What we collect, why we collect it, who touches it and how long we keep it. No surprises.
Version 2.0 - effective July 9, 2026
Emberalis, a business registered in the Netherlands, is the controller for the processing of personal data described in this policy.
The content of your vault (passwords, PINs, wallets, files, messages, instructions) is encrypted on your device before it reaches our servers. We store only encrypted data and cannot decrypt it. This policy therefore mostly concerns the data around your vault: your account, billing, notifications and usage of the service.
| Data | Purpose | Legal basis (GDPR art. 6) |
|---|---|---|
| Name, email, phone number, password (hashed) | Account creation, login, verification, notifications | Performance of a contract (art. 6(1)(b)) |
| Encrypted vault items and files | The core service (we cannot read the content) | Performance of a contract (art. 6(1)(b)) |
| Emergency contact details (name, email, phone) that you enter | Notifying your contacts during the emergency protocol | Legitimate interest of you and your contacts (art. 6(1)(f)) |
| Check-in history, activity log, login metadata | Running the proof-of-life protocol; security and audit trail | Performance of a contract; legitimate interest (security) |
| Billing details, payment history | Subscription billing via Stripe; bookkeeping | Performance of a contract; legal obligation (art. 6(1)(c)) |
| Pseudonymous product analytics (PostHog, EU) | Understanding and improving the product | Legitimate interest (art. 6(1)(f)) |
| Marketing email engagement (Loops) | Onboarding and product emails | Consent (art. 6(1)(a)); unsubscribe in every email |
When you add an emergency contact, you provide us with personal data of someone else (name, email address, phone number). You are responsible for informing them; we also inform them ourselves at the first moment we contact them (the invitation or an emergency notification), including a reference to this policy.
We use the following processors. Where data leaves the European Economic Area, the listed transfer mechanism applies (EU Standard Contractual Clauses or an EU-US Data Privacy Framework certification). Vault content reaches none of them in readable form.
| Vendor | Purpose | Region | Transfer basis |
|---|---|---|---|
| Appwrite Cloud | Backend platform: database, authentication, file storage | United States (NYC region) | EU Standard Contractual Clauses (SCCs) |
| Vercel | Application hosting, edge network and cron scheduling | Global edge, primary EU/US | EU-US Data Privacy Framework / SCCs |
| Stripe | Payments and subscription billing | United States / European Union | EU-US Data Privacy Framework |
| Twilio | SMS and WhatsApp delivery (phone verification, check-ins) | United States | EU-US Data Privacy Framework |
| Resend | Transactional email (verification, check-ins, emergency alerts) | United States | EU Standard Contractual Clauses (SCCs) |
| Loops | Marketing and lifecycle email | United States | EU Standard Contractual Clauses (SCCs) |
| Sentry | Error tracking and cron monitoring | United States | EU-US Data Privacy Framework |
| PostHog | Product analytics (event tracking only, no feature flags) | European Union (EU Cloud) | Processed within the EU |
| LaunchDarkly | Feature flags | United States | EU-US Data Privacy Framework |
| Arcjet | Rate limiting, bot detection and disposable-email blocking | United States | EU Standard Contractual Clauses (SCCs) |
The same list, with more detail, is maintained in our Trust Center. We announce subprocessor changes in the changelog below.
Under the GDPR you can exercise the following rights, free of charge:
Not satisfied with how we handle your data or your request? You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or the supervisory authority of your own EU member state.
Emberalis is not intended for children. You must be 16 years or older to create an account (GDPR art. 8 as applied in the Netherlands). Registration includes a declaration that you meet this requirement; we do not collect dates of birth to verify it. If we learn that an account belongs to someone under 16, we will delete it.
Every change to this policy gets a new version number and a changelog entry below. Material changes (new purposes, new categories of data, new subprocessors that touch personal data) are announced by email before they take effect.
| Version | Date | Change |
|---|---|---|
| 2.0 | July 9, 2026 | Complete GDPR article 13 rewrite: controller identity, legal bases per purpose, named subprocessors with transfer mechanisms, concrete retention periods, complaint right, emergency-contact data category and the 16+ age requirement. |
| 1.0 | December 1, 2025 | Initial privacy policy. |
Questions about this policy or your data? Email privacy@emberalis.com or use the contact page. For how we secure the platform, see the Trust Center.