify you in-app or by email of material changes at least 14 days before they take effect. The “Updated” date above reflects the current version.

Contact: contact@weareinformal.com. Postal address: Informal Content Agency, 3945 W Reno Ave, Unit C, Las Vegas, NV 89118, USA.

01Product02Chat03Brain04Looks05Solutions06Pricing
TCH
Etch by Informal Content AgencymacOS · WindowsLocal-first · Team sync by choice
PrivacyTermsRefundsAI pricingDocumentationTrustSubprocessorsAccessibilityDMCADPAPrivacy request