Privacy policy
matic.sh is a software studio in New York, run by Johnnie Yu. This policy covers the matic.sh website and the apps we publish: Chromatic (chro.matic.sh), and the Even Realities G2 glasses apps Sapling, Perch, Seatback and Kiosk. It says what each one collects, why, where it is kept, who else receives it, and how to have it deleted.
In short: the glasses apps collect nothing about you, apart from Kiosk's anonymous feed counts. Chromatic keeps what it needs to run your assistant, encrypts your keys, does not log what you ask, and deletes idle conversations after 30 days. We do not sell data, show ads or use third-party analytics in any of them.
Who is responsible
matic.sh (Johnnie Yu), New York, United States, is responsible for the data described here. Contact: [email protected].
Chromatic
Chromatic is an assistant for Even Realities G2 glasses. You set it up at chro.matic.sh: you choose a model provider, add your own API key, write instructions, and connect MCP servers (services that give the assistant tools, such as a calendar or an issue tracker). You then ask it questions from your glasses, through Even AI or the Chromatic glasses app.
Signing in, including with Google
Sign-in is handled by Kinde (kinde.com), our authentication provider. You can sign in with Google or with an email code. When you sign in with Google, Google shares your basic profile with Kinde: your name, email address, profile picture and a Google account identifier. Chromatic reads only your email address and an account identifier from what Kinde sends, and stores nothing else from your profile. It uses them only to recognise your account, keep your settings together and, when needed, contact you about your account. We request no other Google data, and we do not access your Gmail, Drive, Calendar or any other Google service through your sign-in.
What Chromatic stores
| Data | Why | How it is kept |
|---|---|---|
| Your email address and an account identifier from Kinde | To recognise your account | Until you delete your account |
| Model provider API keys you add | To call the model you chose, on your behalf | Encrypted (AES-256-GCM). The key that decrypts them is stored separately from the database. Never shown again after you save it. |
| MCP server addresses and any access tokens you add | To call the tools you connected | Encrypted, as above |
| The list of tools each server offers (names and descriptions) | To show the model the right tools | Refreshed about every hour |
| Your instructions, model choice and skills | To shape every answer | Until you change or delete them |
| Your conversation: what you ask, the answers, and the tool calls and results needed to answer | So follow-up questions have context, and so an action waiting for your yes can run exactly as described | Deleted automatically after 30 days without use. Saying "new thread" deletes it at once. |
| Keys for Even AI and paired glasses apps | To let those clients reach your assistant | Only a one-way hash is stored. You can revoke them in the app. |
| Operational logs: request times, which account, token counts and errors | To run and fix the service | Our host's log retention. They do not contain what you ask or what the assistant answers. |
Who else receives data
- The model provider you choose (for example xAI or OpenAI) receives your instructions, your question, your recent conversation and tool results, so it can answer. You pay that provider directly with your own key, and its own privacy policy applies to what it receives.
- The MCP servers you connect receive the tool calls the assistant makes to them, such as a search or the details of an issue to create. Anything that would change something waits for your yes first.
- Kinde handles sign-in and holds your login details under its own policy.
- Railway (railway.com) hosts the service and its database in the United States.
- Even Realities carries your words between your glasses, phone and Chromatic when you use Even AI or the Chromatic glasses app. Its own policy covers that.
We share nothing else, and we do not sell or rent data to anyone.
Security
All traffic uses HTTPS. Secrets are encrypted at rest and bound to their account, and access keys are stored only as hashes. Access to the production systems is limited to the studio.
The glasses apps
These run inside the Even Realities app on your phone and draw on your Even Realities G2 glasses. None of them needs an account, and none uses analytics or ads.
- Sapling makes no network calls and collects no data. Your settings and your grove stay on your phone, inside the Even Realities app.
- Perch makes no network calls and collects no data. It reads the glasses' motion sensor to notice when you look up or sit still; those readings stay in memory on your phone and are never stored or sent. Your pets and their names stay on your phone.
- Seatback makes no network calls, asks for no permissions and reads no sensors. Your flights are stored only on your phone.
- Kiosk sends the feed addresses you add to Kiosk's feed server (kiosk-api.matic.sh), which fetches those feeds and returns their stories. The server keeps a count of how often each feed address is requested, with no IP address, device or anything else that could link a feed to you. Your feeds, what you have read and what you saved stay on your phone.
This website
matic.sh uses no cookies, no analytics and no tracking. Our hosting provider may keep short-lived technical logs of requests (such as the time, the page and the IP address) for security and operations.
Your choices and rights
- You can change or delete your instructions, skills, connections, model keys and access keys in Chromatic at any time.
- To delete your Chromatic account and everything stored with it, or to get a copy of your data, email [email protected] from the address you sign in with. We complete deletion within 30 days. Deleting the account removes your keys, connections, skills and conversations from our database.
- You can remove Chromatic's access to your Google account at any time at myaccount.google.com/permissions.
- Depending on where you live, you may have further rights, such as to correct your data or object to its use. Email us and we will help.
Children
Our apps are not directed at children under 13 (or under 16 in the European Economic Area), and we do not knowingly collect their data. If you believe a child has given us data, email us and we will delete it.
International transfers
We are based in the United States and our services run there. If you use them from elsewhere, your data is processed in the United States.
Changes
If this policy changes, we will update the date at the top. For a significant change to how Chromatic uses your data, we will tell signed-in users before it takes effect.
Contact
[email protected] · matic.sh, New York, United States