This policy explains what Ember collects, how it is used, who it is shared with, and the choices you have.
Summary
Your financial data is used to show you your own finances, and for nothing else. Ember does not sell your data, does not use it for advertising, and earns its money from subscriptions.
Ember runs no analytics, no advertising tags, no session recording, and no third-party trackers. There is no cookie banner because there are no tracking cookies.
Your bank credentials never reach Ember. Bank connections are read-only and cannot move money.
Ember is offered in the United States only. See the Terms of service.
The rest of this page is the detail behind those four statements.
Information Ember collects
| Information | Why Ember has it | Who else sees it |
|---|---|---|
| Account information | To create your account, sign you in, and write to you about it | Email provider |
| Financial information | To show your balances, transactions, and net worth, and to run the calculations you ask for | Aggregation provider, hosting provider |
| Security and usage information | To detect account takeover and abuse | Hosting provider |
| Waitlist information | To send your invite | Email provider |
Account information means your email address and a hash of your password. Passwords are hashed with Argon2id and are never stored in readable form.
Financial information means accounts, balances, transactions, holdings, categories, payees, tags, and anything you type into a memo. It reaches Ember three ways: a bank connection you authorize, a file you import, or a row you enter yourself.
Security and usage information means sign-ins, failed sign-ins, password changes, and invite issuance and redemption, each recorded with the IP address and browser user agent that made the request.
Waitlist information means the email address you submit if you ask for an invite, and which form on the page you used.
Payment information
Ember does not collect payment information. Nothing is billed today, and Ember holds no card or bank-account details for billing. This policy will be updated before that changes.
Information Ember does not collect
Ember does not ask for or store your date of birth, your government identifiers, your physical address, your phone number, or your precise location.
How Ember uses your information
To operate the product for you, and specifically to:
- Show your accounts, balances, transactions, holdings, and net worth.
- Keep connected accounts current.
- Run the calculations, searches, and reports you ask for.
- Send you messages about your account.
- Detect account takeover and abuse, and investigate it.
- Fix defects and understand errors reported by the software itself.
Ember does not use your financial information to build a profile, to target advertising, or to inform anyone else's product. Ember does not use it to train a general-purpose AI model.
How Ember shares your information
Ember uses service providers to run the product. They include:
| Category | What it covers |
|---|---|
| Financial data aggregation | Bank connections and the account data they return. Ember's provider is Plaid, which handles what it collects under its own privacy policy. |
| Hosting and storage | The servers and database Ember runs on, located in the United States. |
| Email and communications | Transactional messages Ember sends you, and mail you send to the address in Contact. |
These providers act on Ember's behalf and are not permitted to use your data for their own purposes.
Ember works with no advertising network, no analytics provider, and no data broker. Beyond the providers above, Ember shares your information only where the law requires it, or to investigate suspected fraud or a violation of the Terms of service.
If Ember is ever acquired or transferred, your information may transfer with it. You will be told before that happens, and this policy continues to apply until it is replaced by one you are notified of.
Bank connections and third-party integrations
Bank connections run through Plaid. You authenticate with your institution inside Plaid's own window, and Ember receives a scoped read-only access token along with the account and transaction data it returns. Ember never sees, transmits, or stores your banking credentials, and the connection cannot move money.
You can disconnect any bank at any time, which revokes Ember's access token with Plaid.
If you connect an AI assistant to Ember over its read-only interface, that assistant can read what your token allows and is governed by its own provider's terms. You create these tokens yourself and can revoke them at any time.
AI features
Ember has three optional AI features: payee matching, memo summaries, and names for charge groups. Each is off by default, and each has its own switch in Settings, because each sends different information.
On Ember's servers the model runs on the same machine as the app, so text these features use does not leave it. Each feature sends the minimum it needs. Payee matching sends merchant names. Memo summaries send item descriptions. Group naming sends memo text alone, never amounts, dates, or account names.
Turning a switch off stops the sending. It does not delete suggestions already stored.
Cookies and tracking technologies
Ember sets one cookie: a signed session cookie that keeps you signed in. It is marked HttpOnly and, in production, Secure. Removing it signs you out and nothing else.
There are no advertising cookies, no analytics cookies, and no pixels or beacons from anyone. Ember does not load third-party scripts on its site or in the app, which is why you are not asked to accept anything on arrival.
Do Not Track and Global Privacy Control
Ember does not sell personal information and does not share it for cross-context behavioral advertising, so a Do Not Track header or a Global Privacy Control signal has nothing to switch off. Ember's behavior is the same whether you send one or not.
Communication preferences
Ember sends transactional mail only: invites, password resets, security notices, waitlist replies, and messages about your account. There is no marketing list and no newsletter.
Because these messages are about the security and operation of your account, they cannot be turned off while the account is open. To stop them, close the account.
How Ember protects your information
Passwords are hashed with Argon2id. Sessions use signed, HttpOnly cookies, marked Secure in production. Sign-in is rate limited per IP address and the account locks after repeated failures. Every state-changing request carries a CSRF token. Every record is filtered by your identity at the query layer, so one person's data has no path to another's. Passkeys are supported for sign-in and as a second factor.
No system is perfectly secure, and Ember does not claim otherwise. More detail is on Security and privacy.
Data retention
Your ledger stays until it is deleted. You can download everything at any time as a ZIP of CSV files from the Download your data link on the Accounts page.
There is no self-service delete button yet. To delete your ledger or close your account, write to privacy@emberfinance.app. Ember removes your ledger and your account record within 30 days and revokes every bank connection with Plaid.
Two things outlive that, and both are deliberate. Security and usage records are append-only and are not removed with the account: they record that an event happened, not what your ledger contains, and Ember does not currently expire them. Waitlist entries are kept until you are invited or you ask for removal.
Your rights and choices
You can:
- Download your full ledger at any time.
- Turn each AI feature on or off in Settings.
- Disconnect any bank, which revokes Ember's access token with Plaid.
- Ask what Ember holds about you, ask for a copy, ask for a correction, or ask for deletion, by writing to privacy@emberfinance.app. Ember answers within 30 days.
Ember will not deny you service, charge you a different price, or give you a lesser product for exercising any of these.
State-specific information
Some states give residents additional rights over their personal information, including the right to know what is collected, to request a copy, to request correction, and to request deletion.
Rather than limiting those rights to residents of states that require them, Ember extends them to everyone in the United States. To exercise any of them, write to privacy@emberfinance.app. If a request is refused, you may ask for that decision to be reviewed by replying to the same address.
Third-party websites
Ember links to sites it does not run, including your bank, Plaid, and the providers named in this policy. Those sites have their own privacy policies, and Ember is not responsible for how they handle your information. This policy covers only Ember.
Transfers
Ember stores and processes your information in the United States. Ember is offered to United States residents only and is not directed at anyone outside it.
Children's privacy
Ember is not for anyone under 18 and does not knowingly collect information from anyone under 18. If you believe someone under 18 has given Ember personal information, write to privacy@emberfinance.app and it will be deleted.
Changes to this policy
If this policy changes, the effective date above changes with it. A change to how Ember handles information it already holds will be sent to the email address on your account before it takes effect.
Contact
Questions about this policy, or any request described in Your rights and choices: privacy@emberfinance.app.
Ember is operated from New York. See the Terms of service for who you are contracting with.
Further reading
- Terms of service: the agreement for using Ember.
- Security and privacy: how accounts and records are protected.
- Bank sync and import: what data flows in, and how.
Also: Terms of service.