Privacy Policy
Ephemerent builds Orrery, a premium agentic code editor and Nexus operations console, and Genesis Fall, a paid desktop-game beta candidate. This policy explains what data we collect, why, who processes it, and the choices you have. It covers subscriptions, direct Stripe game purchases, direct-download fulfillment, support, and local software use. These products are in beta, so this policy may change as they do - see Changes below.
The short version
In preview setup mode, you can inspect the app and configure a workspace before subscribing. Real subscriber agent work uses eligible Orrery Cloud routes. Verified development builds may expose developer-only routes. Hosted Doubleword, Arbiter, or other hosted routes send the prompt and selected context needed for the completion through our relay to the provider. We keep usage meters for quota and organization-budget enforcement.
What we collect
- Account identity. If you sign in, our authentication provider, Supabase, stores your account identifier, email address, and any basic profile fields (display name, avatar URL) your chosen sign-in method provides. You can sign in with Google, GitHub, or an email magic link.
- Subscription & billing status. If you subscribe, we store your plan (Pro / Max / Ultra), subscription status (active, canceled, past-due), renewal date, and the customer/subscription identifiers our payment processor, Stripe, gives us. We do not see or store your full card number — Stripe handles payment details directly.
- Genesis Fall fulfillment. For direct Stripe game purchases, Stripe processes the purchaser email and billing information. Ephemerent stores Checkout Session and payment-intent identifiers, product/price/amount/currency validation fields, fulfillment and review status, and a server-HMAC hash of the normalized purchaser email. Release packages remain in private storage; short-lived signed download URLs are generated only after payment and email verification. The fulfillment order does not store the raw purchaser email, full card number, or permanent public package URL.
- Usage meter (token counts). When you use hosted models, we count the tokens consumed so we can enforce your monthly quota and show your usage. These counts are stored on your device and on our servers, and are numbers and timestamps — not the content of your prompts.
- Prompts & code sent for hosted-model inference. When you choose a hosted Doubleword, Arbiter, or other hosted route, the prompt and code/context required to answer it are transmitted through our relay to the configured provider to generate the completion, and the result is returned to you.
- High-level activity logs. When signed in, we may record events such as sign-in, opening the editor, or starting a task, with a timestamp. These record that an action happened, not the contents of your code.
- Organization administration. If your organization uses Orrery, we store its name, plan, memberships, roles, invitations, verified domains, workspace and connector bindings, scoped policies, pooled usage, audit metadata, and security settings needed to administer the service.
- Explicit Slack context. When an authorized user invokes Orrery through Slack, we process the command, mention, shortcut, interactive action, or user-selected message/thread context, plus Slack team, user, channel, and event identifiers needed to authenticate, route, deduplicate, and answer the request. We do not ingest broad channel history by default.
- On-device identity (optional). In preview setup you can enter an email/name to label your own on-device audit log. This is stored only in your browser’s/app’s local storage on that device and is not sent to us.
What we do NOT collect
We do not collect your source code, repositories, or prompt content for any purpose other than proxying a hosted-model request you explicitly make or providing a cloud feature you request. We do not store prompt or completion content beyond what is needed to relay the request and return the answer, and we do not use your prompts or code to train our own models.
Genesis Fall game data
Genesis Fall stores saves, settings, bounded crash reports, and backup files locally on your computer. Beta 1 includes no telemetry, analytics, advertising tracker, automatic crash upload, cloud save, bundled model weights, or enabled native generative-dialogue service.
The Export Support Bundle action writes bounded diagnostics to your computer. It can include the build ID, platform, settings, world seed and simulation tick, region, and bounded performance/game-state diagnostics. A save is included only when you separately choose that action. Nothing is uploaded automatically.
Experimental LAN co-op sends gameplay traffic directly between players on the network addresses they choose. Ephemerent does not provide a matchmaking relay or hosted game server for Beta 1 and does not receive that LAN traffic. Use co-op only with people and networks you trust.
How we use your data
- To sign you in and keep one identity across the website and the desktop app.
- To provide and bill your subscription, enforce monthly quotas, and show your usage.
- To verify a Genesis Fall payment, issue and refresh short-lived direct-download links, prevent duplicate fulfillment, handle refunds or disputes, and provide purchase support.
- To proxy hosted-model requests through configured providers and return completions to you.
- To operate the beta, debug issues, prevent abuse, and keep the service secure.
- To administer organization membership, policy, pooled usage, audit receipts, Slack bindings, identity integration, and support.
Arbiter: learns from your sessions by default, zero data retention in one switch
Requests to the Arbiter route are metered by compute and counted per account and month. By default Orrery shares your Arbiter coding and research sessions with the Arbiter service so the next version of the model is trained on exactly this kind of work: the prompt and tool results sent to the model, the model's response, and the outcome of the turn (tests passed or failed, a diff accepted or rejected, a research verifier's verdict), tied to an anonymous per-session id. We never receive your account, your email, or file paths outside what the prompt itself contains, and Doubleword turns are never captured. Turn on Zero data retention for Arbiter in Orrery settings (Nexus, Files & Context) and the Arbiter service keeps counts and an access-log line (status, latency, token and compute counts) and nothing else, from the next request on. Captured sessions are used only to train and evaluate Arbiter and are never sold or shared with third parties.
Subprocessors & service providers
We rely on a small number of third parties to run the service. Each processes only the data needed for its role:
- Stripe — payment processing, subscriptions, direct Genesis Fall purchases, tax calculation, and billing. Stripe receives the data needed to charge you and is the system of record for payment details.
- Supabase — authentication, private release-object storage, and the database/Edge Functions that store bounded Genesis Fall fulfillment records, verify direct purchases, and create expiring download links.
- Hosted inference providers - Doubleword, Ephemerent's own Arbiter serving, and future configured providers process hosted route requests under their own terms.
- Google and GitHub — OAuth sign-in, only if you choose one of them to log in.
- Slack - managed organization connector, only when an authorized organization installs and uses it.
- Vercel — hosting for this website and related endpoints; standard server logs (e.g. IP address, request metadata) may be generated.
Cookies and local storage
This website sets no advertising or third-party tracking cookies. The desktop app and the site use local storage (and a Supabase session token/cookie when you are signed in) to keep you logged in and to hold the optional local identity and on-device audit buffer. Clearing your browser’s or app’s local storage removes the on-device data on that device.
Data retention
We keep account, subscription, usage, and Genesis Fall fulfillment records for as long as needed to provide download access, reconcile refunds/disputes, support purchasers, and meet legal, tax, accounting, and fraud-prevention obligations. Stripe retains its own transaction records under its policy. Business metadata audit records are configured for up to 90 days and Enterprise records for up to 365 days unless a signed agreement or legal obligation requires otherwise. When you request deletion, we remove eligible records subject to access continuity, organization administration, legal holds, security records, and billing/fulfillment records we must retain.
Your rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR and the California CCPA/CPRA — including the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. We do not sell your personal information. To exercise any of these rights:
- Use preview setup without starting hosted work.
- Email kt@ephemerent.com to request a copy of, correction of, or deletion of your account data. We may need to verify your identity before acting.
- Cancel or manage your subscription at any time (see the Terms of Service).
- Clear your device’s local storage to remove the local identity and audit buffer.
If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection authority.
International data transfers
Our providers (including Stripe, Supabase, Doubleword, Amazon Web Services, and Vercel) may process data on infrastructure located outside your country, including the United States. Where required, we rely on the appropriate safeguards offered by those providers for such transfers.
Children
Orrery isn’t directed to children under 13 (or the minimum age in your region), and we don’t knowingly collect their data.
Ephemerent Research journal
Ephemerent Research uses the same Supabase account system but has a separate purpose from Orrery Cloud. A free account may submit research without an active plan or subscription. For a journal submission, we store the accountable account identifier, the public display name or pseudonym chosen for the record, submission metadata, editorial events, file metadata, file hashes, and any files the submitter uploads.
Submission files remain private to the submitter and authorized editors until publication. A published record may expose the selected public name, author list, summary, AI disclosure, statements, version history, public files, comments, and peer reviews, including whether a review was human, AI-assisted, or authored by an AI system. The account email and private editor notes are not published. Comments and reviews are moderated and tied to the article version they address.
Journal records may be retained after account deletion when needed to preserve the integrity of a published scholarly record, correction notice, rights investigation, or legal obligation. Contact kt@ephemerent.com for account, privacy, or publication-record requests.
Changes
We’ll update this page when our practices change and revise the “last updated” date. Significant changes affecting paid accounts will be communicated where practical.
Contact
Privacy questions or data requests: kt@ephemerent.com. This service is operated by Ephemerent and its operators.