Privacy Policy
Last updated 2 June 2026
Draft pending legal review. This is a templated document provided for the Ember beta. It is not legal advice and has not been reviewed by counsel. Sections in brackets (such as [COMPANY LEGAL NAME] and [JURISDICTION]) must be completed before this policy is relied upon.
This Privacy Policy explains what data Ember (operated by [COMPANY LEGAL NAME], the “Service”) collects, how we use and share it, and the choices you have. It applies to the Ember platform itself, not to the applications you build with it — for those applications you are the data controller and are responsible for any data they collect.
1. Data we collect
- Account data. Your email address and authentication metadata. We use passwordless magic-link and OAuth sign-in, so we do not store passwords for normal accounts.
- Generated code and project data. The prompts, specifications, pasted content, uploaded assets, generated code, and stored project data for your projects.
- Secrets you provide. API keys and configuration you add to a project, stored so we can deliver them to your deployments. They are not shown back in full and are not used for any other purpose.
- Usage and metering data. Records of generation, build, and deployment activity, model token usage, and computed cost, used to meter your credit balance.
- Payment information. If and when paid billing is offered, payment details are collected and processed by our payment processor; we do not store full card numbers.
- Cookies and auth tokens. Cookies and browser storage necessary to keep you signed in and operate the Service.
- Technical data. IP address and request metadata, used for security, rate limiting, and abuse prevention.
2. How we use data
- To provide the Service: generate code, run sandboxed preview environments, deploy your apps, and operate your account.
- To meter usage and manage your credit balance and any billing.
- To secure the Service, enforce limits, and detect or prevent abuse.
- To maintain and improve the Service, including diagnosing problems and improving reliability and quality.
- To communicate with you about your account, access, or important changes.
- To comply with legal obligations and enforce our Terms.
3. AI processing
To generate and iterate on code, your prompts, specifications, and relevant project files are sent to our AI model providers for processing. We do not sell your data, and we do not use your private project content to train our own models.
4. Third-party processors
We share data with service providers strictly to operate the Service. They process data on our behalf under their own terms and security commitments. The categories of processors include:
- Cloud hosting and compute — to run the platform, sandboxed containers, and your deployments.
- Database and authentication — to store account, project, and metering data and to manage sign-in.
- AI model providers — to perform code generation and iteration.
- Email — to send sign-in links and account and service notices.
- Payments — where applicable, to process paid billing.
- Analytics and error monitoring — to understand usage and diagnose problems.
5. Data retention
We keep your account and project data for as long as your account is active or as needed to provide the Service. During the beta, projects, preview environments, and associated data may be deleted as part of normal operation or cleanup. We retain limited usage, billing, and audit records as needed for security, accounting, and legal purposes, after which they are deleted or anonymized.
6. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. We provide self-service or on-request export and deletion of your account and associated data, including to satisfy GDPR access, portability, and erasure requests. To exercise these rights, email support@emberstudio.app and we will respond within the time required by applicable law. You may also have the right to lodge a complaint with your local data-protection authority.
7. Cookies and local storage
We use cookies and browser storage that are necessary to keep you signed in and to operate the Service, and limited cookies for analytics. We do not use advertising or third-party tracking cookies.
8. Security
We use industry-standard measures to protect data, including access controls, encryption in transit, per-project sandbox isolation, and a static safety gate on generated code. No system is perfectly secure, and you are responsible for safeguarding your own credentials and the apps you deploy.
9. International transfers
We and our processors may store and process data in countries other than the one in which you live, including [JURISDICTION] and other countries where our providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.
10. Children
The Service is not directed to children and is intended for users 18 and older, and in any case not for anyone under 13 (or under 16 where a higher age applies). We do not knowingly collect data from children; if we learn that we have, we will delete it.
11. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by the “last updated” date above and, where appropriate, by additional notice.
12. Contact
For privacy questions or requests, contact support@emberstudio.app.
Questions? Email support@emberstudio.app.