Ephesio

Privacy Notice

Your saved study content and report material are associated with your Ephesio account and are not made available to other users or the public. Ephesio saves this material for your account to restore your study; it does not maintain a public or shared report library. Downloadable PDFs are generated on demand rather than stored as separate PDF files. Service providers process relevant content to operate Ephesio, and the operator has technical access to stored records, as explained below.

Effective October 3, 2026 · Version 2026-10-03.2

Who operates the service

Ephesio is operated by Michael T. Cooper through Ephesiology. For privacy questions or requests concerning your information, email michael@ephesiology.com. This notice describes the Ephesio beta service, not the independent practices of other websites.

Information used and stored

We collect your email address for secure sign-in and study access. We store account identifiers, sign-in link and session records, document-version acceptances and dates, payment and coupon references, selected communities and purposes, saved study progress, responses, notes, team assessments, reflections, and generated report summaries. We also record AI request dates, model and response identifiers, study and user identifiers, token counts, request status, and estimated costs. The token ledger does not contain prompt or response text; study records may contain it separately.

Documents, browser storage, and cookies

When you attach a document, its text is extracted in your browser. Relevant extracted text and its filename are included in AI requests and may be saved with your study; the original file is not uploaded as an Ephesio stored file by this workflow. Draft study material is also saved in browser storage, and temporary checkout information may be saved in session storage. A secure session cookie maintains email sign-in for up to 30 days. Sign-in links expire after 15 minutes. Shared devices may expose locally saved drafts; sign out and clear local browser data when appropriate. Expiration prevents use of a link or session but does not itself delete its database record.

Why we use information

We use information to send sign-in links, verify access and payments, restore studies, generate AI responses and reports, provide support, prevent misuse, and compare AI processing costs with the study fee. Sign-in and service communications are necessary to operate your account. Agreement acceptance does not subscribe you to marketing.

Service providers

Study questions, earlier working responses, relevant extracted document text, notes, and reflections are sent to OpenAI for AI processing. Resend receives your email address and sign-in email for delivery. PayPal processes payments under its own policies; Ephesio stores transaction references and access status rather than your card number. OpenAI Sites and Cloudflare provide hosting and database infrastructure. Owner sign-in uses ChatGPT. Google Fonts receives ordinary connection information when fonts are loaded. Providers may process information in countries outside your country of residence under their own terms and privacy practices.

OpenAI processing and retention

Ephesio sends AI requests with response storage disabled. This does not mean zero retention: OpenAI’s published API policies describe separate abuse-monitoring logs that may retain content, ordinarily for up to 30 days, with exceptions. OpenAI states that API content is not used for model training by default unless the API customer opts in. Do not treat Ephesio as a confidential channel for sensitive information. See OpenAI’s current API data controls for details.

Access, security, and sharing

Authenticated study access is restricted to the account entitled to the study. The operator and authorized service providers may access records as needed for operation, support, security, or legal obligations. Owner usage panels are restricted to the owner account. Ephesio does not publish your saved studies automatically; you control any report copies you share. Technical safeguards reduce risk but cannot guarantee absolute security. We may disclose information when legally required or necessary to address misuse or protect rights and safety.

Retention and your choices

During the beta, saved study, account, payment, agreement, and usage records remain stored until removed; there is no automatic deletion schedule for these records. To request access, correction, or deletion, email michael@ephesiology.com from your registered address. We may verify your identity, and some records may need to be retained for accounting, security, legal obligations, or disputes. Removing a browser draft does not delete server records; removing a document from the current study does not necessarily remove earlier generated text or report copies. Third-party retention and copies already shared may remain subject to separate policies.

Updates

The notice version and date are displayed below. Material changes will require renewed acknowledgment before new study activity. Contact the operator if you need clarification before submitting information.

OpenAI API data controls

User Agreement · Return to Ephesio