Asking for Less.

Even Insider

Welcome back to the Even Insider.

Every device makes the same proposal. It offers to do something for you, and in exchange it asks for something about you. For most of the past two decades that exchange has moved in a single direction. Each generation of software has been a little more capable and a little more curious, until the two became difficult to separate, and a product that wanted to know less began to sound like a product that could do less.

Glasses raise the stakes of that proposal, because glasses are not something you pick up. They are something you have on. They are present for the meeting, the clinic, the dinner and the argument, and they are present for everyone else in the room, none of whom agreed to anything at all.

So the question we had to answer before we designed anything was not how much a pair of glasses could learn about the person wearing them. It was how little it needed to.

Our answer has three parts, and this entry is all three. The product works without knowing you, which is a property of the software rather than a promise about our intentions. Where context genuinely makes it better, and it does, it should be something you hand over deliberately rather than something we assemble quietly. What we hold at all should be small enough to publish as a list, which is what we are doing here.

It already works without knowing you.

Every feature runs on what is in front of it.

Conversate works from the conversation happening in the room, plus whatever brief you chose to hand it before you walked in. Translate needs the sentence being spoken, not the last thousand you said. Teleprompt needs the script you wrote. Navigate needs where you are going. An Even Hub app borrows a corner of your vision and gives it back when you close it.

The consequence is that an account opened this morning behaves exactly like one that has been worn every day since Even G2 shipped. There is no warm-up period, and nothing about you has to accumulate before the product becomes good. This is not a position we are taking. It is a description of how the software is built, and it is visible from the first session.

We should be equally clear about the other half, because pretending otherwise would be the easier and less honest thing to write. Context does make this better. Sharper recognition, answers that land closer to what was meant, less repeating yourself to a device that should have understood the first time. That work is underway, and it is among the most interesting work we do.

The distinction that matters is not how much context. It is where context comes from.
Prep Notes is the shipped example. Before a meeting you hand Conversate a brief - the deck, the terms, the names you keep mispronouncing - and for that session it reads the room through that document. The exchange is legible in both directions. You know exactly what you gave and exactly what came back, and when the session ends, so does the arrangement.

The other kind of context is a profile that accumulates in the background, assembled from whatever happened near a device, on the theory that it may prove valuable later. That is the one we are not building. The reason is not only principle. For the situations Even G2 is actually for, the first kind works better. A brief you chose beats a year of inference about what you might have meant.

Underneath the product sits a business that does not require the second kind either. We do not build advertising profiles from your device data, sell or rent it, or use it to target ads. Our customer is the person who bought the glasses and is wearing them, not an advertiser or another company paying for access to that person. A company whose revenue depends on knowing more about you every year will eventually find reasons to know more about you every year. We would rather not have those reasons.

That produces the practical consequence, and it is the reason this section comes first. The baseline needs nothing. The context you do give has one job and no second life. Send us a session, a transcript or a log to get something fixed, and it goes to a company with nothing else to do with it. That is what safe means here - structural rather than sentimental, and the only version of the claim worth making.

What we do hold, and where it lives.

It would not be honest to claim we hold nothing. We hold a little, and the useful thing to publish is not a reassurance but an inventory.

Your account. The email you signed up with, your paired devices, and what you own. This is what allows the glasses, the ring and the phone to behave as one system, and what returns your apps to you when you replace your phone.

What you hand a feature, while that feature is running. The audio of the sentence being translated. The brief uploaded as Prep Notes. A feature cannot translate a sentence it has not been given. This is transient and scoped to the session, and context files live in a siloed environment for the life of that session rather than beyond it.

What stays on your phone. The transcripts, the history, the durable record of what was said. Even G2 is deliberately thin, a display and a set of sensors, because compute is heat, weight and battery, and something resting on your nose can spare none of the three. The thinking happens on the computer already in your pocket, and processing begins locally wherever it can. That engineering decision has a consequence nobody set out to design: the record of your days sits on hardware you own.

One line of precision, because this is the part most easily misread. Audio does travel in order to be transcribed and translated. What stays local is the record. Those are two different claims and we would rather draw the line exactly than round it off in our own favor.

Numbers, not sentences. That an app launched, how long it ran, which firmware version it ran on, whether it crashed. This is how a fault surfaces before anyone has to write in and report it, how we decide what to build next from what is actually used rather than what we assume, and how a developer learns whether anyone kept their app. It is anonymized and aggregate. It records that a session happened, never what was said inside it. Developer dashboards run on hashed identifiers, and private and beta builds are excluded from them entirely.

The ceiling is the point: enough to know what is affecting the experience and what would improve it, and nothing beyond that. We can see that Translate sessions on a particular firmware version end early. We cannot see who was translating what. That limit is a constraint on how the instrumentation was built, not a policy applied to it afterwards.

None of this has to be taken on faith, because the same inventory exists inside the product.

There is a Privacy page in Settings, and the list above is on it. Health Data, Cloud Backup, AI Memory and Usage Data Sharing are separated into individual controls, each with its own switch and each requiring its own decision - not a single agreement collected once at signup and pointed to forever after. Cloud features are optional. Consent can be withdrawn, backups managed, and cloud data deleted.

We will put it more plainly than a company is generally supposed to. If you do not need anything syncing between your devices and your account, turn all of it off. The core features remain available. That is the first section of this entry made operable, and switching everything off and watching nothing break is faster proof than any paragraph we could write.

What we do hold is protected with encryption, role-based access, least privilege and multi-factor authentication. Nothing said through Conversate and nothing uploaded as context is used to train our models. Third-party Even Hub apps run sandboxed and do not inherit the core app's permissions - an app that wants the microphone or the network has to declare it, and you have to grant it, before it runs.

As stated in our Privacy Policy, our servers are currently located in the Netherlands, where we use secure infrastructure (GCP) to host and protect our users' data. We handle that data in accordance with GDPR requirements and data protection standards. We have roots in Shenzhen, and this is a question people are often too polite to ask us directly, so we would rather answer it here.

Why the line sits where it does.

Every decision described so far descends from a single asymmetry.

The person wearing the device has the knowledge, the control and the benefit. Everyone else in the room carries whatever risk exists, without having chosen it, and frequently without knowing there was a choice to be made. That imbalance is the reason the default has to be collect nothing, with everything beyond it required to earn its place.

It is also why Even G2 has no camera. That was not a response to regulation and not a reaction to any backlash - the decision was made at the founding of this company, before either existed. We design for the wearer, not the viewer. Because there is no camera lens, there is no question about whether anyone is being filmed, and the person across the table never has to work it out. An entire category of features was given up to keep that true, and we would make the same trade again.

The prevailing answer elsewhere is a small recording light, and we think that model is backwards. A light can be obscured. Even working perfectly, it reports only that recording has already started. It places the burden on the person with the least power in the exchange: notice the indicator, understand what it means, object. A safeguard that functions only when the person with less power notices and objects is not a safeguard. It is a default in the wrong place.

Nor can any of this rest on individuals behaving well. No company controls every person who uses its product, but every company is answerable for what its product predictably enables. A safeguard that requires every wearer to be thoughtful is not sufficient. Predictable misuse is a design input, not a public relations surprise.

Wherever a promise can be turned into something a person can press, we turn it into one. The Privacy page and its separate controls. The permission prompt an Even Hub app has to clear before it reaches a microphone. Bring Your Own Agent, which is the furthest version of the same instinct - for anyone unwilling to trust a cloud, including ours, the glasses can be routed to a model running on your own hardware, bypassing our infrastructure entirely. We built the exit from our own product deliberately.

Beneath all of it sits one standard, applied identically to information from customers, employees, partners and developers. Why is this information needed. Who should have access to it. How long should it be kept. A company organized around privacy does not begin by collecting everything and promising to behave well afterwards. It begins by asking whether it needs the information at all.

The test is not only whether a data flow would be acceptable to the person wearing the glasses. It is whether it would be acceptable to the person sitting across from them, who opted into nothing and cannot see a settings page. Even G2 should be trusted by the people around you, not only by you.

What's Next?

Read as a list, everything here looks like something surrendered. A camera. A data pipeline. A set of features that would have been straightforward to build, and that other people have already built.

We read it the other way. Capability can be added in a firmware update. Trust cannot. It accumulates slowly and is spent quickly. A device you are able to forget you are wearing, and that the room is able to forget you are wearing, is not a diminished version of the product. It is the product. The measure that interests us is not how much more the glasses can do. It is how much more they can do while asking for less.

Which leaves one question standing, and it is the one that arrives immediately after this one. If the glasses are built not to accumulate you, what happens to the things you actually want them to hold on to?

That is the next entry. AI Memory is one of the four switches on that Privacy page, and it deserves more than a switch and a sentence. We will get into what a device should remember, where that memory should live, and why those two questions turn out to have a single answer.