01
Scope
This policy explains what Informal Content Agency, a Nevada C corporation (“Informal”, “we”) collects when you use the Etch desktop app, the Etch hosted sync service at sync.etchstudios.ai, and this website, and the choices you have.
For data on our hosted service, Informal is the data controller; for business customers’ workspace content we act as a processor/service provider on their behalf. If your organization runs its own self-hosted etch-server, that organization — not Informal — controls the data on it.
02
Short version
- Etch is local-first: with sync off, your work stays on your own computer.
- With sync on, workspace content is stored on the sync server so your team can collaborate. You own it; we host it.
- Personal bring-your-own-key credentials stay on your device and go only to the provider you configured. Approved workspace provider keys are sent to Etch and stored encrypted at rest for authorized workspace requests.
- Hosted AI is optional and uses Etch-managed credentials by default. The prompt and inputs selected for a request are sent to the disclosed provider; BYOK remains available.
- Crash reports go to a self-hosted GlitchTip instance we operate — not a third-party SaaS. Multiplayer runs on a self-hosted y-sweet server we operate.
- Product analytics use Amplitude in the desktop app (off in Settings) and, when configured, on this website — where they stay off until you accept in the consent banner, and honor Do Not Track and Global Privacy Control.
- Payments are processed by Stripe through Stripe-hosted Checkout and billing portal; we never see or store full card numbers.
- We do not sell personal data and do not use your content to train AI models.
03
What we collect
Account data. Name, email, avatar (from Google sign-in or signup), hashed password (Argon2 — never plaintext), verification and reset tokens, and session/refresh tokens (short-lived access tokens; rotating, revocable refresh tokens).
Sync data (only when team sync is on). Workspace records your team creates: clients, projects, talent, board items, planner entries, project-channel messages, media uploads, canvas documents and periodic canvas checkpoints, membership and invite records, and the append-only change log (the workspace audit trail visible to your team). While a shared canvas is open, the multiplayer server processes ephemeral presence data (cursor, selection, display name).
Workspace secrets. Provider API keys saved at the workspace level are encrypted at rest with a dedicated AEAD key and decrypted only to serve authorized workspace requests. Personal BYOK keys entered in the desktop app stay on your device and never leave your client except to call the provider you chose.
Crash data. If enabled (default on), the app sends stack traces, app version, OS version, device model, and an anonymous installation id to our self-hosted GlitchTip instance. Opt out in Settings → Privacy → Crash reporting.
Analytics. If enabled (default on), the app sends product events (e.g. app.launched, project.created, billing.checkout_started) to Amplitude with a pseudonymous id and coarse properties — no project content, media, prompts, or secrets. Opt out in Settings → Privacy → Usage analytics.
Billing data. Plan, seats, trial and subscription status, invoices, and a Stripe customer id, tied to the workspace billing account. Only a workspace admin can start checkout or change billing. Card details are collected and stored by Stripe, not by Informal — including the payment method collected when a workspace admin starts a paid plan or its 10-day trial. Free requires no payment method.
Hosted AI request and usage data. When you use an Etch-managed route, we process the prompt, project context and input media you select, provider and concrete model, generation settings, job id, status, timestamps, internal metering metadata, and output location. This operational metadata is not presented to workspace members as per-call or per-model pricing. Prompt and input content for image and video generation are sent to fal (Features & Labels, Inc.). Hosted text is sent to OpenRouter and the selected text-model provider. BYOK chat goes to the provider you configured. Etch stores the returned response or a provider-hosted output reference with the job. Inline generated images may be persisted in protected workspace media storage so an authenticated Etch client can retrieve them. They remain private to the generation job and are not automatically published to workspace sync or imported into any project; you choose whether to download or import them. fal generation is not eligible for Zero Data Retention. Informal intends to request fal Store-IO:0 and a 3600-second object lifecycle on submit; until that configuration is live, fal’s defaults apply. Save generated media you need.
Server and website logs. Standard operational logs (IP address, request path, timestamps, rate-limit counters) kept for a limited period for security and debugging. This marketing website may also send optional Amplitude product-analytics events when an Amplitude key is configured for the build. Those events use a pseudonymous id and coarse page or device properties. They do not include form field values, account passwords, payment details, or workspace content. The Amplitude browser SDK is not loaded when Do Not Track or Global Privacy Control is enabled. This is product analytics, not advertising, and it is separate from the in-app Amplitude opt-out in Settings.
Early access requests. When you submit the early-access form on this website, we store the time of the request, your work email, the optional name and company you provide, the page the request came from, your browser identification string, and a one-way hash of your network address. The raw network address is not stored. These fields are written to an append-only file on Etch infrastructure and used only to review and respond to your request. If the form is not configured, the access link opens your email client instead, and your email provider processes that message under its own terms.
Beta waitlist. New-customer checkout availability is determined at request time by Etch’s deployed runtime access gate; this policy does not assert the current launch state. The waitlist is closed and the application form has been removed, so no new applications are being taken. Applications already submitted are stored as follows. The record holds your first name, last name, and email, the phone number you gave if you gave one, your date of birth, the time you applied, a one-way hash of your network address, and a record of the consent you gave — including the exact sentence that was shown to you. The raw network address is not stored. The form also asked about your work, and we hold the answers you gave: whether you work on an Apple Silicon Mac, your role, the size of your team, how many clients you carry, which tools hold your client context today, how often work has to be redone, whether you run production shoots, what AI tooling you already use, what you would use Etch for in your first week, whether you are willing to give us feedback, and anything you wrote in the notes field.
Your date of birth is collected for one purpose: confirming that you are 18 or over, which is a condition of joining the beta. The check runs when you submit the form. If the date you give makes you under 18, the application is refused at that moment and no record of it is written — we keep neither the date nor the rest of your answers. If you are 18 or over, the date is held with your application for the period given under Retention below and is used for nothing else: not to profile you, not to rank or sort applications, and not to target anything at you.
We also generate a private link so you can check your place in line without an account. Your position itself is not stored: it is counted from the applications still ahead of yours each time it is shown. We use these fields to run the waitlist and to review your application — to tell you where you stand, to email you when your position changes meaningfully, and to write to you with the outcome either way. If we accept you, that email carries your invitation. If we decline you, it carries a single-use Stripe code for one free month of Etch Pro, as thanks for the time the application took. Applying does not put you on a marketing list.
We do not collect: your local-only projects when sync is off, personal BYOK keys, or full payment card numbers.
04
Purposes
Where GDPR or similar laws apply, our legal bases are:
- Contract performance — providing sync, collaboration, storage, authentication, billing, trials, customer-directed hosted AI inference, and transactional email (verification, reset, invites). This also covers steps taken at your own request before any contract exists — reviewing a beta waitlist application, confirming we received it, and writing to you with the outcome. The outcome is one message either way: your invitation if we accept you, or, if we decline you, a note telling you so with a single-use Stripe code for one free month of Etch Pro. The code is part of that reply rather than a separate mailing, and sending it does not add you to a marketing list.
- Legitimate interests — securing the Service (abuse prevention, rate limiting), fixing crashes, and understanding aggregate product usage (with opt-outs for crash reporting and analytics). In the United States we rely on legitimate interests for product analytics, with an opt-out in Settings; in the EEA, UK, and Switzerland we enable analytics only with consent. On this website the consent banner appears on your first visit and stays until you choose: Accept turns analytics on (with a granular “Ads & measurement” toggle, off by default, for ad measurement we do not otherwise use), Reject keeps them off. Your choice is stored in this browser, and Do Not Track and Global Privacy Control signals count as refusal whether or not the banner has been answered. We also rely on legitimate interests to confirm that beta applicants are 18 or over. The beta is open to adults only, a date of birth is the least we can ask to establish that, we use it for nothing else, and an application from someone under 18 is refused at submission with no record kept. No law requires this check of us, which is why it sits here rather than under legal obligation.
- Consent — beta waitlist position updates, the optional emails telling you that you have moved up the queue. You give this consent on the waitlist form itself and can withdraw it at any time from the link at the foot of those emails. Withdrawing stops the position updates only: you keep your place in line, and we still write to you with the outcome — your invitation if you are accepted, or the decline and its free-month code if you are not — because that is the thing you asked us for.
- Legal obligation — tax, accounting, and lawful requests.
07
Retention
- Account and workspace data — while your account or workspace is active. Deleting your account is what starts the clock: when you ask us to delete it, in the app or by verified request to the contact below, erasure runs 30 days later. Nothing is removed before that date, you can cancel at any point in the 30 days, and we email you a reminder before the deadline. The date is fixed at the moment you ask, so a later change to the window never moves a deadline you were already given.
- Workspace change-log detail — the change log keeps a lasting record of what happened in a workspace: what changed, when, and who did it. The detailed before-and-after payload attached to each entry is cleared after about 90 days; the entry itself stays. This runs automatically on active workspaces and is not tied to any deletion request.
- Backups — a nightly Postgres dump is copied to a separate NAS host on the same private infrastructure. This is an off-host operational copy, not an independent or geographically separate backup, and full restoration from it has not yet been proven. Deleted data ages out as the copies rotate (target ≤ 30 days).
- Crash reports — rolling ~90 days on self-hosted GlitchTip.
- Analytics — rolling ~12 months aggregated in Amplitude (product events only).
- Server logs — ~14 days for reverse-proxy and application security/debug logs.
- Beta waitlist records — the waitlist is closed and the application form has been removed, so no new applications are being taken. Applications already submitted are still held: your contact details, the answers you gave about your work, and anything you wrote in the free-text fields. We delete them when the programme is wound up, and you can have yours deleted sooner — ask at the contact below, or delete your Etch account, which removes the matching application with it. Your date of birth goes first, and automatically: the age check runs at submission and nothing after it needs the date, so a daily job clears it within 30 days of your applying, leaving only the record that the check passed. The consent record is kept for as long as the application it belongs to, as evidence of the consent you gave. A single-use code we have already emailed you exists in Stripe; deleting your waitlist record does not cancel it.
- Billing records — as required by tax and accounting law. Invoices and payment records are held by Stripe, which retains them on its own schedule to meet the same obligations. Deleting your Etch account does not remove them, and we cannot delete them on request.
- AI usage and job records — while the workspace is active and as needed for billing, abuse prevention, provider reconciliation, and dispute handling. Prompt or media content retained in the workspace follows the workspace retention period; provider-side copies follow the applicable API terms. Etch-managed image and video generation is not eligible for Zero Data Retention: fal receives the prompt and selected inputs to perform the request. Informal intends to request fal Store-IO:0 (no dashboard payload retention) and a 3600-second object lifecycle on submit; until that configuration is live, fal’s defaults apply (request payloads retained about 30 days in fal’s dashboard; generated media on fal CDN URLs without a guaranteed expiry). Save generated media you need. Hosted text routed through OpenRouter follows the selected text provider’s API terms.
What erasure reaches. On the deadline we delete your account record and everything attached to it — memberships, sessions and tokens, email preferences, consent records, invites — together with any workspace where you were the only member, including its content, its uploaded files, and its change history. A workspace that other people are still working in is not deleted; your contributions stay in it and your name comes off. Messages, canvas checkpoints, shares, generated media, and audit entries are reassigned to “Deleted user”. That is anonymisation rather than deletion, and we would rather say so than call it erasure.
What outlives it, and why. Invoices and payment records stay at Stripe under tax and accounting law. If your address is on our do-not-email list because it bounced or you unsubscribed, that entry stays — dropping it would let us mail an address that asked us to stop, and it is the only record left holding your address. We also keep a receipt showing that the erasure happened, which stores a one-way hash of your email address and counts of what was removed, never the address itself. Backups are not instant: deleted data ages out of them as the copies rotate, on the schedule above.
08
Your rights
Everyone can toggle crash reporting and analytics in Settings, keep sync off to stay fully local, export workspace data at any time, and request access, correction, or deletion at the contact below. We verify requests before acting on them. Deleting your account is self-service and reversible for 30 days: ask, and erasure runs on the thirtieth day unless you cancel first. Retention above sets out what that removes and what it does not.
EEA, UK, Switzerland (GDPR/UK GDPR): you may request access, rectification, erasure, restriction, portability, and objection to legitimate-interest processing, withdraw consent where processing is based on consent, and lodge a complaint with your supervisory authority. Personal data is processed in the United States; where GDPR or UK GDPR requires a transfer mechanism, we rely on adequacy regulations where they apply and otherwise on the European Commission’s Standard Contractual Clauses (with the UK addendum where required) in our data processing terms.
California (CCPA/CPRA): you have the rights to know/access, correct, and delete personal information, to opt out of “sale” or “sharing” (we do neither), to limit use of sensitive personal information (we use none beyond providing the Service), and to non-discrimination. You may use an authorized agent; we verify agent authority.
The Service is not directed to children and is not intended for anyone under 18; if you believe a child has provided us data, contact us and we will delete it. Business customers can request a Data Processing Agreement; the current DPA, including its processing schedules and international transfer clauses, is published at /dpa.
09
Security
TLS in transit; Argon2 password hashing; short-lived access tokens with rotating refresh tokens revoked on password change; AEAD encryption at rest for workspace secrets; role-based workspace access with tenant-isolation checks on every scoped request; rate limiting on authentication endpoints.
Data is processed in the United States; if you use the Service from elsewhere, your data is transferred to the US. No system is perfectly secure — report vulnerabilities to the contact below.
10
Changes
We will post updates here and notify you in-app or by email of material changes at least 14 days before they take effect. The “Updated” date above reflects the current version.
Contact: contact@weareinformal.com. Postal address: Informal Content Agency, 3945 W Reno Ave, Unit C, Las Vegas, NV 89118, USA.

