← Back to Ember

Privacy Policy

Your journal is private. We built the architecture to guarantee it.

Effective date: September 13, 2026 · Last updated: September 24, 2026

This Privacy Policy explains how Ember ("we," "us," "our") - a relationship-journaling app for macOS - collects, uses, and protects your information. Ember is developed and operated by a sole developer with no investors, no advertising partners, and no interest in your personal data.

We designed Ember from the ground up as a local-first, privacy-first application. We cannot read your journal entries, see the people you track, or access your stories. This is not a promise - it is a technical reality.

Privacy at a Glance

Local-first storageAll your data lives on your device
Your iCloud, your keysSync uses your private Apple account
No Ember serversWe never receive your content
No account requiredNo email, no login, no sign-up
Minimal analyticsAnonymous, structural events only
Full data exportTake everything with you, anytime

1. Data You Create in Ember

Everything you write, log, or attach in Ember is your content. This includes:

Where this data lives: All content is stored locally on your device using Apple's SwiftData framework. There is no Ember server, no Ember database, and no Ember-operated cloud. We structurally cannot access this data.

2. iCloud Sync

If you are an Ember subscriber, your data syncs across your Apple devices using Apple's CloudKit (CKSyncEngine). This means:

For details on how Apple protects your iCloud data, see Apple's iCloud data security overview.

3. Analytics & Usage Data

We use PostHog, a product analytics platform, to understand how Ember is used at a structural level - which features are adopted, where flows are abandoned, and whether something is broken. This helps us improve the app.

What we collect

What we NEVER collect

We enforce an absolute rule in our analytics code: events may only carry counts, enum tokens, booleans, durations, screen names, and error codes. The following are explicitly prohibited and technically blocked from capture:

Identity & tracking

Ember has no user account system. There is no sign-up, no login, and no email collection. Analytics are recorded using a random, anonymous device identifier generated by PostHog. We never call PostHog's identify function with any personal information. We do not use advertising identifiers (IDFA), and we do not participate in any cross-app tracking or advertising network.

PostHog processes analytics data on servers in the United States. For PostHog's own privacy practices, see PostHog's Privacy Policy.

4. Apple Music Integration

Ember allows you to search and embed songs from the Apple Music catalog into journal entries and stories. This feature:

5. Biometric Authentication

Ember supports optional app locking using Touch ID, Face ID, or your device passcode via Apple's LocalAuthentication framework. This is processed entirely on-device by Apple's Secure Enclave. Ember never receives, stores, or transmits your biometric data - it only receives a boolean success/failure result from the operating system.

6. Location Data

Ember allows you to optionally attach a location to journal entries. This is:

You can remove the location from any entry at any time.

7. Photos & Media

Images, voice recordings, and other media you attach to journal entries or stories are:

8. Purchases & Subscriptions

Ember subscriptions (monthly, yearly, or lifetime) are processed entirely through Apple's App Store and StoreKit. We:

For purchase-related inquiries, refer to Apple's subscription management.

9. App Privacy Summary

The following table summarizes how Ember handles each data category, aligned with Apple's App Privacy requirements:

Data Category Collected Linked to You Used to Track Purpose
Usage Data
(feature usage, screen views)
Yes No No App improvement
Diagnostics
(crash data, error logs)
Yes No No Reliability & bug fixes
Identifiers
(anonymous device ID)
Yes No No Analytics continuity
Purchases
(subscription plan type)
Yes No No Business metrics
User Content
(journal, people, stories)
No* - - Stored on-device only
Contact Info
(names, phone, location)
No* - - Stored on-device only
Location
(journal location pins)
No* - - Stored on-device only
Photos & Media No* - - Stored on-device only
Health & Fitness No - - -
Financial Info No - - -
Contacts (address book) No - - -
Browsing / Search History No - - -
Sensitive Info No - - -

* "No" in the "Collected" column means the data never leaves your device or your personal iCloud account. Apple's App Privacy framework defines "collected" as data transmitted off-device to the developer's servers. Data stored locally and synced via the user's own iCloud does not meet this definition.

10. Third-Party Services

Ember integrates with a limited set of third-party services. We do not sell, rent, license, or share your personal data with anyone.

Service Purpose Data Shared
Apple iCloud (CloudKit) Device-to-device sync Your content - encrypted, under your Apple ID, inaccessible to us
Apple StoreKit Subscription management Handled by Apple - we receive only entitlement status
Apple MusicKit Song search for embeds Search queries go to Apple's catalog API - not to us
PostHog Anonymous product analytics Structural usage events and error codes (see Section 3)

11. Data Retention & Deletion

Your content

All user-created content (journal entries, people, stories, interactions, etc.) is stored on your device and remains there until you delete it. Ember provides built-in deletion for all content types.

iCloud data

If you use iCloud sync, deleting content in Ember also deletes it from your iCloud account across all synced devices. You can also manage or delete Ember's iCloud data through your device's Settings → Apple ID → iCloud → Manage Storage.

Analytics data

Anonymous analytics events are retained by PostHog according to their data retention policies. Because these events contain no personal information and are not linked to your identity, they cannot be attributed back to you. If you wish to request deletion of analytics data, contact us and we will facilitate this through PostHog.

Uninstalling the app

Uninstalling Ember removes all locally stored data, including your journal, people, media, and settings. iCloud data persists in your Apple account until you manually remove it or it is automatically purged by Apple's retention policies.

12. Your Right to Your Data

We believe you should always be able to leave. Ember provides full data export in JSON format - the schema is openly documented in the archive format reference. You can also import from Day One. Your data is yours whether or not you are a paying subscriber.

No lock-in, ever. Even after your subscription expires, you retain full access to your local data and can export everything at any time.

13. Security

Ember employs the following security measures:

14. International Users (GDPR, CCPA & Other Regulations)

European Union (GDPR)

Ember's architecture inherently aligns with GDPR principles:

California (CCPA / CPRA)

Other jurisdictions

Ember's local-first, no-account architecture means we hold minimal data about any user in any jurisdiction. If your local privacy law grants you rights regarding data we process, please contact us and we will honor your request.

15. Children's Privacy

Ember is rated 4+ on the App Store and is suitable for all ages. We do not knowingly collect personal information from children. Because Ember has no account system and all data remains on-device or in the user's own iCloud, there is no mechanism through which a child's personal data would reach us. If you have concerns, please contact us.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through a notice within the app or on our website. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Ember after changes constitutes acceptance of the updated policy.

17. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, you can reach us through:

Ember was made by one person. This policy was written with the same care as the app - plainly, honestly, and with respect for the people who trust us with their memories.