1. Controller
Geordan GesinkHaesselackerstraße 3
69198 Schriesheim
Germany
Email: support@emberalarm.com
2. How Ember Handles Data
Ember is a wake-up alarm app for iOS and Android and includes this website. The core alarm and wake-up checks work without an account. Most app data starts on your device. Data reaches our backend or service providers when you use account, leaderboard, social, cloud-backup, purchase, restore, support, or website features that require it. When purchases are active or needed, the purchase service checks your current Ember Pro entitlement.
- No account is required for the core alarm and challenge features.
- The Ember app does not contain advertising SDKs or third-party behavioral analytics SDKs, and we do not sell personal data.
- Permissions and cloud-backup categories can be managed in Ember and in your device settings.
3. Website, Private Beta Access Requests, and Contact
When you visit emberalarm.com, the website host processes connection data needed to deliver and protect the site. This can include your IP address, request time, requested URL, referrer if supplied, browser or user-agent information, response status, and security logs.
If you request private-beta access, we process the email address and locale you submit, your optional answers about what you hope Ember helps with and how you heard about us, and ordinary request and abuse-prevention data such as request time and IP address. Supabase stores the access request. Resend immediately sends an access code, a secret magic-link token, and beta access by email. While the code remains unactivated, we may send up to two reminder emails. Requesting access does not create an Ember account.
Each access code has an activation deadline. Activating it in Ember before that deadline reserves the access request, First Light, six free months at launch, and the lifetime-plan discount until the tester creates or signs in to an account. This token-based link also works when Apple or Google supplies an account email different from the request email. A code that is not activated by its deadline expires; the same email address can then request and immediately receive new credentials. If you email support, we process your email address, message, and any information you choose to include so we can respond.
4. Data Stored on Your Device
Depending on the features you use, local app data includes:
- alarms, labels, schedules, skip dates, and wake-up check settings
- saved barcode or QR values and vocabulary pairs
- preferences, motivation, equipped and unlocked embers, and an optional emergency-override passkey
- wake-up history, streaks, scores, completion times, alarm counts, and lifetime achievement totals such as aggregate walk-check steps
- a random app-installation ID and random IDs for completed wake-up sessions, generated by Ember solely to merge offline progress without counting it twice; these values contain no hardware or operating-system device identifier
- the display name and handle associated with a registered account
- the active wake-up session and temporary alarm state
Live wake-up sessions remain device-local. Other categories remain local unless they are used for leaderboard or social functions or are included in an enabled cloud backup.
5. Accounts, Cloud Backup, and Social Features
Ember uses Supabase for authentication, account data, cloud backup, and friend leaderboards. Registering creates a permanent account with an email address or an identifier supplied by a sign-in provider such as Apple or Google.
- Profile: backend user ID, editable display name, system-generated random handle, and creation or update timestamps. The handle cannot be edited.
- Optional verified phone:you can add a phone number to your account for contact matching. Supabase Auth and Twilio, our SMS delivery provider, process the number and one-time verification code. Once verified, the number is linked to your backend user ID. It is not required for Ember's core alarm features.
- Social graph: outgoing and incoming friend requests, accepted friend relationships, and response timestamps. Your display name and handle can be visible to people involved in a friend request. Accepted friends can also see your rank. Disabling contact matching does not remove existing friendships. If you remove a friend, Ember retains a pair-specific suppression record so automatic contact matching does not recreate that relationship.
- Optional contact matching:after you consent and grant address-book access, Ember reads only contact phone-number fields. On your device, it normalizes them to E.164 format and hashes them with SHA-256. No contact names, email addresses, postal addresses, or raw address-book phone numbers are uploaded. The backend protects stored matching tokens with a server-keyed HMAC rather than storing the device-generated SHA-256 values. These tokens are linked to your backend user ID and app installation. They are pseudonymous personal data, not anonymous data. Ember uses them only to create a friend connection when both account holders have enabled contact matching and each has the other's verified phone number in their address book. They are not used to contact non-users, advertise, or track you.
- Leaderboard: local calendar date, daily total score, scored-session count, and best session score. Accepted friends can see the ranks calculated from these records.
- Optional wake-time ranking:this is off by default. If you enable it, Ember uploads the local calendar date and completed wake-up minute needed to rank your earliest wake-up for the current day. Wake times are visible only when both you and the accepted friend viewing the ranking have opted in. Turning participation off deletes your uploaded wake-time rows and prevents you from viewing other participants' wake times; your on-device wake history is unchanged.
- Private-beta benefits:a beta access request can be linked to one backend user ID. We store that link, the grant time, eligibility for six free months at launch, a 70% lifetime-plan discount, and the First Light grant. A secret access token permits the link even when the account provider uses a different email address. When an access code is activated or claimed, Ember stores one-way, server-keyed verification values derived from its code and token. If the account is later deleted, those detached values remain so the same credential can be recognized without retaining the deleted account's access request, identity, or individual benefit data.
- Cloud backup:one private snapshot linked to your backend user ID. Depending on the categories selected in Settings, this can include alarms and challenge settings; embers, achievements, and lifetime totals stored as cumulative counters per app installation; preferences, saved code values, vocabulary pairs, and the emergency-override passkey; and wake-up history stored as individual session outcomes with random session IDs. The snapshot also contains the corresponding random app-installation IDs. Ember generates these IDs solely to merge and deduplicate offline progress; they contain no hardware or operating-system device identifier. The live wake-up session and your backup choices are not part of the snapshot. When both Alarms and Progress backup are enabled, Ember also keeps one private record for the account's next armed wake occurrence: its random alarm and occurrence IDs, scheduled time, original local date, time zone, and random app-installation ID. Ember uses this record only to preserve the missed-wake result if the app or its local data is removed before the wake-up check is completed. It does not contain an alarm label, challenge content, contact data, or a hardware identifier.
Cloud backup starts only after an account user enables it. Account users can pause syncing or exclude categories under Settings → Cloud Backup. Pausing retains the latest remote snapshot and stops new changes from uploading until syncing resumes. The separate Delete cloud backup action permanently removes the remote snapshot and wake-occurrence record. Disabling backup, Alarms backup, or Progress backup stops and removes the pending wake-occurrence checkpoint for the account. Ember retains an empty deletion marker linked to the backend user ID, with its deletion time and revision, so another signed-in device or older app version cannot recreate the deleted snapshot. The marker contains no backed-up content and is cleared when backup is explicitly enabled again or the account is deleted. Deleting the account also deletes the authentication user, verified phone, profile, friend records, scores, grants, contact-matching data, and the personal data and account-linked records of any associated beta access request. A previously activated or claimed beta credential remains reusable as described in Section 11.
6. Permissions, Camera, and Fitness Data
Ember requests permissions only for features that need them:
- Alarms and notifications schedule alarms, play alarm audio, show wake-up information, and, where supported, display an alarm over the lock screen until the wake-up check is completed.
- Camera reads a barcode or QR code for a scan check. Camera frames are processed on the device. Ember does not store or upload photos or camera frames. The decoded code value can be saved locally and included in cloud backup if Preferences backup is enabled.
- Motion, physical activity, and step data count steps during a walk check, update its visible progress, and keep the alarm quiet while you are actively walking. Raw sensor events are processed on the device and are not uploaded. The aggregate lifetime step total can be included in the Embers & achievements backup category.
- HealthKit on supported iOS versions is used only to run a temporary walking workout session so a walk check can remain active while the phone is locked. Ember does not read HealthKit data and does not save a workout record. Ember does not use Health Connect, location, or body-sensor data.
- Contacts is requested only when you choose to enable contact matching. Ember reads phone-number fields only. You can decline or revoke access without losing the core app, and you can disable contact matching at any time.
7. Purchases and Ember Pro
Apple or Google processes your Ember Pro transaction through the store account you use. We do not receive your full payment-card or bank-account details. The store provides transaction information needed to confirm the product, purchase, trial, renewal, cancellation, refund, and current entitlement status.
Ember uses RevenueCat to validate store transactions, keep Ember Pro access in sync, restore eligible purchases, and measure paywall-to-purchase conversion. The SDK starts when needed for a signed-in account, a pending paywall, an existing entitlement, or a store action. Signed-out purchase flows use a pseudonymous app-user identifier. If you are signed in, Ember uses your backend account ID as the RevenueCat App User ID so entitlement access can follow the account across devices. RevenueCat may then receive your account email, confirmed phone number, display name, locale, onboarding motivation, beta and profile state, platform, app and build version, and a custom-paywall impression. It also processes transaction and receipt identifiers, product and entitlement details, subscription events, store and device technical information, IP address, and related diagnostic data. Ember does not send RevenueCat alarm schedules, challenge content, saved codes or vocabulary, passkeys, or wake history. RevenueCat does not receive your full payment details from Ember.
8. Technical and Diagnostic Data
When the app contacts Supabase or another required service, those services receive ordinary connection and operational data such as IP address, request time, endpoint, app or platform client information, response status, and error details. We use these limited logs for delivery, authentication, security, abuse prevention, and diagnosing service failures. Ember does not use a third-party advertising or behavioral-tracking SDK in the app. The website uses Vercel Web Analytics and Speed Insights to measure aggregate visits and performance; Vercel may process route, browser, device, timing, IP-derived, and connection data for those services.
9. Purposes and Legal Bases
- provide alarms, accounts, backup, friend features, and support you request: Art. 6(1)(b) GDPR
- process private-beta access requests, issue access codes and activation reminders, administer expiry and replacement requests, and attach promised beta benefits to an account: Art. 6(1)(b) GDPR
- validate purchases, provide Ember Pro, restore access, and administer subscriptions: Art. 6(1)(b) GDPR
- process optional access-request answers and product feedback: Art. 6(1)(a) GDPR; you can withdraw at any time by email
- verify an optional account phone and perform mutual opt-in contact matching: Art. 6(1)(a) GDPR; you can withdraw consent at any time by disabling contact matching, revoking contact access, or contacting us
- operate securely, prevent abuse, and maintain reliable services: Art. 6(1)(f) GDPR
- meet legal duties: Art. 6(1)(c) GDPR
Where motion or step data qualifies as health data, processing for the walk feature relies on your explicit permission and consent under Art. 9(2)(a) GDPR. You can revoke the permission in device settings, although the walk feature will then stop working.
10. Service Providers and International Transfers
We use the following categories of recipients where needed:
- Supabase for backend hosting, database, authentication, phone verification, and contact-matching token processing
- Twilio for sending the one-time code to the phone number you choose to verify
- Vercel for website hosting, delivery, aggregate analytics, and performance measurement
- Resend and our email provider for beta access, reminders, and support email
- RevenueCat for store-transaction validation, entitlement management, and purchase restoration
- Apple and Google for app distribution and, when selected, platform sign-in or app-store transactions
These providers act under their own terms and, where they process data on our behalf, are required to protect it consistently with this policy and applicable law. If personal data is processed outside the EEA, we rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses where required. We do not share personal data with advertisers or data brokers.
11. Retention and Deletion
- On-device data remains until you delete it, clear Ember’s app data, or uninstall the app, subject to device backups you control.
- Account, profile, beta-entitlement, founder-grant, friend, score, and cloud-backup data remains while the account is active. Pausing sync retains the latest cloud snapshot; it is removed only when you use Delete cloud backup or delete the account.
- Ember keeps at most one wake-occurrence record per account. It tracks the next expected wake and is replaced after completion or a schedule change. A missed record remains until it has been incorporated into restored progress, so deleting the app cannot erase the missed wake. Deleting the cloud backup or account removes the record immediately.
- An optional verified phone remains linked to the account until you ask us to remove it or delete the account, including after contact matching is disabled. Disabling contact matching immediately deletes the stored address-book and verified-number matching tokens. Contact sets that have not been refreshed for 90 days no longer qualify for matching; inactive-device tokens are deleted during subsequent contact-discovery cleanup. Existing friendships remain until you remove them or delete the account. Friend-removal suppression records remain until account deletion. Account deletion immediately deletes the verified phone and contact-matching records linked to the deleted account. A pseudonymous token uploaded by another user for that phone number can remain in that user's contact set until they resync or inactive contact data is cleaned up. It is not linked to the deleted account and can no longer match it after the account's verified-number token is deleted.
- Wake-time rows remain while participation is enabled, although only the current day is used for ranking. Turning participation off immediately deletes all uploaded wake-time rows; account deletion removes them as well. Wake-time boards are not retained for offline display.
- Purchase and entitlement records remain as needed to provide or restore access, handle refunds or disputes, prevent fraud, and meet accounting or other legal obligations. Apple, Google, and RevenueCat retain related records under their own policies.
- Unactivated private-beta codes expire at the deadline shown in the access email. Access-request and expiry records may remain through the beta to support replacement requests, prevent abuse, and maintain an operational history. Deleting an associated account deletes the access request's personal data, answers, account link, and individual claim and benefit records. If the code was already activated or claimed, Ember retains only one-way, server-keyed verification values derived from its code and token. This lets the holder use the same credential after reinstalling Ember or creating a replacement account. The retained values contain no raw code or token, email address, answers, user or access-request ID, activation or claim time, or individual benefit record.
- Ember increments one global deleted-account counter. It stores only the total number of deleted accounts, with no per-account record, date, identifier, or account attribute.
- Support correspondence and operational logs are kept only as long as needed for the request, security, legal obligations, or the service provider’s normal backup and log-rotation cycle.
You can delete an Ember account in Settings → Account → Delete account. The deletion removes the live authentication record and cascades to the associated verified phone, contact-matching tokens, profile, friendships, friend-invite keys, leaderboard scores and wake-time records, grants, beta-access-request personal data and account-linked records, and cloud snapshot. Only the global deleted-account count and, for a previously activated or claimed beta code, its detached one-way verification values remain. Data stored only on the device remains there. Previously loaded non-wake leaderboard entries can remain temporarily in another participant's local offline cache until that app reconnects and refreshes or its data is cleared. Account deletion does not cancel a store subscription. Ember clears account profile attributes from the active RevenueCat customer, while Apple, Google, and RevenueCat may retain transaction records required for subscriptions, accounting, fraud prevention, or law. Full instructions and an email option are available on the account deletion page.
12. Your Rights
Under the GDPR, you have the right to:
- access your personal data, Art. 15 GDPR
- rectification, Art. 16 GDPR
- erasure, Art. 17 GDPR
- restriction of processing, Art. 18 GDPR
- data portability, Art. 20 GDPR
- object to processing, Art. 21 GDPR
- withdraw consent at any time for future processing
- lodge a complaint with a supervisory authority, Art. 77 GDPR
Contact support@emberalarm.com to exercise these rights.
13. Security
We use encrypted transport, authentication, access controls, and database row-level security to protect backend data. No online service can be guaranteed completely secure, so keep your device and account credentials protected.
14. Changes to this Policy
We may update this policy when the product, providers, or legal requirements change. The current version and update date are published on this page. Purchase and subscription conditions are set out in our Terms of Use.
Last updated: August 23, 2026.