Where your words go
This is the only statement of what leaves your Mac. Eden shows you this same document inside the application, in Settings and in the panel where you sign a model in, and publishes it at pingback.ai/privacy. If another page of ours ever disagrees with this one, this one is right and the other is wrong.
Every sentence here says what Eden does today. Where something is planned and not built, it says so by name, and says that it is not available yet rather than describing it as though you could use it.
What leaves this Mac, and to whom
Three things can leave, and nothing else does: a question you ask a model, a request to a provider you have connected, and — when Eden has a search, which it does not yet — the words of that search. Each has its own section below, and each names who receives it; one section after those three says how long each receiver keeps what it got.
The model Eden thinks with
Eden thinks with a model behind a door you choose. One door is built today: your own ChatGPT plan. Eden runs OpenAI's Codex app-server on this Mac and speaks to it there; the sign-in is that program's, and Eden never reads or parses the file it keeps its credential in.
When you ask Eden something, the text that question needs goes to OpenAI, on your own plan and your own credential, and what OpenAI may do with it is what the plan you already hold says. That text is your words and the material you pointed Eden at — a thread you asked about, a page you are writing, a file you opened. It is never everything Eden holds.
A turn in Eden's own lane carries no connector tools at all: the model answering you cannot reach into your mail or your calendar on its own, and a test holds that on every commit.
Eden asks for Google only when you connect mail or calendar, and it asks for two scopes, both read: gmail.readonly and calendar.readonly. The ceremony refuses any other scope, so there is no version of this where Eden is quietly holding a write.
Send, forward, trash, permanent delete, unsubscribe and anything that would affect another person's calendar are refused inside Eden, before they reach Google. They are not refused by a policy you have to trust: they stop at the boundary of Eden's own core, and a test holds that line on every commit, in the job that must pass before anything merges. Widening that scope set fails the same job.
What goes to Google is the request that fetches your own mail and your own calendar. What Google sends back stays on this Mac. The tokens from that sign-in are held in your Keychain, device-only and never synchronised to another machine, and Eden reads them without ever asking you to unlock anything by hand.
Web search
Eden has no web search yet. When it has one, the words of the search go to Exa, which runs the search and may use the query under its own terms. Nothing else of your material goes with it, and this document will say so before the search exists rather than after.
How long each receiver keeps it
Eden sets no retention period at any receiver, and can reach inside none of them to delete. What each one keeps, it keeps under its own terms, and the answer differs by door:
- Your ChatGPT plan. What you ask is held by OpenAI for as long as the terms of the plan you already hold say. Eden neither sets that period nor holds a control over it: any control you have is the one that plan gives you, in your OpenAI account.
- Google. Google keeps its own record of the requests Eden makes for your mail and your calendar, for as long as Google's own terms say, and that record is in your Google account rather than in Eden. What Google sends back is kept here, on this Mac, until you delete it.
- Web search. There is no search yet, so Exa holds nothing of yours and never has. When there is one, Exa keeps the words of a search for as long as its own terms say, and Eden will not set that period.
- The doors that are not built. Nothing is held under Eden's own managed inference or under a provider key of your own, for any length of time, because neither exists yet.
- Us. Nothing of yours reaches us, so there is nothing here for us to keep.
What is never written down
This is the rule Eden's own logging is written to, and it is stated here as a rule rather than as something a check has proved: none of the following is ever written to a log or to a crash file, in any build.
- message bodies and subjects
- event titles and attendees
- file names and contents
- page titles, URLs and the contents of pages in the embedded browser
- terminal input, output and working directory
- what Eden asks a model, and what the model answers
- tokens, refresh tokens, keys and Keychain items
- your name or address, or any contact's
- anything captured from another application's interface
- screenshots
What Eden does keep, it keeps encrypted: no plaintext is written into its store or into the envelope of a transition, and a test holds that.
What does not leave at all
Eden sends us nothing. There is no crash reporting, no analytics, no telemetry, no heartbeat and no switch that would turn any of them on, because none of it is built. We do not have a copy of your mail, your calendar, your files or your writing, and there is no Eden account and no Eden server between you and them.
We do not train a model on your material, and we do not sell it. Nothing of yours passes through us to be able to.
Nothing of yours is sent anywhere to be indexed. Eden computes nothing of that kind today, and when it does, it computes it on this Mac and never at a hosted provider.
Which doors exist, and which do not
- Your ChatGPT plan — built, and the only door today.
- Eden's own managed inference, and the free allowance that runs on it — not yet available. It is on the path to launch and it is not built; nothing of yours has ever gone to it, because it does not exist.
- Your own provider key — not yet available.
- A Claude plan — not built, and not planned. Anthropic's developer terms do not permit an application like Eden to offer claude.ai sign-in without prior written approval, so Eden does not offer one.
Where your material is kept, and how to delete it
On this Mac, in Library/Application Support/Eden in your home folder. It is one place, and it is yours.
Delete it and Eden has nothing: a deletion purges the payload, destroys the keys that read it and removes what was derived from it, leaving a tombstone that says a thing was deleted and not what it was. A test holds that the deleted thing is gone from the disk and not merely unlinked.
Two things that deletion does not reach, said plainly: anything you have already exported to a folder of your own is yours to delete too, and anything already sent to a model under your own plan is held by that provider under that provider's terms, not ours.
Which Eden this describes
This document describes the source it was published from. No release of Eden is published yet. When one is, the build proves that this document describes that exact release and refuses to publish a pairing it cannot prove, so the words you consent on are always the words of the Eden you are running.