EtherLegal

What we know about you.

In force since 6 August 2026

Short answer: less than you would expect, and none of your photographs. The long answer is below, in the same order we would want to read it.

The short version

Your photographs never reach us. The five standalone tools read your images on your own GPU and upload nothing — there is no copy on our side, so there is nothing for us to lose, hand over, or be careless with.

We keep an email address, what you saved, and what you paid. We count seven product events. We do not record sessions, do not build profiles, and do not sell anything to anyone.

What we hold

Only what the product cannot work without.

  • Email address, and your name and avatar if you signed in with Google. Needed to have an account at all.
  • Sessions: a signed cookie and a row saying when it expires. Sign out and it goes.
  • Universes you save: the mood words, the palette, the settings. Yours, visible to you, and public only if you chose to make one public.
  • Billing: plan, status, period end, and Stripe’s customer identifier. Card details are Stripe’s and never touch our servers.
  • The credit ledger: every grant and every spend, with a reason. It is append-only, because a balance you cannot audit is a balance you cannot trust.
  • Rate-limit counters: how many renders you started in the current hour.

What we deliberately do not hold

Photographs you upload to the grader or the palette tool. They are read in the browser and never sent.

Generated images. The provider returns a URL, your browser fetches it and grades it locally. We do not copy the file to our storage.

Card numbers, IP logs kept for their own sake, session recordings, mouse movement, cross-site identifiers, advertising pixels.

Requests to font services. Every typeface in the catalogue is served from our own domain, so loading a universe tells Google and Fontshare nothing about you.

Analytics

We count seven things: a universe generated, a section rerolled, a universe saved, a preview rendered, a final exported, a checkout started, a subscription completed. That is the whole list.

Before you sign in you are a random identifier stored in your own browser, tied to nothing. After you sign in the two are linked so we can tell whether people who sign up actually get anywhere.

If your browser sends Do Not Track we count nothing at all, and we do not ask you to reconsider. Analytics run on PostHog’s EU cloud.

Error reports

When something breaks we send the error to Sentry. Before it leaves, every address in the report is stripped — the one that failed, the one you came from, and every step in between: your work lives in the URL hash, so the hash is replaced by its length and preset codes are removed. We collect no performance traces.

There is no session recording. Nobody watches you use the site.

Who else touches it

Each of these does one job and sees only what that job needs.

  • Railway — hosting and the database, servers in the EU.
  • Stripe — payments and tax. They hold your card and billing address; we hold an identifier.
  • Resend — sends the sign-in link. Sees your email address.
  • Anthropic — receives your mood words to build a palette. Nothing else about you goes with them.
  • fal.ai — receives the generated prompt and returns an image. It does not receive your identity.
  • PostHog (EU) and Sentry — analytics and errors, as described above.

How long

Account data lives while the account does. Ask us to delete it and it goes, along with your universes and ledger — write to us and we will do it within thirty days.

The credit ledger and billing records are kept while your account exists and, where tax law requires, for as long as that law says after it closes. Rate-limit counters are worthless after an hour and are cleaned up.

Your rights

Wherever you are, you can ask what we hold, ask for a copy, ask us to correct it, or ask us to delete it. If you are in the EU, EEA or UK, those are rights under the GDPR and you can also complain to your local supervisory authority.

One address for all of it: [email protected]. A person reads it.

Where the data sits

Servers are in the EU. The company is in the United Arab Emirates, so your data is accessible from outside the EEA. Where we send personal data to a processor outside the EEA we rely on the European Commission’s standard contractual clauses.

Cookies

One cookie: the session, set when you sign in and removed when you sign out. It is strictly necessary, so there is no banner asking you to accept it — asking would be theatre.

No advertising cookies. No third-party cookies. Analytics use a random identifier in local storage, not a cookie, and Do Not Track switches it off.

Children

Ether is not for children. We do not knowingly hold data about anyone under sixteen; if you believe we have, write to us and we will remove it.

Who we are

Ether is operated by Studio 1804 FZE LLC, Business Center, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Licence 4423789.01. TRN 105221788000001.

Questions about anything on this page: [email protected]

TermsRefundsColophon