Skip to content

EthenEthenEthen

Legal & Trust Center

Data Retention Policy

Effective date
Not yet in effect
Last updated
Version
1.0 · Pending finalization

Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.

This Data Retention Policy explains how long Ethen keeps each kind of information, what triggers deletion, and what deleting something actually does. It covers conversations, files, generated media, voice transcripts, connected-app records, account records, usage data and logs across Ethen Chat, Ethen Studio, Ethen Platform and the upcube.ai website. It distinguishes three kinds of retention:

  • what Upcube controls;
  • what the companies that provide AI models and other services control;
  • what you control yourself.

Where Upcube has fixed a period, this policy states it. Where it has not, the policy says so instead of guessing. Read it with the Privacy Policy.

On this page
  1. How retention works in Ethen
  2. Retention by category
  3. Deleting a conversation
  4. Deleting your Account
  5. Backups
  6. Legal, security and safety exceptions
  7. Provider retention
  8. Changes to this policy
  9. Related policies
  10. Contact
  11. Version history

How retention works in Ethen

Three kinds of retention

  • Upcube-controlled retention covers data Ethen stores in its own systems: its database, file storage and service logs. This policy sets the rules for it.
  • Provider-controlled retention covers copies held by the companies that process requests for Ethen, such as Model Providers, search and media providers, our sign-in provider and our hosting providers. Each follows its own terms. Deleting something in Ethen does not delete copies a provider already holds.
  • User-controlled retention covers what you keep, delete or clear yourself: conversations and Studio items you delete, data cached in your browser, and files you download or share.

What "delete" means here

This policy uses precise terms:

  • Deleted means removed from Ethen's live database or storage. It can no longer be retrieved through Ethen.
  • Marked deleted means hidden from you and excluded from Ethen's features, but still physically present in storage until it is erased.
  • Access ends means Ethen stops serving the item, even though a stored copy may remain.

Upcube is setting fixed retention periods for the categories marked "not yet fixed" in this policy. This policy will be updated when those periods are adopted and the systems that enforce them are in place.

Retention by category

Data categoryWhy it may be retainedRetention triggerApproved or typical periodExceptionsYour controls
Conversations, messages and chat titles (Ethen Chat)To keep your history availableCreated when you send a messageKept until you delete the conversation. No automatic expiry.Copies already sent to Model Providers follow their termsDelete a conversation; it is deleted immediately with its messages
Streamed response transcriptsTo recover a response interrupted mid-streamCreated while a response streamsKept with the conversation; deleted when the conversation is deleted—Delete the conversation
Sources and citations from researchTo show where an answer came fromSaved with the messageKept with the conversationSearch providers' own retention applies to queries they receivedDelete the conversation
Artifacts and artifact versionsTo keep documents, code and tables you createdCreated in a conversationKept until you delete the artifact or its conversation—Delete the artifact or conversation
Voice transcripts (Ethen Chat)To keep spoken exchanges in your conversationSaved when a voice exchange endsSame as conversationsAudio is not stored by Upcube; the realtime voice provider's retention applies to audio it processedDelete the conversation
Voice audio (Ethen Chat)Not retained by Upcube—Not stored by UpcubeProcessed by the realtime voice provider under its termsDo not use voice
Chat attachments (images and text files; uploads are currently turned off)To give the model your file and show it in the conversationUploadAccess through Ethen ends 30 days after upload. The period for erasing the stored file is not yet fixed; until it is, expired files may remain in private storage.Model Providers' retention applies to file content they receivedDelete the conversation (removes the reference; the stored file follows the attachment rule)
Ethen Studio projects, generated media and historyTo keep your creative work availableGeneration or uploadKept until you delete them. Deleted items are marked deleted and hidden; the period for erasing them is not yet fixed.Media providers' retention applies to prompts and references they receivedDelete items in Studio
Studio review linksTo let people you choose view shared itemsCreated when you shareActive until you revoke the link—Revoke the link
Likeness and voice consent records (Studio)To show what consent was declared for an identity or voiceRecorded when you declare consentNot yet fixedMay be kept as evidence after revocation where needed to handle disputes or misuseRevoke consent in Studio
Account identity (sign-in)To let you sign inAccount creationKept while your Account existsHeld by our sign-in provider, Clerk, under its termsAccount deletion (see below)
Account profile and settingsTo personalize Ethen and apply your preferencesAccount creation or settings changeSettings are deleted when you delete your Account. Profile records are not yet removed by account deletion.—Change settings; delete Account
Connected-app connections and credentials (when available)To act in services you connectWhen you connect a serviceCredentials are revoked and removed from the secrets vault when you disconnect your last connection to that account. Connection records are marked disconnected and kept; a period is not yet fixed.The connected service's own records are governed by that serviceDisconnect the app
Connected-app action records (when available)To show what Ethen did and support troubleshootingEach read or actionEthen marks these records for deletion 90 days after creation. Automatic deletion is not yet scheduled, so this period is not yet enforced.Results of actions, such as sent emails, remain in the connected service—
Pending app actions in Ethen Chat (when available)To resume a request after you connect an app or approve an actionWhen a request pausesCan be resumed for 30 minutes; the record is kept with the conversation—Cancel the pending action; delete the conversation
Usage recordsTo enforce usage limits, operate and improve the ServicesEach requestNot yet fixedMay be kept for security and abuse investigationsExport your recent usage records
Security data: rate-limit countersTo protect against abuseEach requestHeld in memory and reset within one minute——
Coordination dataTo keep requests reliable and avoid duplicatesEach requestShort-lived keys that expire automatically——
Service and access logsTo operate, debug and secure EthenEach requestKept by our hosting and sign-in providers according to their retention settings; Upcube has not set its own periodMay be kept longer for security investigations—
Audit records of account actionsTo record changes such as exports and account deletionWhen the action occursNot yet fixedKept for security and accountability—
Website analyticsTo understand use of upcube.aiEach page viewSet in Google Analytics; Upcube has not published a periodProcessed by Google under its termsBlock analytics cookies (see Cookie Policy)
Browser-cached history and draftsTo load Ethen Chat quickly and save unsent draftsUse of Ethen ChatCleared when you sign out; a signed-out draft lasts up to 24 hours—Sign out or clear site data
Waitlist sign-upsTo tell you when a product is availableWhen you joinNot yet fixed—Ask us to remove you
Billing recordsNot applicableEthen does not currently charge for use—If paid plans start, financial records will be kept as tax and accounting law requires—

Deleting a conversation

When you delete a conversation in Ethen Chat, Ethen immediately deletes, from its database:

  • the conversation;
  • its messages;
  • its streamed transcripts;
  • its artifacts and their versions;
  • any pending app actions linked to it.

This cannot be undone. Deletion does not reach:

  • copies that Model Providers, search providers or the realtime voice provider received while answering your requests;
  • the conversation history cached in another browser where you are still signed in, until you sign out or open Ethen there;
  • attachment files, which follow the attachment rule in the table above.

Deleting your Account

Deleting your Account from Ethen Chat settings currently:

  • signs you out everywhere;
  • deletes your saved settings;
  • deletes your app-connection records.

It does not currently delete your conversations, artifacts, files, Studio items, profile record or sign-in identity. To remove those, delete conversations and Studio items first, then send a deletion request through the contact options in the Legal & Trust Center. The Privacy Policy explains how requests are handled.

Backups

Ethen's database provider, Supabase, keeps operational copies of the database to support recovery. Upcube has not enabled point-in-time recovery and does not currently maintain separate long-term backups, so deleted data is not kept in an Upcube backup archive. Supabase's internal operational copies are governed by its own practices.

We may keep specific information longer than this policy otherwise describes when that is necessary to:

  • comply with a legal obligation or a lawful request from authorities;
  • establish, exercise or defend legal claims;
  • investigate or prevent fraud, security incidents or violations of the Acceptable Use Policy;
  • protect the safety of users or the public.

When we do, we keep only what is needed, for as long as it is needed.

Provider retention

Model Providers, search providers, media providers and the realtime voice provider each receive the content needed to fulfil your requests. Each retains it according to its own terms and its agreement with Upcube or with the routing service in between. Those terms can include logging for abuse monitoring, and they differ between providers. Upcube cannot delete data held by a provider on your behalf. The Subprocessors list identifies each provider. The BYOK Data Handling document explains how retention would differ if you used your own provider account.

Changes to this policy

We will update this policy when retention periods are fixed or changed, and record each change in the version history below.

Contact

Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.

Version history

VersionDateStatusSummary of changes
1.0October 5, 2026Not yet in effectReplaced category-only language with a verified retention table that distinguishes Upcube, provider and user-controlled retention.
0.9September 2026SupersededEarlier public-preview text. Archived.