Ember.Ember

Privacy Policy

Effective October 1, 2026EMBER Origin SAS

Article 1

Who We Are and What This Policy Covers

We are EMBER ORIGIN SAS, with a share capital of 1,000 euros, headquartered at 16 Place des Quinconces, 33000 Bordeaux, registered with the Bordeaux Trade and Companies Register under number 103 569 901 and identified for VAT purposes under number FR91103569901 ("We"). We publish and operate the Ember platform, accessible after authentication from the website www.ember.do (the "Website"), which allows You to use an AI-based strategic co-pilot to structure, manage and develop your professional activity (the "Platform"). We are committed to protecting your personal data and respecting your privacy when You use the Platform ("You"). This privacy policy describes how We collect, use, retain and protect information that directly or indirectly identifies You ("Personal Data"), in the context of: browsing the Website, creating and managing your user account, using the Platform's features, managing your subscription and payment methods, your communications with our support and all data generated or processed as part of your use of the Platform. The processing of your Personal Data is based on Regulation (EU) 2016/679 of April 27, 2016 (GDPR) and the amended French Data Protection Act. For any questions regarding this policy or the exercise of your rights, You may contact Us at: support@ember.do.

Article 2

What Personal Data Do We Process?

We only process the Personal Data necessary for browsing the Website, managing the forms made available to you, operating the Ember Platform and managing your subscription, as listed in Article 3. We never ask You to provide so-called "sensitive" data within the meaning of GDPR (for example: health data, political opinions, religious beliefs, ethnic origin, sexual orientation). If You voluntarily transmit this type of information on the Platform or in your communications with Us, this data is only processed to respond to your one-time request and is immediately deleted once it is resolved. All Personal Data processed as part of the Platform comes from information that You choose to enter. When registering, only your email address is required. You can then complete your profile or add information according to the features you use. You are free to provide only the data you wish; however, the absence of certain information may limit access to or quality of certain features. Personal Data is processed internally by authorized persons, within the limits of their respective duties.

Article 3

Why Do We Process Your Data and For How Long?

The table below summarizes, for each purpose, the categories of Personal Data concerned, the specific data processed, the applicable legal basis and the retention period.

Purpose
Early access requests and pre-registrations
Data Concerned
First name, last name, email, phone, country, sector, company, position
Legal Basis
Legitimate interest
Retention
3 years after last interaction
Purpose
Requests via website
Data Concerned
First name, last name, email, phone
Legal Basis
Legitimate interest
Retention
3 years after last request
Purpose
Security and Website operation
Data Concerned
IP, browser, language, pages visited, cookies, device
Legal Basis
Legitimate interest
Retention
13 months
Purpose
User account
Data Concerned
First name, last name, email, phone, photo, company, position, sector, country
Legal Basis
Contract performance
Retention
While account active + 13 months
Purpose
Account security
Data Concerned
IP, devices, sessions, logs
Legal Basis
Legitimate interest
Retention
13 months
Purpose
Platform usage
Data Concerned
Modules, entered data, preferences, AI recommendations
Legal Basis
Contract performance
Retention
While account active
Purpose
Subscription
Data Concerned
Plan, status, renewal
Legal Basis
Contract performance
Retention
Subscription duration
Purpose
Payment and billing
Data Concerned
Amounts, transactions, invoices
Legal Basis
Legal obligation
Retention
10 years
Purpose
Support
Data Concerned
Emails, messages, requests
Legal Basis
Contract performance
Retention
3 years after last request
Purpose
Platform improvement
Data Concerned
Paths, statistics
Legal Basis
Legitimate interest
Retention
13 months
Purpose
Security, fraud prevention
Data Concerned
Logs, suspicious behavior
Legal Basis
Legitimate interest
Retention
Up to 5 years
Purpose
Claims and disputes management
Data Concerned
Communications, documents, history
Legal Basis
Legitimate interest
Retention
5 years (limitation)
Purpose
Response to authorities
Data Concerned
Data requested by authority
Legal Basis
Legal obligation
Retention
Legal duration
Purpose
Management of your GDPR rights
Data Concerned
Email, proof of identity, requests
Legal Basis
Legal obligation
Retention
1 to 6 years
Purpose
Cookies and audience measurement
Data Concerned
Necessary cookies, statistics, approximate country/region derived from IP (IP address not retained)
Legal Basis
Consent / Legitimate interest
Retention
13 months

Article 4

Who Are Our Subcontractors and Recipients?

To provide the Platform, we use subcontractors within the meaning of Article 28 of the GDPR, bound by contracts compliant with the applicable regulations. Your application data is hosted within the European Union: the Platform database is operated by Supabase and hosted on AWS, Paris region (France). The table below presents our main recipients or categories of recipients, their role, their country and, for providers located outside the European Union, the safeguard governing the transfer (Standard Contractual Clauses of the European Commission, hereinafter "SCC", and/or adherence to the Data Privacy Framework, hereinafter "DPF").

Recipient or category
Generative artificial intelligence and routing providers
Role
Text, analysis and image generation, and request routing
Country
United States
Transfer safeguard
SCC and/or DPF depending on the provider
Recipient or category
Serper
Role
Web search for AI agents
Country
United States
Transfer safeguard
SCC
Recipient or category
Composio
Role
Connection to your Google account and other connected applications
Country
United States
Transfer safeguard
SCC and/or DPF
Recipient or category
Unipile
Role
LinkedIn connection (prospecting)
Country
France
Transfer safeguard
Not required (EU)
Recipient or category
FullEnrich
Role
Business contact enrichment (email address and phone number), at the user’s request
Country
United States
Transfer safeguard
SCC and/or DPF
Recipient or category
Supabase
Role
Database (hosted on AWS, Paris region)
Country
United States (data in EU)
Transfer safeguard
SCC and/or DPF
Recipient or category
Vercel
Role
Web application hosting
Country
United States
Transfer safeguard
SCC and/or DPF
Recipient or category
PostHog
Role
Product usage measurement and session replay with sensitive content masked
Country
United States (data hosted in the EU)
Transfer safeguard
SCC and/or DPF
Recipient or category
Railway
Role
AI engines hosting
Country
United States
Transfer safeguard
SCC
Recipient or category
Upstash
Role
Cache and processing queues
Country
United States
Transfer safeguard
SCC
Recipient or category
Stripe
Role
Payment and invoicing
Country
Ireland / United States
Transfer safeguard
SCC and/or DPF
Recipient or category
Resend
Role
Transactional emails
Country
United States
Transfer safeguard
SCC
Recipient or category
Brevo
Role
Transactional emails and campaigns
Country
France
Transfer safeguard
Not required (EU)
This information may change; the version in force is the one published on this page. The current list of providers, their locations and applicable safeguards is available upon request from joffroy@ember.do. For B2B clients, this list is also provided as part of the contractual framework and when it is updated. Data relating to prospects processed via the Lead Intelligence module is covered by dedicated information on the Prospect data and rights page.

Article 4.5

Google User Data (Gmail, Google Drive, Google Calendar)

You can connect your Google account to the Second Brain (the Ember Second Brain Google application). This article describes precisely how We access, use, store, share, protect, retain and delete Google user data. It applies in addition to the rest of this policy. Ember's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.5.1 Google data We access

Access only starts after You connect your Google account and approve the permissions on Google's consent screen. We request the following permissions, and no others:

  • Email address and basic profile (userinfo.email)To identify the Google account You connected and show it in your settings.
  • Gmail, read-only (gmail.readonly)To search and read the messages, threads and drafts that You ask the Second Brain to consult.
  • Gmail, draft creation (gmail.compose)To create or modify an email draft after your explicit confirmation. This permission technically also allows a draft to be sent. Ember's AI agent can never send an email: it only prepares drafts. A message is sent only if You yourself click Send in Ember's email compose window, when that function is enabled; it then requires the additional permission gmail.send, requested only in that case. Otherwise You send the draft yourself from Gmail.
  • Google Drive, read-only (drive.readonly)To search, list and read the metadata and content of the files You ask the Second Brain to consult, including Google Docs and Google Sheets documents.
  • Google Drive, files created or opened with Ember (drive.file)To create or modify, after your explicit confirmation, a file, a Google Docs document or a Google Sheets spreadsheet.
  • Google Calendar, read-only (calendar.readonly)To list your calendars and read the events that You ask the Second Brain to consult.
  • Google Calendar, events You own (calendar.events.owned)To create or modify, after your explicit confirmation, an event in a calendar You own.

4.5.2 How We use Google data

Google data is used only to provide the features that You request in the Second Brain and that are visible in its interface: answering a question about your emails, files or schedule, preparing an email draft, creating an event or a document. The agent can only use a reviewed list of Google actions. Every action that creates or modifies something in your Google account (draft, event, file, document) is only carried out after You have confirmed the exact account, destination and content. Google data is read when You make a request; Ember does not read it in the background and does not build a copy of your mailbox, your Drive or your calendar.

4.5.3 Who receives Google data

We do not sell Google data. We do not share it with any third party, except the following subcontractors, only as necessary to provide the feature You requested:

  • Composio (United States): technical connector that holds your Google authorization and relays our requests to Google APIs on your behalf.
  • The generative artificial intelligence and routing providers listed in Article 4: the content that the Second Brain read (for example the text of an email or a file) is sent to them so they can write the answer that You asked for.
  • Our hosting and database providers listed in Article 4, which store the conversation as described below.

We may also disclose Google data if the law requires it, to investigate a security issue or abuse, or with your explicit prior consent in the event of a merger or acquisition.

4.5.4 Limited Use commitments

Our use of Google user data complies with the Limited Use requirements of the Google API Services User Data Policy. In particular:

  • We only use Google data to provide or improve the user-facing features of the Second Brain that are visible in its interface.
  • We do not use Google data, nor any content obtained through Google APIs, to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
  • We do not sell Google data and do not transfer it to advertising platforms, data brokers or other information resellers.
  • We do not use Google data to serve advertising, including personalized, retargeted or interest-based advertising, nor for credit or lending decisions.
  • Our team does not read Google data, except with your explicit agreement to view specific messages, files or other data, when necessary for security purposes (for example investigating a bug or abuse), when required by applicable law, or when the data is aggregated and used for internal operations in accordance with applicable law.

4.5.5 Storage, protection and retention

Ember does not keep a separate copy of your Gmail, Drive or Calendar data. The content returned by Google for a request (limited in size) is placed in the conversation in which You made the request, and is stored with that conversation in our database hosted in the European Union, as a technical state of the conversation, for as long as the conversation exists. The long-term memory of the Second Brain is built from the exchanges in your conversations (your messages and Ember’s replies, which may summarize Google data You asked for), never from the raw results returned by Google. Google data is protected as described in Article 7: encryption in transit, access limited to those whose duties require it, separation of environments. Secret links and authorization credentials returned by Google are removed from results before they are transmitted to the model. Authorization tokens are held by Composio and are never shown to You or to the model.

4.5.6 Disconnection and deletion

You can disconnect your Google account at any time from the Second Brain settings (Integrations, then Disconnect). Disconnection immediately blocks any new access to your account, deletes the connection at Composio and deletes the connection records kept by Ember. You can also revoke Ember's access from your Google account permissions page (https://myaccount.google.com/permissions). Deleting a conversation deletes the Google content it contains. Deleting your Ember account disconnects all your connected applications, including Google, and deletes your conversations and data as described in Article 10. You can also contact us at support@ember.do to request the deletion of your data.

Article 5

Who Can Access Your Data?

Your Personal Data is accessible only to the following recipients, within the limits of their duties:

  • Our authorized internal teams, strictly within the scope of their duties (support, billing, maintenance, security)
  • Our technical subcontractors, acting on our behalf and under GDPR-compliant contracts (hosting, security services, payment tools, analytics tools, emailing, support)
  • Administrative or judicial authorities, when required by law or upon formal request
  • Ministerial officers or legal auxiliaries, in the context of debt collection
  • A potential acquirer or buyer, in the event of a transfer, merger or restructuring operation

Article 6

Is Your Data Transferred Outside the EU?

The majority of our subcontractors and service providers are established within the European Union, which guarantees a high level of protection for your Personal Data. However, certain technical services essential to the operation of the Platform may involve transfers of Personal Data outside the European Union, particularly when We use service providers located outside the EU or companies whose parent company is established in a third country (for example for hosting, sending emails, performance analysis or certain advanced features). When such transfers take place, We ensure that they are governed in accordance with current regulations, by means of one of the following guarantees: the signing of Standard Contractual Clauses adopted by the European Commission; the service provider's adherence to the Data Privacy Framework approved by the European Commission (for transfers to the United States); any other appropriate guarantee provided for by the GDPR. We only work with partners presenting strong guarantees in terms of security and confidentiality. You can obtain more information about our subcontractors and applicable guarantees by contacting Us at: support@ember.do.

Article 7

How Do We Protect Your Data?

We implement technical and organizational measures designed to ensure the security and confidentiality of your Personal Data. These measures aim to prevent any loss, destruction, unauthorized access, disclosure or alteration of your data.

  • encryption of data in transit (HTTPS/TLS)
  • separation of technical environments according to access levels
  • strict management of internal authorizations, limited to only those whose duties require it
  • enhanced access controls for Platform administration
  • continuous monitoring of the infrastructure to detect any anomalies or suspicious activities
  • regular backups to ensure service continuity
  • GDPR-compliant subcontracting agreements, including security and confidentiality guarantees

Article 7.5

We also carry out regular updates of our systems and security tools to maintain a high level of protection. In the event of a security incident, identified threat or vulnerability situation, We may take the following measures: quickly identify the problem using our monitoring tools; temporarily suspend all or part of the service to avoid greater damage; correct technical flaws and strengthen our systems; inform You if your Personal Data is directly affected by the incident; cooperate with the competent authorities if necessary to manage the situation. We are committed to responding quickly and appropriately to protect your Personal Data and limit the consequences of any security incident. In the event of a Personal Data breach presenting a high risk to your rights and freedoms, We undertake to inform You as soon as possible and to notify this breach to the CNIL within 72 hours of its discovery, in accordance with the GDPR.

Article 8

What Are Your Rights?

You have, under the conditions provided for by the applicable regulations, the following rights over Your Personal Data:

Right of access

You can obtain confirmation that Personal Data concerning You is or is not being processed and, when it is, receive a copy of it, as well as information on the main characteristics of the processing (purposes, categories of Data, recipients, retention period).

Right to rectification

You may request correction or update of inaccurate or incomplete Data concerning You.

Right to erasure

You may request erasure of all or part of Your Personal Data, in the cases provided for by the GDPR.

Right to restriction

You may request restriction of the processing of Your Data in certain situations (contesting accuracy, unlawful processing, etc.).

Right to object

You may object, for reasons relating to Your particular situation, to processing based on Our legitimate interest.

Right to portability

You may receive the Personal Data that You have provided to Us, in a structured, commonly used and machine-readable format, or request their transmission to another data controller when technically feasible.

Article 8.5

You may also define directives regarding the fate of Your Personal Data after Your death (retention, erasure and, where applicable, communication of this data).

Article 9

How to Exercise Your Rights?

You may exercise Your rights at any time by contacting Us at: support@ember.do. We process Your requests free of charge, except in the case of manifestly unfounded or excessive requests. We will respond to You within a maximum period of one month from their receipt. This period may be extended by two months in the case of complex requests or a multiplicity of requests; in this case, We will inform You of this extension and the reasons for the postponement. When We have reasonable doubt about Your identity, We may ask You for additional information or proof of identity to verify that the request indeed comes from the data subject or their authorized representative. When the processing of Your Data is based on Your consent, You may withdraw this consent at any time by contacting Us at the same address. The withdrawal of Your consent does not affect the lawfulness of processing carried out before this withdrawal. If You believe, after contacting Us, that Your rights are not being respected, You may file a complaint with the CNIL (www.cnil.fr) or seize a competent court.

Article 10

What Happens When You Delete Your Account?

When You delete Your account from Your user area, all of Your Personal Data and Your content are permanently deleted from the Platform.

1. Total and irreversible deletion of Your Data

Account deletion results in the immediate and irreversible deletion of: Your identification information (email, profile), Your content and data entered on the Platform, Your settings and preferences, Your internal histories related to the use of the service, Your communications with support related to Your use of the Platform.

2. Retention limited to legal obligations

All Personal Data and content that You have entered on the Platform are permanently deleted when Your account is deleted. We only retain data strictly necessary to comply with Our legal obligations, including: billing data (retained for 10 years), data necessary for managing any litigation. This data is isolated, secured and not used for other purposes. No other Personal Data is retained after account deletion.

3. Immediate effects

Deleting Your account: immediately terminates Your access to the Platform, cannot be canceled or reversed.

Article 11

How Do We Manage Cookies?

11.1 Trackers used on the Website

When You browse the Website, We only use:

  • 1. Cookies necessary for Website operationThey allow to: maintain your session, remember your language preferences, ensure the general security of the Website. These trackers are essential and do not require your consent.
  • 2. Cookies intended to improve Website performanceThey optimize loading, stability and page display. They do not allow tracking your navigation outside the Website.
  • 3. Website usage analysis with consentWith Your consent, We use Google Analytics, Ember internal measurement, and PostHog to understand pages and sections viewed, general interactions, active time, and entry into the Platform. This data is used only to improve the Website and product. It is not used for advertising.

11.2 Trackers used on the Platform

When You are connected to the Platform, We use essential technical cookies and, with Your consent, product usage measurement trackers.

  • 1. Strictly necessary cookiesThese cookies are essential to ensure the Platform operates. They allow in particular to: maintain your user session, remember certain preferences (such as your language), ensure security and control access to features. These cookies do not require your consent as they are essential to the use of the Platform.
  • 2. Platform usage measurement with consentWith Your consent, PostHog links usage events to Your account to understand journeys, active time, technical blockers, and abandonment. Session replay may be enabled in Second Brain, Lead Intelligence, and Deck Studio. Form fields, conversations, documents, prospect data, and slide content are masked or excluded. You can change Your choice at any time using the cookie settings button.

11.3 No advertising or tracking cookies

We do not use any cookies intended to: display personalized advertising, track your activity on other sites, establish a commercial profile.

Article 12

Can This Policy Change?

Yes, We reserve the right to modify or update this privacy policy at any time. We will inform Platform users by email and by publishing the updated version directly within the Platform. Any modification will take effect as soon as it is published online. Your continued use of the Platform after the publication of a new version constitutes acceptance of this policy as modified. In certain situations (for example, if We wish to use your Personal Data for purposes different from those indicated at the time of collection), when necessary, We will inform You personally and/or seek your agreement before proceeding with the processing.

Article 13

How to Contact Us?

Your questions, comments and requests regarding this privacy policy are welcome and should be addressed to: support@ember.do

Need Help?

For any questions regarding your personal data, contact us:

support@ember.do

06 20 82 52 88

EMBER Origin SAS16 Place des Quinconces33000 BordeauxFrance

Your next decision can start here.

Describe your priority. Ember helps you move forward.