Legal

Privacy Policy

Effective June 16, 2026

Eden (“Eden,” “we,” “us,” or “our”) builds tools that help creators discover, save, and write about content that has already proven to work. This Privacy Policy explains what we collect when you use Eden, why we collect it, who we share it with, and the choices you have. It applies to our marketing site at eden.so, the Eden web app at app.eden.so, our browser extension, and any related services we offer (together, the “Service”).

We try to keep this document plain and short. If anything here is unclear, email us at [email protected] and we’ll explain.

1. Who we are

Eden Suite, Inc. is the data controller for personal information processed through the Service. You can reach us by email at [email protected] or by post at:

Eden Suite, Inc.
1111B S Governors Avenue

STE 37203

Dover, DE 19904

United States

2. Information we collect

We collect three broad categories of information.

a. Information you give us directly

  • Account information. When you sign up we collect your email address, a chosen handle or display name, and (optionally) your profile picture. We sign you in with a one-time code sent to your email; we do not store a password.
  • Billing information. When you subscribe we collect your billing name, country, postal code, and the last four digits of your card. Full payment card details are entered directly into Stripe, our payment processor, and are never stored on our servers.
  • Content you create or save. Boards, sections, notes, swipe-file cards, watchlists, chat messages, uploads, and anything else you put into the Service.
  • Connected accounts. If you connect a social account (for example to import your handle), we store the access tokens and basic profile data needed to keep that connection working.
  • Support requests. If you email support or fill out a form, we receive whatever you send us.

b. Information we collect automatically

  • Usage data. Pages and features you use, buttons you click, the approximate timing of those events, and the device and browser you use to access the Service. We use this to understand which features matter and where the product breaks.
  • Log and device data. Standard server logs, which include IP address, user-agent string, referring URL, and timestamps. We use these for security, abuse prevention, and debugging.
  • Cookies and similar technologies. See Section 7 below.

c. Public information about creators

Eden surfaces publicly available metadata about creator content (such as post text, captions, view counts, like counts, publish dates, thumbnails, and links back to the original post) from third-party platforms including YouTube, X, Instagram, TikTok, LinkedIn, and Substack. The Service acts as a viewer and analytical layer over information that is already public on those platforms, accessed through publicly accessible interfaces (including official APIs where available) and only as needed to respond to user-directed queries. We do not collect private posts, drafts, direct messages, or any content behind a login wall, paywall, or other technical access control, and we do not bypass any such control.

If you are a creator and would like content about your public profile removed from Eden’s index, email [email protected] from an address that can verify ownership of the account and we will process the request promptly.

3. The Eden browser extension

The Eden Web Clipper is an optional browser extension that saves links, images, and individual posts from sites like X, LinkedIn, Instagram, Substack, and YouTube into your Eden boards. It is opt-in: it only runs after you install it, and it only sends data to Eden when you actively click a save action.

a. How the extension signs you in

The extension does not have its own password or sign-in form. Instead, when you click “Connect Eden” in the extension, we open app.eden.so. After you sign in there (or if you are already signed in), the web app passes a long-lived refresh token to the extension over the Chrome extension messaging channel (chrome.runtime.onMessageExternal). The extension’s background service worker verifies that the message came from an Eden origin we trust before accepting it.

That refresh token is stored locally on your device in chrome.storage.local, which is scoped to the extension. We use it only to obtain short-lived access tokens for the Eden API when you save something. The token is not transmitted to any third party. You can disconnect at any time from the extension’s options page or by removing the extension, which clears the stored token.

b. What the extension reads

  • Only when you invoke a save. The extension reads the URL, page title, and (when relevant) the selected text or image URL of the current tab when you click the toolbar button, use the right-click menu, or click an in-page “Save to Eden” button. It does not monitor your browsing in the background.
  • Per-site save buttons. On X, LinkedIn, Instagram, Substack, and YouTube, the extension injects a small “Save” button into individual posts so you can clip them in one click. The accompanying content scripts read only the publicly visible post content (the same content the page already shows you) and only when you click that button. They do not read direct messages, drafts, account settings, or any content behind your account on those platforms.
  • Scoped access. The extension uses Chrome’s activeTab permission so page access is limited to the tab you have activated us on, and host permissions are limited to the supported sites listed above plus Eden’s own domains.

c. What the extension sends to Eden

When you save, the extension sends to the Eden API: the URL you are saving, an optional title and note you typed, the destination board you picked, an access token derived from your stored refresh token, and (for image saves) the source image URL so our server can fetch and store the image. Nothing is sent until you click save.

d. Why the extension asks for each permission

  • storage — remember your refresh token and your preferred destination board between sessions.
  • contextMenus — add the “Save to Eden” right-click option on links, images, and selected text.
  • activeTab — read the URL, title, and selection of the tab you have invoked the extension on, for the duration of that save.
  • scripting — inject the per-site save buttons on the supported platforms above.
  • notifications — show a small success or failure toast after a background save.
  • tabs — open the sign-in tab and the “view in Eden” tab after a save.
  • sidePanel — render the optional Eden side panel inside the browser.
  • Host permissions on x.com, linkedin.com, instagram.com, substack.com, youtube.com, and Eden’s own domains — the supported source sites for the in-page save buttons and the Eden APIs the extension talks to.

4. How we use information

We use the information described above to:

  • Provide, operate, and maintain the Service.
  • Authenticate you, secure your account, and prevent fraud, spam, and abuse.
  • Process payments, manage subscriptions, and send billing receipts.
  • Personalize what you see in the product (for example, the creators in your feed, the boards you have access to, and chat answers grounded in your saved content).
  • Send you transactional and product emails (account notifications, security alerts, billing receipts, important product changes). You cannot opt out of transactional emails while you have an active account.
  • Send you marketing emails about features, tips, and updates. You can opt out of these at any time by clicking the unsubscribe link in any marketing email or by updating your email preferences in your account.
  • Respond to support requests and feedback you send us.
  • Measure and improve the product, debug issues, and analyze how features are used.
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information, and we do not share it with third parties for their own advertising.

5. AI features and how your content is used

Eden includes AI features (for example, chatting with a board, generating drafts from your swipe file). When you use these features:

  • We send the relevant inputs (your prompt and the content you have asked the AI to use as context) to third-party AI providers through an AI gateway service (OpenRouter) that routes each request to an underlying model provider. Outputs are returned to you and stored in your account.
  • We route AI requests only to providers operating under no-logging / no-training data policies, so your content is not used to train their general-purpose models.
  • We do not use your private content (boards, notes, drafts, uploads, chat messages) to train our own models or any third party’s general-purpose models.
  • We may use aggregated, de-identified usage data (for example, how often a feature is used, latency, error rates) to improve the product.

6. Who we share information with

We share personal information only with the categories of recipients below, and only as needed for the purposes described in this policy.

a. Service providers (sub-processors)

We use a small set of vendors to run the Service. Each is bound by contractual terms (including data processing agreements where applicable) that require them to protect your data and use it only to provide their service to us. The current list includes:

  • Hosting and infrastructure (Amazon Web Services, Cloudflare, Railway): cloud hosting, file storage, content delivery, and bot protection.
  • Databases (InstantDB, Neon): real-time database powering accounts, boards, and collaboration, and managed PostgreSQL for scheduling and related data.
  • Payments and billing (Stripe): subscription billing and payment processing.
  • Email delivery (Loops): transactional and marketing email.
  • Analytics (PostHog, Google Analytics): usage analytics, feature flagging, and conversion measurement.
  • Affiliate program (FirstPromoter): tracking referrals and paying affiliates.
  • AI providers (via OpenRouter, an AI gateway): large language model providers used to power in-product AI features, together with web search (Tavily) and text-to-speech (ElevenLabs) used by specific AI features.
  • Social publishing (Ayrshare): when you connect a social account to schedule or publish, we share the post content and the credentials needed to publish on your behalf.
  • Customer support tooling (Intercom): tools we use to read and reply to your support messages.

For an up-to-date list of sub-processors, including any new additions, email [email protected].

b. Other users

If you share a board, invite collaborators, or make a board public, the people you share with can see the content and metadata of that board (including your handle and display name). Public boards may also appear in unauthenticated views.

c. Legal and safety

We may disclose information when we have a good-faith belief that doing so is necessary to comply with a law, regulation, legal process, or enforceable governmental request, to enforce our Terms, to detect or prevent fraud or abuse, or to protect the rights, property, or safety of Eden, our users, or the public.

d. Business transfers

If Eden is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you (for example, by email or a notice in the Service) before your information becomes subject to a different privacy policy.

7. Cookies and similar technologies

We use cookies and similar technologies for three purposes:

  • Essential. Sign-in sessions, security, and remembering your preferences. The Service does not work without these.
  • Analytics. Understanding how the product is used so we can improve it (PostHog).
  • Attribution. If you arrive through an affiliate link, we set a 60-day cookie via FirstPromoter so the right affiliate is credited if you subscribe.

You can clear or block cookies in your browser settings. If you block essential cookies, parts of the Service may stop working.

8. How long we keep information

We keep personal information for as long as your account is active and for a limited period afterwards so we can comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:

  • Account and content. Kept while your account exists. When you delete your account we delete or anonymize it within 30 days, except where we must retain it for legal or accounting reasons.
  • Billing records. Retained for as long as required by tax and accounting law (typically up to 7 years).
  • Server logs. Retained for up to 90 days for security and debugging, then deleted or aggregated.
  • Analytics data. Retained in aggregated or pseudonymized form for as long as it is useful for product analysis.
  • Backups. Encrypted backups may persist for up to 90 days after deletion before being overwritten.

9. How we protect information

We use standard, modern security practices to protect your information. This includes encryption in transit (TLS), encryption at rest for our primary databases and object storage, scoped access controls, audit logging, and regular review of who can access what.

No system is perfectly secure. If you believe your account has been compromised or you have found a security issue, email [email protected] and we will respond as quickly as we can.

10. Your rights and choices

Depending on where you live, you have the right to access, correct, delete, export, or restrict the processing of your personal information, and the right to object to certain processing. You also have the right to lodge a complaint with your local data protection authority.

You can exercise most of these rights yourself inside the Service:

  • Access and correction. Update your profile, email, and preferences in your account settings.
  • Export. Request a copy of your account data by emailing [email protected].
  • Deletion. Delete your account from your account settings, or email [email protected]. We will process the request as described in Section 8.
  • Marketing opt-out. Click unsubscribe in any marketing email.

For any other request, email [email protected]. We will verify your identity before responding and answer within the timeframes required by applicable law (typically 30 days).

For users in the European Economic Area, UK, and Switzerland

Our legal bases for processing your personal information are: (i) performance of our contract with you (to provide the Service), (ii) our legitimate interests (to operate, secure, and improve the Service, and to grow our business), (iii) your consent (where required, for example for certain cookies and marketing emails), and (iv) compliance with legal obligations.

For California residents

You have specific rights under the California Consumer Privacy Act (as amended by the CPRA), including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of any “sale” or “sharing” of personal information as those terms are defined under California law. We do not sell or share your personal information.

11. International data transfers

Eden is based in the United States and our infrastructure runs primarily in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. Our AI processing is likewise routed to providers in the United States or other jurisdictions with comparable safeguards. Where required, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) for such transfers.

12. Children

The Service is not directed to children under 16 and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, email [email protected] and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change, we will update the “Effective” date at the top and, where appropriate, give you additional notice (for example, by email or a notice in the Service) before the change takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.

14. How to contact us

For any privacy question or request, email [email protected]. For general support, email [email protected]. You can also write to us at the address in Section 1.

This policy is governed by the laws of the State of Delaware, USA.