Legal & Trust Center
Privacy Policy
Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.
This Privacy Policy explains how Upcube collects, uses, shares and protects personal data when you use Ethen, including Ethen Chat, Ethen Studio, Ethen Platform and the upcube.ai website. It describes what we collect, why, which other companies process it on our behalf, and which AI model providers can receive your prompts. It also covers how long data is kept and the choices you have. Data paths in Ethen depend on the product, model and features you use, so this policy names those paths instead of describing them in general terms. Read it together with the Terms of Service, the Data Retention Policy, the Subprocessors list and the Cookie Policy.
On this page
- Who operates Ethen
- Ethen privacy at a glance
- What this policy covers
- Information you give us
- Information we collect automatically
- Information we receive from others
- How we use information
- Model training and product improvement
- How AI model providers are involved
- Bring your own key
- Connected services
- Local and cloud processing
- How we share information
- Where information is processed
- How long we keep information
- How we protect information
- Your choices and rights
- Organizations and administrators
- Children
- Changes to this policy
- How to contact us
- Related policies
- Contact
- Version history
Who operates Ethen
Ethen is operated by Upcube. The full legal name, place of registration and notice address of the contracting company will be stated here before this document takes effect.
In this policy, "Upcube", "we", "us" and "our" mean the company that operates Ethen. "You" means the person using Ethen or visiting our websites. Other capitalized terms, such as Prompt, Output, Model Provider and Connected Service, have the meanings given in the Terms of Service.
Ethen privacy at a glance
- AI model providers receive your prompts. When you send a message in Ethen Chat, the prompt and the relevant conversation context go to the company whose model answers it. By default that is Meta, through Meta's Muse API. Some modes and models you choose use other providers, such as OpenAI, Anthropic, Google or DeepSeek, reached through the Vercel AI Gateway. Not every prompt goes to every provider.
- Conversations are kept until you delete them. Deleting a conversation removes it, with its messages and artifacts, from Ethen's database right away. Copies a model provider has already received are governed by that provider's terms.
- Model training. Upcube's position on using your content for model training is described in Model training and product improvement.
- Analytics. The upcube.ai website uses Google Analytics. Ethen does not use advertising cookies.
- Your data is stored in the United States. Ethen's database runs in a U.S. region of Amazon Web Services, operated for us by Supabase.
What this policy covers
This policy applies to personal data Upcube processes when you:
- visit upcube.ai or any other Ethen website;
- create or use an Account;
- use Ethen Chat at chat.upcube.ai, including its research and voice features;
- use Ethen Studio at studio.upcube.ai;
- join a waitlist on Ethen Platform at platform.upcube.ai;
- contact us or take part in a survey, test or event.
Some Ethen products are announced but not yet available, including Ethen Code, connected apps and bring-your-own-key access. Where this policy describes them, it says so. Before any of them becomes available, this policy and the product-specific documents linked below will be updated to match how the released product behaves.
This policy does not cover third-party services you choose to use alongside Ethen, such as a Google account you connect or a website a research result links to. Those services have their own privacy practices.
If an Organization gives you access to Ethen under an agreement with Upcube, that Organization may have its own obligations and controls for the data it provides. See Organizations and administrators.
Information you give us
Account and profile information
To create an Account you provide an email address and a password, or you sign in with Google. Sign-in is handled by Clerk, our identity provider. If you sign in with Google, Clerk receives the basic profile information Google shares, typically your name, email address and profile photo. Your Account may also hold a display name and an avatar. Ethen links your conversations, projects and settings to an internal account identifier.
One Account works across Ethen products that share sign-in: Ethen Chat, Ethen Studio and Ethen Platform.
Prompts, conversations and outputs
When you use Ethen Chat, we process and store:
- the messages you send, including any text you paste or dictate;
- the responses Ethen returns, along with the steps and tool activity shown alongside them;
- sources and citations returned by research features;
- artifacts created in a conversation, such as documents, code or tables, and their earlier versions;
- the conversation's title, which by default is taken from the first words of your first message (you can turn automatic titles off);
- technical details about each response, such as which model and provider produced it, whether a fallback was used, and timing information.
During generation, Ethen also keeps a running transcript of the response as it streams, so an interrupted response can be recovered. That transcript is stored with the conversation and is deleted with it.
Files and attachments
File attachments are currently turned off in Ethen Chat. Every upload must pass an automated file scanner, and no scanner is configured yet, so Ethen refuses uploads instead of accepting them unchecked. When attachments are turned on, Ethen Chat will accept image files (PNG, JPEG and WebP) and plain-text and Markdown files of up to 5 MB. Attachments will be checked before they are accepted and are stored in private storage associated with your project, never in a public location. Images will be passed to models that can read images, and text files will be passed as part of the prompt, up to a length limit. Access to an attachment through Ethen ends 30 days after upload. See the Data Retention Policy for what happens to the stored file.
Media in Ethen Studio
When you use Ethen Studio, we process the prompts, settings and reference media you provide, and we store the images, video and audio Studio generates for you, along with project, history and review information. If you upload images, audio or video, or create a character or voice identity, we process that media and the consent information you record about it. The Ethen Studio Media, Likeness & Generated Content policy explains the rules that apply to uploads and likeness.
Voice and transcripts
When you use voice in Ethen Chat, your microphone audio is streamed from your browser to our realtime voice provider so the model can listen and respond. Upcube's own servers do not receive or store the audio. When the voice exchange ends, its text transcript is saved to your conversation like any other message. The Voice Consent Policy policy explains this path and your responsibilities when other people can be heard.
Code and repository information
Ethen Code is not yet available. When it is released, it will process source code, repository metadata, terminal activity and similar information as described in Ethen Code & Repository Data, and this policy will be updated before release.
Connected apps
Connected apps are not yet available. When they are, connecting a service such as Gmail, Google Drive or Google Calendar will give Ethen access to information in that service within the permissions you approve. Connected Apps & Integrations explains what will be accessed, what Ethen can do with your approval, and how credentials are stored.
Payment information
Ethen does not currently charge for use, and we do not collect payment card details. If paid plans are introduced, payments will be processed by a payment provider. This policy and the Refund & Cancellation Policy will be updated first.
Waitlists and messages you send us
If you join a waitlist, we receive your email address, the product you are interested in and the page you came from. If you write to us, we receive your message and contact details.
Information we collect automatically
Device, log and security information
When your browser or device connects to Ethen, our hosting providers receive standard technical information: IP address, browser type, device information, the pages or endpoints requested, timestamps and error codes. We use this information to deliver the Services, keep them secure and diagnose problems. Ethen also uses your IP address to apply short-lived rate limits that protect against abuse. These counters are held in memory and reset within a minute.
Usage information
We record how the Services are used, for example which features you use, how many messages you send, which models answer and whether requests succeed. We use this information to operate the Services, enforce usage limits during the beta period, understand reliability, and improve how Ethen works.
Cookies and browser storage
Ethen uses cookies and browser storage to keep you signed in, remember preferences such as your theme, and preserve unsent drafts. On Ethen Chat, it also keeps a copy of your recent conversation history in your browser so the app loads quickly; that copy is cleared when you sign out. The upcube.ai website uses Google Analytics. The Cookie Policy lists each item and explains your controls.
Information we receive from others
- Sign-in providers. If you sign in with Google, we receive the profile information Google shares with Clerk.
- AI model and tool providers. Model Providers return the Outputs you request. Search providers return web pages, snippets and source information. Media providers return generated images, video and audio.
- Connected services. When connected apps become available, we will receive information from the services you connect, limited to the permissions you grant.
- Organizations. If an Organization manages your access, it may give us your name, email address and role.
How we use information
| Purpose | Information used | Why we do it |
|---|---|---|
| Provide Ethen and its features | Account information, Prompts, files, media, conversations, Outputs, settings | To do what you ask: answer prompts, generate media, save conversations and keep your work available to you. |
| Send requests to the model or tool you use | Prompts, conversation context, attachments, search queries | Model and tool providers can only answer what they receive. See How AI model providers are involved. |
| Keep your history and recover interrupted work | Conversations, streamed transcripts, browser caches | So you can return to a conversation and recover from interruptions. |
| Keep accounts and the Services secure | IP addresses, session records, rate-limit counters, logs | To prevent unauthorized access, fraud and abuse, and to investigate incidents. |
| Enforce limits and policies | Usage information, content when misuse is reported or suspected | To apply fair-use limits and enforce the Acceptable Use Policy. |
| Understand and improve the website | Google Analytics data from upcube.ai | To understand which pages are useful and how visitors find Ethen. |
| Operate, troubleshoot and improve the Services | Usage information, error and performance data | To find and fix problems and decide what to build next. |
| Communicate with you | Email address, messages | To respond to requests, send service notices and, where you have joined a waitlist, tell you about availability. |
| Meet legal obligations | Any information, as required | To comply with law, respond to lawful requests and protect rights and safety. |
Information required by the privacy laws of specific U.S. states, the European Economic Area, the United Kingdom and other regions, including legal bases for processing and safeguards for international transfers, will be added before this policy takes effect wherever those laws apply to Upcube.
Model training and product improvement
Upcube's formal commitment on model training, product improvement and human review of content will be stated in this section before this policy takes effect. As of the date of this version, the Ethen services described here do not include any process that sends your Prompts, files, conversations or Outputs to a model-training or fine-tuning pipeline operated by Upcube.
Model Providers process the content they receive under their own terms, which may differ. Those terms can cover whether, and for how long, a provider keeps requests and whether it may use them for its own purposes. Upcube sends requests to Model Providers using Upcube's own accounts. The Subprocessors list names each provider.
How AI model providers are involved
Not every prompt goes to every provider
Ethen routes each request to one model. The model depends on the product you use, the mode or model you choose, and whether the default model is available. Your prompt and the conversation context needed to answer it go to the provider of that model, and to the routing service in between where one is used. Other providers do not receive it.
| When you… | What is sent | Who receives it |
|---|---|---|
| Send a message in Ethen Chat with the default model (Faros) | Your message and relevant conversation context | Meta, through Meta's Muse API. "Faros" is the name Ethen uses for its default conversational experience; it currently runs on Meta's Muse model. |
| Choose a faster or deeper mode, or select a specific model | Your message and relevant conversation context | The provider of that model, such as OpenAI, Anthropic, Google or DeepSeek, reached through the Vercel AI Gateway. |
| Turn on the safe-fallback setting | Your message and context, only if the first model fails temporarily | An alternative model through the Vercel AI Gateway. Fallback is off unless you turn it on. |
| Use voice in Ethen Chat | Your microphone audio and the spoken conversation | OpenAI's realtime voice model, reached through the Vercel AI Gateway. |
| Turn on web search or deep research | Search queries based on your request, and the addresses of pages to read | Tavily, a search provider, and Firecrawl, a page-extraction provider. |
| Generate media in Ethen Studio | Your prompt, settings and any reference media | fal, a media-generation platform, or OpenAI, depending on the model you choose. |
What providers do and do not receive
Requests are sent using Upcube's credentials, so providers see Upcube as their customer. Providers receive the content needed to fulfil the request, such as the prompt, prior messages from the conversation, attached content and search queries. Ethen does not send your password to any Model Provider.
How providers handle data
Each provider processes requests under its agreement with Upcube or the routing service, and under its own published terms. Retention and logging practices differ between providers. Deleting a conversation in Ethen does not delete copies a provider has already received. The Data Retention Policy explains this difference.
Bring your own key
Bring-your-own-key access, in which requests are authenticated with a Model Provider account you supply, is not currently available in Ethen. When it becomes available, using your own key will change which account the provider bills and whose agreement with the provider applies. It will not change the fact that Ethen processes your prompt and stores your conversation. The BYOK Data Handling document explains the details.
Connected services
When connected apps become available, Ethen will access a Connected Service only after you authorize it, and only within the permissions you approve. Reading from a connected app happens as part of the request you make. Creating drafts, changing calendar events or sending messages requires your approval as described in Connected Apps & Integrations. Credentials for connected services are stored encrypted in a managed secrets vault operated by Upcube's database provider, and are used only by Ethen's servers. They are not exposed to your browser.
Local and cloud processing
Ethen Chat, Ethen Studio and Ethen Platform run on cloud infrastructure: your requests are processed on Upcube's hosting providers and sent to the providers described above. Ethen does not currently offer a local runtime. Ethen Code, when released, will include a local runtime that runs on your own computer. Local processing can keep some information on your device, but it does not make Ethen fully offline. Your Account, sign-in and any cloud model you choose will still use the network. Each local feature will describe which parts run locally and which do not.
How we share information
We share personal data only in the following ways:
- Service providers (subprocessors). Companies that host Ethen, store data, handle sign-in, run AI models, provide search, generate media, provide caching or provide website analytics. They process data for us under contract. The Subprocessors page lists them, what each does, and which products use them.
- Model Providers, at your request. As described in How AI model providers are involved.
- Connected Services, at your direction. When connected apps become available, Ethen will send information to a connected service only to carry out an action you request and approve.
- People you share with. Ethen Studio lets you create review links. Anyone with a link can view what you shared until you revoke it.
- Organizations. If an Organization manages your access, its administrators may be able to see information about your use, as described below.
- Legal and safety reasons. We may disclose information if we believe in good faith that it is required by law or legal process, or that it is needed to protect the rights, property or safety of users, the public or Upcube, or to investigate fraud, security issues or violations of our terms.
- Business transfers. If Upcube is involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
- With your consent. In other cases, only when you ask us to or agree to it.
How website analytics is treated under U.S. state laws that regulate the "sale" or "sharing" of personal information, and how to opt out where that applies, will be stated here before this policy takes effect.
Where information is processed
Ethen's database and file storage are hosted by Supabase on Amazon Web Services in the United States (the us-west-2 region). Ethen's applications run on Vercel, and the upcube.ai website runs on Cloudflare's global network. Model, search and media providers may process requests in other locations under their own terms. If you use Ethen from outside the United States, your information will be transferred to and processed in the United States.
How long we keep information
We keep personal data for as long as we need it to provide Ethen and for the other purposes described here. Conversations stay in your history until you delete them. Some categories have fixed periods; others do not have one yet. The Data Retention Policy sets out each category, what triggers deletion, which periods are fixed, and where provider retention differs from ours.
How we protect information
We use access controls that limit each user's conversations to that user's own account, encryption in transit, an encrypted secrets vault for third-party credentials, server-side handling of API keys, file-admission checks, rate limits, and emergency shut-off controls. No system is perfectly secure, and Ethen does not hold security certifications today. The Enterprise Security describes these controls and their limits.
Your choices and rights
Controls inside Ethen
| What you can do | How | What it does |
|---|---|---|
| Delete a conversation | Delete it from your Ethen Chat history | Removes the conversation, its messages, streamed transcripts and artifacts from Ethen's database immediately. |
| Delete an artifact | Delete it from the conversation or artifacts view | Removes the artifact and its versions. |
| Delete Studio items | Delete them in Ethen Studio | Removes them from your projects and history. Deleted items are marked as deleted and are no longer shown; they are not immediately erased from storage. |
| Turn off automatic titles | Ethen Chat settings | New conversations are titled "New Chat" instead of using your first message. |
| Control fallback | Ethen Chat settings | Decides whether a temporary failure can be retried on another model. |
| Review and end sessions | Ethen Chat settings | Lists your signed-in sessions and lets you sign them out, including all at once. |
| Export data | Ethen Chat settings | Downloads a file with your settings, connected-app connection details (never credentials) and your 500 most recent usage records. Conversations are not yet included in the export. |
| Clear browser data | Sign out, or clear site data in your browser | Removes cached history, drafts and preferences from that browser. |
Deleting your account
Deleting your Account from Ethen Chat settings currently does three things:
- it signs out all of your sessions;
- it removes your saved settings;
- it removes your app-connection records.
It does not currently delete your conversations, artifacts, files, Studio items or sign-in identity. To remove those, delete conversations and Studio items individually before you close your Account, or send a deletion request using the details in How to contact us.
Privacy rights
Depending on where you live, you may have the right to:
- ask for a copy of your personal data;
- correct it;
- delete it;
- receive it in a portable format;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- appeal a decision we make about your request.
You can exercise these rights through the contact options in the Legal & Trust Center. We will need to verify your identity before acting on a request, and we will not discriminate against you for exercising your rights. If an Organization controls your Account, we may refer your request to that Organization.
Organizations and administrators
Ethen does not yet offer Organization administration features. When it does, administrators of an Organization's Workspace may be able to manage member accounts, configure which features and providers members can use, and access or delete content in the Workspace under the Organization's agreement with Upcube. In that setting, the Organization decides how its members' data is used, and Upcube processes it on the Organization's behalf. Members should direct privacy requests about Workspace content to their Organization.
Children
The minimum age for creating an Account, and any rules for younger people, will be stated here before this document takes effect.
If you believe a child has given us personal data in violation of our rules, tell us through the contact options in the Legal & Trust Center, and we will delete it.
Changes to this policy
We will post any change to this policy on this page, with a new version number and date, and record it in the version history below. How Upcube will notify you of material changes, and how much notice it will give before they apply, will be stated here before this document takes effect.
How to contact us
Questions, requests and complaints about this policy or Ethen's handling of personal data can be sent through the contact options in the Legal & Trust Center. You may also have the right to complain to a data protection authority where you live.
Contact
Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.
Version history
| Version | Date | Status | Summary of changes |
|---|---|---|---|
| 1.0 | October 5, 2026 | Not yet in effect | Complete rewrite: names the model and service providers that receive data, explains provider routing, retention, deletion and local processing, and replaces the earlier public-preview text. |
| 0.9 | September 2026 | Superseded | Earlier public-preview text. Archived. |