Ethos

Privacy

Last updated 27 August 2026

ETHOS holds what you give it about one person, and answers you from it. This page says what that means for your data in plain terms: what is kept, who else sees it, how long it stays, and how to take it back.

What we hold

  • Your email address and sign-in identity.
  • What you hand over to build an archive: chat exports, documents, photographs and recordings — including material about a person who has died.
  • The conversations you have with an archive, and any corrections you leave.
  • A built voice, when you ask for one to be made from a recording.

What we do not do

  • We do not train any model on your archive.
  • We do not sell your data, and we do not share it for advertising.
  • We hold the key to your archive, which is how we can let you back in when you lose your password — it also means we could technically read what is there. We do not, and nobody outside the list below ever sees it, but you should know it rather than find out later.

Who else it reaches

Building and answering from an archive needs other companies. Each one receives only what its job needs:

WhoWhat they receiveWhy
Clerkyour email address and sign-in identityso you can sign in and only you can reach your archive
Railwayeverything you put into an archive, and the conversations you have with itthe servers this product runs on
Anthropicthe words of the archive relevant to what you asked, and your messagewriting the reply
OpenAIrecordings you upload, and archive textturning speech into words, and finding which words answer a question
ElevenLabsa voice sample, only when you ask for a voice to be builtthe built voice, and speaking replies aloud
Bright Dataa web address you paste, when you use the web-link doorfetching that public page
Anamthe photograph of the person, only when you ask for a moving face on a video callbuilding and animating that face while the call is running
Sentry and PostHogcrash reports and screen names — never message contentfinding faults; disabled entirely when not configured

The person the archive is about

An archive is built from one person’s own words, and often that person has died. You are responsible for having the right to hand over what you hand over. ETHOS speaks only from what it was given: it does not invent facts about them, and every reply is labelled as generated rather than as the person.

How long it stays, and taking it back

  • Anything you handed over can be taken out of the answers, or destroyed outright, from inside the app — per file, or per person.
  • You can delete your whole account from the app’s settings. That removes every archive you made, everything anyone gave them, and the sign-in itself.
  • What you delete stops being used immediately and is removed from our servers. A copy can survive in a rolling backup for up to thirty days — backups are never read to answer anybody, and a restore does not bring a deleted archive back. There is no other copy. What deletion removes, in full.

Voices and faces

Two of the things ETHOS can build are treated as biometric identifiers under several laws, so they are named separately here rather than folded into “what we hold”:

  • A voiceprint. When you ask for a voice to be built, the recording you supply is sent to our speech provider, which derives a model of how that person sounded. That model is what speaks; the recording itself stays with the archive.
  • Facial geometry. When you ask for a moving likeness, the photograph you supply is measured to drive it.

Neither is built unless you ask for it. Neither is used to identify anybody, to match against any other person, or for any purpose beyond answering you in that one archive. Both are destroyed when you delete the archive or the account — including at the provider, not only here — and we keep them no longer than the archive they belong to.

Where it goes in the world

The servers this runs on are in Frankfurt, Germany. Several of the companies listed above operate in the United States, so material is transferred there when an answer is written, speech is transcribed, or a voice is built. If you are in the UK or the EU, that is a transfer outside your jurisdiction and you should know it before you hand anything over.

Your rights over it

Wherever you live, you can do all of the following — most of them from inside the app, without asking us:

  • See what is held. Everything, in a folder, from Settings.
  • Take it back. Per file, per person, or the whole account.
  • Correct it. Any reply can be corrected; any source removed.
  • Take it elsewhere. The export is a plain folder, readable without this app, and it stays free.
  • Object, or complain. Write to us, and if we handle it badly, to your national data-protection regulator.

We do not charge for any of these and we do not require a reason. If you are in the EU or UK, these are your GDPR rights; in California and several other US states, your rights there. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

How it is protected

Material is encrypted in transit and at rest, reachable only by an account that has been signed in, and every request is scoped to its owner on the server rather than in the app. We hold the key, which is stated plainly above. No system is perfect, and this one is young; if something goes wrong that affects you, we will tell you rather than wait to be asked.

When this changes

The date at the top is the last time this page changed. If a change affects what happens to material you have already handed over, we will say so in the app rather than only here — a policy that changes quietly is not a policy.

Age

ETHOS is for people aged 18 and over. It is not designed for children and is not directed at them.

Asking us

Write to fishman56256@gmail.com to ask what is held about you, to correct it, or to have it removed.