Ember — Privacy Policy
Last updated: August 24, 2026
Overview
Ember is designed to work without an account. We collect the minimum
data needed to run the service, and we never sell your data.
Data we collect
- Your library stays on your device — the video files,
transcripts, AI summaries, categories, search index, and source links Ember
stores are kept in local storage on your iPhone. They are not uploaded to a
library of ours and we cannot browse them. Ember does not sync your library
to iCloud.
- AI processing uses transient cloud requests — to build the
summary and search index for a saved video, Ember sends a compressed excerpt
of that video (or, for some sources, its public URL) and short text passages
from it to our processing gateway, which forwards them to AI providers
(currently Google Gemini via OpenRouter for analysis and OpenAI for search
embeddings). These requests are protected by Apple App Attest, are used only
to produce your result, and are configured for zero data retention — we do
not store your video, transcript, or summary on our servers, and providers
are not permitted to retain or train on them. For a personal-library item,
the finished summary and search index are stored only on your device.
- Shared folders are the server-storage exception — if you
create or join a shared folder, we store the folder name and invite code;
a random installation hash; the display name, generated-avatar settings,
optional 144-by-144 avatar photo, and subscription-expiry status you use in
shared folders; and, for each added item, its public source link, title,
platform, media type, duration, category, the adder's display name, AI
analysis data, and segment-search embeddings. This lets invited members see
the folder and rebuild the item on their own devices without repeating the
same AI work. We do not store the item's video or other media bytes on our
server. Removing an item deletes its shared item and analysis records;
deleting a folder deletes that folder's item, analysis, and membership
records.
- App and device identifiers — a random identifier generated by
the app, plus app version, language, and operating-system version. It is not
your Apple ID and does not identify you across other companies' apps. Apple's
App Attest and DeviceCheck are used to verify that requests come from a
genuine copy of Ember.
- Anonymous usage events — basic events such as app opens, a save
completing, a playback starting, or a search being run. We record the
length of a search query, never the query text itself, and never the
caption, transcript, summary, or link of any video you saved.
- Requests to the original platform — when you save a link,
Ember contacts the source platform (for example Instagram, YouTube, or TikTok)
directly from your device to fetch the video and its metadata. Those companies
see that request under their own privacy policies. We do not proxy it and we
do not log it.
What we don't do
- No account or sign-up is required; we do not collect your email or contacts.
If you use shared folders, we do store the display profile described above.
- No advertising SDKs, no cross-app tracking, and no App Tracking Transparency
prompt — because there is no tracking to ask about.
- We do not sell or share your data with third parties for marketing.
- We do not use your videos, transcripts, or summaries to train AI models,
and our AI providers are contractually barred from doing so.
Purchases
Subscriptions are processed by Apple. We use RevenueCat to check anonymized
purchase state (e.g. whether Ember Plus is active) to unlock features, keyed to
the same random identifier described above. We never see your payment details.
Storage limits and what deletion means
- The free plan keeps up to 30 saved items; deleting an item frees its slot.
Nothing is deleted automatically by Ember.
- If an Ember Plus subscription ends, shared folders you own become read-only
but are not deleted.
Data retention & deletion
Your personal library lives on your device, so deleting the app deletes that
local library. You can also delete individual videos, or use Privacy → Delete all
saved videos, at any time. Removing a shared item or deleting a shared folder
deletes the corresponding server records as described above. A shared display
profile can remain associated with the random installation hash after you leave a
folder; to request deletion of that profile or other server data that is not
available through the app, email us at the address below. Anonymous usage events
are tied to a random device identifier, not to your identity; that identifier is
abandoned when you delete the app. You can export your locally saved data as a
JSON file from Privacy → Export my data.
Contact
Questions? Email haeundaekiwi@gmail.com.