Everything Since
Privacy by mode

Where your data goes.

See what stays on your device, what each optional service receives, and the controls you have over your data.

At a glance

Local

Account: Not required

On your device
The workspace in the app’s encrypted local database and user-made exports.
Sent to a service
Nothing for core note use.
Hosted deletion
No hosted note copy exists for Local.

BYOK intelligence

Account: Not required for local app use

On your device
The workspace and locally stored settings.
Sent to a service
The evidence and instructions needed for the request go directly to the provider chosen by the user, under that provider’s terms.
Hosted deletion
Use the chosen provider’s controls for provider-held data; removing the local key does not delete provider records.

Sync

Account: Required

On your device
Desktop clients keep an encrypted local replica of the complete workspace.
Sent to a service
The complete workspace is encrypted and stored on the Sync service so it can open on every signed-in device, together with the minimum account and operational metadata needed to synchronize clients.
Hosted deletion
Account deletion removes hosted Sync data and the wrapped vault key under the published retention process; local copies and user-made exports remain.

Managed Intelligence

Account: Required

On your device
The workspace remains local unless Sync is enabled.
Sent to a service
User-authorized evidence, instructions, and necessary request context pass through the managed gateway to configured model providers. Derived hosted memory exists only when that feature is enabled.
Hosted deletion
The account control deletes hosted managed-memory and service data under the published retention process. Provider processing and legally required records follow their applicable terms.

Control is visible

Local

No account gate

Create, edit, search, import, and export without buying a hosted service.

Sync

Your workspace, everywhere

Sync keeps your notes up to date on every device you sign in to, and in your browser. Everything is encrypted on the way and while stored. Sync is separate from Intelligence.

Intelligence

Evidence by permission

Requests show their mode and evidence boundary. BYOK and managed provider paths are distinct choices.

Retention and deletion

  • Product analytics are off by default and require explicit device consent. When enabled, only allowlisted content-free events and coarse bounded values are sent; notes, prompts, titles, filenames, Space names, URLs, precise location, and analytics IP addresses are not stored.
  • Operational logs carry request health, timestamps, and pseudonymous service identifiers, not workspace prose.
  • Managed Intelligence also records account-linked usage: model, feature, time, input/output token counts, cost estimates, and request outcome. These records support service limits, reliability, and cost accounting independently of optional product analytics. They contain no prompts, answers, notes, filenames, or Space titles and are available only to authorized operators.
  • Detailed managed-usage records are kept for 90 days, account-linked summaries for up to 395 days, and service totals for up to 730 days. Account deletion removes linked usage history and existing usage exports; protected backups follow the backup retention process. Other providers apply their own retention terms.
  • After paid Sync access ends, existing encrypted uploads remain downloadable for 30 days before scheduled deletion. After Intelligence access ends, hosted derived memory is retained for 30 days before deletion.
  • Deleting hosted data does not erase local copies, user-made exports, another provider’s records, invoices that must be retained, or data already shared by the user elsewhere.
  • Your account shows the lifecycle of hosted Sync data and derived memory, including controls to request earlier deletion.

Hosted Sync and Intelligence are operated by Everything Since. For support or a privacy request, email support@everythingsince.com.