Skip to content
Erphele

Privacy Policy

Last updated July 31, 2026

Our promise

  • We never sell your data - not to advertisers, not to anyone.
  • We never use your private content to train AI models.
  • Your data is encrypted in transit and at rest, and isolated to your account.
  • You can see everything Erphele knows, delete any of it, or export it all - at any time.
  • The same protection applies to everyone, whatever you keep here.

Overview

Erphele is a personal productivity agent that helps you manage your tasks, calendar, notes, and day-to-day thinking - and remembers what matters to you. This policy explains what we collect, why we collect it, and the choices you have. Our rule is simple: we collect what's needed to run Erphele well for you, and nothing more.

Information we collect

Account information. You sign in with Google, with Apple, or with a one-time code sent to your email - all handled by our authentication provider, Clerk. We receive your name, email address, and profile image. Erphele never sees or stores a password.

Content you create. Tasks, projects, goals, calendar entries, chat messages, notes, journal entries, people you mention, uploaded files and photos, agent-generated files and sites, long-term memories, and daily briefs.

Voice. If you send a voice message, we store the recording (so you can play it back) and a transcript of it. Both live in your account and are deleted with it.

Preferences & usage. Theme, language, timezone, region, notification settings, and usage counts used to enforce plan limits.

Device & notifications. Web push subscriptions and mobile push tokens so Erphele can reach you when you ask it to.

Location. Only in the foreground, and only when you explicitly ask - for a place lookup or to save coordinates on a place-based task. Erphele never requests background or always-on location.

Computer Use. If you pair the desktop app and enable Computer Use, we store the commands the agent proposed, your approval decisions, and the command output - so you always have a complete record of what happened on your machine. See our Security page for how pairing is protected.

Live sources you configure. If you add a live tile (a stock symbol, a currency pair, a website), we periodically fetch that public data to keep the tile fresh. The source itself receives only the request - never your identity or content.

Visitor submissions on your hosted sites. If you publish a site with a form, submissions from visitors are delivered to your site inbox and stored in your account. You are the owner of that data and responsible for handling it appropriately.

Visitor traffic on your hosted sites. Pages published on erphele.site keep a small daily traffic rollup for their owner - see “Visitors to hosted sites” below.

Diagnostics & product analytics. Sentry (hosted in the EU) receives crash and performance diagnostics, and PostHog (EU Cloud) receives a small set of explicit product events. Automatic interaction capture, automatic pageviews, advertising tracking, and session replay are all disabled.

Data stored on your device

To make Erphele fast and usable offline, the app keeps a local cache on your device: your profile, recent conversations, notes, tasks, and similar content. Cached entries expire automatically after about 30 days, and the entire cache is wiped when you sign out or delete your account. On mobile, session credentials are stored in the operating system's secure keychain, never in plain storage.

How we use your information

To provide and operate Erphele: run the agent, manage your tasks and calendar, generate files and sites, deliver notifications, enforce plan limits, and provide proactive help. We use aggregate, non-identifying information to maintain and improve the service. We do not sell your personal data, and we do not use it for advertising.

AI processing

Where your chats run. When you talk to Erphele, your messages and the context needed to answer them are sent to AI models. Every ordinary (non-temporary) turn, on every plan including Free, is routed through OpenRouter and pinned to OpenAI-hosted endpoints, which serve the model Erphele runs on. The same lane handles the work you don't see directly: chat titles, memory distillation, recall reranking, web-search summaries, and daily briefs.

Temporary chats. A temporary chat is deliberately not pinned to OpenAI. It is sent with zero-data-retention and no-data-collection flags, which route it to whichever zero-retention endpoint serves the same model - operated by a provider other than OpenAI, because OpenAI's own endpoints are not zero-retention eligible. We store nothing from a temporary chat, and the provider serving it is instructed not to retain or log it.

Voice, images, speech, and recall. Voice messages are transcribed by Alibaba Cloud's Qwen ASR model through OpenRouter. Voice inside a temporary chat - and any transcription that has to fall back - goes to Google's Gemini model on Vertex instead, because that lane has zero-retention endpoints and dedicated speech models do not. Generated images and read-aloud speech also run on Google's Gemini models. For semantic memory and note recall, short snippets of your content are sent to Google's Gemini API to create embeddings - numerical representations used only to search your own content.

Connecting your own OpenAI account. Paid plans can run replies on your own account instead of ours, in one of two ways: an API key you connect (requests go directly to OpenAI's API with storage disabled) or your ChatGPT subscription, where requests go to OpenAI's ChatGPT backend under your own plan. Either way, those requests are governed by your agreement with OpenAI, including its own retention and model-training settings - which you control in your OpenAI or ChatGPT account, not here. Consumer ChatGPT accounts allow training on your conversations unless you turn it off there. Any key you connect is encrypted at rest, never shared, and revoked and deleted when you remove it or delete your account. Temporary chats never run on a connected account - they stay on Erphele's own zero-retention lane or they don't run at all.

We never use your private content to train AI models - not ours, and we never hand it to anyone else to train on. That covers everything Erphele processes for you on our own infrastructure and providers. The single exception is the one you choose yourself: traffic you deliberately route to your own OpenAI or ChatGPT account follows that account's terms and settings.

Service providers

We rely on a small set of processors, each handling data only to perform its function:

Clerk - authentication and identity. • Convex - database and file storage, in the EU (AWS eu-west-1). • Vercel - web and hosted-site delivery. • OpenRouter - routing of every AI request, and billing for it. • OpenAI - the chat, reasoning, and utility model behind every ordinary turn on every plan, plus any traffic you route to your own OpenAI or ChatGPT account. • Alibaba Cloud - voice-message transcription (Qwen ASR). • Google - embeddings for recall, image generation, and read-aloud speech (Gemini, including Vertex for private transcription). • Other zero-retention model hosts - temporary chats route to whichever zero-retention endpoint serves the model at that moment, so the host varies and is not OpenAI. • Polar - subscription billing as merchant of record; we share only your email and account ID and never see payment details. • Expo - mobile push delivery. • Sentry - crash and performance diagnostics, EU region. • PostHog - product analytics, EU Cloud. • Open-Meteo - weather. • OpenStreetMap / Nominatim - place search when you ask for one.

Live tiles fetch public market data from Stooq, CoinGecko, and Frankfurter - those requests carry no identity or content. We keep this list current: when the model behind a feature changes, this page changes with it.

Data retention & deletion

We retain your data for as long as your account is active. You can delete individual items (tasks, chats, files, memories) anytime, or delete your entire account from Settings → Account. Account deletion takes effect immediately: access is blocked, notifications stop, and Computer Use is disabled. A background job then removes your content from every table and storage bucket, deletes your identity at Clerk, and revokes any API key you connected. Your device's local cache is wiped as well. Processors may retain limited records where legally required (for example, billing records at Polar).

You can also export everything as a single ZIP - your data as both machine-readable JSON and human-readable files, including your attachments. Export links expire after 24 hours.

Security

Your data is encrypted in transit (TLS) and at rest, and isolated to your account - enforced on every request. Everyone gets the same protection, whatever they keep in Erphele. No system is perfectly secure, but we follow industry-standard practices and welcome responsible disclosure at support@erphele.com. See our Security page for details.

Visitors to hosted sites

This section is about people who visit a site an Erphele user published on erphele.site, not about Erphele account holders.

When a published page is viewed, we record a per-site, per-day rollup so the site's owner can see how it is doing: the number of page views, the number of distinct visitors, the most-viewed paths, and the hosts that referred traffic. Visitors are counted using a keyed pseudonym computed at our web edge and rotated every day - the visitor's IP address itself is never written to our database and is never shared with the site owner. There are no analytics cookies, no cross-site tracking, no advertising identifiers, and no profile that follows a visitor between sites or days. These rollups are deleted automatically after 90 days, and immediately if the site or the owner's account is deleted.

Anything else a visitor sends - a form submission, for example - belongs to the site owner and is handled under their own terms, not ours. Abuse on a hosted site can be reported from any page at /__erphele/report.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Most of these you can exercise directly in the app; for anything else, contact us and we'll help.

Children

Erphele is not directed to children under 13, and we do not knowingly collect their data.

International transfers

Your account data is stored in the EU (Convex on AWS eu-west-1), and diagnostics and product analytics are hosted in the EU as well. AI processing is different: requests are served by providers in other regions - primarily the United States (OpenRouter, OpenAI, Google) and, for voice transcription, Alibaba Cloud. Billing runs through Polar, and authentication through Clerk, both US-based. Those transfers are made under the standard contractual clauses or equivalent safeguards our providers offer, and the data sent is limited to what the request needs. Wherever your data is processed, it is handled in accordance with this policy.

Changes to this policy

We may update this policy as Erphele evolves. Material changes will be reflected by the “Last updated” date above, and where appropriate we'll notify you in the app.

Contact

Erphele is operated by a licensed self-employed software professional in the Kingdom of Saudi Arabia, who is the data controller for the information described here. Registered business details are provided on request. Questions about privacy? Email support@erphele.com.