๐Ÿ”ฅ Ember

Privacy Policy

Ember ยท Heart & SOUL Technologies, Inc.

Effective Date: October 1, 2026
Last Updated: October 1, 2026

The short version

Your conversations with Ember are stored, and they are not private from us. We keep what you send so Ember can remember you. Our staff can read conversations, and sometimes do โ€” for safety, for quality, and to fix problems.

We do not sell your personal information.

Ember is not end-to-end encrypted. Text messages travel over the carrier network, which we do not control. Do not send Ember anything you need to keep secret.

You can stop everything by replying STOP, and you can ask us to delete your data by emailing privacy@heyember.io.

1. Who we are

Ember is operated by Heart & SOUL Technologies, Inc. ("we", "us"), a Delaware corporation, c/o Harvard Business Services, Inc., 16192 Coastal Highway, Lewes, DE 19958.

This policy explains what personal information we collect when you use Ember, why we collect it, who we share it with, and what you can ask us to do with it. It applies to the Ember messaging service and to heyember.io.

This policy works alongside our Terms of Service. Where the Terms describe what the service is, this policy describes what happens to your information.

2. Ember is for adults

Ember is available only to people 18 years of age or older. We do not knowingly collect personal information from anyone under 18.

We use automated analysis of conversation content, and third-party age-verification services, to identify users who may be under 18. When we identify a likely minor we remove their access and delete their data. If you believe a minor is using Ember, contact safety@heyember.io and we will act on it.

3. What we collect

3.1 Information you give us by texting Ember

3.2 Information Ember derives from your conversations

Ember is designed to remember you. To do that, automated systems read your messages and write down structured information about you, which is stored separately from the messages themselves and used to shape future replies. This includes:

Some of this information is sensitive. People tell Ember about their health, their relationships, their finances, their beliefs, and their mental state. When you tell Ember something sensitive, that is what gets stored.

3.3 Safety and crisis information

Automated systems assess your messages for signs of distress, self-harm, and crisis. This assessment runs on every message before Ember replies. We store:

3.4 If you connect a Google or Microsoft account

Connecting a Google or Microsoft account is optional. Ember works fully without it. See section 6 for exactly what we do with that data.

3.5 Payment information

Ember is currently free, and we do not collect payment information. If we introduce a paid plan, payment will be processed by Stripe; we will not receive or store your full card number, and we will update this policy before any charge is made.

3.6 Website and advertising information

When you visit heyember.io, we and our advertising partners collect standard web information โ€” your IP address, browser and device type, the page you came from, and which version of the page you saw. We use Google Ads and Meta advertising tools, and we send them events about actions taken on our site and about sign-ups, so we can measure which advertising works.

This is the one part of Ember that involves advertising technology. The content of your conversations with Ember is never sent to advertising platforms.

4. How we use your information

5. Our staff can read your conversations

We want to be direct about this, because the marketing word "private" can be misread.

Your conversations with Ember are not confidential and not privileged. They are not protected the way a conversation with a doctor, therapist, or lawyer is protected. Authorised personnel at Heart & SOUL Technologies can read them, and do read them โ€” as part of a structured safety and quality review process, when investigating a problem you report, and when investigating a safety concern.

Access to conversation content by our staff is logged.

6. Google and Microsoft account data

If you choose to connect a Google account (Gmail and Google Calendar) or a Microsoft account (Outlook mail and calendar), Ember can act on your email and calendar on your behalf. This section describes that specifically, because Google requires it and because it deserves its own explanation.

6.1 What we ask for

AccessWhat Ember does with it
Read your emailSearch and read your email so you can ask Ember about it โ€” for example, "did I get the invoice yet?" โ€” and summarise your inbox when you ask.
Draft, send, and reply to emailWrite a draft for you, or send an email or reply on your behalf when you ask.
Organise your inboxWhen you ask Ember to clean up your inbox, archive messages or move them to the trash, and unsubscribe you from mailing lists.
Read and manage calendar eventsTell you what is on your calendar, and add, change, or cancel events when you ask.

Ember never sends, changes, or deletes anything without your yes. Before any email is sent, any event is created, changed or cancelled, or any inbox change is made, Ember shows you exactly what it is about to do and waits for you to confirm it by message. Reading your email and calendar to answer your question does not need a separate confirmation.

6.2 Google API Services Limited Use

Ember's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Specifically, in relation to data obtained from Google APIs:

6.3 What we store

We store your Google or Microsoft access credentials in encrypted form, using a key derived separately for each user. We store the list of permissions you granted. We do not keep a copy of your mailbox or your calendar. Ember retrieves emails and events when you ask or when a feature you turned on needs them. We do keep:

One exception you should understand: if you ask Ember about an email and Ember replies describing what it found, that reply is part of your conversation and is stored like any other message. Content from your email can therefore end up in your conversation history, and in the derived information described in section 3.2.

6.4 Disconnecting

You can disconnect at any time, and you have two independent routes:

When you disconnect, we revoke the credential with Google or Microsoft and delete it from our systems. Conversation history that discussed your email or calendar is not automatically removed โ€” to remove that, ask us to delete your data (section 9).

7. Who we share information with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

We do use service providers who process information on our behalf, under contract, and only on our instructions:

ProviderWhat they handle
AnthropicGenerates Ember's replies. Receives conversation content.
OpenAIGenerates text embeddings used for memory search, transcribes voice messages you send, serves as a fallback reply provider, and is used for internal quality evaluation. Receives conversation content.
SupabaseDatabase and account infrastructure. Stores conversation content and derived information.
Google CloudHosting and infrastructure.
LinqDelivers and receives iMessage and text messages. Handles message content and phone numbers.
TwilioDelivers text messages (SMS). Handles message content and phone numbers.
TavilyWeb search. When Ember looks something up, receives a search query based on your message.
Image safety scanning serviceImage safety scanning. Receives images you send.
Sentry, PostHogError monitoring and product analytics.
Workplace messaging toolSafety-event alerts to our team, which can include short excerpts of messages.
Google Ads, MetaAdvertising measurement. Receive web and sign-up events. When you first start using Ember, Meta receives a hashed version of your phone number and, if you came from one of our ads, technical details of that visit. Never conversation content.

The AI providers above, Anthropic and OpenAI, receive your conversations only through their business APIs, under terms that do not permit them to use that data to train their models.

We may also disclose information: when we are legally required to; when we believe in good faith that disclosure is necessary to prevent imminent harm to you or someone else; and in connection with a merger, acquisition, or sale of assets, with notice to you.

8. How long we keep it

We keep most information for as long as you use Ember, because remembering you is what Ember does. We do not delete it on a timer; it is deleted when you ask us to (section 9.3).

CategoryKept for
Conversation contentUntil you ask us to delete it.
Derived memory about youUntil you ask us to delete it. You can also correct it at any time (section 9.4).
Distress signalsAffect Ember's replies for 24 hours, then kept as part of your safety history until you ask us to delete your data.
Tasks and remindersDeleted 90 days after they are completed or cancelled.
Crisis referral recordsRetained as long as required for the legal reporting obligation described in 3.3.
Messaging consent and opt-out recordsRetained after you opt out, because we need them to prove we honoured your opt-out.
Google and Microsoft credentialsDeleted when you disconnect.

Note that opt-out records survive deletion by design. If you tell us to stop messaging you and we delete every trace of you, we lose the record that you asked us to stop.

9. Your choices and your rights

9.1 Stopping messages

Reply STOP to any message from Ember. You can also reply STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE, or OPT OUT, or simply say in your own words that you want the messages to stop. You will get one confirmation message and nothing after that.

A stop request applies to every number we message you from, not just the one you replied to.

Stopping messages is not the same as deleting your data. To delete, see 9.3.

9.2 Access

You can ask us for a copy of the personal information we hold about you. Email privacy@heyember.io.

9.3 Deletion

You can ask us to delete your personal information. Email privacy@heyember.io from a request that lets us verify you control the phone number. A member of our team handles each deletion request by hand.

We will delete your conversation history, the derived information about you, and your Google credentials if any. We will retain the narrow categories described in section 8 where the law requires it or where the record exists to protect you.

9.4 Correction

Ember's memory of you can be wrong. You can correct it in conversation โ€” tell Ember it has something wrong โ€” or email us.

9.5 Timing

We respond to requests within the time the law requires. Requests to stop messaging are honoured promptly and in any event within ten business days, as required by 47 CFR 64.1200(a)(10).

10. State privacy rights

10.1 California

If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect and how we use it, to delete it, to correct it, and to limit the use of sensitive personal information. You also have the right not to be discriminated against for exercising these rights โ€” we will not degrade Ember or charge you differently because you made a request.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA.

We collect information that the CCPA treats as sensitive personal information โ€” principally the contents of your messages, which may reveal health, sexual orientation, religious beliefs, or other sensitive characteristics. We use it only to provide the service, keep you safe, and improve Ember, as described in section 4.

10.2 Other states

Residents of other states with comprehensive privacy laws โ€” including Colorado, Connecticut, Virginia, Utah, Texas, and others โ€” have similar rights to access, delete, correct, and port their information, and to appeal a refused request. Email privacy@heyember.io and tell us which state you are in.

11. Security

We encrypt data in transit and at rest. Google account credentials are encrypted with a key derived separately for each user. Staff access to conversation content is restricted and logged.

No system is perfectly secure. Text messages in particular are not end-to-end encrypted โ€” they travel across carrier networks we do not control, and they sit in your phone's message history. Please do not send Ember information you cannot afford to have exposed.

12. Where your information is processed

We are based in the United States and process information there. Our service providers may process information in other countries. If you use Ember from outside the United States, you are sending your information to the United States.

Ember is intended only for people located in the United States (see our Terms of Service, section 2). If you are located anywhere else, do not use Ember.

13. Changes to this policy

We will update this policy as Ember changes. When we make a material change, we will update the date at the top and, where the change is significant, tell you by message.

14. Contact us

Heart & SOUL Technologies, Inc.

To stop receiving messages, reply STOP to any message from Ember.