Back to home PRIVACY & SECURITY

Your memory,
belongs only toYou。

A device that remembers reality should never have been built if privacy were bolted on afterwards. So the boundaries are fixed: raw video does not leave the device by default, decryption keys are not ours, and deleted means deleted.

Your device

Sensing and recognition all happen here
Raw footage Raw audio Precise location Facial features On-device model
END-TO-END ENCRYPTED

Cloud

Receives only the part you agreed to upload
Encrypted event summaries Your retrieval index Account and subscription
Local by default. Encrypted end to end. Yours to delete.
VISION · SENSE · SILENT

It has three states,
and you control the switch.

Not just on and off. Most of the time it sits in the middle mode, keeping only what is needed to decide whether this moment should be recorded at all.

VISION · full sensing

What should be kept
those few minutes.

Image, sound and space all come in. For the moments you genuinely want to keep — a child riding off for the first time, a meeting worth reviewing, a stretch of road you will want to see again.

SENSE · essential sensing

stops by default at
this tier.

Keeps only the minimum needed to judge whether a moment is worth recording. The vast majority of uneventful time passes in this mode without ever reaching long-term storage.

SILENT · sensing off

Press it,
means nothing at all.

One physical action: no capture, no cache, no judgement, and no software confirmation needed. It switches to this mode by itself when you enter a space you marked as private.

User control: physical switch · local first · revocable / deletable

NON-NEGOTIABLE

Six
the lines we will not cross.

These are not privacy-policy phrases but our own acceptance criteria. If one cannot be met, the feature does not ship. A long-term data product has to earn long-term trust first — the order cannot be reversed.

Local first

Face, voice and precise location recognition all happen on the device. Raw video does not leave it by default, and is never set to upload by default.

The keys are yours

Decryption keys are generated and held by your device. We do not have them, so we cannot read your content.

Visible, and stoppable

There is a clear indicator light when the device is working, and pausing takes one press — no menus involved.

Deleted means deleted

Deleting removes the original clip, the conclusions derived from it and the index entries, and backups are fully cleared within one cycle — not just flagged as hidden.

No training, no selling

Your memories never enter any model's training set, are never merged with other people's data, and are never sold. Our revenue comes from helping you own and use your own data, not from passing it on.

other people's boundaries

Other people can ask to be blurred or removed from your records. That is built into the device, not a paid extra.

WHERE THE DATA LIVES

what stays on the device and what goes up.

Rather than say we take privacy seriously, we would rather draw the boundaries. Below is the default state. You can tighten it; we will never loosen it on your behalf. The same line applies to third parties in health, mobility, home or work: they receive only the one capability you ticked, not your life's data.

Stays on the device

By default this content stays on your Earthory One and your phone.

  • Raw footage and raw audio
  • Face and voice signatures
  • GPS-level precise location traces
  • Intermediate inference from on-device models
  • Any moment you marked as on-device only

Uploaded only with your consent

Upload exists for multi-device sync and faster retrieval. Everything is encrypted with your key before it is transferred or stored.

  • Encrypted event summaries (who, where, what)
  • Encrypted retrieval index
  • Clips you chose to back up
  • Account, device and subscription details
  • Crash logs (no content, can be turned off)
WHAT WE ARE PROTECTING

What we want to hold on to
was exactly one of those afternoons.

Privacy sounds abstract, but it comes down to one thing: this footage belongs to the few people who were there, not to a server, and not to us.

DATA LIFECYCLE

A memory
goes through.

From being seen to being forgotten, you can interrupt at every step. This is the same pipeline as above, seen again from the privacy side.

Enters the buffer

Footage first enters a temporary buffer on the device and is not written to long-term storage. Press pause at this point and nothing is left behind.

On-device decision

A model on the device decides whether this moment is worth keeping. Most uneventful time is discarded right here, not filtered after upload.

Encryption and indexing

What is kept is encrypted on the device, turned into summaries and indexes that contain no original content, and only then may be uploaded.

Review and revoke

The App shows every access, and lets you revoke everything from one day, one place or one person in a single action.

Expiry and permanent deletion

Cleared automatically once your retention period is reached. A manual delete removes the original clip, the conclusions drawn from it and the index entries, and backups disappear entirely within one cycle.

QUESTIONS WE GET

A few questions you might have.

Can Earthory staff see my memories?

No. Keys are generated and held by your device, and the server stores ciphertext. Even with the entire store in hand, no one could turn it back into images or text. There is no “read user content” step anywhere in our support process.

What if someone else is captured?

A clear indicator light while recording is the first priority in the hardware design. Anyone can ask to be blurred or removed from your records, and that is built into the device. In private settings we also suggest you pause — pausing is made easy precisely so you never have to hesitate.

Will my data be used to train models, or sold?

Neither. Your memories never enter any model's training set, are never merged with other people's data, and are never sold. Your memory store grows only inside your own account — there is no opt-in, and no change of terms will alter it. We make money from hardware and subscriptions, not from passing your data on.

What happens to my data if I stop using Earthory?

You can export everything in a standard format and then close your account. Closing it deletes the ciphertext and indexes in the cloud, and cold backups are fully cleared within one backup cycle. Data on your own devices is yours to wipe, and we keep no recoverable copy.

If I connect a health app or a car system, how much can they see?

Only the one capability you ticked, at minimum permission. If you let a health app read exercise duration, exercise duration is all it gets — not the footage, location or conversation from that period. Permission can be revoked at any time, access ends immediately, and the history of past access stays in your audit log.

Would you comply with law enforcement requests?

We comply to the extent the law requires, but all we can provide is account information, because we do not hold the decryption keys. We publish regular transparency reports covering how many requests we received and how they were handled, and notify affected users where the law permits.

Want to try it?
Leave us your details.