Privacy Policy

Last updated 26 August 2026.

Who is responsible

Etch is operated by NuHouse Empreendimentos e Participações Ltda., CNPJ 32.151.695/0001-07, with its registered office at Rua Henrique Meyer, 280, Sala 505, Joinville-SC, 89201-405, Brazil ("Etch", "we", "us"). NuHouse is the controller of the personal data described below.

Write to contact@useetch.com for any question about this policy, to exercise the rights described under Your rights, or to reach us as the controller.

This policy describes the processing carried out by the Etch application and by the server that supports it. It does not describe Apple's own processing of your Apple ID, your iCloud storage or your App Store purchases, which is governed by Apple's privacy policy.

Applicable law

Etch is operated from Brazil and this policy is governed by Brazilian law, in particular:

Etch is not offered in the European Economic Area and is not directed at users located there. If that changes, this policy will be updated before the change takes effect.

Encarregado (data protection officer)

NuHouse has not appointed a formal encarregado. It processes personal data as a small processing agent within the meaning of ANPD Resolution CD/ANPD No. 2 of 27 January 2022, which relieves such agents of the appointment obligation in Article 41 of the LGPD and requires instead that a channel be published for data subjects and for the ANPD. That channel is contact@useetch.com.

Summary

What we process, and why

Your Apple user identifier. Sign in with Apple provides Etch with a character string that identifies you to this application and to no other. Etch requests no other scope from Apple — not your name, not your email address, not a private relay address. Against that identifier we store a single number: how many AI descriptions you have used from the free allowance. That record is the entire account we hold. Legal basis: performance of a contract to which you are a party (LGPD, Article 7, V).

A session token, held on your device. After you sign in, our server issues a token that your device stores in the system keychain and presents with later requests. It contains your Apple user identifier and an expiry date, and nothing else. Legal basis: performance of a contract to which you are a party (LGPD, Article 7, V).

Your subscription's original transaction identifier, if you subscribe. It is read from a receipt signed by Apple and is what allows our server to confirm that a subscription is active. Your monthly allowances for AI descriptions and for conversation messages are counted against that transaction identifier rather than against you, so a subscription shared across your devices has one allowance. Legal basis: performance of a contract to which you are a party (LGPD, Article 7, V).

Aggregate service counters. Our server records, as operational log entries, the endpoint called, the outcome status, the platform a saved link came from (Instagram, TikTok or YouTube), which AI model was used and how many tokens a call consumed. These entries contain no identifier of any kind, are not linked to you, to your account or to your device, and never contain a saved URL. They exist to tell us whether the service is working and what it costs to run. Legal basis: these entries are aggregate and carry no identifier, and so are not personal data under Article 12 of the LGPD. To the extent any entry were treated as personal data, we rely on our legitimate interest in operating and securing the service (LGPD, Article 7, IX).

Your device's IP address reaches our infrastructure provider, Cloudflare, because a network request cannot be delivered without one. Etch does not read it, does not store it and does not associate it with your account. Cloudflare retains its own operational records under its own terms and privacy policy.

What we do not collect

When information leaves your device

Saving a link sends the URL to our server, which fetches the public page to read its title, author, caption and thumbnail. The URL is not retained after the response is returned: it is written to no record, no log entry and no counter.

Making an item searchable sends the item's text to OpenAI, which returns a list of numbers representing what the text means. That list is stored with the item on your device and is what search compares against. The text sent is the item's caption and, once they exist, any note you have written and any description Etch's AI has produced for the item. This happens for every item you save, on every plan. No identifier, account or other item accompanies it.

A note you write is part of that text. We state this separately because the consequence differs: a note is your own sentence rather than something a third party published. A note is sent to OpenAI when you write or change it, on every plan, and it is not metered. If you would prefer a sentence never to leave your device, do not record it as a note.

An AI description is produced only when you request one, only on the paid feature, and only within your plan's monthly allowance. Our server downloads the item's thumbnail from the platform hosting it and sends that image, together with the item's caption, to OpenAI, which returns a short description and tags.

Conversation mode sends your question, together with up to eight items from your own library, to OpenAI, which returns an answer drawn only from those items. Each item is sent as an opaque identifier and up to 400 characters of the text Etch holds about it — the author's handle, your note, the caption, the description Etch's AI wrote and its tags. Neither the item's URL nor its thumbnail is sent. Your device selects which items are relevant; our server never reads your library and cannot choose them. This is a paid feature and is metered per month.

Searching sends the words you type to OpenAI, so that they can be turned into the same list of numbers before they can be compared. The comparison and the ranking of your library take place entirely on your device; your library is never sent anywhere in order to be searched. We do not retain search terms. Under OpenAI's API terms, content submitted through the API is not used to train its models and is deleted within 30 days, save where OpenAI must retain it longer to comply with the law.

Who processes data with us

Who Role What they do Where
Apple Independent controller Sign in with Apple, iCloud storage of your library, payments and subscription management Apple's own regions
Cloudflare Processor, on our instructions Runs our server and stores the allowance counters Cloudflare's global network
OpenAI Processor, on our instructions Converts text into vectors for search, and writes descriptions and conversation answers United States

Apple acts as an independent controller for sign-in, iCloud and payments, under its own terms. Cloudflare and OpenAI act as processors (operadores) and process data only on our instructions.

International transfers

Cloudflare and OpenAI are established outside Brazil, so using Etch involves an international transfer of your Apple user identifier, the allowance counters, and the text and search terms described above. Your library's storage location follows your iCloud account and is determined by your arrangement with Apple rather than by us.

These transfers are made on the basis of Article 33, IX of the LGPD — the transfer is necessary for the performance of a contract to which you are a party — and, in respect of each provider, on the basis of the data protection terms forming part of our contract with them, which is the specific contractual clauses route in Article 33, II, "a" of the LGPD, as regulated by ANPD Resolution CD/ANPD No. 19 of 23 August 2024.

How long we keep it

Your rights

Under Article 18 of the LGPD you may ask us for:

You may also petition the Autoridade Nacional de Proteção de Dados (ANPD — Brazilian National Data Protection Authority) in relation to your data, under Article 18, §1.

Two of these rights are built into the application and need not be requested:

For anything else, write to contact@useetch.com. We respond within 15 days, which is the period Article 19, II of the LGPD sets for confirmation and access requests.

Automated decisions

Etch does not take decisions about you based solely on automated processing. Its AI features describe saved content and answer questions about your own library; they produce no decision affecting your legal situation or your interests within the meaning of Article 20 of the LGPD.

Security

Sessions are issued and verified by our server using signed tokens, are transmitted only over encrypted connections, and are stored on your device in the system keychain. Your library is protected by Apple's own iCloud security and is accessible only through your Apple ID.

Children and adolescents

Etch is a general-audience product and is not directed at children or adolescents. Under Article 14 of the LGPD, read with the Estatuto da Criança e do Adolescente (Statute of the Child and Adolescent, Federal Law No. 8.069/1990), a child is a person under 12 and an adolescent is a person aged 12 to 17.

We do not knowingly process the personal data of a child under 12. Such processing requires the specific and prominent consent of at least one parent or legal guardian, and Etch has no mechanism to obtain it. If you believe a child under 12 has provided personal data to us, write to contact@useetch.com and we will delete it.

Where an adolescent uses Etch, we process their data only in their best interest, as Article 14 requires, and only as described in this policy.

Changes to this policy

If this policy changes in a way that affects what we process or why, the application will state so before the change takes effect. The date at the top of this page always reflects the version in force.

Contact

NuHouse Empreendimentos e Participações Ltda. CNPJ 32.151.695/0001-07 Rua Henrique Meyer, 280, Sala 505, Joinville-SC, 89201-405, Brazil contact@useetch.com