← Back to Ethos

Privacy Policy

Last updated: June 2026

At Ethos, privacy is treated as infrastructure, not an afterthought. You are entrusting the system with your thoughts, your habits, and your private data. This Privacy Policy details exactly how we handle, protect, and process your information with extreme respect for boundaries.

1. Vault Encryption architecture

Any data stored within your Vault is encrypted symmetrically in your browser using AES-256-GCM before ever touching our servers. The encryption key never leaves your device. We use a split-secret model meaning we cannot read, mine, or access your vaulted data under any circumstance. We literally lack the mathematical capacity to unlock your Vault.

2. Core Journal Data and Syncing

Standard journal entries, habits, and time-tracking metrics are stored securely on our servers to enable cross-device synchronization and immediate data retrieval. Your data is isolated per user, so it can never mix with anyone else's, and we enforce strict ownership rules on every request. Your data is never sold, traded, or used for targeted advertising.

3. AI Features and What Reaches OpenAI

Ethos's AI features — chat, insights, memory, and search — run on OpenAI as our language-model and search-index processor. They are part of our paid plans, and on those plans they are on by default. Being honest about what that means: two things happen automatically, in the background, without you starting a chat. As you write, the text of your journal entries, notes, habits, saved links, goals, and calendar events is sent to OpenAI to build your private search-and-recall index, and short factual memories are distilled from your activity so the assistant can remember them. When you do open a conversation or ask for an insight, only the slice the request needs is sent — never your whole history. Every request carries a "do not store" instruction so OpenAI does not retain the exchange for its own use, and our agreement with OpenAI forbids using your content to train any model; the one narrow exception is long-running research, where OpenAI holds the response only while that job is running. You stay in control: you can turn individual data sources off, limit what is shared to aggregate signals instead of your raw text, or use the AI kill switch to stop everything at once, all from your Ethos settings. On the free plan, none of your content is sent to OpenAI. For the full, plain-language account, see the Data & Memory page.

4. Telemetry and Analytics

We collect minimal, anonymized product telemetry solely to maintain service reliability. This includes sync state health, error logs for crash resolution, and performance metrics. These metrics never contain the contents of your journal, the titles of your notes, or the names of your habits.

5. Account Deletion and Right to be Forgotten

You may delete your account at any time through the dashboard. Upon deletion, all associated records, configurations, metrics, and files are permanently removed from our systems. Deletion begins immediately, your files are removed, and the storage they used is freed.

6. Third-Party Subprocessors

We employ high-grade infrastructure providers to deliver the service, and we vet every subprocessor for security compliance. Our storage and hosting providers act strictly as custodians of your encrypted files and structured data, with no rights to parse or own the contents within. OpenAI is our AI subprocessor: it processes the content described in section 3 to power chat, insights, memory, and search, under an agreement that forbids training on your data. When you enable Enhanced URL Reading in Settings → Connections, Ethos sends the URL you share to Mendable AI (Firecrawl) so it can read that page; Mendable AI acts as a subprocessor for this feature only, no personal data beyond the URL is transmitted, and you can disable it at any time.

7. Cookies and Local Storage

We avoid third-party tracking cookies entirely. Ethos uses secure, HTTP-only cookies strictly for authentication and session management. We use your browser's local storage for device-specific preferences (like theme, density, language) and for storing your wrapped Vault encryption keys.

8. Google Sign-In

If you choose to sign in with Google, Google provides Ethos with identity-only account data: your Google account ID, verified email status, email address, name, and profile picture. We use this data only to create or link your Ethos account and to authenticate future sessions. Google Sign-In does not grant Ethos access to your Google Drive, Gmail, Calendar, or other Google API data, and Ethos does not store Google access or refresh tokens for sign-in.

9. Google API User Data

When you connect Google Drive (files you create or open with Ethos), Google Drive app data, Gmail, Calendar, Google Docs, Google Sheets, Google Slides, Google Contacts, Google Classroom, or Google Forms through Settings → Connections, Ethos receives an OAuth access token and refresh token, both encrypted at rest with AES-256-GCM. The assistant uses these tokens only to fulfil explicit user requests — for example, creating or organizing a Drive file the app made or you opened with Ethos, reading or writing a hidden app-private Drive appDataFolder file the user authorizes, drafting a Calendar event the user describes, sending an email the user composes in Ethos and confirms, running eligible low-risk Google actions such as Drive uploads/folder organization, Calendar create/update, Docs/Sheets/Slides creation, or Sheets append when the user enables Full access, proposing edits to a Doc / Sheet / Slide as a draft that the user must confirm before it is applied, listing/creating/updating/deleting a Google contact after confirmation where required, listing Classroom courses, coursework, topics, announcements, and materials and applying confirmed Classroom writes, or reading Google Forms and responses and editing Forms only after user authorization and confirmation where required. We never share Google user data with third parties, never use it to train AI models, never read your Gmail inbox, and never read or write files, Drive app data, contacts, Classroom records, or Forms bodies/responses the user did not request. Disconnecting from Settings → Connections calls Google's token revocation endpoint and immediately invalidates the local connection. Deleting your Ethos account additionally purges all OAuth tokens and stored Google identifiers within seconds. The encrypted OAuth access and refresh tokens are the only Google data we store, and only for the lifetime of your connection; the Google content those tokens reach — calendar events, document, spreadsheet, and slide content, contacts, and form data — is used to fulfil your request and is never cached beyond the single assistant turn that uses it. Ethos's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.