Legal

Privacy Policy

What personal data Emberblocks processes, why, where it lives, who sees it, and how to exercise your rights. Written to be read, not skimmed past.

Last updated · See also our Terms of Service

In short(a summary, not the policy itself)

  • We collect what running Emberblocks needs: your email, your workspace, billing handled by Dodo Payments, and the data you put into your apps.
  • Your data is stored in the EU (Frankfurt). Some providers we rely on, like hosting, email and AI models, process it in the US under standard contractual clauses.
  • For the data inside your apps, you are the controller and we are your processor; section 12 is the processing agreement.
  • Prompts you send to Ember go to third-party model providers; we store only usage counts, never the prompt, and never train on them.
  • No selling of data, no ad tracking. Plausible runs without cookies; PostHog only if you accept analytics cookies, and never in published apps.
  • Ask us anything, or exercise any GDPR right, at hello@emberblocks.com. Account deletion is by email today.
Contents
  1. 1. Who we are and what this policy covers
  2. 2. Two roles: your data, and your users’ data
  3. 3. Personal data we collect
  4. 4. Why we use it, and the legal basis
  5. 5. AI features
  6. 6. Who we share data with (sub-processors)
  7. 7. Where data is stored and international transfers
  8. 8. Cookies and local storage
  9. 9. How long we keep data
  10. 10. How we protect data
  11. 11. Your rights
  12. 12. Processing on behalf of our customers
  13. 13. Children
  14. 14. Emails we send
  15. 15. Links to other sites and apps built by others
  16. 16. Automated decision-making and profiling
  17. 17. Changes to this policy
  18. 18. Contact

1.Who we are and what this policy covers

Emberblocks is operated by Apostolos Papadopoulos, a sole trader established in Greece, at Filippou 2, 546 30 Thessaloniki, Greece (“Emberblocks”, “we”, “us”). For the personal data described in this policy we are the controller under the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019, except where section 12 says otherwise.

This policy covers emberblocks.com, the Emberblocks builder, the anonymous sandbox, the Emberblocks API and MCP server, the emails we send, and the apps and public links our customers publish on the platform (together, the “Service”). It forms part of our Terms of Service.

Privacy questions and requests: hello@emberblocks.com. We are not required to appoint a data protection officer; the same address reaches the person responsible for data protection.

2.Two roles: your data, and your users’ data

Emberblocks is a two-sided platform, so we wear two hats. It matters, because it decides who you should ask when you want something done with your data.

  • We are the controller for the data of builders and workspace members (your account, billing, support, analytics on emberblocks.com), for waitlist and sandbox visitors, and for the technical data our own infrastructure generates. Sections 3 to 11 describe this processing.
  • We are a processor for everything a customer puts into their workspace: rows in Ember DB, uploaded files, data synced from Airtable or Postgres, and the personal data of the app users and public-link visitors who use apps a customer publishes. The customer decides why and how that data is used; we act on their instructions. Section 12 sets out the terms of that processing.

If you use an app that someone else built on Emberblocks and have a question about your data in it, please ask the organisation that runs the app first. We help them answer, and we will point you to them if you write to us.

3.Personal data we collect

We collect only what the Service needs to work. By category:

Categories of personal data Emberblocks collects as controller
CategoryWhat it includesWhere it comes from
AccountEmail address, a Supabase user id, sign-in method, the name and profile picture Google shares if you sign in with Google, workspace names and your role in each, timestamps of sign-ins.You; Google (only if you choose Google sign-in).
SandboxA temporary guest account and its session cookie, the template you opened, and a one-way hash (SHA-256) of your IP address used only to rate-limit sandbox creation. No email is asked for.Your browser.
WaitlistEmail address, the page you signed up from, and a SHA-256 hash of your IP address used to rate-limit sign-ups. The raw address is never stored.You.
BillingPlan, subscription status, trial dates, invoices, and the name, email, country and tax details you give Dodo Payments at checkout. Card numbers never reach us; Dodo Payments, our merchant of record, holds them.You; Dodo Payments.
Usage and limitsCounts we keep per workspace to enforce plan limits: rows, published apps, active app users, AI calls and tokens per month, public-link submissions. Prompts and AI answers are not stored on our side.Generated by the Service.
Content you createApp definitions, expressions, workflows, email and PDF templates, and anything you type into the builder or into Ember, our AI assistant. This can contain personal data if you put it there.You.
ConnectionsCredentials for the data sources you connect (Airtable tokens, Postgres connection strings, webhook secrets), encrypted at rest with a key derived per workspace.You.
NotificationsIf you turn on push notifications in an app: your email, the browser’s push endpoint and encryption keys, and a shortened browser identifier so you can recognise the device later.Your browser.
Technical and securityRequest logs at our hosting provider (IP address, browser type, URL, timestamp, status), error reports, and salted, truncated IP hashes we keep in rate-limit counters for public links.Your device; generated by the Service.
AnalyticsAggregate page statistics from Plausible (no cookies, no persistent identifier). If you accept analytics cookies on emberblocks.com, PostHog product analytics: pages and features used, browser and device type, and, when you are signed in, your user id and email so we can follow one journey from sign-up to first published app.Your browser.
Support and correspondenceEmails you send us, rights requests, transfer and rights-complaint notices, and our replies.You.

We do not knowingly collect special categories of data (health, religion, biometrics and the like) about builders. If you put such data into an app, section 12 explains what we expect of you and what we do with it.

4.Why we use it, and the legal basis

Each purpose rests on one of the legal bases in Article 6 GDPR:

Purposes of processing and their legal bases
PurposeData usedLegal basis
Provide the Service: accounts, workspaces, the builder, publishing, notifications, API and MCP accessAccount, content you create, connections, notifications, usage and limitsPerformance of a contract (Art. 6(1)(b))
Let you try Emberblocks anonymously in the sandboxSandboxLegitimate interest in letting visitors evaluate the product before signing up (Art. 6(1)(f))
Bill paid plans, issue invoices, keep accountsBillingContract (Art. 6(1)(b)); legal obligation under Greek tax and accounting law (Art. 6(1)(c))
Run Ember, our AI assistant, when you ask it to draft somethingThe prompt and context you send, which may include parts of your app definition and sample dataContract (Art. 6(1)(b)); you choose when to use it
Keep the Service secure, prevent abuse, enforce plan limitsTechnical and security, usage and limits, IP hashesLegitimate interest in protecting the Service and other users (Art. 6(1)(f))
Understand how emberblocks.com and the builder are used, and improve themAnalyticsPlausible: legitimate interest (aggregate, cookieless). PostHog: consent (Art. 6(1)(a)); withdraw any time by clearing cookies or via the cookie notice
Tell you about product updates, onboarding tips and launchesAccount or waitlist emailCustomers: legitimate interest in keeping you informed about the product you use (Art. 6(1)(f)), with an unsubscribe link in every email. Waitlist: your sign-up (consent, Art. 6(1)(a))
Answer support requests and rights requestsSupport and correspondenceContract (Art. 6(1)(b)); legal obligation for rights requests (Art. 6(1)(c))
Comply with the law, respond to lawful requests, establish or defend legal claimsWhatever the situation requiresLegal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))

Where we rely on legitimate interest we have weighed it against your rights and concluded that the processing is what you would reasonably expect and has little impact on you. You can object at any time (see section 11).

We do not sell personal data, and we do not use it for automated decisions that produce legal or similarly significant effects on you.

5.AI features

When you use Ember to draft an app, a field, an expression or sample data, the text you type and the context the builder attaches (the relevant parts of your app definition, field names, and sometimes example rows) are sent to OpenRouter, which routes the request to a model provider such as Anthropic, OpenAI or Google. The reply is shown to you and applied to your draft; we store the resulting app definition, not the prompt or the raw answer. We keep only monthly counts of calls and tokens per workspace to enforce plan limits.

We do not train models ourselves and do not use your prompts to train anything. The model providers process your request under their own terms, which are linked in section 6; some may retain requests for a limited period for abuse monitoring. Ember is optional. If a prompt would contain data you must not share with a third-party processor, do not send it: build the field or expression by hand instead.

6.Who we share data with (sub-processors)

We do not sell or rent personal data. We share it with the providers below, each bound by a contract that limits what they may do with it, and each acting as our processor unless noted:

Sub-processors and other recipients
ProviderPurposeLocation of processing
Supabase (privacy)Database, authentication, file storage. Holds all account and workspace data.EU: Frankfurt, Germany (eu-central-1)
Vercel (privacy)Hosting, content delivery, serverless functions, request logs. Data passes through Vercel while a request is served.Global edge network; functions in the United States
Dodo Payments (privacy)Merchant of record for paid plans: checkout, card processing, invoices, taxes. Independent controller for the payment itself.United States
OpenRouter (privacy) and the model providers it routes to (Anthropic, OpenAI, Google)AI features (Ember). Receives only what you send to Ember.United States
Resend (privacy)Transactional email (sign-in links, invitations, transfers, billing notices) and emails your workflows send.United States
Plausible (privacy)Cookieless, aggregate website analytics on emberblocks.com. Receives no persistent identifier.EU: Germany
PostHog (privacy)Product analytics on emberblocks.com and in the builder, only after you accept analytics cookies. Never loaded in published apps or public links.EU: Frankfurt, Germany (PostHog EU Cloud)
Google (privacy)Sign in with Google, if you choose it. Google is an independent controller for your Google account.Global

Data sources you connect (Airtable, your own Postgres databases, webhooks your workflows call) are your relationship with those providers and are not our sub-processors. We also disclose personal data when the law requires it, to establish or defend legal claims, or, with notice to you, to a successor if the business is transferred.

When we add or replace a sub-processor that handles customer data we update this list and bump the date at the top of the page. If you object to a change you may stop using the Service and ask us to delete your data.

7.Where data is stored and international transfers

Your account and workspace data lives in Supabase’s Frankfurt region in Germany. Application code runs on Vercel, whose edge network serves requests worldwide and whose serverless functions run in the United States, so data transits Vercel’s infrastructure while a request is processed. Email, payments and AI providers listed in section 6 are based in the United States.

Transfers outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses in each provider’s data processing agreement and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards at hello@emberblocks.com.

8.Cookies and local storage

We keep cookies to the minimum the Service needs:

Cookies and similar technologies
NamePurposeType and lifetime
sb-…-auth-token (and its numbered chunks)Keeps you signed in to Emberblocks, or to an app you use, and to the sandbox guest account.Strictly necessary; session, refreshed while you use the Service
sidebar_stateRemembers whether you collapsed the sidebar.Functional; 7 days
ph_… (PostHog)Product analytics on emberblocks.com and the builder: distinguishes returning browsers and links events to your account when signed in.Analytics; set only after you accept it; up to 12 months
PlausibleNone. Plausible works without cookies or local storage.n/a

Published apps can be installed on your device and used offline. To make that work, the app stores its own data and any changes you make while offline in your browser’s local storage until they are sent; this stays on your device and is controlled by the customer who runs the app.

You can delete or block cookies in your browser at any time. Blocking the sign-in cookie signs you out. We do not currently respond to “Do Not Track” signals because no common standard defines what they should do.

9.How long we keep data

Retention periods
DataRetained for
Account and workspace dataFor as long as your account exists. When you ask us to delete your account, or a workspace is deleted, live data is removed within 30 days and drops out of encrypted backups within a further 30 days.
Sandbox guest accounts and their apps24 hours from creation, then deleted automatically, unless you claim the sandbox by signing up, in which case it becomes a normal workspace.
WaitlistUntil you unsubscribe or ask us to remove you, or until we retire the list.
Billing records and invoicesFor as long as Greek tax and accounting law requires, currently at least five years after the end of the financial year.
Push notification subscriptionsUntil you turn notifications off for that device or the app is deleted.
Rate-limit countersPublic-link counters expire with their time window (at most one calendar month). Sandbox and waitlist hashes are deleted with the sandbox or waitlist row.
Hosting request logsA short period at Vercel, measured in days, unless we preserve specific entries to investigate abuse or an incident.
Product analytics events (PostHog)12 months, then deleted.
Support correspondence and rights requests24 months after the matter closes, longer if needed to establish or defend a legal claim.

Deleting your account is done by email today: write to hello@emberblocks.com from the address on the account. Workspace owners can delete apps and data sources from the workspace at any time.

10.How we protect data

  • All traffic is encrypted in transit (TLS). Data at rest is encrypted by Supabase.
  • Data-source credentials (Airtable tokens, Postgres connection strings, webhook secrets) are encrypted with AES-256-GCM under a key derived separately for each workspace, and are never returned to the browser after you save them.
  • Every table is protected by row-level security, so a workspace can only reach its own data; internal counters and credentials are reachable only by the server.
  • Sign-in uses one-time email links or Google; we never store passwords.
  • IP addresses used for rate limiting are stored only as one-way hashes.
  • Access to production is limited to the operator and protected by multi-factor authentication.

One deliberate exception you should know about: files uploaded to apps are stored in a public bucket. Their URLs are long and unguessable, but anyone who has a URL can open the file without signing in. Do not upload files that must stay confidential, and tell your app users the same.

No system is perfectly secure. If a breach affects your personal data in a way that is likely to put you at risk we will tell you and the Hellenic Data Protection Authority as GDPR requires.

11.Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you and get a copy;
  • Rectify inaccurate or incomplete data;
  • Erase your data (“right to be forgotten”), subject to records we must keep by law;
  • Restrict processing while a dispute about the data is resolved;
  • Port the data you gave us to another provider in a machine-readable form (your apps and Ember DB data can also be exported as CSV from the product);
  • Object to processing based on legitimate interest, including product emails, at any time;
  • Withdraw consent where processing rests on it (analytics cookies, waitlist), without affecting what happened before;
  • Complain to a supervisory authority (see below).

To exercise a right, email hello@emberblocks.com from the address on your account, or tell us how we can verify it is you. We answer within one month; for complex requests we may take up to two months more and will tell you why. Requests are free unless they are clearly unfounded or excessive.

Our lead supervisory authority is the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr. You may also complain to the authority where you live or work in the EEA. We would appreciate the chance to resolve the matter first.

If you are an app user of a customer’s app, address these rights to that customer; we will assist them. If you write to us we will forward your request to the customer where we can, and act on it ourselves where the law requires.

12.Processing on behalf of our customers

This section applies between Emberblocks and each customer (the workspace owner and its organisation) for the personal data the customer stores in, syncs to or collects through the Service (“Customer Data”). It is the data processing agreement required by Article 28 GDPR, and it forms part of the Terms of Service.

  • Roles. The customer is the controller of Customer Data and decides its purposes and means. We are the processor and act only on the customer’s documented instructions, which are: the Terms, this policy, and the settings the customer chooses in the product. We will tell the customer if we believe an instruction breaks the law.
  • Nature and purpose. Hosting, storing, displaying, syncing, transforming and transmitting Customer Data so the customer’s apps, workflows, emails, documents and public links work as configured, for the life of the customer’s account.
  • Types of data and data subjects. Whatever the customer chooses to put into their apps, typically business contact details, records about the customer’s staff, clients, suppliers or operations, and the accounts of the people the customer invites as app users.
  • Confidentiality. Only people who need access to run and support the Service have it, and they are bound by confidentiality. We look at Customer Data only to operate the Service, to support the customer at their request, to enforce the Terms, or as the law requires.
  • Security. The measures in section 10, including the public-bucket caveat for uploads.
  • Sub-processors. The customer authorises the sub-processors in section 6 and the mechanism there for changes. We hold each sub-processor to obligations no less protective than these, and remain responsible for them.
  • Transfers. As described in section 7.
  • Assistance. We help the customer respond to data-subject requests (the product exposes search, edit, export and delete for every record), and, taking account of the nature of the processing, with security, breach notification, impact assessments and consultations with authorities. We notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
  • Deletion. When the customer deletes an app, a data source or a workspace, or when the account ends, Customer Data is deleted as described in section 9. Before that the customer can export it as CSV. We keep nothing afterwards unless EU or Greek law requires it.
  • Information and audit. We make available the information reasonably needed to show compliance with this section, and answer reasonable written security questionnaires no more than once a year. Any on-site audit needs 30 days’ notice, a mutually agreed scope, and is at the customer’s cost.

What we expect from the customer. The customer is responsible for having a lawful basis for the Customer Data they collect, for the privacy notice their app users see, for not storing special-category data or data about children without appropriate measures, for what they expose through public links (which anyone with the link can open), and for the content of emails and documents their workflows send.

13.Children

The Service is for business and professional use and is not directed at anyone under 18. We do not knowingly collect personal data from children as controller. If you believe a child has created an account, write to hello@emberblocks.com and we will delete it. Customers who build apps used by minors are responsible for the safeguards that requires.

14.Emails we send

Service emails (sign-in links, invitations, app transfers, trial and billing notices, security alerts, and messages your workflows send) are part of running the Service and cannot be switched off while you have an account.

Product emails (onboarding tips, new features, launch news) go to account holders and waitlist subscribers. Every one carries an unsubscribe link; one click stops them. You can also object by emailing us. We do not share our lists with anyone for their own marketing.

15.Links to other sites and apps built by others

The Service links to third-party sites (documentation, provider terms, the sources you connect), and customers’ apps may link anywhere they like. Those sites have their own privacy policies, and we are not responsible for them. An app built on Emberblocks belongs to the customer who published it, even when it carries a “Powered by Emberblocks” badge.

16.Automated decision-making and profiling

We do not make decisions about you by automated means that have legal or similarly significant effects. Plan limits and rate limits are applied automatically, but they concern usage of the Service, not you as a person, and you can always contact us if one seems wrong. Ember generates drafts on request; it does not evaluate people.

17.Changes to this policy

We update this policy when the Service, our providers or the law change. The date at the top always shows the current version. For material changes (a new category of data, a new purpose, a new sub-processor for Customer Data) we will also email account holders or show a notice in the product before the change takes effect. Continuing to use the Service after that means you accept the updated policy; if you do not, stop using the Service and ask us to delete your data.

18.Contact

Apostolos Papadopoulos, trading as Emberblocks
Filippou 2, 546 30 Thessaloniki, Greece
hello@emberblocks.com

For privacy requests, put “Privacy request” in the subject line so we can prioritise it. We aim to acknowledge within five business days and to answer within one month.