← Back to Ember
Privacy Policy
Your journal is private. We built the architecture to guarantee it.
Effective date: September 13, 2026 · Last updated: September 24, 2026
This Privacy Policy explains how Ember ("we," "us," "our") - a relationship-journaling app for macOS - collects, uses, and protects your information. Ember is developed and operated by a sole developer with no investors, no advertising partners, and no interest in your personal data.
We designed Ember from the ground up as a local-first, privacy-first application. We cannot read your journal entries, see the people you track, or access your stories. This is not a promise - it is a technical reality.
Privacy at a Glance
Local-first storageAll your data lives on your device
Your iCloud, your keysSync uses your private Apple account
No Ember serversWe never receive your content
No account requiredNo email, no login, no sign-up
Minimal analyticsAnonymous, structural events only
Full data exportTake everything with you, anytime
1. Data You Create in Ember
Everything you write, log, or attach in Ember is your content. This includes:
- People - names, nicknames, phone numbers, locations, birthdays, photos, custom attributes, "how we met" notes, and relationship settings (world membership, intention, decay preferences)
- Journal entries - text, dates, @-mentions of people, #tags, ~world references, &story links, attached images, voice recordings, and optional location pins
- Stories - multi-chapter narratives with text, images, songs, and people references
- Interactions - logged contact events with people, including medium (call, text, in-person, etc.), duration, presence scores, and optional notes
- Worlds - named life-context groups (Work, Family, Personal, etc.) with color and decay settings
- Tags - user-created labels for organizing entries
- Connections - explicit links between two people you've defined
- Graph layouts - the positions of nodes on your relationship graph
Where this data lives: All content is stored locally on your device using Apple's SwiftData framework. There is no Ember server, no Ember database, and no Ember-operated cloud. We structurally cannot access this data.
2. iCloud Sync
If you are an Ember subscriber, your data syncs across your Apple devices using Apple's CloudKit (CKSyncEngine). This means:
- Data flows directly between your devices and your personal iCloud account
- Sync is handled entirely by Apple's infrastructure - Ember has no intermediate servers
- Your data is encrypted in transit and at rest under Apple's iCloud security architecture
- We have no ability to read, access, or decrypt your synced data
- You can disable iCloud sync for Ember at any time in your device's system settings
For details on how Apple protects your iCloud data, see Apple's iCloud data security overview.
3. Analytics & Usage Data
We use PostHog, a product analytics platform, to understand how Ember is used at a structural level - which features are adopted, where flows are abandoned, and whether something is broken. This helps us improve the app.
What we collect
- App lifecycle events - app launched, app locked/unlocked, demo started/completed
- Feature usage signals - which screens are visited, which palette modes are opened, whether the graph or timeline is explored
- Creation counts (bucketed) - e.g. "user has 4–10 people," never the exact number
- Error and reliability data - sync failures, save errors, graph rendering issues (error codes and domains only, with all descriptions sanitized to strip personal data)
- Crash reports - if the app crashes, PostHog's crash reporting records the technical crash type (e.g. a signal or exception) and a stack trace of the code paths involved. Stack traces contain only function, type, and framework names - never your journal entries, people, or any content you create
- Subscription events - purchase started, completed, or cancelled (plan type only)
- Enum tokens - structural values like interaction medium ("call", "text"), relationship intention ("Tending", "Rooted"), screen names, sort/filter selections
What we NEVER collect
We enforce an absolute rule in our analytics code: events may only carry counts, enum tokens, booleans, durations, screen names, and error codes. The following are explicitly prohibited and technically blocked from capture:
- Names of people, worlds, tags, or stories
- Journal entry text, interaction notes, story content, or any free-form text
- Search queries you type
- Photos, media files, or any content bytes
- Phone numbers, locations, birthdays, or custom attributes
- "How we met" descriptions or any user-typed labels
- Entity UUIDs that could identify specific records
- File paths containing your username or content
- Your email address, Apple ID, or any personally identifying information
- GPS coordinates or place names from journal location pins
Identity & tracking
Ember has no user account system. There is no sign-up, no login, and no email collection. Analytics are recorded using a random, anonymous device identifier generated by PostHog. We never call PostHog's identify function with any personal information. We do not use advertising identifiers (IDFA), and we do not participate in any cross-app tracking or advertising network.
PostHog processes analytics data on servers in the United States. For PostHog's own privacy practices, see PostHog's Privacy Policy.
4. Apple Music Integration
Ember allows you to search and embed songs from the Apple Music catalog into journal entries and stories. This feature:
- Uses Apple's MusicKit framework to search the public Apple Music catalog
- Does not access your personal Apple Music library, playlists, or listening history
- Stores only the song metadata you choose to embed (title, artist, album art, preview URL) locally on your device
- We never see which songs you search for or embed - search queries go directly to Apple
5. Biometric Authentication
Ember supports optional app locking using Touch ID, Face ID, or your device passcode via Apple's LocalAuthentication framework. This is processed entirely on-device by Apple's Secure Enclave. Ember never receives, stores, or transmits your biometric data - it only receives a boolean success/failure result from the operating system.
6. Location Data
Ember allows you to optionally attach a location to journal entries. This is:
- Never automatic - you must explicitly tap a button and choose to add a location
- Stored locally on your device (and synced via your iCloud if sync is enabled)
- Never sent to Ember - we do not operate any location-processing servers
- Never included in analytics - GPS coordinates and place names are explicitly excluded from all analytics events
You can remove the location from any entry at any time.
7. Photos & Media
Images, voice recordings, and other media you attach to journal entries or stories are:
- Stored in the app's local sandboxed storage (Application Support directory)
- Synced via your iCloud account if cloud sync is enabled
- Never uploaded to any Ember server or third-party service
- Never analyzed, processed, or scanned for content by Ember
8. Purchases & Subscriptions
Ember subscriptions (monthly, yearly, or lifetime) are processed entirely through Apple's App Store and StoreKit. We:
- Never receive your credit card number, billing address, or Apple ID
- Only verify your subscription status through Apple's on-device StoreKit APIs
- Record plan type (monthly/yearly/lifetime) in analytics for business metrics - never transaction IDs or payment details
For purchase-related inquiries, refer to Apple's subscription management.
9. App Privacy Summary
The following table summarizes how Ember handles each data category, aligned with Apple's App Privacy requirements:
| Data Category |
Collected |
Linked to You |
Used to Track |
Purpose |
Usage Data (feature usage, screen views) |
Yes |
No |
No |
App improvement |
Diagnostics (crash data, error logs) |
Yes |
No |
No |
Reliability & bug fixes |
Identifiers (anonymous device ID) |
Yes |
No |
No |
Analytics continuity |
Purchases (subscription plan type) |
Yes |
No |
No |
Business metrics |
User Content (journal, people, stories) |
No* |
- |
- |
Stored on-device only |
Contact Info (names, phone, location) |
No* |
- |
- |
Stored on-device only |
Location (journal location pins) |
No* |
- |
- |
Stored on-device only |
| Photos & Media |
No* |
- |
- |
Stored on-device only |
| Health & Fitness |
No |
- |
- |
- |
| Financial Info |
No |
- |
- |
- |
| Contacts (address book) |
No |
- |
- |
- |
| Browsing / Search History |
No |
- |
- |
- |
| Sensitive Info |
No |
- |
- |
- |
* "No" in the "Collected" column means the data never leaves your device or your personal iCloud account. Apple's App Privacy framework defines "collected" as data transmitted off-device to the developer's servers. Data stored locally and synced via the user's own iCloud does not meet this definition.
10. Third-Party Services
Ember integrates with a limited set of third-party services. We do not sell, rent, license, or share your personal data with anyone.
| Service |
Purpose |
Data Shared |
| Apple iCloud (CloudKit) |
Device-to-device sync |
Your content - encrypted, under your Apple ID, inaccessible to us |
| Apple StoreKit |
Subscription management |
Handled by Apple - we receive only entitlement status |
| Apple MusicKit |
Song search for embeds |
Search queries go to Apple's catalog API - not to us |
| PostHog |
Anonymous product analytics |
Structural usage events and error codes (see Section 3) |
11. Data Retention & Deletion
Your content
All user-created content (journal entries, people, stories, interactions, etc.) is stored on your device and remains there until you delete it. Ember provides built-in deletion for all content types.
iCloud data
If you use iCloud sync, deleting content in Ember also deletes it from your iCloud account across all synced devices. You can also manage or delete Ember's iCloud data through your device's Settings → Apple ID → iCloud → Manage Storage.
Analytics data
Anonymous analytics events are retained by PostHog according to their data retention policies. Because these events contain no personal information and are not linked to your identity, they cannot be attributed back to you. If you wish to request deletion of analytics data, contact us and we will facilitate this through PostHog.
Uninstalling the app
Uninstalling Ember removes all locally stored data, including your journal, people, media, and settings. iCloud data persists in your Apple account until you manually remove it or it is automatically purged by Apple's retention policies.
12. Your Right to Your Data
We believe you should always be able to leave. Ember provides full data export in JSON format - the schema is openly documented in the archive format reference. You can also import from Day One. Your data is yours whether or not you are a paying subscriber.
No lock-in, ever. Even after your subscription expires, you retain full access to your local data and can export everything at any time.
13. Security
Ember employs the following security measures:
- App Lock - optional biometric (Touch ID / Face ID) or passcode lock, with configurable idle timeout and automatic locking when the app moves to the background
- Local storage - data is stored in Apple's sandboxed Application Support directory, protected by macOS file system encryption
- iCloud encryption - synced data is encrypted in transit (TLS) and at rest on Apple's servers
- No remote access - there are no API endpoints, no admin panels, no backdoors. We cannot access your data even if compelled to
- Sanitized error reporting - error descriptions captured by the app are run through a scrubbing function that strips names, file paths, UUIDs, and quoted strings before any analytics capture. Automatic crash reports carry a technical stack trace (function and framework names only) and never include your journal content
14. International Users (GDPR, CCPA & Other Regulations)
European Union (GDPR)
Ember's architecture inherently aligns with GDPR principles:
- Data minimization - we collect only anonymous, structural analytics; no personal data
- Purpose limitation - analytics are used solely for product improvement and reliability
- Storage limitation - your content is stored only on your devices and your iCloud
- Right of access & portability - full JSON export is built into the app
- Right to erasure - delete any content in Ember, or Ember's iCloud data in your iCloud storage settings; contact us for analytics data deletion
- Legal basis - our analytics processing is based on legitimate interest in improving the app. We do not process any special category data
California (CCPA / CPRA)
- We do not sell your personal information
- We do not share your personal information for cross-context behavioral advertising
- You have the right to know, delete, and opt out - though given our architecture, there is effectively no personal data for us to disclose, delete, or stop selling
Other jurisdictions
Ember's local-first, no-account architecture means we hold minimal data about any user in any jurisdiction. If your local privacy law grants you rights regarding data we process, please contact us and we will honor your request.
15. Children's Privacy
Ember is rated 4+ on the App Store and is suitable for all ages. We do not knowingly collect personal information from children. Because Ember has no account system and all data remains on-device or in the user's own iCloud, there is no mechanism through which a child's personal data would reach us. If you have concerns, please contact us.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through a notice within the app or on our website. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Ember after changes constitutes acceptance of the updated policy.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, you can reach us through:
Ember was made by one person. This policy was written with the same care as the app - plainly, honestly, and with respect for the people who trust us with their memories.