Skip to content

Eaon Plan Privacy Policy

Effective September 5, 2026/Last updated September 5, 2026

Eaon Plan (“Eaon,” “we,” “us,” or “our”) provides access to artificial intelligence models, tools, APIs, and related services.

This Privacy Policy explains what information Eaon collects, how it is used, when information may be transmitted to other companies, how long it may be retained, and what choices you may have.

1. Scope

This Privacy Policy applies to Eaon's:

  • website;
  • applications;
  • accounts;
  • subscription services;
  • APIs;
  • AI chat and generation features;
  • account dashboards; and
  • related online services.

It does not govern independent websites or services operated by unrelated third parties.

2. Information You Provide

Account Information

When you create an Eaon account, we may collect:

  • email address;
  • username;
  • display name;
  • password or authentication information;
  • profile information;
  • account preferences; and
  • unique account identifiers.

Passwords should be stored using secure hashing or authentication systems rather than in readable form.

Authentication Information

If you sign in through another authentication provider, we may receive information such as:

  • email address;
  • name;
  • profile image; and
  • provider-specific account identifier.

We do not receive your password for a third-party authentication service.

3. Prompts and AI Content

When you use Eaon, we process content you provide, which may include:

  • prompts;
  • chat messages;
  • code;
  • documents;
  • images;
  • files;
  • tool instructions;
  • search queries;
  • system instructions; and
  • other submitted content.

We call this information “Input.”

We also process content returned by AI models, which we call “Output.”

Processing Input and Output is necessary to provide AI features.

4. Conversation History

If conversation history or cloud synchronization is enabled, Eaon may store conversations so that you can access them later.

Stored conversations may include:

  • Input;
  • Output;
  • selected model;
  • conversation title;
  • message timestamps;
  • attachments; and
  • related conversation metadata.

Eaon does not currently offer conversation history or cloud synchronization: Input and Output pass through to the model provider to generate a response and are not stored by Eaon. If Eaon introduces a feature that stores conversations, this section will be updated first, and retention for that feature will be disclosed here before it is enabled.

If Eaon offers temporary, incognito, or no-history conversations, any different retention rules will be presented for that feature.

5. How AI Requests Are Processed

Eaon uses external infrastructure to process AI requests.

When you submit a request, information necessary to process that request may pass through one or more inference, routing, networking, or hosting systems before reaching the applicable AI model.

Necessary request content may therefore be transmitted to:

  • inference infrastructure providers;
  • API-routing services;
  • AI model operators;
  • cloud infrastructure providers; and
  • related technical processors.

Only information reasonably necessary to provide the requested functionality should be transmitted.

6. Inference Usage Records

Infrastructure involved in processing AI requests may maintain operational records about requests.

These records may include:

  • model used;
  • input-token count;
  • output-token count;
  • cached-token usage;
  • request time;
  • request status;
  • latency;
  • estimated or actual request cost;
  • usage deducted;
  • source IP address;
  • error information; and
  • request identifiers.

Certain inference-routing infrastructure used by Eaon may process request content for forwarding without additionally retaining independent copies of conversation or code bodies after processing.

This does not necessarily mean every company in the processing chain follows the same retention policy.

The AI model that ultimately processes a request may be operated by another organization with its own processing and retention practices.

7. Device and Log Information

When you use Eaon, we may automatically receive technical information such as:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • application version;
  • date and time of access;
  • pages viewed;
  • referring URL;
  • error logs;
  • session information;
  • security events; and
  • approximate location derived from an IP address.

We use this information to operate, secure, and troubleshoot the Service.

8. Usage Information

Eaon may record information about your use of the Service, including:

  • models selected;
  • tokens consumed;
  • usage-window consumption;
  • feature usage;
  • tool calls;
  • requests made;
  • request results;
  • model latency;
  • errors;
  • API activity;
  • remaining plan allowance; and
  • estimated or actual resource consumption.

This information may be used for transparent usage reporting, billing, rate limits, capacity planning, security, and product improvement.

9. API Keys

If Eaon issues an API key, we may store:

  • a secure representation of the key;
  • key identifier;
  • creation date;
  • last-used date;
  • associated account;
  • permissions;
  • usage records; and
  • revocation status.

You are responsible for protecting your API keys.

Activity performed using your key may be associated with your account.

10. Payment Information

Subscription payments may be processed by a third-party payment processor.

Eaon may receive:

  • transaction identifier;
  • payment status;
  • subscription status;
  • amount;
  • currency;
  • billing country;
  • payment-method type;
  • renewal date;
  • refund information; and
  • limited billing information.

Eaon does not intend to store full credit-card numbers when payment processing is handled by a payment provider.

Payment processors may process payment information according to their own privacy policies and legal obligations.

11. Customer Support

If you contact Eaon, we may collect:

  • your contact information;
  • support messages;
  • screenshots;
  • attachments;
  • diagnostic information; and
  • information necessary to resolve your request.

12. How We Use Information

Eaon may use information to:

  • provide the Service;
  • create and maintain accounts;
  • authenticate users;
  • process AI requests;
  • provide conversation history;
  • provide API functionality;
  • calculate usage;
  • display transparent usage information;
  • enforce limits;
  • process subscriptions;
  • process refunds;
  • prevent fraud;
  • detect abuse;
  • secure accounts;
  • troubleshoot technical issues;
  • monitor Service reliability;
  • communicate with users;
  • respond to support requests;
  • comply with legal obligations;
  • enforce our Terms of Service; and
  • improve Eaon's reliability and functionality.

13. AI Training

Eaon does not use private user prompts, conversations, files, code, or AI responses to train an Eaon-owned general-purpose AI model unless the user has affirmatively chosen to participate in a feature that permits such use.

If we introduce optional training, research, or data-contribution programs, we will describe them separately and obtain consent where required.

Third-party model or infrastructure providers may have independent policies governing their processing of requests.

Eaon will not claim that a third party provides zero retention, no training, or equivalent protections unless Eaon has a reasonable basis for that representation.

14. Information We Share

Eaon does not sell personal information merely for monetary consideration.

We may disclose information to the following categories of recipients when necessary.

AI Model and Inference Providers

Request content and request metadata may be transmitted to services necessary to generate AI Output.

Hosting and Infrastructure Providers

Information may be processed by cloud hosting, database, networking, content-delivery, logging, or security providers that help operate Eaon.

Authentication Providers

If you use external authentication, relevant account information is processed by the authentication provider.

Payment Processors

Payment and transaction information is processed as necessary to manage subscriptions and payments.

Analytics Providers

Where enabled, analytics providers may receive information about visits, product interactions, device characteristics, and usage events.

We may preserve or disclose information where reasonably necessary to:

  • comply with applicable law;
  • respond to lawful legal process;
  • protect Eaon's legal rights;
  • investigate fraud;
  • investigate security incidents;
  • prevent abuse;
  • enforce our Terms; or
  • protect users and others.

15. Service Providers

Companies that process information on Eaon's behalf may only receive information reasonably necessary for their function.

Because Eaon's technical infrastructure may change, the specific processors used to provide the Service may change over time.

Where legally required, Eaon will provide additional information concerning relevant processors or categories of recipients.

16. Cookies and Local Storage

Eaon may use cookies, browser storage, and similar technologies for:

  • authentication;
  • session management;
  • account security;
  • preferences;
  • appearance settings;
  • fraud prevention;
  • analytics; and
  • Service functionality.

Where applicable law requires consent for non-essential cookies or analytics, Eaon will request it.

Blocking necessary cookies may prevent some Service features from functioning.

17. Analytics

Eaon may collect product-usage analytics to understand:

  • page visits;
  • feature usage;
  • signup flows;
  • conversion events;
  • errors;
  • performance; and
  • general usage patterns.

Where practical, we may use aggregated or de-identified analytics.

Where the GDPR, UK GDPR, or similar laws apply, Eaon may process personal information based on:

Contract

We process information necessary to provide the Service you request, including accounts, AI requests, subscriptions, and requested features.

Legitimate Interests

We may process information to:

  • secure the Service;
  • prevent abuse;
  • troubleshoot failures;
  • maintain infrastructure;
  • understand Service performance; and
  • improve reliability,

where those interests are not overridden by applicable privacy rights.

We rely on consent where required, including certain optional cookies, analytics, communications, or future voluntary data programs.

We may process information when required to comply with applicable law.

19. Retention

Eaon retains information only for as long as reasonably necessary for the purpose for which it was collected, subject to security, fraud-prevention, accounting, and legal obligations.

Account Information

Account information may generally be retained while your account remains active and for 30 days afterward.

Conversations

Eaon does not currently store conversation history, so there is nothing to retain. See Section 4.

API and Usage Records

Operational records such as model usage, token counts, timestamps, cost measurements, and API activity may be retained for up to 7 years, consistent with standard financial and tax recordkeeping practice.

Security Information

Security and abuse-prevention records may be retained for 12 months or longer where necessary to investigate abuse or defend against security threats.

Payment Records

Transaction and billing records may be retained for the period necessary to comply with:

  • accounting requirements;
  • tax law;
  • chargeback obligations;
  • fraud prevention; and
  • financial recordkeeping requirements.

Backups

Deleted information may remain in backups for a limited period until those backups are overwritten or expire.

20. Security

Eaon uses reasonable technical and organizational safeguards designed to protect information.

Measures may include:

  • encrypted HTTPS/TLS connections;
  • secure credential storage;
  • access controls;
  • authentication protections;
  • restricted administrative access;
  • logging and monitoring;
  • abuse detection;
  • credential rotation; and
  • vulnerability remediation.

No Internet service can guarantee absolute security.

21. Account and API-Key Responsibility

You should protect your login credentials and API keys.

Where Eaon permits API-key sharing, the account owner remains responsible for activity performed using that key.

You should not publish private API keys publicly.

If you believe a credential has been compromised, you should revoke or rotate it and contact Eaon where appropriate.

22. Your Privacy Rights

Depending on your jurisdiction, you may have rights to:

  • access personal information;
  • obtain information about processing;
  • correct inaccurate information;
  • request deletion;
  • obtain a portable copy of certain information;
  • object to certain processing;
  • restrict certain processing;
  • withdraw consent; and
  • appeal certain privacy decisions.

Requests may be sent to sanscreates@eaon.dev.

We may need to verify your identity before processing a request.

Certain information may be exempt from deletion or other requests when retention is legally permitted or required.

23. California and Other U.S. State Privacy Rights

Residents of certain U.S. states may have additional privacy rights, including rights to:

  • know what personal information is collected;
  • access it;
  • correct it;
  • delete it;
  • obtain a portable copy; and
  • opt out of certain forms of sale, sharing, or targeted advertising where applicable.

Eaon does not sell personal information for monetary consideration.

Eaon does not share personal information for cross-context behavioral advertising.

Eaon will not unlawfully discriminate against users for exercising applicable privacy rights.

24. International Processing

Eaon and its service providers may process information in countries different from the country in which you live.

These countries may have different privacy laws.

Where applicable law requires safeguards for international transfers, Eaon will use appropriate legal mechanisms.

25. Children and Minors

Eaon is not intended for children under 13.

A person under 13 may not create or use an Eaon account.

Users under 18 must have parental or guardian permission and supervision where required by applicable law.

Different jurisdictions may impose higher minimum ages or additional consent requirements.

If Eaon learns that it collected personal information from a child in violation of applicable law, we will take reasonable steps to delete that information.

A parent or guardian may contact sanscreates@eaon.dev regarding a minor's information.

26. Automated Decision-Making

Eaon may use automated systems for purposes such as:

  • fraud detection;
  • abuse detection;
  • rate limiting;
  • security monitoring; and
  • content-safety enforcement.

Where applicable law provides rights concerning solely automated decisions with significant legal or similar effects, Eaon will comply with those requirements.

27. Business Transfers

If Eaon is involved in a merger, acquisition, restructuring, financing, bankruptcy, sale of assets, or similar transaction, personal information may be transferred as part of that transaction subject to applicable law.

Eaon may link to external websites or services.

Eaon is not responsible for the independent privacy practices of unrelated third parties.

29. Changes to This Policy

We may update this Privacy Policy as Eaon, its infrastructure, or applicable law changes.

If changes are material, we will provide notice where required, such as through:

  • the Eaon website;
  • the Service;
  • account notifications; or
  • email.

The date at the top of this Policy indicates the most recent revision.

30. Contact

Questions, privacy requests, or concerns may be submitted to:

Eaon Plan / Eaon Privacy email: sanscreates@eaon.dev Billing email: sanscreates@eaon.dev Support email: sanscreates@eaon.dev Website: https://ai.eaon.dev Business email: sanscreates@eaon.dev

Where applicable, you may also have the right to lodge a complaint with the privacy or data-protection authority responsible for your jurisdiction.