Privacy Policy

Effective Date: February 25, 2026

Last Updated: February 25, 2026

Your privacy matters to us. This Privacy Policy explains how Eonest ("Company," "we," "us," or "our") collects, uses, discloses, retains, and protects your personal information when you use Eonest Sheets and our related services, applications, and websites (collectively, the "Service"). It also describes your rights and choices regarding your information.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

1. Information We Collect

We collect information in the following ways:

1.1 Information You Provide Directly

  • Account Information: Name, email address, password (hashed), and organizational affiliation when you register for an account.
  • Profile Information: Display name, profile photo, job title, and preferences you choose to share.
  • Content: Data, files, spreadsheets, text, and other materials you create, upload, or share through the Service ("User Content").
  • Communications: Messages you send to us for support, feedback, or other inquiries, and communications with other users through the Service.
  • Payment Information: Billing name, billing address, and payment method details. Payment card information is collected and processed by our third-party payment processor and is not stored on our servers.
  • Feedback: Ratings, reviews, suggestions, and other feedback you provide about the Service.

1.2 Information Collected Automatically

  • Usage Data: Information about how you interact with the Service, including features used, actions taken, timestamps, frequency and duration of use, and crash reports.
  • Device Information: Device type, operating system, browser type and version, unique device identifiers, and screen resolution.
  • Log Data: IP address, access times, pages viewed, referring URLs, and other standard server log information.
  • Cookies and Similar Technologies: We use cookies, pixels, web beacons, and similar technologies to collect information about your browsing activity. See Section 8 (Cookies and Tracking Technologies) for more detail.

1.3 Information from Third Parties

  • Single Sign-On Providers: If you sign in using a third-party authentication provider (e.g., Google, Microsoft), we receive your name, email address, and profile photo from that provider.
  • Integrations: If you connect the Service to third-party applications, we may receive data from those applications as needed to provide the integration features.
  • Business Partners: We may receive information from partners who help us provide or promote the Service.

2. How We Use Your Information

We use your information for the following purposes:

Category of Data Examples Purpose
Account & Service Delivery Name, email, content, usage data Provide, operate, and maintain the Service; authenticate users; process transactions
AI Features & Analysis User Content, usage patterns Power AI-generated insights, analysis, and recommendations within the Service
Service Improvement Usage data, feedback, crash reports Analyze trends, diagnose technical issues, and improve the Service
Model Training (Opt-In) De-identified Content, feedback Improve AI model quality and accuracy, subject to your opt-out right (see Section 5)
Safety & Security All categories as necessary Detect and prevent fraud, abuse, security threats, and enforce our Terms
Communications Name, email, preferences Send service notifications, updates, support responses, and (with consent) marketing
Legal Compliance All categories as necessary Comply with legal obligations, respond to lawful requests, and enforce our rights

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following limited circumstances:

3.1 Service Providers

We share information with trusted third-party service providers who perform services on our behalf, such as hosting, payment processing, analytics, email delivery, and customer support. These providers are contractually bound to use your information only as necessary to provide their services to us and are required to maintain appropriate security measures.

3.2 Collaboration and Sharing Features

When you use the Service's collaboration features—such as sharing a spreadsheet or inviting a team member—other users you authorize may see your name, email address, and the content you choose to share.

3.3 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or governmental request. We may also disclose information if we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, investigate fraud, or respond to a government request.

3.4 Business Transfers

In connection with any merger, acquisition, financing, sale of company assets, or transition of service to another provider, your information may be transferred as part of such a transaction. We will notify you via email or prominent notice on the Service before your information becomes subject to a different privacy policy.

3.5 With Your Consent

We may share your information for any other purpose with your explicit consent.

3.6 Aggregated or De-Identified Data

We may share aggregated or de-identified data that cannot reasonably be used to identify you for any purpose, including industry analysis, research, and marketing.

4. Data Security

We implement and maintain industry-standard technical, administrative, and organizational security measures designed to protect your information from unauthorized access, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest (AES-256 or equivalent).
  • Multi-factor authentication options for account access.
  • Role-based access controls limiting employee access to personal information on a need-to-know basis.
  • Regular security assessments, penetration testing, and vulnerability scanning.
  • Incident response procedures and breach notification protocols.
  • Employee security awareness training and background checks for personnel with access to personal data.

While we strive to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk.

5. AI, Model Training, and Your Choices

5.1 How AI Features Use Your Data

Our AI features process your User Content to generate analyses, insights, and recommendations. This processing is integral to providing the Service.

5.2 Model Training Opt-Out

We may use de-identified or aggregated User Content and Feedback to train and improve our AI models. You may opt out of having your Content used for model training at any time through your account settings (Settings > Privacy > Model Training). If you opt out:

  • New content you create will not be used for future model training.
  • Content already incorporated into trained models cannot be removed retroactively, but we will stop using your stored content in future training runs.

5.3 Safety and Trust Exceptions

Even if you opt out of model training, we may use Content that has been flagged for trust and safety review to improve our systems for detecting harmful content, enforcing our policies, and advancing safety research. We use automated processes to filter or de-identify sensitive data in these cases.

6. Data Retention

We retain your personal information for as long as your account is active or as necessary to provide the Service, fulfill the purposes described in this Privacy Policy, and comply with our legal obligations. Specific retention practices include:

  • Account Information: Retained for the duration of your account and for up to 30 days after account deletion to allow for reactivation, unless a longer retention period is required by law.
  • User Content: Retained while your account is active. If you delete specific content, it will be removed from active systems within 30 days, although it may persist in backups for up to 90 days.
  • Usage and Log Data: Generally retained for up to 24 months for analytics and security purposes, then aggregated or deleted.
  • Payment Records: Retained as required by applicable tax and financial regulations.

When retention is no longer necessary, we will securely delete or de-identify your information.

7. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

7.1 Access and Portability

You may request a copy of the personal information we hold about you in a structured, commonly used, and machine-readable format.

7.2 Correction

You may request that we correct inaccurate or incomplete personal information. You can also update most account information directly through your account settings.

7.3 Deletion

You may request that we delete your personal information. We will comply with your request subject to certain exceptions, such as when retention is necessary to comply with legal obligations or to resolve disputes.

7.4 Restriction and Objection

You may request that we restrict or stop processing your personal information in certain circumstances.

7.5 Opt-Out of Marketing

You can opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by updating your preferences in your account settings. Note that you may continue to receive transactional or service-related communications.

7.6 Do Not Track

Some browsers transmit "Do Not Track" signals. We currently do not respond to such signals, but we respect your cookie preferences as described in Section 8.

7.7 How to Exercise Your Rights

To exercise any of the above rights, please contact us at [email protected]. We will respond to your request within 30 days (or such shorter period as required by applicable law). We may request verification of your identity before processing your request.

8. Cookies and Tracking Technologies

8.1 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function, such as session management and authentication. These cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with the Service, allowing us to improve functionality and performance.
  • Preference Cookies: Remember your settings and choices, such as language and display preferences.
  • Marketing Cookies: Used to deliver relevant advertising and measure the effectiveness of marketing campaigns. These are only used with your consent.

8.2 Managing Cookies

You can manage your cookie preferences through the cookie settings banner presented when you first visit the Service, or at any time through your browser settings. Disabling certain cookies may affect the functionality of the Service.

9. Children's Privacy

The Service is not intended for or directed at children under the age of 13 (or such higher age as required by applicable law). We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information promptly. If you believe we may have collected information from a child under 13, please contact us at [email protected].

10. International Data Transfers

Your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. If you access the Service from outside the United States, you understand and consent to the transfer of your information to the United States, which may have different data protection laws than your jurisdiction. We take appropriate safeguards to ensure that your information is protected in accordance with this Privacy Policy.

11. U.S. State Privacy Rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another U.S. state with applicable consumer privacy legislation, you may have additional rights under those laws, including:

  • Right to Know: Request details about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: We do not sell your personal information. If this practice changes, we will provide a mechanism for you to opt out.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, please contact us at [email protected] or use the methods described in Section 7.7. You may also designate an authorized agent to exercise these rights on your behalf.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will provide notice by posting the updated policy on our website, sending you an email, or displaying a prominent notice within the Service at least 30 days before the changes take effect. We encourage you to review this Privacy Policy periodically. The "Last Updated" date at the top indicates when the policy was most recently revised.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Eonest – Privacy Team
7111 Woodmont Ave
Bethesda, MD 20815, United States

Email: [email protected]
General Support: [email protected]

For data subject access requests or privacy complaints, we aim to respond within 30 days.

© 2026 Eonest. All rights reserved.