Legal
Privacy Policy
Last updated July 20, 2026
This policy applies to all visitors, users, and customers of Ember, Inc. and the Ember AI incident commander platform at emberoncall.com. References to "Ember", "we", "us", or "our" mean Ember, Inc..
Who we are
Ember, Inc. is a Delaware corporation with its principal place of business at 115 Broadway, Suite 1502, New York, NY 10006. We build and operate Ember, an AI incident commander that reads alerts, logs, traces, and recent deploys, names the likely root cause, drafts the fix or rollback, and writes the incident timeline and postmortem.
What we collect
We collect information in three categories:
- Account information. Your name, work email address, and company name when you sign up. A hashed password, or an OAuth token if you authenticate via Google or GitHub. On paid plans, billing contact details and a payment method token supplied by Stripe. We never see or store raw card numbers.
- Telemetry you submit. To run an incident, Ember ingests the signals you send or route through a configured integration: alert payloads, log excerpts, trace spans, metric snapshots, and deploy metadata from PagerDuty, Datadog, Opsgenie, Sentry, CloudWatch, and similar tools. We process this data on your behalf to produce the root-cause analysis, fix draft, timeline, and postmortem.
- Usage and product data. API request logs, feature interaction events, session identifiers, error reports, and aggregate performance metrics. We use this to operate and improve the Service. We also collect standard server logs including IP address, browser type, and referring URL.
The Service is intended for professional use by software engineering and operations teams. We do not knowingly collect personal information from anyone under 16.
How we use it
We use the information we collect to:
- Authenticate you, provision your account, and process payments and invoices.
- Run the incident pipeline: ingest your telemetry, produce root-cause analysis, draft fix and rollback commands, write timelines and postmortems, and push results to the integrations you have configured (Slack, Jira, GitHub, etc.).
- Monitor service health, debug errors, and improve reliability, latency, and model accuracy across the platform using aggregate usage patterns.
- Send transactional email: incident summaries, billing receipts, and security alerts. We do not send marketing email without separate consent, and you may unsubscribe from non-essential communications at any time.
- Comply with legal obligations and enforce our Terms of Service.
Your telemetry is not used to train shared models. Log excerpts, alert payloads, trace spans, and other operational signals you submit are processed solely to run your incidents. They are not fed into any shared model training pipeline, not sold, and not used to improve Ember's AI capabilities in a way that exposes your data to other customers. This is a contractual commitment and is enforced at the infrastructure level.
Legal bases (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing are:
- Contract. Processing necessary to deliver the Service under our Terms of Service, including account management, the incident pipeline, and billing.
- Legitimate interests. Operating, securing, and improving the platform, and detecting abuse, where those interests are not overridden by your rights and freedoms.
- Legal obligation. Retaining records required by law and responding to lawful requests from public authorities.
- Consent. Where we rely on consent (for example, optional analytics cookies) you may withdraw it at any time without affecting the lawfulness of prior processing.
Sharing and subprocessors
We do not sell personal data. We share data only in the following circumstances:
- Subprocessors. We engage third-party service providers to host infrastructure (AWS), process payments (Stripe), deliver transactional email (Postmark), collect error reports (Sentry), and route model calls (OpenAI, Anthropic, and others depending on your plan and configuration). Each subprocessor is bound by data processing agreements that restrict use to the stated purpose.
- Integrations you configure. When you connect a third-party tool (Slack, PagerDuty, GitHub, Jira, etc.), Ember sends data to that tool on your instruction. Those tools' own privacy policies govern that data once it arrives.
- Business transfers. If Ember is acquired or merges, customer data may transfer as part of that transaction. We will notify affected customers before data is subject to a materially different privacy policy.
- Legal requirements. We may disclose data when required by law, subpoena, or court order, or to protect the rights, property, or safety of Ember, our customers, or the public. We will notify you of government requests where legally permitted to do so.
A current list of subprocessors is available on request at privacy@emberoncall.com.
Data retention
Account data is retained for the life of your account and for 90 days after deletion, to allow account recovery and satisfy billing record requirements.
Incident telemetry (logs, traces, alert payloads, postmortems) is retained for 365 days on Free, 730 days on Team, and configurable up to 2,190 days on Scale. You may request earlier deletion via your dashboard settings or by contacting support@emberoncall.com.
Server logs are retained for 90 days. Aggregate, de-identified usage metrics may be retained indefinitely for product analytics. Backups rotate on a 30-day cycle and are purged within 30 days of the primary record's deletion.
Security
Ember encrypts data in transit using TLS 1.2 or higher and at rest using AES-256. Access to production systems is restricted to authorized personnel and protected by multi-factor authentication and least-privilege controls. We perform annual penetration tests and operate a responsible disclosure program.
Full details are on our Security page. To report a vulnerability, email security@emberoncall.com.
International transfers
Ember is incorporated in Delaware and our primary infrastructure runs in the United States. If you are located outside the US, your data is transferred to and processed in the US. For customers in the EEA or UK we rely on Standard Contractual Clauses adopted by the European Commission to provide appropriate safeguards for those transfers. On Scale plans we can discuss data-residency options including EU-region deployment. Contact privacy@emberoncall.com for details.
Your rights
Depending on where you are located, you may have rights regarding your personal data. To exercise any of these rights, email privacy@emberoncall.com. We will respond within 30 days (or within the period required by applicable law) and may need to verify your identity before acting.
GDPR (EEA, UK, and Switzerland). You have the right to access a copy of your personal data, rectify inaccuracies, request erasure, restrict processing, receive your data in a portable format, and object to processing based on legitimate interests. You may also lodge a complaint with your local supervisory authority. UK residents may contact the Information Commissioner's Office at ico.org.uk.
CCPA/CPRA (California). California residents have the right to know what personal information we collect, use, and disclose; to delete personal information we hold about you (subject to legal exceptions); to correct inaccurate personal information; to opt out of the sale or sharing of personal information for cross-context behavioral advertising (we do not sell or share data for this purpose); and to non-discrimination for exercising these rights.
Other US states. Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws have similar rights of access, correction, deletion, portability, and opt-out as described above.
Cookies
We use strictly necessary cookies to maintain your authenticated session and protect form submissions against cross-site request forgery. We may also set first-party analytics cookies to understand product usage. You can review cookie categories, manage preferences, and opt out of non-essential cookies on our Cookies page.
Changes to this policy
We may update this policy when our practices change or when law requires it. The "Last updated" date at the top of this page reflects the most recent revision. For material changes that affect your rights we will notify account holders by email at least 14 days before the change takes effect.
Contact
For privacy questions, data requests, or concerns, contact us at:
- Privacy: privacy@emberoncall.com
- General: hello@emberoncall.com
- Post: Ember, Inc., 115 Broadway, Suite 1502, New York, NY 10006, United States