Ember

TRUST AND DATA

Privacy Policy

This policy explains what Ember collects, why it is needed and the controls available to people and companies using the service.

Last updated 12 September 2026

1. Who this policy covers

Ember is a workspace operating system provided by Ember Labs for project-based companies. A customer company controls the business records entered by its authorized members. Ember Labs operates the service and processes those records to provide the product.

2. Information we process

Depending on how Ember is used, the service may process:

  • Account details such as name, work email, company membership and role.
  • Company, client, contact, project, department and supplier records.
  • Briefs, deliverables, decisions, approvals, changes and audit history.
  • Commercial records including estimates, quotations, purchase orders and invoices.
  • Messages, approved reply content and attachments intentionally added to Ember.
  • Technical and security information needed to operate and protect the service.

3. Google account data

When a company administrator connects Google Workspace, Ember requests the gmail.send permission so authorized Ember users can send an approved project message from that connected mailbox. Ember does not request permission to read, modify or delete Gmail messages.

Ember stores the connected email address, granted permission, encrypted authorization token and the delivery result needed to operate and audit the connection. Google user data is used only to provide the user-facing email feature, protect it, maintain it and comply with applicable requirements. It is not sold, used for advertising or used to train general-purpose AI models.

Ember's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. How information is used

  • Provide, secure and support the customer's Ember workspace.
  • Apply company roles, permissions, approvals and automation rules.
  • Generate user-requested drafts and record approved delivery actions.
  • Diagnose failures, prevent abuse and maintain an accountable audit trail.
  • Communicate about the service and respond to support requests.

5. Sharing and service providers

Ember may use carefully selected providers for authentication, infrastructure, monitoring, connected email and other functions needed to deliver the service. Providers receive only the information needed for their function and are not permitted to use customer data for their own advertising. Information may also be disclosed when legally required or necessary to protect users and the service.

6. Company separation and security

Business records are scoped to the customer company. Ember uses role-based access, server-side authorization, encrypted transport, protected credentials, audit history, monitoring and backups. No online service can guarantee absolute security, so customers should assign access carefully and report suspected misuse promptly.

7. Retention and deletion

Information is retained for as long as needed to provide the workspace, preserve required business and audit records, resolve disputes and meet applicable obligations. A company administrator can disconnect Google Workspace at any time; Ember revokes the connection and removes the stored authorization token. Requests to access, correct, export or delete information can be sent through the support page.

8. Changes and contact

Material changes will be posted here with a revised date. Questions about this policy or Google data can be sent to [email protected].