Skip to content

EthenEthenEthen

Legal & Trust Center

Connected Apps & Integrations

Effective date
Not yet in effect
Last updated
Version
1.0 · Pending finalization

Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.

This document explains how Ethen connects to other apps on your behalf. It covers:

  • the permissions Ethen asks for when you connect Gmail, Google Drive or Google Calendar;
  • what Ethen can read, and which actions it can take only with your approval;
  • how connection credentials are stored and refreshed;
  • what happens when you disconnect, and what is kept afterwards.

It applies to individuals and Organizations using connected apps in Ethen Chat and Ethen Platform. Connected apps are not yet available. This document describes the system as built for the launch set, and it will be updated if anything changes before release. Read it with the Privacy Policy and the Terms of Service.

On this page
  1. Current availability
  2. What a connected app is
  3. How you authorize a connection
  4. Permissions Ethen requests
  5. What Ethen can read
  6. What Ethen can do, and when it asks first
  7. How approvals work
  8. Pausing and resuming requests
  9. How credentials are stored
  10. Refreshing access
  11. Webhooks, events and background work
  12. Disconnecting and revoking access
  13. What is kept after you disconnect
  14. Third-party terms
  15. Organizations and admin-installed integrations
  16. Security and reporting problems
  17. Related policies
  18. Contact
  19. Version history

Current availability

Connected apps are not yet available to Ethen users. The first services planned are Gmail, Google Drive and Google Calendar. They will become available after Google completes its review of Ethen's access to these services. Until then, Ethen cannot connect to your Google account or any other app.

Ethen's code also includes connectors for other services, such as Slack, Microsoft Outlook, Microsoft Teams and GitHub. These are not part of the launch set and are not available. If any is added, this document will describe its permissions first.

What a connected app is

A connected app (a "Connected Service") is a third-party service, such as your email, files or calendar, that you authorize Ethen to access through your own account with that service. Connecting a service lets Ethen Chat do two things:

  • use information from the service when it answers you, for example finding an email or a file;
  • take actions in the service that you approve, for example creating a draft or adding a calendar event.

Connected apps are managed by Ethen Platform, which handles authorization, credential storage, permissions and approvals. Ethen Chat sends tool requests to Ethen Platform and receives results.

How you authorize a connection

Connections use OAuth, the standard authorization method these services provide. When you connect:

  1. Ethen sends you to the service's own sign-in and consent screen, such as Google's.
  2. The service shows you the permissions Ethen is requesting, and you decide whether to grant them.
  3. If you agree, the service gives Ethen a credential (an access token, plus a refresh token that lets Ethen renew access) for your account.
  4. Ethen stores the credential securely and uses it only on its servers.

Ethen never sees or stores your password for the connected service. Ethen requests permissions in stages. It asks only for read access when you first connect, and asks for additional permissions, such as permission to send email, only when you first try to do something that needs them.

Permissions Ethen requests

ServiceWhen you connectRequested later, only if needed
GmailYour basic Google profile and email address; read your email (gmail.readonly)Create drafts (gmail.compose); send email on your behalf (gmail.send)
Google DriveYour basic Google profile and email address; read your files (drive.readonly)—
Google CalendarYour basic Google profile and email address; read your calendars and events, and check free/busy times (calendar.readonly, calendar.events.readonly, calendar.freebusy)Create and update events (calendar.events)

Ethen asks for Gmail and Google Drive access through one Google authorization, and for Google Calendar through a separate one, because Google classifies these permissions differently.

What Ethen can read

Once a service is connected, Ethen can search and read within the permissions you granted. These read actions run as part of your request, without a separate approval step:

ServiceRead actions
GmailSearch your messages; read a message thread
Google DriveSearch your files; read a file's details; read a file's content
Google CalendarList your calendars; list and read events; find free time

What Ethen reads is passed to the AI model answering your request, as the Privacy Policy describes. Ethen keeps a limited copy of each result, up to 64 KB, with the record of the action.

What Ethen can do, and when it asks first

ServiceActionRisk levelApproval
GmailCreate a draftMediumAsks each time, unless you grant a standing approval
GmailSend a new emailHighAlways asks. External recipients are highlighted.
GmailReply in a threadHighAlways asks. External recipients are highlighted.
Google CalendarCreate an eventMediumAsks each time, unless you grant a standing approval. Events with attendees outside your domain also ask.
Google CalendarUpdate an eventMediumSame as creating an event
Google Drive——Ethen cannot change, share or delete Drive files

Ethen cannot delete emails, files or calendar events, change sharing settings, make purchases or change account permissions in any connected service.

How approvals work

Ethen evaluates every action before it runs. Each action is classified by what it does and by its risk:

  • Reading and searching are low risk. They run without an approval step.
  • Creating and changing content, such as drafts and calendar events, is medium risk. Ethen asks for your approval before running it.
  • Sending and publishing, such as sending email, are high risk. Ethen always asks for your approval, every time.

Some details can raise an action to "ask", but never lower it. For example, an email or invitation to someone outside your organization's email domain always asks, as does an action whose recipients Ethen cannot confirm.

When Ethen asks for approval, it shows the action, the account it will use, and the details, such as the recipients and content. An approval request expires after 30 minutes if you do not respond. If you approve, the action runs once, as shown. If you decline or let it expire, nothing happens.

Standing approvals

For medium-risk actions you use often, such as creating email drafts, you can grant a standing approval. It lets that exact action run on that connection without asking each time, for a period you choose of up to 90 days. You can revoke it at any time. A standing approval stops applying automatically if Ethen changes how the action works. Standing approvals cannot be granted for sending, deleting, purchasing or administrative actions.

What Ethen will not do on its own

A model in Ethen Chat may suggest an action, but the suggestion alone never causes it to happen. Actions run only through the connected-app system and its approval rules. Ethen does not run connected-app actions on a schedule or in response to outside events. Each action starts from a request you make in a conversation.

Pausing and resuming requests

If a request needs a connection or permission you have not granted yet, or needs your approval, Ethen pauses it and shows a card in the conversation. You can connect the app, grant the permission or approve the action, and Ethen resumes the request. You can also cancel it. A paused request can be resumed for 30 minutes. Ethen saves the original request with the conversation so it can resume accurately, and deletes it if you delete the conversation.

How credentials are stored

Connection credentials are stored in a managed secrets vault provided by Supabase, Ethen's database provider. The vault keeps them encrypted at rest. Only Ethen's server-side systems can retrieve them; they cannot be read through the parts of Ethen that run in your browser, and they are never sent to AI models.

Credentials are held by Upcube on your behalf, not by you, so that Ethen can act when you ask it to. The Enterprise Security document describes how access to production systems is controlled.

Refreshing access

Access tokens from services like Google expire after a short time. Ethen uses the refresh token to obtain a new access token when needed, so you do not have to reconnect. Ethen refreshes a connection's token when a request needs it, and may also refresh active connections during routine maintenance. If the service rejects the refresh token, for example because you changed your password or revoked access, the connection is marked as needing reconnection.

Webhooks, events and background work

The launch set does not use webhooks or event subscriptions. Ethen does not receive notifications from Gmail, Google Drive or Google Calendar, and does not watch your accounts for changes. Ethen's background processes are limited to maintenance tasks, such as renewing credentials and removing expired records. They do not read your content or take actions in your accounts.

Disconnecting and revoking access

You can disconnect a connected app at any time. When you disconnect:

  • Ethen marks the connection as revoked and stops using it immediately;
  • Ethen removes the product permissions attached to it;
  • if it was your last connection to that account, Ethen asks the service (for example, Google) to revoke the credential, and revokes the credential stored in Ethen's vault.

You can also revoke Ethen's access from the service's own settings. For Google, that is the third-party access page in your Google Account. Ethen will then mark the connection as needing reconnection.

Approvals that were waiting when you disconnected cannot run, because the connection is no longer active.

What is kept after you disconnect

Disconnecting stops access. It does not erase everything Ethen recorded while the connection was active:

WhatWhat happens after disconnecting
The credentialRevoked with the service and removed from Ethen's vault (when it was the last connection to that account)
The connection record (service, account email, permissions granted, dates)Kept, marked as disconnected. A retention period is not yet fixed.
Records of reads and actions, including limited copies of resultsKept until they expire. They are marked for deletion 90 days after creation; see the Data Retention Policy.
Conversations that used connected-app informationKept until you delete them
Drafts, emails, events or other results created in the serviceRemain in the service. Ethen does not delete them.

Third-party terms

Your use of a connected service remains governed by your agreement with its provider, such as Google's Terms of Service and privacy policy. Actions Ethen takes on your instruction are actions taken in your account, subject to that service's rules. Upcube is not responsible for the service's availability or behavior.

Ethen's use of information received from Google APIs will follow Google's API Services User Data Policy, including its Limited Use requirements, once Google approves Ethen's access.

Organizations and admin-installed integrations

Ethen does not yet offer Organization administration. Connections are personal: by default, a connection belongs to the person who created it and is not available to other members of a Workspace. When Organization features become available, this document will describe any administrator controls, such as restricting which apps members can connect, and what administrators can see.

Security and reporting problems

Treat a connected app like any other access to your email or files:

  • connect only accounts you are authorized to use;
  • read approval requests carefully before approving;
  • revoke standing approvals you no longer need;
  • disconnect apps you no longer use.

If you believe a connection has been misused or compromised, disconnect it, revoke access in the service's own settings, and tell us through the contact options in the Legal & Trust Center.

Contact

Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.

Version history

VersionDateStatusSummary of changes
1.0October 5, 2026Not yet in effectFirst version, written from the implemented permission and approval system for the Google launch set.