Privacy Policy

What we collect, why we collect it, who touches it and how long we keep it. No surprises.

Version 2.0 - effective July 9, 2026

Who is responsible (controller)

Emberalis, a business registered in the Netherlands, is the controller for the processing of personal data described in this policy.

The short version: zero-knowledge

The content of your vault (passwords, PINs, wallets, files, messages, instructions) is encrypted on your device before it reaches our servers. We store only encrypted data and cannot decrypt it. This policy therefore mostly concerns the data around your vault: your account, billing, notifications and usage of the service.

What we collect, why, and on which legal basis

DataPurposeLegal basis (GDPR art. 6)
Name, email, phone number, password (hashed)Account creation, login, verification, notificationsPerformance of a contract (art. 6(1)(b))
Encrypted vault items and filesThe core service (we cannot read the content)Performance of a contract (art. 6(1)(b))
Emergency contact details (name, email, phone) that you enterNotifying your contacts during the emergency protocolLegitimate interest of you and your contacts (art. 6(1)(f))
Check-in history, activity log, login metadataRunning the proof-of-life protocol; security and audit trailPerformance of a contract; legitimate interest (security)
Billing details, payment historySubscription billing via Stripe; bookkeepingPerformance of a contract; legal obligation (art. 6(1)(c))
Pseudonymous product analytics (PostHog, EU)Understanding and improving the productLegitimate interest (art. 6(1)(f))
Marketing email engagement (Loops)Onboarding and product emailsConsent (art. 6(1)(a)); unsubscribe in every email

Data about your emergency contacts

When you add an emergency contact, you provide us with personal data of someone else (name, email address, phone number). You are responsible for informing them; we also inform them ourselves at the first moment we contact them (the invitation or an emergency notification), including a reference to this policy.

  • Contacts can decline an invitation, after which their details are removed from the active protocol
  • Contacts can exercise the same GDPR rights (access, erasure) via privacy@emberalis.com
  • Deleting your account also deletes all emergency-contact data you entered

Subprocessors and international transfers

We use the following processors. Where data leaves the European Economic Area, the listed transfer mechanism applies (EU Standard Contractual Clauses or an EU-US Data Privacy Framework certification). Vault content reaches none of them in readable form.

VendorPurposeRegionTransfer basis
Appwrite CloudBackend platform: database, authentication, file storageUnited States (NYC region)EU Standard Contractual Clauses (SCCs)
VercelApplication hosting, edge network and cron schedulingGlobal edge, primary EU/USEU-US Data Privacy Framework / SCCs
StripePayments and subscription billingUnited States / European UnionEU-US Data Privacy Framework
TwilioSMS and WhatsApp delivery (phone verification, check-ins)United StatesEU-US Data Privacy Framework
ResendTransactional email (verification, check-ins, emergency alerts)United StatesEU Standard Contractual Clauses (SCCs)
LoopsMarketing and lifecycle emailUnited StatesEU Standard Contractual Clauses (SCCs)
SentryError tracking and cron monitoringUnited StatesEU-US Data Privacy Framework
PostHogProduct analytics (event tracking only, no feature flags)European Union (EU Cloud)Processed within the EU
LaunchDarklyFeature flagsUnited StatesEU-US Data Privacy Framework
ArcjetRate limiting, bot detection and disposable-email blockingUnited StatesEU Standard Contractual Clauses (SCCs)

The same list, with more detail, is maintained in our Trust Center. We announce subprocessor changes in the changelog below.

How long we keep your data

  • Account and vault data:until you delete your account. Deletion is self-service (Settings > Delete my account), executed after a 14-day grace period, well within 30 days.
  • Invoices and payment records: 7 years (Dutch statutory bookkeeping obligation); kept at Stripe.
  • Data exports: the downloadable archive expires after 48 hours or 3 downloads and is then removed.
  • Error logs and diagnostics: at most 90 days, with PII scrubbed before they are stored.
  • Marketing contact: until you unsubscribe or delete your account.
  • After account deletion: an anonymized deletion record (dates and plan only, no personal data) is kept for accountability.

Your rights

Under the GDPR you can exercise the following rights, free of charge:

  • Access & portability:download a complete copy of your data yourself via Settings > Privacy (art. 15 and 20)
  • Erasure:delete your account and all data yourself via Settings > Delete my account (art. 17)
  • Rectification: correct your profile details directly in Settings (art. 16)
  • Objection & restriction: object to processing based on legitimate interest, such as analytics (art. 18 and 21), via privacy@emberalis.com
  • Withdraw consent: unsubscribe from marketing email at any time via the link in each email

Not satisfied with how we handle your data or your request? You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or the supervisory authority of your own EU member state.

Cookies and tracking

  • Strictly necessary: a session cookie for login and a login-indicator cookie; no consent required
  • Analytics: PostHog event tracking (pseudonymous, hosted in the EU, no advertising or cross-site tracking)
  • We do not sell personal data and we do not run third-party advertising

Age requirement

Emberalis is not intended for children. You must be 16 years or older to create an account (GDPR art. 8 as applied in the Netherlands). Registration includes a declaration that you meet this requirement; we do not collect dates of birth to verify it. If we learn that an account belongs to someone under 16, we will delete it.

Changes to this policy

Every change to this policy gets a new version number and a changelog entry below. Material changes (new purposes, new categories of data, new subprocessors that touch personal data) are announced by email before they take effect.

VersionDateChange
2.0July 9, 2026Complete GDPR article 13 rewrite: controller identity, legal bases per purpose, named subprocessors with transfer mechanisms, concrete retention periods, complaint right, emergency-contact data category and the 16+ age requirement.
1.0December 1, 2025Initial privacy policy.

Contact us

Questions about this policy or your data? Email privacy@emberalis.com or use the contact page. For how we secure the platform, see the Trust Center.