Privacy Policy
Last updated: 7 August 2026
Ember handles conversations between coaches and their clients, and some of what clients write is personal. That's exactly why this policy is short, plain, and honest — the same reasons the product exists. Questions: [email protected] (Handy Gunawan, sole trader, Indonesia — the operator of Ember).
The one-paragraph version
We store what the product needs to work and nothing more. We don't sell data, we don't run ad tracking, and we don't use your content to train AI. Coaches control their workspace and can delete it; a client's answers are visible to their coach — that's the product — and to nobody else.
What we store, and why
- If you just try the app (no account): your sandbox lives in your own browser's storage. It never reaches our servers.
- Coach accounts: your email, and a password hash if you use one (with "Continue with Google", Google confirms who you are and we store the email). Needed so you can sign in.
- Your workspace: the questionnaires you build, the names and contact details you enter for the people you work with, sends and their status. Needed so your work follows you across devices.
- Client answers: what a client types or picks when filling a form through their link. Stored so their coach can read it — that is the product's entire purpose. Answers can include sensitive things; we treat the whole category as sensitive.
- Billing: handled by Paddle (see below). We store your plan status, never your card.
What we deliberately don't do
- No selling or renting data. Ever.
- No advertising trackers, no cross-site cookies.
- No using your forms or your clients' answers to train AI models.
- No reading your workspace out of curiosity — access is limited to what's needed to run the service or what you explicitly ask us to look at (e.g. a support request).
Who processes data for us
- Supabase — database and sign-in infrastructure (hosted Postgres).
- Cloudflare — hosting and delivery, plus privacy-friendly, cookie-free traffic analytics.
- Paddle — our Merchant of Record. When you buy, Paddle collects your email, billing details, and payment method under Paddle's privacy policy.
- Google — only if you choose "Continue with Google", for the sign-in itself.
Clients: what your coach sees
If someone sent you a fill link: your answers go to the coach who sent it — no one else. You don't need an account, and we don't contact you. The link is private; anyone holding it can open that form, so treat it like a note meant for you. If you want your answers corrected or deleted, your coach can do it, or email us and we'll help.
Your rights
See it, export it, fix it, delete it — for anything we hold about you. Coaches can export from the app and delete their account (which deletes the workspace, including answers). For anything else, email [email protected] and it gets handled by a person, usually within a few days. If you're in the EU/UK, these map to your GDPR rights, including the right to complain to your local authority.
Security, plainly
Traffic is encrypted (HTTPS). Database access is locked per coach at the database layer, not just in the app. Client fill links use unguessable random ids, and the anonymous surface of our API can't list or browse anything. Payments never touch our servers. No system is unbreakable, but the defaults here were built cautious.
Changes
If this policy changes in a way that matters, we say so visibly (email or in-app), not silently. The date at the top is always current.