Legal & Trust Center
Data Retention Policy
Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.
This Data Retention Policy explains how long Ethen keeps each kind of information, what triggers deletion, and what deleting something actually does. It covers conversations, files, generated media, voice transcripts, connected-app records, account records, usage data and logs across Ethen Chat, Ethen Studio, Ethen Platform and the upcube.ai website. It distinguishes three kinds of retention:
- what Upcube controls;
- what the companies that provide AI models and other services control;
- what you control yourself.
Where Upcube has fixed a period, this policy states it. Where it has not, the policy says so instead of guessing. Read it with the Privacy Policy.
On this page
How retention works in Ethen
Three kinds of retention
- Upcube-controlled retention covers data Ethen stores in its own systems: its database, file storage and service logs. This policy sets the rules for it.
- Provider-controlled retention covers copies held by the companies that process requests for Ethen, such as Model Providers, search and media providers, our sign-in provider and our hosting providers. Each follows its own terms. Deleting something in Ethen does not delete copies a provider already holds.
- User-controlled retention covers what you keep, delete or clear yourself: conversations and Studio items you delete, data cached in your browser, and files you download or share.
What "delete" means here
This policy uses precise terms:
- Deleted means removed from Ethen's live database or storage. It can no longer be retrieved through Ethen.
- Marked deleted means hidden from you and excluded from Ethen's features, but still physically present in storage until it is erased.
- Access ends means Ethen stops serving the item, even though a stored copy may remain.
Upcube is setting fixed retention periods for the categories marked "not yet fixed" in this policy. This policy will be updated when those periods are adopted and the systems that enforce them are in place.
Retention by category
| Data category | Why it may be retained | Retention trigger | Approved or typical period | Exceptions | Your controls |
|---|---|---|---|---|---|
| Conversations, messages and chat titles (Ethen Chat) | To keep your history available | Created when you send a message | Kept until you delete the conversation. No automatic expiry. | Copies already sent to Model Providers follow their terms | Delete a conversation; it is deleted immediately with its messages |
| Streamed response transcripts | To recover a response interrupted mid-stream | Created while a response streams | Kept with the conversation; deleted when the conversation is deleted | — | Delete the conversation |
| Sources and citations from research | To show where an answer came from | Saved with the message | Kept with the conversation | Search providers' own retention applies to queries they received | Delete the conversation |
| Artifacts and artifact versions | To keep documents, code and tables you created | Created in a conversation | Kept until you delete the artifact or its conversation | — | Delete the artifact or conversation |
| Voice transcripts (Ethen Chat) | To keep spoken exchanges in your conversation | Saved when a voice exchange ends | Same as conversations | Audio is not stored by Upcube; the realtime voice provider's retention applies to audio it processed | Delete the conversation |
| Voice audio (Ethen Chat) | Not retained by Upcube | — | Not stored by Upcube | Processed by the realtime voice provider under its terms | Do not use voice |
| Chat attachments (images and text files; uploads are currently turned off) | To give the model your file and show it in the conversation | Upload | Access through Ethen ends 30 days after upload. The period for erasing the stored file is not yet fixed; until it is, expired files may remain in private storage. | Model Providers' retention applies to file content they received | Delete the conversation (removes the reference; the stored file follows the attachment rule) |
| Ethen Studio projects, generated media and history | To keep your creative work available | Generation or upload | Kept until you delete them. Deleted items are marked deleted and hidden; the period for erasing them is not yet fixed. | Media providers' retention applies to prompts and references they received | Delete items in Studio |
| Studio review links | To let people you choose view shared items | Created when you share | Active until you revoke the link | — | Revoke the link |
| Likeness and voice consent records (Studio) | To show what consent was declared for an identity or voice | Recorded when you declare consent | Not yet fixed | May be kept as evidence after revocation where needed to handle disputes or misuse | Revoke consent in Studio |
| Account identity (sign-in) | To let you sign in | Account creation | Kept while your Account exists | Held by our sign-in provider, Clerk, under its terms | Account deletion (see below) |
| Account profile and settings | To personalize Ethen and apply your preferences | Account creation or settings change | Settings are deleted when you delete your Account. Profile records are not yet removed by account deletion. | — | Change settings; delete Account |
| Connected-app connections and credentials (when available) | To act in services you connect | When you connect a service | Credentials are revoked and removed from the secrets vault when you disconnect your last connection to that account. Connection records are marked disconnected and kept; a period is not yet fixed. | The connected service's own records are governed by that service | Disconnect the app |
| Connected-app action records (when available) | To show what Ethen did and support troubleshooting | Each read or action | Ethen marks these records for deletion 90 days after creation. Automatic deletion is not yet scheduled, so this period is not yet enforced. | Results of actions, such as sent emails, remain in the connected service | — |
| Pending app actions in Ethen Chat (when available) | To resume a request after you connect an app or approve an action | When a request pauses | Can be resumed for 30 minutes; the record is kept with the conversation | — | Cancel the pending action; delete the conversation |
| Usage records | To enforce usage limits, operate and improve the Services | Each request | Not yet fixed | May be kept for security and abuse investigations | Export your recent usage records |
| Security data: rate-limit counters | To protect against abuse | Each request | Held in memory and reset within one minute | — | — |
| Coordination data | To keep requests reliable and avoid duplicates | Each request | Short-lived keys that expire automatically | — | — |
| Service and access logs | To operate, debug and secure Ethen | Each request | Kept by our hosting and sign-in providers according to their retention settings; Upcube has not set its own period | May be kept longer for security investigations | — |
| Audit records of account actions | To record changes such as exports and account deletion | When the action occurs | Not yet fixed | Kept for security and accountability | — |
| Website analytics | To understand use of upcube.ai | Each page view | Set in Google Analytics; Upcube has not published a period | Processed by Google under its terms | Block analytics cookies (see Cookie Policy) |
| Browser-cached history and drafts | To load Ethen Chat quickly and save unsent drafts | Use of Ethen Chat | Cleared when you sign out; a signed-out draft lasts up to 24 hours | — | Sign out or clear site data |
| Waitlist sign-ups | To tell you when a product is available | When you join | Not yet fixed | — | Ask us to remove you |
| Billing records | Not applicable | Ethen does not currently charge for use | — | If paid plans start, financial records will be kept as tax and accounting law requires | — |
Deleting a conversation
When you delete a conversation in Ethen Chat, Ethen immediately deletes, from its database:
- the conversation;
- its messages;
- its streamed transcripts;
- its artifacts and their versions;
- any pending app actions linked to it.
This cannot be undone. Deletion does not reach:
- copies that Model Providers, search providers or the realtime voice provider received while answering your requests;
- the conversation history cached in another browser where you are still signed in, until you sign out or open Ethen there;
- attachment files, which follow the attachment rule in the table above.
Deleting your Account
Deleting your Account from Ethen Chat settings currently:
- signs you out everywhere;
- deletes your saved settings;
- deletes your app-connection records.
It does not currently delete your conversations, artifacts, files, Studio items, profile record or sign-in identity. To remove those, delete conversations and Studio items first, then send a deletion request through the contact options in the Legal & Trust Center. The Privacy Policy explains how requests are handled.
Backups
Ethen's database provider, Supabase, keeps operational copies of the database to support recovery. Upcube has not enabled point-in-time recovery and does not currently maintain separate long-term backups, so deleted data is not kept in an Upcube backup archive. Supabase's internal operational copies are governed by its own practices.
Legal, security and safety exceptions
We may keep specific information longer than this policy otherwise describes when that is necessary to:
- comply with a legal obligation or a lawful request from authorities;
- establish, exercise or defend legal claims;
- investigate or prevent fraud, security incidents or violations of the Acceptable Use Policy;
- protect the safety of users or the public.
When we do, we keep only what is needed, for as long as it is needed.
Provider retention
Model Providers, search providers, media providers and the realtime voice provider each receive the content needed to fulfil your requests. Each retains it according to its own terms and its agreement with Upcube or with the routing service in between. Those terms can include logging for abuse monitoring, and they differ between providers. Upcube cannot delete data held by a provider on your behalf. The Subprocessors list identifies each provider. The BYOK Data Handling document explains how retention would differ if you used your own provider account.
Changes to this policy
We will update this policy when retention periods are fixed or changed, and record each change in the version history below.
Contact
Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.
Version history
| Version | Date | Status | Summary of changes |
|---|---|---|---|
| 1.0 | October 5, 2026 | Not yet in effect | Replaced category-only language with a verified retention table that distinguishes Upcube, provider and user-controlled retention. |
| 0.9 | September 2026 | Superseded | Earlier public-preview text. Archived. |