Privacy Policy
Last updated: July 14, 2026. This Privacy Policy explains what EidoStack collects, how the Service uses it, how provider keys are handled, and the choices available to you.
1. Information we collect
We collect information needed to operate, secure, support, and improve EidoStack. Some fields depend on the features you use and the environment in which the Service is deployed.
- Account and authentication data — email address, password authentication data, profile name and avatar, email-verification and account-recovery data, onboarding state, and Google or GitHub OAuth account information when you use those sign-in or account-linking options.
- Workspace data — chats, prompts, messages, folders, saved settings, model selections, context preferences, and other content you choose to store in the application.
- Usage and subscription data — selected models, input and output token counts, message counts, context statistics, estimated costs, plan, billing period, subscription state, and related identifiers or end dates when available to the application.
- Support and contact data — messages, subjects, email addresses, support reasons, attachments, and the information you include in a public contact form or authenticated support request.
- Technical and security data — IP address, device and browser information, user agent, referrer, session data, authentication events, rate-limit events, and other logs or security records where collected.
- Traffic analytics — page-view and website usage information through self-hosted Umami when analytics is enabled for the Site or App. The current configuration does not use user identification, session replay, heatmaps, or custom event properties.
Provider-key ciphertext saved by the vault is stored locally in your browser and is not treated as ordinary server-side profile data in the active settings flow. The API stores a per-user vault salt and may receive a provider key for an explicitly supported runtime operation, as described in Section 3.
2. How we use information
- create and secure accounts, sessions, authentication, and account recovery;
- provide chats, model selection, comparison, context, usage, and saved settings;
- calculate and display token, context, model-usage, and estimated-cost statistics;
- provide support, answer contact requests, and deliver service communications;
- process subscription status and plan access when paid plans are available;
- detect abuse, prevent fraud, troubleshoot failures, and protect the Service;
- understand traffic and product performance through configured analytics; and
- meet legal obligations, enforce our agreements, and establish or defend claims.
We do not sell personal information or use it to build advertising profiles. EidoStack does not train, improve, or own third-party AI models through your use of the Service. Product analytics and aggregate usage information may be used to understand and improve the Service, but prompts, responses, and provider keys are not used for model training by EidoStack.
3. Provider-key handling
Provider keys are entered by you and handled through a browser-based vault. The browser uses Web Crypto primitives to derive encryption keys from your master password and stores encrypted provider values in account-scoped browser storage. The API stores the per-user salt needed for that derivation; the active settings flow does not upload the encrypted provider-key record to a server database.
After you unlock the vault, decrypted provider values exist in browser memory for runtime use. Chat responses and optional automatic chat-title generation go directly from the browser to the selected provider. The API receives no provider key for title generation and is used only to persist the confirmed title. This means the vault protects local persistence; it does not mean a key is never present in plaintext or can never cross a network boundary.
Locking or resetting the vault removes runtime availability and, depending on the action, local encrypted records. Clearing browser storage or losing the master password can remove the local record and require you to enter a key again. You are responsible for protecting your master password and any vault backup. Do not send provider keys in support requests.
4. Sharing and disclosures
We disclose information only as needed for the purposes in this Policy, including to:
- infrastructure, hosting, database, security, and email-delivery providers that help us operate the Service;
- the AI provider you select, when your browser or an explicitly supported EidoStack operation sends a prompt, response context, or runtime credential to that provider;
- the payment provider shown at checkout, if a paid-plan checkout uses a third-party payment provider; and
- authorities, professional advisers, or other parties when required for law, security, legal claims, a merger, acquisition, or protection of rights.
Third parties process information under their own terms and privacy notices. We do not control how an AI provider uses data after a request reaches that provider. Review the policies of every provider whose account or API you connect to EidoStack.
5. Security
We use safeguards appropriate to the Service, including TLS for supported network connections, HttpOnly session and refresh cookies, access controls, rate limiting, token rotation, encrypted browser vault storage, and restricted infrastructure access. No security measure is perfect, and we cannot guarantee that the Service, your device, a provider, or a network is completely secure.
If you believe an account or provider key has been compromised, lock or reset the vault, revoke the affected provider credential, and contact support@eidostack.com as soon as possible.
6. Cookies and browser storage
The authentication flow uses necessary HttpOnly session and refresh cookies, and the OAuth flow uses a short-lived state cookie. These cookies help authenticate requests, rotate sessions, and protect sign-in callbacks. Blocking or deleting them can prevent sign-in or other authenticated features from working.
The vault and some interface preferences use browser storage rather than ordinary account fields. Browser storage is controlled by your browser and may be cleared independently of your EidoStack account. When enabled, Umami receives configured page-view information and browser metadata, supports Do Not Track, excludes search queries, and does not identify users or record session replay or heatmaps. Analytics can be blocked through browser or privacy controls, although some browser controls may affect the Service.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information, receive a copy of certain information, or withdraw consent where processing relies on consent. You may also have the right to lodge a complaint with a data-protection authority.
You can update profile information in the application and can delete your account through the implemented account flow. For a privacy request, email support@eidostack.com with the account email, the request you are making, and any information needed to verify that you control the account. We may ask for additional verification before disclosing or deleting information.
8. Retention and account deletion
We retain account, workspace, usage, support, and technical information for as long as needed to provide the Service, maintain security, resolve disputes, meet legal or tax obligations, enforce agreements, and protect backups. The exact retention period depends on the type of information and the reason it was collected; the current repository does not define one universal period for every category.
When you delete an account, the application deletes the account record, sessions, chats, folders, and default settings through a database transaction. Limited information may remain in backups, security logs, support communications, or legal records until it is no longer needed. Account deletion does not delete information already sent to an AI provider, and it does not clear the provider-key vault from your browser. Reset the vault or clear its browser storage separately if you want to remove those local records.
9. International processing
EidoStack and its service providers may process information in countries different from the country where you live. Where required, we use the safeguards and transfer mechanisms required by applicable data-protection law. Your selected AI provider may independently process requests in additional locations under its own policy.
10. Changes and contact
We may update this Policy when the Service, processing activities, or legal requirements change. We will post the new version and update the “Last updated” date. If a change is material, we will provide additional notice when reasonably required. Your continued use after the effective date means the updated Policy applies to future processing.
Privacy questions, requests, and security reports can be sent to support@eidostack.com.