Privacy Policy
Ephemerent builds Orrery, a premium agentic code editor and Nexus operations console you install on your own computer. This policy explains what data we collect, why, who processes it, and the choices you have. It covers preview setup and the paid subscription tiers (Pro, Max, and Ultra). Orrery is in beta, so this policy may change as the product does - see Changes below.
The short version
In preview setup mode, you can inspect the app and configure a workspace before subscribing. Real agent work requires a trial or subscription. If you subscribe and use hosted DeepSeek API, Doubleword, Arbiter, or other hosted routes, the prompt and code context needed for the completion are sent through our relay to the provider, and we keep usage meters for quota enforcement.
What we collect
- Account identity. If you sign in, our authentication provider, Supabase, stores your account identifier, email address, and any basic profile fields (display name, avatar URL) your chosen sign-in method provides. You can sign in with Google, GitHub, or an email magic link.
- Subscription & billing status. If you subscribe, we store your plan (Pro / Max / Ultra), subscription status (active, canceled, past-due), renewal date, and the customer/subscription identifiers our payment processor, Stripe, gives us. We do not see or store your full card number — Stripe handles payment details directly.
- Usage meter (token counts). When you use hosted models, we count the tokens consumed so we can enforce your monthly quota and show your usage. These counts are stored on your device and on our servers, and are numbers and timestamps — not the content of your prompts.
- Prompts & code sent for hosted-model inference. When you choose a hosted DeepSeek API, Doubleword, Arbiter, or other hosted route, the prompt and code/context required to answer it are transmitted through our relay to the configured provider to generate the completion, and the result is returned to you.
- High-level activity logs. When signed in, we may record events such as sign-in, opening the editor, or starting a task, with a timestamp. These record that an action happened, not the contents of your code.
- On-device identity (optional). In preview setup you can enter an email/name to label your own on-device audit log. This is stored only in your browser’s/app’s local storage on that device and is not sent to us.
What we do NOT collect
We do not collect your source code, repositories, or prompt content for any purpose other than proxying a hosted-model request you explicitly make or providing a cloud feature you request. We do not store prompt or completion content beyond what is needed to relay the request and return the answer, and we do not use your prompts or code to train our own models.
How we use your data
- To sign you in and keep one identity across the website and the desktop app.
- To provide and bill your subscription, enforce monthly quotas, and show your usage.
- To proxy hosted-model requests through configured providers and return completions to you.
- To operate the beta, debug issues, prevent abuse, and keep the service secure.
Subprocessors & service providers
We rely on a small number of third parties to run the service. Each processes only the data needed for its role:
- Stripe — payment processing, subscriptions, and billing. Stripe receives the data needed to charge you and is the system of record for payment details.
- Supabase — authentication and the database that stores your account profile, subscription state, and usage counters.
- Hosted inference providers - DeepSeek API, Doubleword, and future configured providers process hosted route requests under their own terms.
- Google and GitHub — OAuth sign-in, only if you choose one of them to log in.
- Vercel — hosting for this website and related endpoints; standard server logs (e.g. IP address, request metadata) may be generated.
Cookies and local storage
This website sets no advertising or third-party tracking cookies. The desktop app and the site use local storage (and a Supabase session token/cookie when you are signed in) to keep you logged in and to hold the optional local identity and on-device audit buffer. Clearing your browser’s or app’s local storage removes the on-device data on that device.
Data retention
We keep your account, subscription, and usage data for as long as your account exists and as needed to provide the service and meet legal/accounting obligations (for example, billing records Stripe retains for tax and compliance). Transient prompt/completion content handled by the relay is not retained by us beyond what is needed to fulfil the request. When you ask us to delete your account, we remove your profile and associated logs from our systems; some billing records may be retained where the law requires.
Your rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR and the California CCPA/CPRA — including the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. We do not sell your personal information. To exercise any of these rights:
- Use preview setup without starting hosted work.
- Email hello@ephemerent.com to request a copy of, correction of, or deletion of your account data. We may need to verify your identity before acting.
- Cancel or manage your subscription at any time (see the Terms of Service).
- Clear your device’s local storage to remove the local identity and audit buffer.
If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.
International data transfers
Our providers (including Stripe, Supabase, DeepSeek, and Vercel) may process data on infrastructure located outside your country, including the United States. Where required, we rely on the appropriate safeguards offered by those providers for such transfers.
Children
Orrery isn’t directed to children under 13 (or the minimum age in your region), and we don’t knowingly collect their data.
Changes
We’ll update this page when our practices change and revise the “last updated” date. Significant changes affecting paid accounts will be communicated where practical.
Contact
Privacy questions or data requests: hello@ephemerent.com. This service is operated by Ephemerent and its operators.