Privacy Policy
Effective date: July 15, 2026. This Policy explains how Sounds & Sirens LLC ("Emberel," "we," "us," or "our") handles personal information when you use Emberel's websites, applications, messaging channels, and related services.
Emberel is ad-free. We do not sell personal information, share it for cross-context behavioral advertising, or use advertising trackers.
1. Information we collect
- Account and profile information: email address, display name, password hash, account status, preferences, time zone, and a phone number if you add one.
- Your content: Sparks, reminders, tasks, notes, checklists, links, tags, files, voice recordings and transcripts, photos and OCR results, email or SMS captures, and the dates, people, places, and other details contained in them.
- Connected-service information: Google account identifiers, encrypted authorization tokens, Calendar and Tasks data you choose to sync, and connection and sync status.
- Billing information: plan, subscription status, billing period, and Stripe customer and subscription identifiers. Stripe processes your payment details; Emberel does not store full card numbers.
- Communications and consent: support messages, delivery history, notification settings, SMS consent and opt-out records, and inbound or outbound message metadata.
- Technical and security information: session identifiers, login attempts, device and push tokens, request and error information, IP-derived security signals, and activity needed to prevent abuse and operate the Service.
2. Where information comes from
We receive information directly from you; automatically when you use the Service; from integrations you connect; from Stripe when you purchase a subscription; and from communications providers when they deliver email, SMS, or push notifications.
3. How we use information
- provide, personalize, and maintain the Service;
- parse, transcribe, organize, search, sync, and resurface your content;
- deliver reminders, account messages, and requested communications;
- process subscriptions and provide customer support;
- protect accounts, investigate abuse, and enforce our Terms;
- debug failures, measure reliability, and improve features; and
- comply with law and protect our users, Emberel, and others.
4. AI processing
Emberel uses Cloudflare Workers AI to interpret captures, transcribe voice, read photos through OCR, and answer questions from your own data. We send only the content needed for the feature you request. Cloudflare states that it does not use Workers AI customer content to train AI models or improve its or third-party services without explicit consent. Emberel does not use your private content to train a model for other customers.
5. When we disclose information
We disclose information only as described here:
- Cloudflare: application hosting, database and file storage, email delivery, security, and Workers AI processing.
- Stripe: checkout, subscription management, and payment processing.
- Twilio: SMS and WhatsApp delivery when those features are enabled. Mobile opt-in and consent information is not shared for marketing.
- Google and Firebase: Google sign-in, optional Calendar and Tasks sync, and optional mobile push delivery.
- At your direction: integrations, assistants, recipients, or other destinations you choose.
- Legal and safety: when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or the integrity of the Service.
- Business transaction: in connection with a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice requirements.
Service providers may process information only to provide contracted services and under their applicable agreements with us.
6. Cookies and similar technology
The app uses essential cookies for sign-in, OAuth state, security, and preferences. These are required for requested functionality. We do not currently use advertising cookies, cross-site behavioral tracking, or a third-party audience analytics beacon.
7. SMS and communication choices
You opt in only through your signed-in account by adding a mobile number at https://app.emberel.com/settings and checking the express-consent box, which is unchecked by default. A first inbound text from the saved number verifies control of that number; it is not a separate opt-in method. See our SMS Consent & Messaging Policy for the exact language, steps, and public screenshot. Messages include user-requested capture confirmations, reminders, summaries, and account notices; message frequency varies and message and data rates may apply. Consent is not a condition of purchase. Reply STOP to opt out, START to opt back in, or HELP for help at any time. We keep timestamped consent and opt-out records. Text messaging originator opt-in data and consent are never shared with or sold to third parties or affiliates for marketing or promotional purposes; Twilio receives only the information needed to deliver the messages requested by the user.
8. Retention
We keep active account information and content while your account is active and as needed to provide the Service. Current automated retention rules include:
- Deleted items and attachments: permanently removed after 30 days.
- AI run and notification delivery records: removed after 90 days.
- Expired authentication tokens and login-attempt records: removed after 30 days; expired sessions are removed after they lapse.
- Generated account-export files: removed after seven days.
- Account deletion: the self-service deletion flow removes the account, its content, integrations, credentials, and stored files immediately after any active Stripe subscription is successfully canceled. Limited records may be retained when required by law, to resolve disputes, or to prevent fraud.
Backups and provider systems may retain limited residual copies for a short period under their security and retention processes.
9. Security and breach response
We use administrative, technical, and physical safeguards appropriate to the size and nature of the Service. These include TLS in transit, provider-managed encryption at rest, salted password hashing, field-level encryption for sensitive integration tokens, access controls, request validation, and tenant-scoped data access. No system is completely secure.
If a breach affects information protected by applicable notification law, we will investigate and provide notices to affected people and authorities as required.
10. Your choices and privacy requests
Regardless of where you live, you may ask to access, correct, export, or delete personal information associated with your account. You can update many preferences, export your data, disconnect Google, and delete your account from Settings. You may also email [email protected]. We may verify your identity before completing a request and may deny or limit a request where law permits.
11. Children
Emberel is intended for adults and account holders must be at least 18. The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Contact us if you believe a child provided information so we can investigate and delete it.
12. Processing locations
Emberel and its service providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. We rely on provider contractual and security safeguards as applicable.
13. Changes to this Policy
We may update this Policy as Emberel changes. We will post the new effective date and provide additional notice before a material change when required by law.
14. Contact
Sounds & Sirens LLC
Mount Vernon, NY 10552, United States
[email protected]