Back to EmberLegal

Privacy Policy

Last updated · 2026-09-26Vũ Đăng CôngVietnam

Recent changes: This update clarifies measurement and advertising practices already in use, including Meta and TikTok pixels, app Meta and RevenueCat events, and account-linked usage and sync diagnostics. It also describes session performance measurement that Ember may begin with an internal test group. That measurement has not begun collecting data yet. The previous statement that Ember used no ad networks or only anonymous, aggregated metrics was inaccurate.

This Privacy Policy explains how Vũ Đăng Công ("Ember", "we", "us") collects, uses, and protects information when you use the Ember mobile app on iOS or Android, keepember.com, or the Ember web app at app.keepember.com.

Ember is a personal CRM that helps you remember people, dates, and the notes you keep about them. Your content syncs through the cloud with end-to-end encryption as described below.

01

Who we are

  • Vũ Đăng Công is an independent developer based in Vietnam and the operator of Ember.
  • Contact: hi@keepember.com.
02

What data we collect

  • Account: name and email received when you sign in with Apple, Google, or an email sign-in method. Existing accounts may also use a password. We request only the sign-in scopes described below.
  • Content you create: people you add, their details, dates, notes, tags, and groups; reminders and records of interactions.
  • Voice input and Keeper AI: speech you choose to transcribe, questions you ask, and the context needed to answer them.
  • Public Tarot questions: when you sign in to receive an interpretation, a question entered on the public Tarot page passes through the URL and may appear in browser history and server logs.
  • Device and diagnostic data: a push token if you enable reminders, app and operating system versions, device model, crash and error reports, sync diagnostics, and, when enabled, app performance measurements. The measurement section explains which records are linked to an account.
  • Usage: when you open the app, how long it stays open, screens visited from a fixed list, and counts of selected actions. These first-party usage records are linked to your account but do not contain your contacts, notes, journal entries, or Keeper conversation content.
  • Payments: Apple In-App Purchase or Google Play Billing handles payment. Ember does not receive your card details.
  • Optional location and contacts: a contact's city for weather, address text you enter for geocoding, optional birth-chart coordinates, and device contacts only when you choose to import them. Ember does not track your location in the background.
  • Website waitlist: if you join it, your email address and selected language.
03

How we use your data

  • To provide Ember, authenticate you, send reminders, sync your data when enabled, and answer requests you make to Keeper and other AI features.
  • To send service messages and messages you have chosen to receive.
  • To diagnose errors, understand use of the service, and measure and improve advertising as described below.
  • We do not use the content of your contacts, notes, journal, or Keeper conversations for advertising, and we do not sell that content. The advertising measurement section explains how website pixels and app events can be treated as sharing or selling under some laws.
04

Sign-in services

  • Google Sign-in: we receive your email, name, and profile picture. We do not access Gmail, Drive, Calendar, or other Google services. You may revoke access through your Google account.
  • Apple Sign-in: we receive your name and either your email address or Apple's private relay address if you choose to hide it.
  • Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
05

Third-party services

  • Supabase: database, authentication, and cloud storage in Singapore.
  • AI providers: OpenAI, Google Gemini, DeepSeek, and Anthropic Claude, sometimes routed through OpenRouter. We send the context needed for a feature you request. Each provider processes it under its own terms. Where supported, requests use a no-training or zero-retention setting. DeepSeek is based in China and may use received inputs under its policies.
  • Amazon Simple Email Service (Amazon SES) and Resend: send service and marketing emails. SES is the active primary provider for email campaigns and certain verification messages. Resend is the fallback for those routes and also sends some billing, lifecycle, and support emails directly.
  • Apple App Store and Google Play: app distribution, billing, and refunds.
  • RevenueCat: subscription and purchase status across the stores. It receives purchase history, an app user identifier, and device or platform information, but not payment card details. For refund requests, it may send the store your use of the subscription, lifetime app spend, and previous refund count; this does not include your contacts, notes, or journal.
  • WeatherAPI, Geoapify, and Photon / OpenStreetMap (Nominatim): optional weather and address services using the location or address information needed for your request.
06

Measurement, advertising, and diagnostics

  • On keepember.com: Google Analytics 4 (Google LLC, United States) counts page views and clicks on app-store links. Sensitive tokens are removed from page addresses before sending them, and Google's advertising storage is off on this site. Vercel Web Analytics and Speed Insights (Vercel Inc., United States) count page views and measure page speed without cookies. The Meta Pixel (Meta Platforms, Inc.), TikTok Pixel, and the OpenAI (ChatGPT Ads) Measurement Pixel tell those companies about page views and app-store link clicks; they may set their own cookies for ad measurement and audience creation. Meta's automatic form-field collection is off. The OpenAI Pixel's automatic advanced matching cannot be turned off: it detects supported identifiers, such as an email address, already on the page, hashes them in your browser, and sends only that hash. We do not deliberately send names, email addresses, phone numbers, or private app content as pixel event fields.
  • Your choice on keepember.com: in the EU and EEA, the United Kingdom, Iceland, Liechtenstein, Norway, and when we cannot determine your country, Google Analytics sends cookie-free requests and the Meta, TikTok, and OpenAI pixels wait until you allow measurement. Elsewhere, including Vietnam, analytics cookies and those pixels are on by default, with a notice and a way to decline. A cookie-free Google Analytics request can still carry your IP address as part of the network connection. Use "Analytics choices" at the bottom of a page to change your choice. The ember_analytics_consent cookie can remember it for up to one year. The Ember web app honours Global Privacy Control and Do Not Track; keepember.com does not currently respond to these signals, so use the "Analytics choices" link to decline.
  • On app.keepember.com: the regional consent rules cover Google Analytics, Meta Pixel, and TikTok Pixel, including authenticated pages. If measurement is declined or a consent decision is still required, these tools do not load there. Record identifiers are removed or shortened in page addresses before analytics events. When measurement is allowed, Google Analytics may also use advertising storage. The web app does not load these tools when your browser sends Global Privacy Control or Do Not Track. Public Tarot pages, including those opened at keepember.com/tarot, follow the same web app consent rules and may load Google Analytics, Meta Pixel, and TikTok Pixel.
  • In the mobile app, Firebase Analytics (Google LLC, United States) records screen views with record identifiers removed and counts selected actions. It uses a random app-instance identifier, is not attached to your Ember account, and does not use the device advertising identifier.
  • The Meta SDK in the mobile app reports installs and opens, completed sign-up, views of the subscription screen, purchase starts, completed paid Tarot readings, and counts of selected contact, reminder, journal, Keeper, and Insight actions. Insight events identify the system used, not the result. We do not send names, emails, phone numbers, or the content of those actions as event fields. On iOS, IDFA and Meta's anonymous identifier are used for ad matching only after you allow tracking through the iOS prompt. On Android, Meta's anonymous identifier is used for ad measurement. The current production configuration disables Android advertising ID collection.
  • RevenueCat to Meta Conversions API: trial starts, subscriptions, renewals, and purchases, including value, are reported to Meta for advertising measurement. On iOS, device matching identifiers are sent only after tracking permission is granted.
  • Ember's own usage statistics: app opens, time open, and visits to a fixed list of screens are linked to your account and kept for 180 days. Sync diagnostics, including timing, error information, and a device identifier, are also linked to your account to help fix sync problems. They currently have no active time-based deletion job and remain while the account exists. A server queue also holds account-linked app advertising measurement events for delivery and acknowledgement; no fixed retention period has been verified for it.
  • App performance measurements: Ember may begin measuring session performance with an internal test group and plans to extend this to all users with the next store release. For each session, the app may send launch and first-content timing, app and operating system versions, device model, memory, and a separate random installation identifier. The session record is designed without an account ID and without a stored IP address. Its 90-day retention limit depends on the daily deletion job being active; Ember will verify that job before the broader release.
  • Sentry (Functional Software, Inc., United States) receives crash and error reports with device model, operating system, app version, and recent screen names with record identifiers removed. Ember does not attach an account identifier. The project's IP scrubbing setting is currently off, so an IP address may be retained by Sentry under its settings.
  • In some places, including California, sharing data with advertising partners for ad measurement may count as "sharing" or "selling" personal information. You can decline website measurement as described above and deny iOS tracking when prompted.
07

Data retention

  • Account and synced content: retained while your account is active. Following an account deletion request, synced data and backups are removed within the periods described in the account deletion process, currently up to 30 days.
  • Account-linked app usage statistics: 180 days, or until account deletion if sooner.
  • Account-linked sync diagnostics: currently retained while the account exists. No active 90-day cleanup has been verified.
  • Server-side app advertising measurement queue: no fixed deletion period has been verified; account-linked rows are removed with the account.
  • Planned app performance sessions: if internal testing begins, the planned 90-day limit depends on an active daily deletion job. Ember will confirm the job before the measurement reaches all users in the next store release.
  • Data held by Google, Meta, TikTok, OpenAI, RevenueCat, Sentry, and other providers follows each provider's own retention rules.
08

Your rights and choices

  • Access and portability: export your data from the app Settings. Rectification: edit your data in the app.
  • Deletion: use Settings > Data > Delete account, or contact hi@keepember.com if you cannot open the app.
  • Object or restrict processing, or request account-linked data deletion: email us at hi@keepember.com.
  • Withdraw Google or Apple sign-in authorization through your provider account.
  • Website measurement: use the "Analytics choices" link. On iOS, use Settings > Privacy & Security > Tracking to control app tracking permission.
  • The mobile app does not currently have a separate switch for Firebase Analytics, account-linked usage statistics, or app performance measurements. Contact us to request deletion of data linked to your account.
  • You may complain to your local data-protection authority.
09

Security

  • HTTPS protects data in transit; Supabase manages encryption at rest and row-level access controls.
  • Contacts, notes, journal entries, and other sensitive fields are encrypted on your device before cloud sync using keys Ember does not hold. Ember staff cannot read those encrypted fields. Account-level usage records and diagnostics remain visible to authorized operations. When you ask Keeper or another AI feature to process content, the needed context is decrypted on your device and sent to the AI provider. Plaintext AI request and response content in a temporary server queue is usually deleted within about one to two hours; failed jobs queued for retry may be retained for up to seven days.
  • Sign-in credentials are kept in secure device storage where applicable.
10

Children's privacy

Ember is not directed to children under 13 or the minimum age in their country. We do not knowingly collect their data, and we delete accounts we identify as belonging to children.

11

International transfers

Cloud data is hosted with Supabase in Singapore. Other service providers may process data in other countries, including the United States. Where required, cross-border transfers use Standard Contractual Clauses or other applicable safeguards.

12

Changes to this policy

  • 26 September 2026: This update clarifies measurement and advertising practices already in use, including Meta and TikTok pixels, app Meta and RevenueCat events, and account-linked usage and sync diagnostics.
  • We publish this clarification immediately because it describes measurement and advertising practices already taking place. App performance measurement is the one planned activity described here and may begin with an internal test group before the next store release.
  • When we update this policy, we change the "Last updated" date and explain recent changes on this page. If a future change requires advance notice or consent under applicable law, we will provide it before that change takes effect.
13

Contact

Questions about this policy or a data request? Email hi@keepember.com.