Privacy Policy
Effective date: August 31, 2026. This Policy explains how Sounds & Sirens LLC ("Emberel," "we," "us," or "our") handles personal information when you use Emberel's websites, applications, messaging channels, and related services.
Emberel is ad-free. We do not sell personal information, share it for cross-context behavioral advertising, or use advertising trackers.
1. Information we collect
- Account and profile information: email address, display name, password hash, account status, preferences, time zone, and a phone number if you add one.
- Your content: Sparks, reminders, tasks, notes, checklists, links, tags, files, voice recordings and transcripts, photos and OCR results, email or SMS captures, and the dates, people, places, and other details contained in them.
- Connected-service information: Google account identifiers, encrypted authorization tokens, Calendar and Tasks data you choose to sync, and connection and sync status.
- Billing information: plan, subscription status, billing period, and Stripe customer and subscription identifiers. Stripe processes your payment details; Emberel does not store full card numbers.
- Communications and consent: support messages, delivery history, notification settings, SMS consent and opt-out records, and inbound or outbound message metadata.
- Technical and security information: session identifiers, login attempts, device and push tokens, request and error information, IP-derived security signals, and activity needed to prevent abuse and operate the Service.
2. Where information comes from
We receive information directly from you; automatically when you use the Service; from integrations you connect; from Stripe when you purchase a subscription; and from communications providers when they deliver email, SMS, or push notifications.
3. How we use information
- provide, personalize, and maintain the Service;
- parse, transcribe, organize, search, sync, and resurface your content;
- deliver reminders, account messages, and requested communications;
- process subscriptions and provide customer support;
- protect accounts, investigate abuse, and enforce our Terms;
- debug failures, measure reliability, and improve features; and
- comply with law and protect our users, Emberel, and others.
4. AI processing
Emberel uses Cloudflare Workers AI to interpret captures, transcribe voice, read photos through OCR, and answer questions from your own data. We send only the content needed for the feature you request. Cloudflare states that it does not use Workers AI customer content to train AI models or improve its or third-party services without explicit consent. Emberel does not use your private content to train a model for other customers.
5. When we disclose information
We disclose information only as described here:
- Cloudflare: application hosting, database and file storage, email delivery, security, and Workers AI processing.
- Stripe: checkout, subscription management, and payment processing.
- Twilio: SMS and WhatsApp delivery when those features are enabled. Mobile opt-in and consent information is not shared for marketing.
- Google and Firebase: Google sign-in, optional Calendar and Tasks sync, and optional mobile push delivery.
- At your direction: integrations, assistants, recipients, or other destinations you choose.
- Legal and safety: when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or the integrity of the Service.
- Business transaction: in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice requirements.
Service providers may process information only to provide contracted services and under their applicable agreements with us.
6. Cookies and similar technology
The app uses essential cookies for sign-in, OAuth state, security, and preferences. These are required for requested functionality. We do not currently use advertising cookies, cross-site behavioral tracking, or a third-party audience analytics beacon.
7. SMS and communication choices
The SMS campaign was approved on September 2, 2026. SMS sending and new mobile-number setup remain disabled pending controlled activation tests. After activation, you may opt in only through your signed-in account by adding a mobile number in Settings and checking the separate express-consent box, which is optional and unchecked by default. A first inbound text from the saved number verifies control; it is not a separate opt-in method, and Emberel does not support keyword-based initial enrollment. See our SMS Consent & Messaging Policy for the exact language, steps, and staged public evidence of the protected control. Messages include user-requested capture confirmations, reminders, summaries, and account notices; message frequency varies and message and data rates may apply. Consent is not a condition of purchase. Reply STOP to opt out, START to opt back in after opting out, or HELP for help. Emberel keeps an immutable consent history tied to your account and mobile number, including the disclosure version, consent, number changes or removal, and STOP/START events; that history is removed when you delete your account. Text messaging originator opt-in data and consent are never shared with or sold to third parties or affiliates for marketing or promotional purposes; Twilio receives only the information needed to deliver messages requested by the user.
8. Retention
We keep active account information and content while your account is active and as needed to provide the Service. Current automated retention rules include:
- Deleted items and attachment records: recoverable for 30 days, then eligible for a bounded scheduled purge. The threshold is not a guaranteed hard-deletion timestamp.
- AI run, notification delivery, and hashed SMS retry-receipt records: eligible for scheduled purge after 90 days.
- Inbound email retry copies: raw mail is deleted after the capture is accepted. A failed copy becomes eligible for the Email Worker’s daily cleanup after 30 days; backlog or a missed provider run can extend that timing.
- Expired authentication tokens and login-attempt records: eligible for scheduled cleanup after 30 days; sessions expire at their recorded deadline and are removed by cleanup.
- Generated account-export files: become eligible for scheduled cleanup after seven days.
- Account deletion: after any active Stripe subscription is successfully canceled, the self-service flow removes user-scoped D1 records and attempts stored-file deletion on a best-effort basis. A provider failure can require follow-up or lifecycle cleanup. Limited records may be retained when required by law, to resolve disputes, or to prevent fraud.
Backups and provider systems may retain limited residual copies for a short period under their security and retention processes.
9. Security and breach response
We use administrative, technical, and physical safeguards appropriate to the size and nature of the Service. These include TLS in transit, provider-managed encryption at rest, salted password hashing, field-level encryption for sensitive integration tokens, access controls, request validation, and tenant-scoped data access. No system is completely secure.
If a breach affects information protected by applicable notification law, we will investigate and provide notices to affected people and authorities as required.
10. Your choices and privacy requests
Regardless of where you live, you may ask to access, correct, export, or delete personal information associated with your account. You can update many preferences, export your data, disconnect Google, and delete your account from Settings. You may also email support@emberel.com. We may verify your identity before completing a request and may deny or limit a request where law permits.
11. Children
Emberel is intended for adults and account holders must be at least 18. The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Contact us if you believe a child provided information so we can investigate and delete it.
12. Processing locations
Emberel and its service providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. We rely on provider contractual and security safeguards as applicable.
13. Changes to this Policy
We may update this Policy as Emberel changes. We will post the new effective date and provide additional notice before a material change when required by law.
14. Contact
Sounds & Sirens LLC
Mount Vernon, NY 10552, United States
support@emberel.com