Privacy & Security

Ember is local-first and private by design. We can't read your journal — not as a promise, but as a technical reality. Here's what that means and how to lock the app down further.

Local-first, no account

Everything you write lives on your device using Apple's storage. There is no Ember server, no Ember database, and no account to create — no email, no login, no sign-up. When you sync, your data flows only through your iCloud account (see Sync & Backup).

We structurally cannot access your entries, the people you track, or your stories. There's nothing for us to read.

App lock

You can lock Ember behind Touch ID, Face ID, or your device passcode. Turn it on in Settings, then:

  • Lock instantly any time with ⌘⌃L when you step away.
  • Ember re-locks automatically when it moves to the background, and on an idle timeout you choose.
  • While locked, menu actions — creating, searching, importing, exporting, navigating — are disabled until you unlock.

Biometrics are handled entirely on-device by Apple's Secure Enclave. Ember only ever receives a yes/no result — never your fingerprint or face data.

Screenshot: the lock screen / Settings lock options
Shield the window in a keystroke.

What leaves your device

Ember uses minimal, privacy-friendly analytics to understand which features are used and to catch crashes — never your content. Events carry only structural data: counts (bucketed, never exact), enum tokens, booleans, durations, screen names, and error codes. The following are technically blocked from ever being captured:

  • Names of people, worlds, tags, or stories
  • Journal text, interaction notes, or any free-form writing
  • Search queries, photos, media, phone numbers, birthdays, or locations

Crash reports include a technical stack trace (function and framework names only) so we can fix bugs — never your journal content. Analytics use a random, anonymous identifier; there's no advertising ID and no cross-app tracking.

The complete details are in the Yours to keep Privacy Policy.

Deleting everything

If you use iCloud sync, deleting content in Ember also removes it from your iCloud across your devices. To erase Ember's whole iCloud copy at once, go to System Settings → Apple Account → iCloud → Manage Storage and delete Ember's data there. Uninstalling the app removes everything stored locally.