# Privacy policy — Eden

What Eden collects, why, where it keeps it, who can see it, and how you take it with you or delete it.

Canonical: https://eden.actor/privacy/

Human page: https://eden.actor/privacy/

[Skip to content](https://eden.actor/privacy/#content)

[Eden](https://eden.actor/)

### The Read menu
What it is: The nav’s menu of what there is to read.
How it works: Tap Read and a menu of links opens under it; Esc or a tap outside closes it. On a narrow screen the nav folds into a Menu button that holds the same links, Community and Contact.
Opens to:
  The menu
  - [What we believe](https://eden.actor/beliefs/)

[Community](https://eden.actor/privacy/#community)

### Request an invite, in the nav
What it is: The site’s one ask, in the nav: a button that opens a small form under it.
How it works: Tap it and the form opens under the button (on a phone, as a panel under the nav) with the email field ready; Esc or a tap outside closes it. Sending thanks you in place. It goes to Eden’s own request list, which Joel reads; you hear back when you’re let in.
Opens to:
  The form
  ```text-view:invite
  Email                      you@example.com  (required)
  Where's your mail?         Choose one  (required)
                             Gmail · Outlook · iCloud · Other
  What would you use it for? Optional
  [ Request an invite ]
  Joel reads every request.
  ```
  *What ASCII can't carry: Colour and the field's focus ring aren't shown here.*

# Eden privacy policy

**Effective 29 September 2026**

Eden is a home for your digital life, made by Joel Adejola, as The Pingback ("The Pingback", "we", "us"). This policy says what Eden collects, why, where it keeps it, who can see it, and how you take it with you or delete it. It covers Eden and its pages at eden.actor.

1. [In short](https://eden.actor/privacy/#in-short)
2. [Who we are](https://eden.actor/privacy/#who-we-are)
3. [What Eden collects, and why](https://eden.actor/privacy/#what-eden-collects-and-why)
4. [Where your data lives, and how it's protected](https://eden.actor/privacy/#where-your-data-lives-and-how-it-s-protected)
5. [Who can see your data](https://eden.actor/privacy/#who-can-see-your-data)
6. [Eden's intelligence](https://eden.actor/privacy/#eden-s-intelligence)
7. [What we share, and with whom](https://eden.actor/privacy/#what-we-share-and-with-whom)
8. [Google user data: Limited Use](https://eden.actor/privacy/#google-user-data-limited-use)
9. [How long we keep it](https://eden.actor/privacy/#how-long-we-keep-it)
10. [Take all of it and leave](https://eden.actor/privacy/#take-all-of-it-and-leave)
11. [Delete your home](https://eden.actor/privacy/#delete-your-home)
12. [Your rights](https://eden.actor/privacy/#your-rights)
13. [Where your data is processed](https://eden.actor/privacy/#where-your-data-is-processed)
14. [Children](https://eden.actor/privacy/#children)
15. [If something goes wrong](https://eden.actor/privacy/#if-something-goes-wrong)
16. [Changes to this policy](https://eden.actor/privacy/#changes-to-this-policy)
17. [Contact](https://eden.actor/privacy/#contact)

## In short

- Your home holds your data for you. We don't sell it, we don't use it for ads, and Eden never trains models on it.
- Nothing of yours reaches an AI model until you agree on Eden's consent screen, which names every company involved.
- Eden reads your mail and calendar only after you connect Google. It sends, changes or deletes nothing there unless you do it, approve it, or granted it.
- You can download a full copy of your home, and delete it, whenever you like.

## Who we are

Joel Adejola, as The Pingback, is responsible for the personal information described here. The Pingback is being formed as a public benefit corporation whose charter names custody of your data, and of the actors that act for you, as its public benefit. When it exists, it takes on this policy and its promises, and this page will say so.

Contact: founders@pingback.ai

## What Eden collects, and why

### When you ask for an invitation

Eden opens by invitation. When you ask for one, Eden keeps your email address, which mail service you use, and what you'd use Eden for, if you say, so Joel can let you in. The one email it sends you is your invitation. Your address joins no mailing list.

### When you write to Joel

Your name, if you give it, your email address and your message go to founders@pingback.ai as an email, so Joel can reply. Eden keeps no copy.

### When you sign in

You sign in with a passkey, made on your own device and unlocked the way the device unlocks: Face ID, a fingerprint or your screen lock. Eden keeps no password, and a passkey's private key never leaves your device or your password manager.

Eden keeps the email address you were invited at and the name you give it, to know it's you and to greet you by name. A Google account you connect is a source of mail and calendar, never a way to sign in.

### When you connect your Google mail and calendar

Connecting is its own step, after sign-in, with Google's own consent screen.

| Permission (Google scope) | What Eden does with it |
| --- | --- |
| Read your mail (`gmail.readonly`) | Brings your mail into your home, so Eden can show it to you, see who is waiting on you, draft replies for you to review, and learn what you're holding, each with its source. |
| Read your calendar (`calendar.readonly`) | Brings your calendars into your home, for Today and your week, and so Eden knows when you're free. |
| Send mail (`gmail.send`) | Sends mail when you press Send, or a reply you granted Eden to send for you. |
| Label, archive and trash (`gmail.modify`) | Labels, archives or trashes a thread when you do it in Eden, with Undo. Eden never deletes mail permanently. |
| Keep drafts in Gmail (`gmail.compose`) | Keeps your drafts in Gmail's Drafts as well as in your home. |
| Change your calendar (`calendar.events`) | Adds, moves or answers an event when you approve it, or under a grant you gave. |

Eden first reads the last week of your mail and calendar, then up to the last 90 days. It reads older mail only when something points to it. It keeps what it learned and the passage each fact rests on. It never infers your health, money, faith, politics, sexuality or intimate life: those enter only if you tell Eden, or connect a source meant for them.

While you stay connected, Eden keeps bringing in new mail and calendar changes, including when you're away.

What Eden may do on its own is set by grants you choose when you start, and can change in Settings at any time. Anything that reaches another person, or can't be undone, asks you first or tells you after.

### What you give Eden

Your conversation with Eden, the corrections you make, what you write, your settings and grants, and any other service you choose to connect.

In voice mode, your voice streams to Gemini Live, on Google Cloud's Vertex AI, while you talk. Dictation is turned into text on your own device wherever the device does it well: in Eden for Mac and Eden's iPhone app, your voice doesn't leave the device. Where it can't, such as in a browser, your words are sent to Gemini to be written out. Every recording you make, whether a voice note, dictation, voice mode or a meeting, is kept in your home beside its transcript, so it's yours on every device.

### What Eden makes from it

- **What Eden knows about you**, shown on your You page, where you can read it, correct it and see what changed.
- **Knowledge**: facts about your life, each with its source and its history.
- **Today**: the things that need you, and what Eden has taken care of.
- **Drafts**: replies in your words, which go nowhere until you send them.
- **Receipts and traces**: a record of what Eden did, how it got there, and what it left alone.

### What Eden doesn't collect

Eden runs no analytics, no advertising trackers and no telemetry. Its pages load only Eden's own code.

Eden sets only the cookies signing in needs: one for your session, and one for a sign-in in progress. It sets no third-party cookies.

## Where your data lives, and how it's protected

- **Your home.** Each person's home is a small computer of its own. It runs as a separate app on Fly.io, in the United States, on a private network of its own, with its own encrypted disk. Your mail, calendar, knowledge, conversation, drafts and receipts live there.
- **Backups.** Your home streams a continuous backup to a storage bucket of its own on Cloudflare R2, encrypted at rest, under a key that reaches only that bucket.
- **Your Google tokens stay in your home.** They are kept apart from the rest of your home and sealed under a key made for your home alone. They are never shown to Eden's actors, never sent to a model and never written to a log.
- **Your account.** Eden's front door, which signs you in at eden.actor and reaches your home, keeps your email address, your name, how you sign in, and your sessions, on an encrypted disk, with an encrypted backup kept by Tigris.
- **In transit.** Everything travels over TLS.
- **Logs** record what happened, never what it was about: no address, token, cookie, secret or content.
- **Our own access.** Every account we use to run Eden requires multi-factor sign-in.

## Who can see your data

- **You**, on the devices you sign in on.
- **Eden, and any actor you add**, only under the grants you give. Every act leaves a receipt.
- **The companies Eden thinks with**, only what a task needs, as the next section says.
- **Us.** We operate the machines your home runs on. We don't read your home, your mail or your calendar unless:
  1. you ask us to, and agree to let us see specific items, for example to help with a problem you report;
  2. it's necessary for security, such as investigating abuse; or
  3. the law requires it.
- **Google** sees what its own services always see.

## Eden's intelligence

Eden thinks with Google's Gemini models on Google Cloud's Vertex AI.

- **Only what a task needs is sent:** the messages Eden is reading, the facts relevant to what you asked, and your words in the conversation. Never your sign-in tokens.
- **Nothing is trained on it.** Google doesn't train on what Eden sends, and Eden never uses Google user data to develop, improve or train generalised AI or machine-learning models.
- **Gemini requests.** Eden sends them through Vercel's AI Gateway with zero data retention enabled and Vertex AI pinned as the provider. Google doesn't train on or retain these requests through this route.
- **Voice mode.** Live sessions go directly to Vertex AI with session resumption off, so Google doesn't retain session audio for resumption. Until Google grants Eden an exemption from abuse logging, Google's safety systems may log voice requests they flag for up to 90 days, only to check for abuse.
- **Narrow decisions.** TypeSafe's Jev runs through Vercel's AI Gateway for yes-or-no probabilities, choices from a fixed set, and bounded scores. Jev is a separate judge for those decisions; Gemini handles Eden's language work and voice.
- **Web searches** Eden makes for you go to Exa. Eden sends the words of a search, never your mail or calendar themselves. Under [Exa's standard terms](https://exa.ai/assets/Exa_Labs_Terms_of_Service.pdf), Exa may keep a search and use it to improve its service, including to train its models. Eden is moving to Exa's zero-retention terms, and this page will say when it has.

If you sign Eden in to an AI plan of your own, such as ChatGPT or Claude, the work Eden does on that plan goes to that provider under your plan's terms. Eden tells you exactly which work that is before you connect it.

## What we share, and with whom

We don't sell your personal information. We don't use it, or share it, for advertising. We don't give it to data brokers.

We share it only with the companies that run Eden, bound by their terms to use it only to provide their service:

| Company | What it does for Eden |
| --- | --- |
| Fly.io | Runs your home and Eden's front door, in the United States |
| Cloudflare | Stores your home's encrypted backups (R2) |
| Tigris | Stores the front door's encrypted backup |
| Google | The Gmail and Calendar you connect, and the Gemini models Eden thinks, writes out speech and speaks with |
| Vercel | Carries model requests (AI Gateway) and serves Eden's pages |
| TypeSafe | Runs Jev for narrow yes-or-no, fixed-choice and bounded-score decisions |
| Exa | Runs web searches |
| Resend | Sends your invitation email, and your messages to Joel |

We may also disclose information when the law requires it, or when it's necessary to protect someone's safety or Eden's security.

If The Pingback merges, is acquired or sells its assets, your data moves only under this policy's promises. We'll tell you first, and your Google user data moves only with your explicit consent.

## Google user data: Limited Use

Eden's use and transfer to any other app of information received from Google APIs will adhere to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

The use of information received from Google Workspace APIs will adhere to the [Google Workspace User Data and Developer Policy](https://developers.google.com/workspace/workspace-api-user-data-developer-policy), including the Limited Use requirements.

In plain words:

- Eden uses your Google data only to provide the features you see in Eden.
- Eden transfers it only to provide those features (to the companies listed above), for security, to comply with the law, or, with your explicit consent, as part of a merger, acquisition or sale of assets.
- No person reads it except in the three cases under "Who can see your data".
- It's never used for advertising, never sold, and never used to train generalised AI or machine-learning models.

You can remove Eden's access at any time in your Google Account, at myaccount.google.com/permissions, or by disconnecting the account in Eden's Settings.

## How long we keep it

| What | How long |
| --- | --- |
| Your home: mail and calendar brought in, knowledge, conversation, drafts, receipts | Until you delete your home |
| A Google account you disconnect | Eden revokes its access at Google, deletes its token and stops bringing in mail and events. What was already brought in stays in your home until you delete it. |
| Your account at the front door | Until you delete your home, and up to 24 hours more in the front door's own backups |
| Your sessions | Until you sign out, they expire, or you delete your home |
| Your place on the invitation list | Until you're let in, or you ask us to remove it |
| A message you write to Joel | In founders@pingback.ai's mail, until Joel deletes it |

When you delete your home, we keep one record that names no one: when the deletion was asked for and finished, and whether Google confirmed Eden's access was revoked.

If we ever have to end Eden, we'll tell you in advance and give you time to download your home before anything is deleted.

## Take all of it and leave

In Settings, **Download a copy** gives you everything your home holds for you, as one file: your profile, settings, grants, connected accounts, the mail and calendar Eden brought in, your conversation, what Eden knows with its sources and history, your drafts and your receipts. It leaves out your sign-in tokens, which are keys to your accounts rather than your data.

## Delete your home

In Settings, **Delete your home**. Eden offers you a full copy first, and asks you to type your email address. Then:

1. Your home revokes Eden's access at Google and forgets its tokens.
2. Every device signed in to your account is signed out.
3. Your home's machine and its disk are destroyed.
4. Its backups, and the key that reached them, are deleted.
5. Your account, and everything the front door kept for it, is deleted.

Your mail and calendar at Google aren't touched. This can't be undone. You can also ask us to delete your home by writing to founders@pingback.ai from your email address.

## Your rights

Wherever you live, you can see what Eden holds, correct it, download it, delete it, and withdraw your consent to Google access by disconnecting. Write to founders@pingback.ai for anything Eden doesn't let you do itself, and we'll answer within 30 days.

In the European Economic Area, Switzerland and the United Kingdom, we process your data to provide Eden to you, with your consent (connecting Google, and each permission as it's asked), and for our legitimate interest in keeping Eden secure. You also have the right to object to and restrict processing, and to complain to your data protection authority.

In California, we don't sell or share your personal information, as California law defines those words, and we don't use sensitive personal information to infer characteristics about you. You have the right to know, delete and correct it, and we won't treat you differently for using these rights.

## Where your data is processed

Your data is processed in the United States.

## Children

Eden is for people aged 18 and over. We don't knowingly collect personal information from children. If you believe a child has signed in, write to founders@pingback.ai and we'll delete their home.

## If something goes wrong

If a security incident affects your data, we'll tell you, and the authorities the law requires, without undue delay.

## Changes to this policy

We post every change here, with a new effective date. If a change affects how Eden uses your data, especially your Google data, Eden tells you in the app and asks you to agree before it uses your data in the new way.

## Contact

founders@pingback.ai

A home for your digital life, so you can return to reality.

[Discord](https://discord.gg/c8fPV4X26J)

[X · @PingbackAI](https://x.com/PingbackAI)

[Instagram · @thepingback](https://www.instagram.com/thepingback)

[Substack](https://letter.pingback.ai/)

[GitHub](https://github.com/thepingback)

[LinkedIn](https://www.linkedin.com/company/thepingback)

Eden

- [Request an invite](https://eden.actor/#invite)

Instruments

- [Eden](https://eden.actor/)

Read

- [What we believe](https://eden.actor/beliefs/)
- [The Pingback’s writing](https://eden.actor/privacy/#)

The Pingback

- [About](https://pingback.ai/)
- [Contact](https://eden.actor/contact/)

[The **Pingback**](https://pingback.ai/)

An institution for knowing.

Eden is made by [The Pingback](https://pingback.ai/). Designed and built by [Joel](https://adejola.com/).

[Privacy](https://eden.actor/privacy/)

[Terms](https://eden.actor/terms/)

© 2026 The Pingback

### Human · Machine
What it is: A switch in the footer: Human is the page as built, Machine is the same page as text, made for agents.
How it works: Choose Machine and the page gives way to its own markdown twin in one mono column: every word, each link as [label](address), each picture described, each product view drawn. Copy copies all of it; choose Human to go back. The choice is remembered on this device, and ?view=machine opens it from a link.
Opens to:
  Machine
  ```text-view:machine
  Human · Machine                        [ Copy ]
  # <the page’s title>
  <the whole page as markdown, in one column>
  ```
