Legal

Privacy Policy

This policy explains how Ember processes personal data.

1. Controller

Geordan Gesink
Haesselackerstraße 3
69198 Schriesheim
Germany
Email: support@emberalarm.com

2. How Ember Handles Data

Ember is a wake-up alarm app for iOS and Android and includes this website. The core alarm and wake-up checks work without an account. Most app data starts on your device. Data reaches our backend or service providers when you use account, leaderboard, social, cloud-backup, purchase, restore, support, or website features that require it, or enable optional usage analytics or advertising measurement. When purchases are active or needed, the purchase service checks your current Ember Pro entitlement.

3. Website, Former Pre-release Access Records, and Contact

When you visit emberalarm.com, the website host processes connection data needed to deliver and protect the site. This can include your IP address, request time, requested URL, referrer if supplied, browser or user-agent information, response status, and security logs.

During Ember's pre-release access program, we processed the email address and locale submitted, optional answers about what Ember should help with and how the person heard about us, and ordinary request and abuse-prevention data such as request time and IP address. Supabase stored the access request, and Resend delivered the access code, secret magic-link token, and access or reminder emails. The program has ended: we no longer accept new or replacement access-code requests, issue new codes, or send access reminders. An access request did not create an Ember account.

Each code issued during the program is subject to its stated activation deadline. Activation by that deadline reserves First Light, Ember Pro without charge until April 1, 2027, and the lifetime-plan discount until the qualifying access is connected to an account. The token-based link can still connect a previously activated access when Apple or Google supplies an account email different from the request email. An unactivated code expires at its stated deadline and is not replaced. If you email support, we process your email address, message, and any information you choose to include so we can respond.

4. Data Stored on Your Device

Depending on the features you use, local app data includes:

Live wake-up sessions remain device-local. Other categories remain local unless they are used for leaderboard or social functions or are included in an enabled cloud backup.

5. Accounts, Cloud Backup, and Social Features

Ember uses Supabase for authentication, account data, cloud backup, and friend leaderboards. Registering creates a permanent account with an email address or an identifier supplied by a sign-in provider such as Apple or Google.

Cloud backup starts only after an account user enables it. Account users can pause syncing or exclude categories under Settings → Cloud Backup. Pausing retains the latest remote snapshot and stops new changes from uploading until syncing resumes. The separate Delete cloud backup action permanently removes the remote snapshot and wake-occurrence record. Disabling backup, Alarms backup, or Progress backup stops and removes the pending wake-occurrence checkpoint for the account. Ember retains an empty deletion marker linked to the backend user ID, with its deletion time and revision, so another signed-in device or older app version cannot recreate the deleted snapshot. The marker contains no backed-up content and is cleared when backup is explicitly enabled again or the account is deleted. Deleting the account also deletes the authentication user, verified phone, profile, friend records, scores, grants, contact-matching data, and the personal data and account-linked records of any associated former access request. A previously activated or claimed access credential remains reusable as described in Section 11.

6. Permissions, Camera, and Fitness Data

Ember requests permissions only for features that need them:

7. Purchases and Ember Pro

Apple or Google processes your Ember Pro transaction through the store account you use. We do not receive your full payment-card or bank-account details. The store provides transaction information needed to confirm the product, purchase, trial, renewal, cancellation, refund, and current entitlement status.

Ember uses RevenueCat to validate store transactions, keep Ember Pro access in sync, restore eligible purchases, and measure paywall-to-purchase conversion. The SDK starts when needed for a signed-in account, a pending paywall, an existing entitlement, or a store action. Signed-out purchase flows use a pseudonymous app-user identifier. If you are signed in, Ember uses your backend account ID as the RevenueCat App User ID so entitlement access can follow the account across devices. RevenueCat may then receive your account email, confirmed phone number, display name, locale, onboarding motivation, legacy access-program state, profile state, platform, app and build version, and a custom-paywall impression. It also processes transaction and receipt identifiers, product and entitlement details, subscription events, store and device technical information, IP address, and related diagnostic data. Ember does not send RevenueCat alarm schedules, challenge content, saved codes or vocabulary, passkeys, or wake history. RevenueCat does not receive your full payment details from Ember.

Our backend can receive a limited purchase-event summary from RevenueCat to reconcile purchases, refunds, and proceeds. It contains protected transaction and event references, product, store, currency, amounts, purchase dates, subscription status, and estimated store deductions. The purchase-ledger rows omit direct Ember account IDs, customer profiles, email addresses, and the full RevenueCat event payload. The planned verified purchase analytics described in Section 8 would use separate consent and delivery records to link eligible purchase events to a signed-in account and send limited summaries to PostHog. That forwarding is not active. The ledger does not send data to advertising platforms.

8. Technical and Diagnostic Data

When the app contacts Supabase or another required service, those services receive ordinary connection and operational data such as IP address, request time, endpoint, app or platform client information, response status, and error details. We use these limited logs for delivery, authentication, security, abuse prevention, and diagnosing service failures. The website uses Vercel Web Analytics and Speed Insights to measure aggregate visits and performance; Vercel may process route, browser, device, timing, IP-derived, and connection data for those services.

Optional usage analytics

From app version 1.2.0, Usage analytics lets you choose whether to send limited usage events to PostHog Cloud in the EU (Frankfurt). This is off by default. Declining does not affect alarms, checks, or paid access. You can change your choice in Settings → Usage analytics.

If you opt in, events record app openings, onboarding steps, the first saved alarm, paywall views, plan selections, purchase-flow outcomes, and completed wake-up checks with an outcome and duration range. They include event time, app and build version, platform, language, and a pseudonymous analytics identifier. When signed in, your account ID can link these events across sessions. We use them to understand where setup or purchases fail and whether people keep using Ember.

For signed-in users who enable Usage analytics, we also plan to register that choice with our backend. While that consent is active, verified purchase, trial, renewal, refund, and subscription-status summaries could be sent from our purchase system to PostHog in the EU and linked to the same Ember account ID as usage events. These summaries would include the product, offer, purchase status, event time, applicable amount and currency, and protected event or transaction references. They would help us understand purchases and continued use together. Our backend would retain a record of your choice and when it changed, linked to your account ID. This forwarding remains disabled for production purchases, including version 1.2.2.

We do not send PostHog your name, email, phone number, alarm schedule or label, saved codes, challenge content, free-form answers, precise location, or raw error messages. Session recording, automatic screen and interaction capture, and location enrichment are disabled. PostHog receives ordinary connection data, including the IP address needed to receive a request. Raw store receipts and payment-card details would not be sent to PostHog. Purchase validation and financial records needed for paid access would continue independently of optional analytics.

Turning Usage analytics off stops new events and discards events still queued on your device. For the planned purchase-summary forwarding, it would also request withdrawal of the backend purchase-analytics registration. That change requires a successful network connection; an offline choice cannot immediately stop events already being processed remotely. Turning analytics off does not delete events already received by PostHog. To request deletion of those records, contact support@emberalarm.com. Account deletion also stops analytics on that device and removes its account-linked backend consent registration; it does not automatically erase earlier PostHog records.

Optional advertising measurement — version 1.2.2

From version 1.2.2, Ember on iOS and Android uses AppsFlyer to understand which ads lead to installations, trials, and purchases. Its AppsFlyer and Meta connections are enabled. The following describes this version and test builds with advertising measurement enabled. Advertising measurement stays off until you explicitly allow it. This choice is separate from Usage analytics; declining does not affect alarms, checks, purchases, or paid access.

After permission, AppsFlyer receives installation and app-session events, installation, vendor, and customer identifiers, app and device technical data, connection data including IP address and the approximate location derived from it, and advertising identifiers where permitted. Technical data includes launch and battery information used for fraud prevention. These identifiers are pseudonymous personal data. We use this information to measure and improve Ember ads and prevent fraud. Alarm schedules, wake-up history, saved codes, and challenge content are not sent to AppsFlyer.

The RevenueCat-to-AppsFlyer connection is enabled for this release. With your advertising-measurement permission, RevenueCat links the AppsFlyer installation identifier to its customer record and sends purchase, trial, renewal, and refund information. This includes product and transaction references, amounts, currency, event times, its app-user identifier, available technical identifiers, and a hashed email address when available. A hash is a transformed identifier, not anonymous data. RevenueCat is the only sender of these financial events; the app does not send a second copy through AppsFlyer. The separate backend purchase summaries described in Section 7 remain outside this sharing route.

AppsFlyer shares permitted installation, session, and conversion data with Meta to measure and improve Ember ads. These notifications can include permitted device identifiers and purchases associated with other acquisition sources or no attributed ad. Meta Advanced Matching is off; this integration does not use hashed email for Meta Advanced Matching. The Reddit connection is inactive and receives no events through this integration. Direct partner sharing requires your advertising-measurement permission and, on iOS, Apple's tracking permission. Ember requests that system permission only after you allow measurement. If you decline Apple's permission, advertising identifiers and direct AppsFlyer event notifications to partners are disabled. Aggregate measurement through Apple's SKAdNetwork and AppsFlyer's privacy controls may still be available while your Ember measurement choice is on.

Turning Advertising measurement off in Settings stops further collection by the app and requests removal of the RevenueCat attribution link and exclusion of partner sharing. Server changes require a connection and successful synchronization; an offline choice cannot instantly stop events already being processed remotely. Turning it off or deleting an Ember account does not automatically erase earlier advertising records. The Settings deletion request prepares an email to support@emberalarm.com with the available AppsFlyer and RevenueCat identifiers retained on your device. You choose whether to send it. We handle that request with the relevant providers, including any earlier customer identifiers.

9. Purposes and Legal Bases

Where motion or step data qualifies as health data, processing for the walk feature relies on your explicit permission and consent under Art. 9(2)(a) GDPR. You can revoke the permission in device settings, although the walk feature will then stop working.

10. Service Providers and International Transfers

The following providers process data where needed or processed it for the former access program:

These providers act under their own terms and, where they process data on our behalf, are required to protect it consistently with this policy and applicable law. If personal data is processed outside the EEA, we rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses where required. Advertising measurement and sharing with Meta follow the release availability, separate permissions, and limits described in Section 8. We do not sell personal data to advertisers or data brokers.

11. Retention and Deletion

You can delete an Ember account in Settings → Account → Delete account. The deletion removes the live authentication record and cascades to the associated verified phone, contact-matching tokens, profile, friendships, friend-invite keys, leaderboard scores and wake-time records, grants, former access-request personal data and account-linked benefit records, and cloud snapshot. The global deleted-account count and, for a previously activated or claimed access code, its detached one-way verification values remain. The separate purchase and optional analytics records described above follow their own retention and deletion rules. Data stored only on the device remains there. Previously loaded non-wake leaderboard entries can remain temporarily in another participant's local offline cache until that app reconnects and refreshes or its data is cleared. Account deletion does not cancel a store subscription. Ember clears account profile attributes from the active RevenueCat customer, while Apple, Google, and RevenueCat may retain transaction records required for subscriptions, accounting, fraud prevention, or law. Full instructions and an email option are available on the account deletion page.

12. Your Rights

Under the GDPR, you have the right to:

Contact support@emberalarm.com to exercise these rights.

13. Security

We use encrypted transport, authentication, access controls, and database row-level security to protect backend data. No online service can be guaranteed completely secure, so keep your device and account credentials protected.

14. Changes to this Policy

We may update this policy when the product, providers, or legal requirements change. The current version and update date are published on this page. Purchase and subscription conditions are set out in our Terms of Use.

Last updated: October 6, 2026.