1. Who we are
Ember is operated by StableModels LLC, a North Carolina limited liability company, which is the controller of the personal information described here. This policy covers embersites.com, the builder at embersites.app, our APIs and command-line tools, and the hosting of sites published through Ember. Reach us — for anything, including privacy requests — at support@embersites.com. It's the only channel we operate, and a real person answers.
It does not cover what a customer's published site does with its own visitors' information — that's between the site's owner and its visitors. Section 6 covers the one thing Ember does there.
2. What we collect and why
| Category | Purpose |
|---|---|
| Account and identity — your email; a salted, one-way hash of your password if you set one (never the password itself); your name, picture and account id if you sign in with Google; the terms version you accepted | Create and secure your account; sign you in |
| What you put into Ember — site content, chat transcripts, uploads, and anything you ask us to import | Build, store, render, and publish your sites |
| Usage and diagnostics — features used, builds and publishes, credits consumed, model and token cost per turn, errors, session replays (see below) | Understand and improve the product; fix what breaks |
| Advertising measurement — campaign parameters and ad-click identifiers; page views, clicks, form submissions, site performance, registration, and subscription events; and a subscription's value and currency | Attribute visits and conversions to Ember advertising campaigns and measure their performance |
| Billing records — plan, subscriptions, invoices, credit ledger, domain purchases. Card numbers never reach Ember | Take payment; meter credits; keep tax records |
| Request data — IP address, user agent, timestamps | Security, abuse prevention, rate limiting, debugging |
We do not train AI models on your content, and our providers are engaged under terms that exclude training on our traffic.
Session replay — please read this one
Session replay is on across the Ember app and this marketing site, and it records the text you type into form fields — so a replay can show your chat prompts, the site content you write, and the values you enter into inputs, not just clicks and scrolling. This is deliberate: Ember is built around a conversation, and a replay without the typed text tells us almost nothing about where the product confuses people. Two carve-outs are in place and stay there:
- Real password fields are masked and never recorded.
- Stripe's payment forms are never captured — they render in Stripe's own iframes, which our recorder cannot see into, so card numbers are structurally outside replay rather than filtered out of it.
Email us if you'd rather not be recorded and we'll exclude your account.
Cookies
We use cookies and browser storage for what the product needs: your sign-in session, your theme preference, the analytics identifier that links your activity across embersites.com and embersites.app, and first-party advertising-measurement identifiers. An ad-click identifier is present when you arrive from an Ember ad. We do not use third-party advertising cookies on our surfaces.
3. Who else touches it
We use a small number of service providers to run Ember — hosting, payments, analytics, and the AI models that build your site. The full list, and exactly what each one does, is on our Service Providers page, which forms part of this policy and is kept current as providers change.
The three worth knowing without clicking: Cloudflare is effectively all of our infrastructure, so your site content and account data live there; Stripe holds your card details, which never reach Ember; and your prompts and the relevant parts of your site are sent to AI model providers to generate what you asked for — so don't paste secrets or other people's sensitive information into the chat.
We do not sell your personal information or use your prompts, site content, or account data for cross-context behavioural advertising. On Ember's production marketing site, Ryze AI receives page-view, click, form-submission, and site-performance events. On the marketing site and app, Google Ads receives page-view, registration, and subscription conversion events while its measurement integration is enabled. Meta receives page views, completed registrations, and checkout starts through its browser Pixel, plus a purchase event only after Stripe confirms an initial paid subscription. When you visit from an Ember ad, these providers may also receive a click or browser identifier so we can attribute and measure our own campaigns. We may also disclose information where legally required, or where we reasonably believe it necessary to protect our rights, our users' safety, or to investigate abuse. If Ember is acquired or merged, account data may transfer as part of that transaction, subject to this policy.
4. Sites you publish are public
A published Ember site is served to anyone on the internet and can be crawled, indexed, archived, and copied by parties we don't control. Anything you put into a published page, including personal information, is public. Unpublishing stops us serving it but can't retrieve copies made elsewhere.
5. How long we keep it
- Account and site content — while your account is open, then 30 days after it closes so you can retrieve it, then deleted. Export before you close (see the Terms).
- Deleted sites — recoverable from Deleted Sites for a limited window, then removed. Chat transcripts go with the site they belong to.
- Billing records — as long as tax and accounting law requires, typically seven years, even after your account closes.
- Product analytics and session replays — on our analytics provider's retention schedule, then deleted; replays are the shortest-lived.
- Advertising measurement — on each measurement provider's retention schedule, or sooner when you ask us to opt you out or delete what the provider allows us to delete.
- Visitor analytics for published sites — detailed records about 90 days, daily aggregates longer (section 6).
- Security and diagnostic logs — a short rolling window.
Backups age out on their own schedule after deletion.
6. Analytics on your published site
Ember gives you visitor analytics for your published sites. This is about your visitors' information, which you are responsible for — so here is exactly what happens, in enough detail to describe in your own privacy notice.
Publishing injects one small first-party script. Per page view it records the page path (query strings stripped), the visitor's country from the network request, the referring site's hostname only, whether the device is mobile or desktop, and bytes served.
It is cookieless. No cookie is set and no identifier is stored on the visitor's device. To count returning visitors within a day we compute a one-way hash of the visitor's IP address, user agent, your site's identifier, and a secret salt that rotates every day; the raw IP and user agent are not stored. Because the salt changes daily the same person can't be recognised across two days, and because your site's identifier is in the hash the same person on two Ember sites produces two unrelated values. Identifiable bots aren't recorded. We don't use any of it to profile or track your visitors elsewhere.
7. Your privacy rights
United States. US state privacy laws may let you ask us to tell you what we hold about you, to correct it, to delete it, and to give you a portable copy. This includes residents of California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws. California residents also have the right not to be treated worse for asking. We don't sell personal information or share it for cross-context behavioural advertising. The limited advertising measurement described in section 3 is not used to profile you across businesses.
Canada. You may ask whether we hold personal information about you, how we have used or disclosed it, and for access to it; challenge its accuracy and have it corrected; withdraw consent where the law permits; and challenge our compliance. These rights arise under PIPEDA or applicable provincial private-sector privacy law. If we cannot resolve a concern, you may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.
Australia. You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. You may also complain about our handling of personal information. If we cannot resolve a complaint, you may contact the Office of the Australian Information Commissioner.
Some of it you can do yourself: edit your profile and plan in account settings, download your site's
files from the builder's file browser or the ember command-line tool, delete sites from the
dashboard. For anything else — a copy of your data, account deletion, opting out of session replay or
advertising measurement —
email support@embersites.com from the address on your
account. We verify it's you first and respond within the time applicable law requires — generally 45
days for US requests, 30 days for PIPEDA requests, and a reasonable period for Australian requests.
You may use an authorised agent where the law allows. If you think we've handled your information
badly, contact us first; the regulator routes above remain available to you.
8. Where we operate, and security
Ember is a US business serving customers in the United States, Canada (except Quebec), and Australia. We're operated from the United States. Your information is transferred to and primarily stored and processed in the United States by us and the providers listed on our Service Providers page; those providers may be subject to US law and lawful access by US authorities. Cloudflare's network is global, so a published site is served to its visitors from wherever is nearest them.
We do not offer GDPR, UK GDPR, or regulatory features for countries outside our supported markets — no data processing addendum, no standard contractual clauses, no data-residency guarantees, and no EU or UK representative. If you need those, Ember isn't the right product for you.
We protect your information with encryption in transit and at rest, isolated per-customer storage, scoped credentials, and access limited to those who need it. Authentication is passwordless — Google sign-in or a short-lived emailed link — so there's no Ember password to leak. No system is perfectly secure; if a breach affects your personal information we'll notify you and any regulator within the time the law requires.
9. Children and changes
Ember isn't for people under 18 and we don't knowingly collect their personal information; email us if you believe a child has given us any and we'll delete it.
We'll update this policy as Ember changes and will change the date at the top. For material changes we'll give at least 30 days' notice by email to the address on your account or in the product, on the same terms as changes to the Terms of Service.