Privacy Policy
Ephemerent builds Orrery, a premium agentic code editor and Nexus operations console, and The Quiet Earth, a paid desktop-game beta. This policy explains what data we collect, why, who processes it, and the choices you have. It covers preview setup, personal subscriptions, organization plans, managed connectors such as Slack, game purchases handled by itch.io, and optional game-support bundles. These products are in beta, so this policy may change as they do - see Changes below.
The short version
In preview setup mode, you can inspect the app and configure a workspace before subscribing. Real subscriber agent work uses eligible Orrery Cloud routes. Verified development builds may expose developer-only routes. Hosted DeepSeek API, Doubleword, Arbiter, or other hosted routes send the prompt and selected context needed for the completion through our relay to the provider. We keep usage meters for quota and organization-budget enforcement.
What we collect
- Account identity. If you sign in, our authentication provider, Supabase, stores your account identifier, email address, and any basic profile fields (display name, avatar URL) your chosen sign-in method provides. You can sign in with Google, GitHub, or an email magic link.
- Subscription & billing status. If you subscribe, we store your plan (Pro / Max / Ultra), subscription status (active, canceled, past-due), renewal date, and the customer/subscription identifiers our payment processor, Stripe, gives us. We do not see or store your full card number — Stripe handles payment details directly.
- Usage meter (token counts). When you use hosted models, we count the tokens consumed so we can enforce your monthly quota and show your usage. These counts are stored on your device and on our servers, and are numbers and timestamps — not the content of your prompts.
- Prompts & code sent for hosted-model inference. When you choose a hosted DeepSeek API, Doubleword, Arbiter, or other hosted route, the prompt and code/context required to answer it are transmitted through our relay to the configured provider to generate the completion, and the result is returned to you.
- High-level activity logs. When signed in, we may record events such as sign-in, opening the editor, or starting a task, with a timestamp. These record that an action happened, not the contents of your code.
- Organization administration. If your organization uses Orrery, we store its name, plan, memberships, roles, invitations, verified domains, workspace and connector bindings, scoped policies, pooled usage, audit metadata, and security settings needed to administer the service.
- Explicit Slack context. When an authorized user invokes Orrery through Slack, we process the command, mention, shortcut, interactive action, or user-selected message/thread context, plus Slack team, user, channel, and event identifiers needed to authenticate, route, deduplicate, and answer the request. We do not ingest broad channel history by default.
- On-device identity (optional). In preview setup you can enter an email/name to label your own on-device audit log. This is stored only in your browser’s/app’s local storage on that device and is not sent to us.
What we do NOT collect
We do not collect your source code, repositories, or prompt content for any purpose other than proxying a hosted-model request you explicitly make or providing a cloud feature you request. We do not store prompt or completion content beyond what is needed to relay the request and return the answer, and we do not use your prompts or code to train our own models.
The Quiet Earth game data
The Quiet Earth stores saves, settings, bounded crash reports, and backup files locally on your computer. Beta 1 includes no telemetry, analytics, advertising tracker, automatic crash upload, cloud save, bundled model weights, or enabled native generative-dialogue service.
The in-game Export Support Bundle action writes a bounded diagnostic bundle to your computer. It can include the build ID, platform, settings, world seed and simulation tick, region, bounded performance and game-state diagnostics, and—only when you separately choose the save-including action—a copy of your save. The exporter is designed to redact absolute paths, network addresses, invite tokens, model paths, credentials, and other private diagnostic content. Nothing is uploaded automatically. You decide whether to inspect and share the bundle with Ephemerent or the itch community.
Experimental LAN co-op sends gameplay traffic directly between players on the network addresses they choose. Ephemerent does not provide a matchmaking relay or hosted game server for Beta 1 and does not receive that LAN traffic. Other people or network operators on the chosen network may be able to observe network metadata, so use co-op only with people and networks you trust.
Purchases and downloads are handled by itch.io. itch.io receives and processes the account, payment, tax, download, and transaction information needed for that service under its own privacy terms. Ephemerent receives the purchase and support information itch makes available to creators but does not receive your full payment-card number.
How we use your data
- To sign you in and keep one identity across the website and the desktop app.
- To provide and bill your subscription, enforce monthly quotas, and show your usage.
- To proxy hosted-model requests through configured providers and return completions to you.
- To operate the beta, debug issues, prevent abuse, and keep the service secure.
- To administer organization membership, policy, pooled usage, audit receipts, Slack bindings, identity integration, and support.
Subprocessors & service providers
We rely on a small number of third parties to run the service. Each processes only the data needed for its role:
- Stripe — payment processing, subscriptions, and billing. Stripe receives the data needed to charge you and is the system of record for payment details.
- itch.io — The Quiet Earth purchases, buyer access, downloads, updates, owner/test keys, and community support. itch.io is the payment and download authority for the game beta.
- Supabase — authentication and the database that stores your account profile, subscription state, and usage counters.
- Hosted inference providers - DeepSeek API, Doubleword, and future configured providers process hosted route requests under their own terms.
- Google and GitHub — OAuth sign-in, only if you choose one of them to log in.
- Slack - managed organization connector, only when an authorized organization installs and uses it.
- Vercel — hosting for this website and related endpoints; standard server logs (e.g. IP address, request metadata) may be generated.
Cookies and local storage
This website sets no advertising or third-party tracking cookies. The desktop app and the site use local storage (and a Supabase session token/cookie when you are signed in) to keep you logged in and to hold the optional local identity and on-device audit buffer. Clearing your browser’s or app’s local storage removes the on-device data on that device.
Data retention
We keep your account, subscription, and usage data for as long as your account exists and as needed to provide the service and meet legal/accounting obligations (for example, billing records Stripe retains for tax and compliance). Business metadata audit records are configured for up to 90 days and Enterprise records for up to 365 days unless a signed agreement or legal obligation requires a different period. Transient prompt/completion content handled by the relay is not retained by us beyond what is needed to fulfill the request unless an authorized organization explicitly enables a documented content-retention feature. When you ask us to delete your account, we remove your profile and associated logs from our systems subject to organization administration, legal holds, security records, and billing records we must retain.
Your rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR and the California CCPA/CPRA — including the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. We do not sell your personal information. To exercise any of these rights:
- Use preview setup without starting hosted work.
- Email hello@ephemerent.com to request a copy of, correction of, or deletion of your account data. We may need to verify your identity before acting.
- Cancel or manage your subscription at any time (see the Terms of Service).
- Clear your device’s local storage to remove the local identity and audit buffer.
If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.
International data transfers
Our providers (including Stripe, Supabase, DeepSeek, and Vercel) may process data on infrastructure located outside your country, including the United States. Where required, we rely on the appropriate safeguards offered by those providers for such transfers.
Children
Orrery isn’t directed to children under 13 (or the minimum age in your region), and we don’t knowingly collect their data.
Ephemerent Research journal
Ephemerent Research uses the same Supabase account system but has a separate purpose from Orrery Cloud. A free account may submit research without an active plan or subscription. For a journal submission, we store the accountable account identifier, the public display name or pseudonym chosen for the record, submission metadata, editorial events, file metadata, file hashes, and any files the submitter uploads.
Submission files remain private to the submitter and authorized editors until publication. A published record may expose the selected public name, author list, summary, AI disclosure, statements, version history, public files, comments, and peer reviews, including whether a review was human, AI-assisted, or authored by an AI system. The account email and private editor notes are not published. Comments and reviews are moderated and tied to the article version they address.
Journal records may be retained after account deletion when needed to preserve the integrity of a published scholarly record, correction notice, rights investigation, or legal obligation. Contact hello@ephemerent.com for account, privacy, or publication-record requests.
Changes
We’ll update this page when our practices change and revise the “last updated” date. Significant changes affecting paid accounts will be communicated where practical.
Contact
Privacy questions or data requests: hello@ephemerent.com. This service is operated by Ephemerent and its operators.