What we keep,
and what we do not
The short version: we keep an email address, and whatever you chose to pay. We do not keep a record of who watched the Monday hour, and we never sell anything to anyone.
What we collect, and why
- Your email address. So we can send you the Monday link and sign you in. This is the only thing we actually need.
- Your first name, if you gave it. Only so the emails do not open with "Hello,". It is optional and it stays optional.
- When and where you agreed. A timestamp and the page the form was on. We are required to be able to show that you asked for the emails.
- Your membership status, if you have one. Whether Go Deeper is active, and when the period ends.
- Donations. The amount and the date. Deliberately not linked to your account. See below.
- What you kept. If you press "Keep this" on an article or a product, we store the address of that page and the date. Not what you read, not how long for, and not what you opened and did not keep.
- What you wrote. Reflections you type into your own space, exactly as you wrote them. Nobody at Ethos reads them, they are never used to decide what to show you, and they are not sent to the guide or to any other service. They are the most personal thing on this site and they are treated that way.
- Which circles you asked about. A waiting list, so we can tell you once when a circle opens.
What we deliberately do not collect
This part matters more than the list above, because it is the promise the Monday hour rests on.
- No record of who watched. There is no viewer table in our database. The endpoint the player calls performs no write at all, and the player sends no heartbeat, no watch time and no presence signal.
- No viewer list or count in the room. The player has no such feature. Cloudflare bills us per minute delivered, so we can see a total number of minutes in a billing dashboard, never who they belonged to.
- No record of who watched. Worth saying twice: the measurement below never touches the Monday hour.
- No card details. Stripe handles payment and we never see the number.
- No donor ledger. A donation is not joined to your account. We cannot tell you what you gave, because we did not write it next to your name.
Measurement
We count pages. We do not follow people. There is no cookie banner on this site because there is nothing here to consent to. That is a design decision, not an oversight.
How it is set up:
- No analytics cookies. Consent for advertising and analytics storage is set to denied before any tag loads, and we leave it denied. Nothing is written to your browser for measurement.
- No advertising or remarketing pixels. No Meta pixel, no ad network, nothing that recognises you on another website.
- It never touches the Monday hour. No measurement reports who watched, for how long, or whether they stayed. The live page is counted as a page, never as an audience.
- What we do see: how many visits a page had, roughly where they came from, and whether people who saw the sign-up form used it. Nothing that identifies you.
We use Google Tag Manager to load this. It is a loader, not a tracker, and everything we load through it has to work without cookies, or it does not go in.
If you would rather not be counted at all, any tracker blocker stops it, and nothing on the site breaks when you do.
Cookies
One cookie, and only after you sign in. It holds a signed session identifier so the site knows you signed in. It cannot be read by JavaScript, it expires after sixty days, and there is no cookie banner because there is nothing to consent to beyond the thing you asked for.
The guide
When you ask the guide a question, the question and the passages it retrieved from our own pages are sent to a language model running on Cloudflare's network. It is not sent to OpenAI, to Anthropic, or to anybody else, and it is not used to train anything.
We do not store your question. There is no log of what people asked, no history attached to your account, and the guide has no memory between questions, so it cannot build a picture of you across a session.
Your reflections are never sent to it. Nothing you write in your own space is ever part of what the guide reads.
It is rate limited by IP address, held in a temporary store for an hour. That is the only thing about the request that touches your network address, and it is not joined to your account.
Who else touches it
- Cloudflare: hosting, the database, and the video. Standard server logs, kept briefly.
- Resend: sends the emails.
- Stripe: takes the payments and holds the payment data under its own policy.
- Google: Tag Manager, and the measurement tools loaded through it.
That is the whole list. Nobody buys data from us, because we do not sell it, and we would not be interested in an offer.
How long we keep it
- Sign-in links: fifteen minutes, then deleted. They also delete themselves the moment they are used.
- Your account: until you ask us to remove it.
- If you unsubscribe: we keep the address marked as unsubscribed, so that we do not accidentally email you again. Ask and we will delete it outright instead.
- Payment records: as long as accounting law requires, which is longer than we would otherwise keep anything.
Your rights
You can delete everything yourself. There is a button in your own space marked "Delete everything". It removes your account, everything you kept, everything you wrote, your sign-in links and your subscription record, immediately. No waiting period, no copy kept for us, and nothing to explain. If you pay for a membership, cancel it in Stripe first, or you will keep paying for a door that no longer opens.
If you are in the EU or the UK, you can also ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to us using it. Write to us and we will do it. There is no form and we will not ask why.
You can also complain to your data protection authority. In Denmark that is Datatilsynet.
Changes
If this page changes in a way that matters, we will say so at a Monday Service and in the members' news. We will not quietly edit it and hope nobody re-reads it.
Ask us anything
Write to [email protected] and a person will answer.
Data controller: ETHOS ApS, Gl. Kongevej 1, Copenhagen. The CVR number is not yet listed here and has to be before launch. This page has also not been read by a lawyer.