Privacy Policy
Emberis helps organizations preserve and query their own reasoning. Because we work with sensitive company knowledge, being clear and honest about data is core to the product, not an afterthought. This policy explains what we collect, why, and the choices you have.
1. Who this applies to
This policy covers visitors to our website and users of the Emberis application. Where an organization is our customer, that organization is the controller of the workspace data it connects, and Emberis acts as a processor handling that data under the customer's instructions.
2. Information we collect
- Account information: name, work email, organization name, and role, provided when you sign up or request access.
- Workspace content you connect: documents, messages, tickets, code activity, and meeting records you or your organization choose to sync from tools such as Slack, Gmail, GitHub, Notion, Jira, ClickUp, and similar sources, used solely to build and operate your organization's reasoning graph.
- Usage data: log data, device and browser information, and how you interact with the product, used to keep the service secure and improve it.
- Billing information: processed by our payment provider (Stripe). We do not store full card numbers on our systems.
- Communications: messages you send us, including demo requests and support.
- Cookies: strictly necessary and analytics cookies to run and improve the site and app.
3. How we use information
- To provide, operate, and secure the Emberis service.
- To extract decision reasoning and build the coverage and answers you ask for.
- To process payments, manage subscriptions, and prevent fraud.
- To respond to requests, provide support, and send service communications.
- To improve the product and develop new features, using aggregated or de-identified data where possible.
4. AI processing and your content
Emberis uses AI models to extract and answer from your reasoning. We do not use your organization's private workspace content to train shared or third-party foundation models. Where we use third-party model providers to process a request, they act as sub-processors under contractual confidentiality and data-protection terms, and process content only to return your result.
5. Legal bases (EEA/UK)
Where GDPR applies, we process personal data on the bases of contract (to provide the service you request), legitimate interests (to secure and improve the service), consent (where required, e.g. certain cookies), and legal obligation.
6. How we share information
We do not sell your personal data. We share it only with:
- Service providers / sub-processors: cloud hosting, payment processing (Stripe), analytics, and AI model providers, each bound to protect the data.
- Within your organization: according to the roles and permissions your administrators set.
- Legal and safety: where required by law or to protect rights, safety, and the integrity of the service.
- Business transfers: in connection with a merger, acquisition, or asset sale, with notice where required.
7. Data retention
We keep personal and workspace data for as long as your account is active or as needed to provide the service, then delete or de-identify it within a commercially reasonable period, unless a longer period is required by law. Customers can request deletion of their workspace data on termination.
8. Security
We protect data with encryption in transit and at rest, role-based access controls, tenant isolation, and employee-controlled privacy settings. No method of transmission or storage is perfectly secure, but we work to protect your information and to be transparent if something goes wrong.
9. International transfers
Data may be processed in countries other than your own. Where required, we use appropriate safeguards such as Standard Contractual Clauses for such transfers.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object or withdraw consent. To exercise these rights, contact founder@emberis.ai. California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them; we do not sell personal information.
11. Children
Emberis is a business product not directed to children and is not intended for anyone under 18.
12. Changes to this policy
We may update this policy from time to time. We will change the “last updated” date above and, for material changes, provide additional notice.
13. Contact
Questions or requests: founder@emberis.ai.