Legal

Privacy Policy

The short version: your data is yours, we collect only what we need to run the service, we never sell it, and tenant isolation is enforced at the database layer. The long version follows.

Effective June 11, 2026

EternalEngine ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the EternalEngine platform, website, and related services (collectively, the "Service"). Please read this policy carefully. By accessing or using the Service, you agree to this Privacy Policy. Business customers processing their own customers' data through the Service are additionally covered by ourData Processing Agreement.

Information We Collect

Information You Provide

When you register for an account, contact us, or use our Service, you may provide us with personal information including your name, email address, company name, billing information, and any other information you choose to share through our contact forms or platform interactions.

Information Collected Automatically

When you access the Service, we may automatically collect technical information such as your IP address, browser type, operating system, referring URLs, pages visited, and timestamps. We use structured logging for operational purposes and do not include personally identifiable information in system logs.

Usage Data

We collect anonymized usage metrics to improve our Service, including feature usage patterns, performance data, and error reports. This data is aggregated and cannot be used to identify individual users.

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process transactions and manage your account
  • Communicate with you, including responding to inquiries and sending service-related notifications
  • Improve and personalize the Service based on usage patterns
  • Detect, investigate, and prevent fraudulent or unauthorized activity
  • Comply with legal obligations and enforce our Terms of Service

Data Sharing & Service Providers

We do not sell your personal information.We share data only in the limited circumstances below:

  • Service Providers: Vendors that help us operate the Service, each limited to the data their function requires and contractually obligated to protect it. Today these include Stripe (subscription billing and PayGate payment processing — card details go to Stripe, not our servers), Cloudflare (edge network, DDoS protection, and web application firewall in front of the platform), email delivery infrastructure providers (for PostFrame and transactional mail), and AI model providers such as Anthropic (the AI assistant sends your prompt and relevant workspace context to generate a response; our AI providers are used under terms that do not permit training on your data).
  • Legal Requirements: We may disclose information if required by law, regulation, or valid legal process (such as a subpoena or court order).
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
  • With Your Consent: We may share information for any other purpose with your explicit consent.

Tenant Data Isolation

EternalEngine is a multi-tenant platform with strict data isolation enforced at every layer. Your data is separated from other tenants through row-level security policies, authenticated context propagation, and our Eternal Law E06 (Security), which mandates that tenant identifiers are always derived from authenticated sessions and never from user-supplied input. This means your data can never be accessed by another tenant, even in the event of a software bug.

Security

We take the security of your data seriously and implement industry-standard measures to protect it, including TLS encryption in transit, encrypted off-site backups (X25519/age and restic), secrets held in an encrypted vault, parameterized database queries, schema validation on every external input, and engineering practices aligned to OWASP ASVS and NIST SP 800-218. While no system can guarantee absolute security, our platform is governed by a fixed set of engineering rules — tenant isolation, parameterized queries, validated inputs, no secrets in code or logs — enforced automatically in our build pipeline before any change can ship. Read more on theSecurity page.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information. Our formal GDPR compliance program is in progress, but we honor these requests for every user today, regardless of location:

  • Access: Request a copy of the personal information we hold about you (GDPR Art. 15).
  • Rectification: Request correction of inaccurate or incomplete personal information.
  • Erasure: Request deletion of your personal information, subject to legal retention requirements (GDPR Art. 17).
  • Portability: Request a machine-readable copy of your data for transfer to another service (GDPR Art. 20).
  • Objection: Object to processing of your personal information for direct marketing or other purposes.
  • Withdrawal of Consent: Withdraw your consent at any time where processing is based on consent.

The complete list of everything you can request — and the self-serve paths for most of it — is on Your Data & Requests. To exercise any of these rights, please contact us atinfo@eternalengineos.io. We will respond to your request within 30 days.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law. Account data is retained while your account is active and for up to 90 days after account deletion — that window exists so you can change your mind or export. After it, your business data will be permanently deleted from our production systems — deletion is a commitment we honor within that 90-day window, never silently skipped. One narrow exception, kept deliberately and disclosed here: we retain a minimal account ledger — the name and email the account was created with, plus the deletion record — for fraud and abuse prevention and accurate account history. No business data, files, or customer records are ever part of that ledger. Anonymized usage data may be retained indefinitely for analytical purposes.

AI & Your Data

The built-in AI assistant processes the prompt you write and the relevant workspace context needed to answer it (for example, the deal you ask it to summarize). This processing happens through vetted AI model providers under agreements that prohibit using your content to train their models. AI usage is metered against your plan's token cap; we store usage metadata (token counts, timestamps, feature used) for billing and abuse prevention. We do not use Your Content to train AI models, and AI features never share your data across tenants.

Cookies

We use essential cookies to operate the Service, including session management and authentication tokens. Optional product-analytics cookies are set only after you accept them in the in-app notice, and you can withdraw that choice at any time. We do not use third-party tracking cookies for advertising. You can manage cookie preferences through your browser settings, but disabling essential cookies may prevent certain features from functioning properly. The full inventory of what we set and why is in our Cookie Policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Effective" date at the top of this page and, where appropriate, through email notification. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.