Informações legais

Política de Privacidade

Esta política explica como o Ember trata dados pessoais.

1. Controller

Geordan Gesink
Haesselackerstraße 3
69198 Schriesheim
Germany
Email: support@emberalarm.com

2. How Ember Handles Data

Ember is a wake-up alarm app for iOS and Android and includes this website. The core alarm and wake-up checks work without an account. Most app data starts on your device. Data reaches our backend or service providers when you use account, leaderboard, social, cloud-backup, purchase, restore, support, or website features that require it, or enable optional usage analytics or advertising measurement. When purchases are active or needed, the purchase service checks your current Ember Pro entitlement.

  • No account is required for the core alarm and challenge features.
  • Optional usage analytics is available from app version 1.2.0 and is off by default. Optional advertising measurement is available from version 1.2.2 on iOS and Android. Verified purchase-summary forwarding to PostHog remains disabled for production purchases. Section 8 explains these separate features. We do not sell personal data.
  • Permissions and cloud-backup categories can be managed in Ember and in your device settings.

3. Website, Former Pre-release Access Records, and Contact

When you visit emberalarm.com, the website host processes connection data needed to deliver and protect the site. This can include your IP address, request time, requested URL, referrer if supplied, browser or user-agent information, response status, and security logs.

During Ember's pre-release access program, we processed the email address and locale submitted, optional answers about what Ember should help with and how the person heard about us, and ordinary request and abuse-prevention data such as request time and IP address. Supabase stored the access request, and Resend delivered the access code, secret magic-link token, and access or reminder emails. The program has ended: we no longer accept new or replacement access-code requests, issue new codes, or send access reminders. An access request did not create an Ember account.

Each code issued during the program is subject to its stated activation deadline. Activation by that deadline reserves First Light, Ember Pro without charge until April 1, 2027, and the lifetime-plan discount until the qualifying access is connected to an account. The token-based link can still connect a previously activated access when Apple or Google supplies an account email different from the request email. An unactivated code expires at its stated deadline and is not replaced. If you email support, we process your email address, message, and any information you choose to include so we can respond.

4. Data Stored on Your Device

Depending on the features you use, local app data includes:

  • alarms, labels, schedules, skip dates, and wake-up check settings
  • saved barcode or QR values and vocabulary pairs
  • preferences, motivation, equipped and unlocked embers, and an optional emergency-override passkey
  • wake-up history, streaks, scores, completion times, alarm counts, and lifetime achievement totals such as aggregate walk-check steps
  • a random app-installation ID and random IDs for completed wake-up sessions, generated by Ember solely to merge offline progress without counting it twice; these values contain no hardware or operating-system device identifier
  • the display name and handle associated with a registered account
  • the active wake-up session and temporary alarm state

Live wake-up sessions remain device-local. Other categories remain local unless they are used for leaderboard or social functions or are included in an enabled cloud backup.

5. Accounts, Cloud Backup, and Social Features

Ember uses Supabase for authentication, account data, cloud backup, and friend leaderboards. Registering creates a permanent account with an email address or an identifier supplied by a sign-in provider such as Apple or Google.

  • Profile: backend user ID, editable display name, system-generated random handle, and creation or update timestamps. The handle cannot be edited.
  • Optional verified phone:you can add a phone number to your account for contact matching. Supabase Auth and Twilio, our SMS delivery provider, process the number and one-time verification code. Once verified, the number is linked to your backend user ID. It is not required for Ember's core alarm features.
  • Social graph: outgoing and incoming friend requests, accepted friend relationships, and response timestamps. Your display name and handle can be visible to people involved in a friend request. Accepted friends can also see your rank. Disabling contact matching does not remove existing friendships. If you remove a friend, Ember retains a pair-specific suppression record so automatic contact matching does not recreate that relationship.
  • Optional contact matching:after you consent and grant address-book access, Ember reads only contact phone-number fields. On your device, it normalizes them to E.164 format and hashes them with SHA-256. No contact names, email addresses, postal addresses, or raw address-book phone numbers are uploaded. The backend protects stored matching tokens with a server-keyed HMAC rather than storing the device-generated SHA-256 values. These tokens are linked to your backend user ID and app installation. They are pseudonymous personal data, not anonymous data. Ember uses them only to create a friend connection when both account holders have enabled contact matching and each has the other's verified phone number in their address book. They are not used to contact non-users, advertise, or track you.
  • Leaderboard: local calendar date, daily total score, scored-session count, and best session score. Accepted friends can see the ranks calculated from these records.
  • Optional wake-time ranking:this is off by default. If you enable it, Ember uploads the local calendar date and completed wake-up minute needed to rank your earliest wake-up for the current day. Wake times are visible only when both you and the accepted friend viewing the ranking have opted in. Turning participation off deletes your uploaded wake-time rows and prevents you from viewing other participants' wake times; your on-device wake history is unchanged.
  • Former-tester benefits:a qualifying access from the former pre-release program can be linked to one backend user ID. We store that link, the grant time, Ember Pro access ending April 1, 2027, a 70% lifetime-plan discount, and the First Light grant. A secret access token permits a previously activated access to be linked even when the account provider uses a different email address. For an access code activated or claimed during the program, Ember stores one-way, server-keyed verification values derived from its code and token. If the account is later deleted, those detached values remain so the same credential can be recognized without retaining the deleted account's access request, identity, or individual benefit data.
  • Cloud backup:one private snapshot linked to your backend user ID. Depending on the categories selected in Settings, this can include alarms and challenge settings; embers, achievements, and lifetime totals stored as cumulative counters per app installation; preferences, saved code values, vocabulary pairs, and the emergency-override passkey; and wake-up history stored as individual session outcomes with random session IDs. The snapshot also contains the corresponding random app-installation IDs. Ember generates these IDs solely to merge and deduplicate offline progress; they contain no hardware or operating-system device identifier. The live wake-up session and your backup choices are not part of the snapshot. When both Alarms and Progress backup are enabled, Ember also keeps one private record for the account's next armed wake occurrence: its random alarm and occurrence IDs, scheduled time, original local date, time zone, and random app-installation ID. Ember uses this record only to preserve the missed-wake result if the app or its local data is removed before the wake-up check is completed. It does not contain an alarm label, challenge content, contact data, or a hardware identifier.

Cloud backup starts only after an account user enables it. Account users can pause syncing or exclude categories under Settings → Cloud Backup. Pausing retains the latest remote snapshot and stops new changes from uploading until syncing resumes. The separate Delete cloud backup action permanently removes the remote snapshot and wake-occurrence record. Disabling backup, Alarms backup, or Progress backup stops and removes the pending wake-occurrence checkpoint for the account. Ember retains an empty deletion marker linked to the backend user ID, with its deletion time and revision, so another signed-in device or older app version cannot recreate the deleted snapshot. The marker contains no backed-up content and is cleared when backup is explicitly enabled again or the account is deleted. Deleting the account also deletes the authentication user, verified phone, profile, friend records, scores, grants, contact-matching data, and the personal data and account-linked records of any associated former access request. A previously activated or claimed access credential remains reusable as described in Section 11.

6. Permissions, Camera, and Fitness Data

Ember requests permissions only for features that need them:

  • Alarms and notifications schedule alarms, play alarm audio, show wake-up information, and, where supported, display an alarm over the lock screen until the wake-up check is completed.
  • Camera reads a barcode or QR code for a scan check. Camera frames are processed on the device. Ember does not store or upload photos or camera frames. The decoded code value can be saved locally and included in cloud backup if Preferences backup is enabled.
  • Motion, physical activity, and step data count steps during a walk check, update its visible progress, and keep the alarm quiet while you are actively walking. Raw sensor events are processed on the device and are not uploaded. The aggregate lifetime step total can be included in the Embers & achievements backup category.
  • HealthKit on supported iOS versions is used only to run a temporary walking workout session so a walk check can remain active while the phone is locked. Ember does not read HealthKit data and does not save a workout record. Ember does not use Health Connect, device location services, or body-sensor data.
  • Contacts is requested only when you choose to enable contact matching. Ember reads phone-number fields only. You can decline or revoke access without losing the core app, and you can disable contact matching at any time.

7. Purchases and Ember Pro

Apple or Google processes your Ember Pro transaction through the store account you use. We do not receive your full payment-card or bank-account details. The store provides transaction information needed to confirm the product, purchase, trial, renewal, cancellation, refund, and current entitlement status.

Ember uses RevenueCat to validate store transactions, keep Ember Pro access in sync, restore eligible purchases, and measure paywall-to-purchase conversion. The SDK starts when needed for a signed-in account, a pending paywall, an existing entitlement, or a store action. Signed-out purchase flows use a pseudonymous app-user identifier. If you are signed in, Ember uses your backend account ID as the RevenueCat App User ID so entitlement access can follow the account across devices. RevenueCat may then receive your account email, confirmed phone number, display name, locale, onboarding motivation, legacy access-program state, profile state, platform, app and build version, and a custom-paywall impression. It also processes transaction and receipt identifiers, product and entitlement details, subscription events, store and device technical information, IP address, and related diagnostic data. Ember does not send RevenueCat alarm schedules, challenge content, saved codes or vocabulary, passkeys, or wake history. RevenueCat does not receive your full payment details from Ember.

Our backend can receive a limited purchase-event summary from RevenueCat to reconcile purchases, refunds, and proceeds. It contains protected transaction and event references, product, store, currency, amounts, purchase dates, subscription status, and estimated store deductions. The purchase-ledger rows omit direct Ember account IDs, customer profiles, email addresses, and the full RevenueCat event payload. The planned verified purchase analytics described in Section 8 would use separate consent and delivery records to link eligible purchase events to a signed-in account and send limited summaries to PostHog. That forwarding is not active. The ledger does not send data to advertising platforms.

8. Technical and Diagnostic Data

When the app contacts Supabase or another required service, those services receive ordinary connection and operational data such as IP address, request time, endpoint, app or platform client information, response status, and error details. We use these limited logs for delivery, authentication, security, abuse prevention, and diagnosing service failures. The website uses Vercel Web Analytics and Speed Insights to measure aggregate visits and performance; Vercel may process route, browser, device, timing, IP-derived, and connection data for those services.

Optional usage analytics

From app version 1.2.0, Usage analytics lets you choose whether to send limited usage events to PostHog Cloud in the EU (Frankfurt). This is off by default. Declining does not affect alarms, checks, or paid access. You can change your choice in Settings → Usage analytics.

If you opt in, events record app openings, onboarding steps, the first saved alarm, paywall views, plan selections, purchase-flow outcomes, and completed wake-up checks with an outcome and duration range. They include event time, app and build version, platform, language, and a pseudonymous analytics identifier. When signed in, your account ID can link these events across sessions. We use them to understand where setup or purchases fail and whether people keep using Ember.

For signed-in users who enable Usage analytics, we also plan to register that choice with our backend. While that consent is active, verified purchase, trial, renewal, refund, and subscription-status summaries could be sent from our purchase system to PostHog in the EU and linked to the same Ember account ID as usage events. These summaries would include the product, offer, purchase status, event time, applicable amount and currency, and protected event or transaction references. They would help us understand purchases and continued use together. Our backend would retain a record of your choice and when it changed, linked to your account ID. This forwarding remains disabled for production purchases, including version 1.2.2.

We do not send PostHog your name, email, phone number, alarm schedule or label, saved codes, challenge content, free-form answers, precise location, or raw error messages. Session recording, automatic screen and interaction capture, and location enrichment are disabled. PostHog receives ordinary connection data, including the IP address needed to receive a request. Raw store receipts and payment-card details would not be sent to PostHog. Purchase validation and financial records needed for paid access would continue independently of optional analytics.

Turning Usage analytics off stops new events and discards events still queued on your device. For the planned purchase-summary forwarding, it would also request withdrawal of the backend purchase-analytics registration. That change requires a successful network connection; an offline choice cannot immediately stop events already being processed remotely. Turning analytics off does not delete events already received by PostHog. To request deletion of those records, contact support@emberalarm.com. Account deletion also stops analytics on that device and removes its account-linked backend consent registration; it does not automatically erase earlier PostHog records.

Optional advertising measurement — version 1.2.2

From version 1.2.2, Ember on iOS and Android uses AppsFlyer to understand which ads lead to installations, trials, and purchases. Its AppsFlyer and Meta connections are enabled. The following describes this version and test builds with advertising measurement enabled. Advertising measurement stays off until you explicitly allow it. This choice is separate from Usage analytics; declining does not affect alarms, checks, purchases, or paid access.

After permission, AppsFlyer receives installation and app-session events, installation, vendor, and customer identifiers, app and device technical data, connection data including IP address and the approximate location derived from it, and advertising identifiers where permitted. Technical data includes launch and battery information used for fraud prevention. These identifiers are pseudonymous personal data. We use this information to measure and improve Ember ads and prevent fraud. Alarm schedules, wake-up history, saved codes, and challenge content are not sent to AppsFlyer.

The RevenueCat-to-AppsFlyer connection is enabled for this release. With your advertising-measurement permission, RevenueCat links the AppsFlyer installation identifier to its customer record and sends purchase, trial, renewal, and refund information. This includes product and transaction references, amounts, currency, event times, its app-user identifier, available technical identifiers, and a hashed email address when available. A hash is a transformed identifier, not anonymous data. RevenueCat is the only sender of these financial events; the app does not send a second copy through AppsFlyer. The separate backend purchase summaries described in Section 7 remain outside this sharing route.

AppsFlyer shares permitted installation, session, and conversion data with Meta to measure and improve Ember ads. These notifications can include permitted device identifiers and purchases associated with other acquisition sources or no attributed ad. Meta Advanced Matching is off; this integration does not use hashed email for Meta Advanced Matching. The Reddit connection is inactive and receives no events through this integration. Direct partner sharing requires your advertising-measurement permission and, on iOS, Apple's tracking permission. Ember requests that system permission only after you allow measurement. If you decline Apple's permission, advertising identifiers and direct AppsFlyer event notifications to partners are disabled. Aggregate measurement through Apple's SKAdNetwork and AppsFlyer's privacy controls may still be available while your Ember measurement choice is on.

Turning Advertising measurement off in Settings stops further collection by the app and requests removal of the RevenueCat attribution link and exclusion of partner sharing. Server changes require a connection and successful synchronization; an offline choice cannot instantly stop events already being processed remotely. Turning it off or deleting an Ember account does not automatically erase earlier advertising records. The Settings deletion request prepares an email to support@emberalarm.com with the available AppsFlyer and RevenueCat identifiers retained on your device. You choose whether to send it. We handle that request with the relevant providers, including any earlier customer identifiers.

9. Purposes and Legal Bases

  • provide alarms, accounts, backup, friend features, and support you request: Art. 6(1)(b) GDPR
  • administer qualifying records from the former pre-release program and attach or provide promised former-tester benefits to an account: Art. 6(1)(b) GDPR
  • validate purchases, provide Ember Pro, restore access, and administer subscriptions: Art. 6(1)(b) GDPR
  • retain optional answers previously submitted with an access request and process product feedback: Art. 6(1)(a) GDPR; you can withdraw at any time by email
  • verify an optional account phone and perform mutual opt-in contact matching: Art. 6(1)(a) GDPR; you can withdraw consent at any time by disabling contact matching, revoking contact access, or contacting us
  • optional usage analytics and planned consented verified purchase summaries, to improve onboarding, purchases, and the wake-up experience: Art. 6(1)(a) GDPR; withdraw at any time in Settings → Usage analytics
  • optional advertising measurement and permitted partner sharing: consent under Art. 6(1)(a) GDPR; withdraw in Settings → Advertising measurement when the feature is available
  • operate securely, prevent abuse, and maintain reliable services: Art. 6(1)(f) GDPR
  • meet legal duties: Art. 6(1)(c) GDPR

Where motion or step data qualifies as health data, processing for the walk feature relies on your explicit permission and consent under Art. 9(2)(a) GDPR. You can revoke the permission in device settings, although the walk feature will then stop working.

10. Service Providers and International Transfers

The following providers process data where needed or processed it for the former access program:

  • Supabase for backend hosting, database, authentication, phone verification, and contact-matching token processing
  • Twilio for sending the one-time code to the phone number you choose to verify
  • Vercel for website hosting, delivery, aggregate analytics, and performance measurement
  • Resend, our former access-email provider, which delivered access and reminder emails during the pre-release program
  • RevenueCat for store-transaction validation, entitlement management, and purchase restoration
  • PostHog for optional usage analytics in its EU cloud region
  • AppsFlyer for optional advertising measurement in version 1.2.2, with Meta as a measurement recipient under the conditions described in Section 8; the Reddit connection remains inactive
  • Apple and Google for app distribution and, when selected, platform sign-in or app-store transactions

These providers act under their own terms and, where they process data on our behalf, are required to protect it consistently with this policy and applicable law. If personal data is processed outside the EEA, we rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses where required. Advertising measurement and sharing with Meta follow the release availability, separate permissions, and limits described in Section 8. We do not sell personal data to advertisers or data brokers.

11. Retention and Deletion

  • On-device data remains until you delete it, clear Ember’s app data, or uninstall the app, subject to device backups you control.
  • Account, profile, former-tester entitlement, founder-grant, friend, score, and cloud-backup data remains while the account is active. Pausing sync retains the latest cloud snapshot; it is removed only when you use Delete cloud backup or delete the account.
  • Ember keeps at most one wake-occurrence record per account. It tracks the next expected wake and is replaced after completion or a schedule change. A missed record remains until it has been incorporated into restored progress, so deleting the app cannot erase the missed wake. Deleting the cloud backup or account removes the record immediately.
  • An optional verified phone remains linked to the account until you ask us to remove it or delete the account, including after contact matching is disabled. Disabling contact matching immediately deletes the stored address-book and verified-number matching tokens. Contact sets that have not been refreshed for 90 days no longer qualify for matching; inactive-device tokens are deleted during subsequent contact-discovery cleanup. Existing friendships remain until you remove them or delete the account. Friend-removal suppression records remain until account deletion. Account deletion immediately deletes the verified phone and contact-matching records linked to the deleted account. A pseudonymous token uploaded by another user for that phone number can remain in that user's contact set until they resync or inactive contact data is cleaned up. It is not linked to the deleted account and can no longer match it after the account's verified-number token is deleted.
  • Wake-time rows remain while participation is enabled, although only the current day is used for ranking. Turning participation off immediately deletes all uploaded wake-time rows; account deletion removes them as well. Wake-time boards are not retained for offline display.
  • Optional analytics events are retained in PostHog for up to one year. Turning analytics off stops new events from this device and requests withdrawal of backend purchase analytics as described in Section 8; the backend change requires network synchronization. Contact us to request deletion of previously collected events and the associated analytics profile.
  • The planned backend purchase-analytics consent record would remain active until you withdraw it or delete your account. Daily cleanup would remove an unactivated registration after one day and a revoked consent record after 30 days. A separate minimal record of an account-wide withdrawal would remain until account deletion so retrying an earlier request cannot cancel a later consent. Account deletion would remove both kinds of account-linked records and cancel pending deliveries. Undelivered purchase summaries would stop being retried after seven days or 12 attempts. Delivery metadata would lose its consent/account link when the consent record is deleted and would be removed with its purchase-ledger event in the daily cleanup after that event is more than 24 months old.
  • The version 1.2.2 advertising integration retains a limited set of AppsFlyer and RevenueCat identifiers on your device so you can request deletion after opting out. For AppsFlyer's own retention rules, see its Services Privacy Policy. Advertising records already received by providers require a separate deletion request; disabling collection does not erase them.
  • Purchase and entitlement records remain as needed to provide or restore access, handle refunds or disputes, prevent fraud, and meet accounting or other legal obligations. Apple, Google, and RevenueCat retain related records under their own policies. Limited backend purchase summaries are removed by a daily cleanup once their event date is more than 24 months old. They have no account link and are not automatically removed by deleting an Ember account.
  • The pre-release program has ended. Ember issues no new or replacement access codes and sends no access reminders. Unactivated codes expire at the deadline shown in their access email. Access-request and expiry records remain only as needed to honor qualifying former-tester benefits, prevent abuse, maintain a necessary operational history, or meet legal obligations, and are deleted when no longer needed for those purposes. Deleting an associated account deletes the access request's personal data, answers, account link, and individual claim and benefit records. If the code was activated or claimed, Ember retains only one-way, server-keyed verification values derived from its code and token. This lets the holder use the same credential after reinstalling Ember or creating a replacement account. The retained values contain no raw code or token, email address, answers, user or access-request ID, activation or claim time, or individual benefit record.
  • Ember increments one global deleted-account counter. It stores only the total number of deleted accounts, with no per-account record, date, identifier, or account attribute.
  • Support correspondence and operational logs are kept only as long as needed for the request, security, legal obligations, or the service provider’s normal backup and log-rotation cycle.

You can delete an Ember account in Settings → Account → Delete account. The deletion removes the live authentication record and cascades to the associated verified phone, contact-matching tokens, profile, friendships, friend-invite keys, leaderboard scores and wake-time records, grants, former access-request personal data and account-linked benefit records, and cloud snapshot. The global deleted-account count and, for a previously activated or claimed access code, its detached one-way verification values remain. The separate purchase and optional analytics records described above follow their own retention and deletion rules. Data stored only on the device remains there. Previously loaded non-wake leaderboard entries can remain temporarily in another participant's local offline cache until that app reconnects and refreshes or its data is cleared. Account deletion does not cancel a store subscription. Ember clears account profile attributes from the active RevenueCat customer, while Apple, Google, and RevenueCat may retain transaction records required for subscriptions, accounting, fraud prevention, or law. Full instructions and an email option are available on the account deletion page.

12. Your Rights

Under the GDPR, you have the right to:

  • access your personal data, Art. 15 GDPR
  • rectification, Art. 16 GDPR
  • erasure, Art. 17 GDPR
  • restriction of processing, Art. 18 GDPR
  • data portability, Art. 20 GDPR
  • object to processing, Art. 21 GDPR
  • withdraw consent at any time for future processing
  • lodge a complaint with a supervisory authority, Art. 77 GDPR

Contact support@emberalarm.com to exercise these rights.

13. Security

We use encrypted transport, authentication, access controls, and database row-level security to protect backend data. No online service can be guaranteed completely secure, so keep your device and account credentials protected.

14. Changes to this Policy

We may update this policy when the product, providers, or legal requirements change. The current version and update date are published on this page. Purchase and subscription conditions are set out in our Terms of Use.

Última atualização: 6 de outubro de 2026.