In short(a summary, not the policy itself)
- We collect what running Emberblocks needs: your email, your workspace, billing handled by Dodo Payments, and the data you put into your apps.
- Your data is stored in the EU (Frankfurt). Some providers we rely on, like hosting, email and AI models, process it in the US under standard contractual clauses.
- For the data inside your apps, you are the controller and we are your processor; section 12 is the processing agreement.
- Prompts you send to Ember go to third-party model providers; we store only usage counts, never the prompt, and never train on them.
- No selling of data, no ad tracking. Plausible runs without cookies; PostHog only if you accept analytics cookies, and never in published apps.
- Ask us anything, or exercise any GDPR right, at hello@emberblocks.com. Account deletion is by email today.
Contents
- 1. Who we are and what this policy covers
- 2. Two roles: your data, and your users’ data
- 3. Personal data we collect
- 4. Why we use it, and the legal basis
- 5. AI features
- 6. Who we share data with (sub-processors)
- 7. Where data is stored and international transfers
- 8. Cookies and local storage
- 9. How long we keep data
- 10. How we protect data
- 11. Your rights
- 12. Processing on behalf of our customers
- 13. Children
- 14. Emails we send
- 15. Links to other sites and apps built by others
- 16. Automated decision-making and profiling
- 17. Changes to this policy
- 18. Contact
1.Who we are and what this policy covers
Emberblocks is operated by Apostolos Papadopoulos, a sole trader established in Greece, at Filippou 2, 546 30 Thessaloniki, Greece (“Emberblocks”, “we”, “us”). For the personal data described in this policy we are the controller under the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019, except where section 12 says otherwise.
This policy covers emberblocks.com, the Emberblocks builder, the anonymous sandbox, the Emberblocks API and MCP server, the emails we send, and the apps and public links our customers publish on the platform (together, the “Service”). It forms part of our Terms of Service.
Privacy questions and requests: hello@emberblocks.com. We are not required to appoint a data protection officer; the same address reaches the person responsible for data protection.
2.Two roles: your data, and your users’ data
Emberblocks is a two-sided platform, so we wear two hats. It matters, because it decides who you should ask when you want something done with your data.
- We are the controller for the data of builders and workspace members (your account, billing, support, analytics on emberblocks.com), for waitlist and sandbox visitors, and for the technical data our own infrastructure generates. Sections 3 to 11 describe this processing.
- We are a processor for everything a customer puts into their workspace: rows in Ember DB, uploaded files, data synced from Airtable or Postgres, and the personal data of the app users and public-link visitors who use apps a customer publishes. The customer decides why and how that data is used; we act on their instructions. Section 12 sets out the terms of that processing.
If you use an app that someone else built on Emberblocks and have a question about your data in it, please ask the organisation that runs the app first. We help them answer, and we will point you to them if you write to us.
3.Personal data we collect
We collect only what the Service needs to work. By category:
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, a Supabase user id, sign-in method, the name and profile picture Google shares if you sign in with Google, workspace names and your role in each, timestamps of sign-ins. | You; Google (only if you choose Google sign-in). |
| Sandbox | A temporary guest account and its session cookie, the template you opened, and a one-way hash (SHA-256) of your IP address used only to rate-limit sandbox creation. No email is asked for. | Your browser. |
| Waitlist | Email address, the page you signed up from, and a SHA-256 hash of your IP address used to rate-limit sign-ups. The raw address is never stored. | You. |
| Billing | Plan, subscription status, trial dates, invoices, and the name, email, country and tax details you give Dodo Payments at checkout. Card numbers never reach us; Dodo Payments, our merchant of record, holds them. | You; Dodo Payments. |
| Usage and limits | Counts we keep per workspace to enforce plan limits: rows, published apps, active app users, AI calls and tokens per month, public-link submissions. Prompts and AI answers are not stored on our side. | Generated by the Service. |
| Content you create | App definitions, expressions, workflows, email and PDF templates, and anything you type into the builder or into Ember, our AI assistant. This can contain personal data if you put it there. | You. |
| Connections | Credentials for the data sources you connect (Airtable tokens, Postgres connection strings, webhook secrets), encrypted at rest with a key derived per workspace. | You. |
| Notifications | If you turn on push notifications in an app: your email, the browser’s push endpoint and encryption keys, and a shortened browser identifier so you can recognise the device later. | Your browser. |
| Technical and security | Request logs at our hosting provider (IP address, browser type, URL, timestamp, status), error reports, and salted, truncated IP hashes we keep in rate-limit counters for public links. | Your device; generated by the Service. |
| Analytics | Aggregate page statistics from Plausible (no cookies, no persistent identifier). If you accept analytics cookies on emberblocks.com, PostHog product analytics: pages and features used, browser and device type, and, when you are signed in, your user id and email so we can follow one journey from sign-up to first published app. | Your browser. |
| Support and correspondence | Emails you send us, rights requests, transfer and rights-complaint notices, and our replies. | You. |
We do not knowingly collect special categories of data (health, religion, biometrics and the like) about builders. If you put such data into an app, section 12 explains what we expect of you and what we do with it.
4.Why we use it, and the legal basis
Each purpose rests on one of the legal bases in Article 6 GDPR:
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the Service: accounts, workspaces, the builder, publishing, notifications, API and MCP access | Account, content you create, connections, notifications, usage and limits | Performance of a contract (Art. 6(1)(b)) |
| Let you try Emberblocks anonymously in the sandbox | Sandbox | Legitimate interest in letting visitors evaluate the product before signing up (Art. 6(1)(f)) |
| Bill paid plans, issue invoices, keep accounts | Billing | Contract (Art. 6(1)(b)); legal obligation under Greek tax and accounting law (Art. 6(1)(c)) |
| Run Ember, our AI assistant, when you ask it to draft something | The prompt and context you send, which may include parts of your app definition and sample data | Contract (Art. 6(1)(b)); you choose when to use it |
| Keep the Service secure, prevent abuse, enforce plan limits | Technical and security, usage and limits, IP hashes | Legitimate interest in protecting the Service and other users (Art. 6(1)(f)) |
| Understand how emberblocks.com and the builder are used, and improve them | Analytics | Plausible: legitimate interest (aggregate, cookieless). PostHog: consent (Art. 6(1)(a)); withdraw any time by clearing cookies or via the cookie notice |
| Tell you about product updates, onboarding tips and launches | Account or waitlist email | Customers: legitimate interest in keeping you informed about the product you use (Art. 6(1)(f)), with an unsubscribe link in every email. Waitlist: your sign-up (consent, Art. 6(1)(a)) |
| Answer support requests and rights requests | Support and correspondence | Contract (Art. 6(1)(b)); legal obligation for rights requests (Art. 6(1)(c)) |
| Comply with the law, respond to lawful requests, establish or defend legal claims | Whatever the situation requires | Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interest we have weighed it against your rights and concluded that the processing is what you would reasonably expect and has little impact on you. You can object at any time (see section 11).
We do not sell personal data, and we do not use it for automated decisions that produce legal or similarly significant effects on you.
5.AI features
When you use Ember to draft an app, a field, an expression or sample data, the text you type and the context the builder attaches (the relevant parts of your app definition, field names, and sometimes example rows) are sent to OpenRouter, which routes the request to a model provider such as Anthropic, OpenAI or Google. The reply is shown to you and applied to your draft; we store the resulting app definition, not the prompt or the raw answer. We keep only monthly counts of calls and tokens per workspace to enforce plan limits.
We do not train models ourselves and do not use your prompts to train anything. The model providers process your request under their own terms, which are linked in section 6; some may retain requests for a limited period for abuse monitoring. Ember is optional. If a prompt would contain data you must not share with a third-party processor, do not send it: build the field or expression by hand instead.
7.Where data is stored and international transfers
Your account and workspace data lives in Supabase’s Frankfurt region in Germany. Application code runs on Vercel, whose edge network serves requests worldwide and whose serverless functions run in the United States, so data transits Vercel’s infrastructure while a request is processed. Email, payments and AI providers listed in section 6 are based in the United States.
Transfers outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses in each provider’s data processing agreement and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards at hello@emberblocks.com.
9.How long we keep data
| Data | Retained for |
|---|---|
| Account and workspace data | For as long as your account exists. When you ask us to delete your account, or a workspace is deleted, live data is removed within 30 days and drops out of encrypted backups within a further 30 days. |
| Sandbox guest accounts and their apps | 24 hours from creation, then deleted automatically, unless you claim the sandbox by signing up, in which case it becomes a normal workspace. |
| Waitlist | Until you unsubscribe or ask us to remove you, or until we retire the list. |
| Billing records and invoices | For as long as Greek tax and accounting law requires, currently at least five years after the end of the financial year. |
| Push notification subscriptions | Until you turn notifications off for that device or the app is deleted. |
| Rate-limit counters | Public-link counters expire with their time window (at most one calendar month). Sandbox and waitlist hashes are deleted with the sandbox or waitlist row. |
| Hosting request logs | A short period at Vercel, measured in days, unless we preserve specific entries to investigate abuse or an incident. |
| Product analytics events (PostHog) | 12 months, then deleted. |
| Support correspondence and rights requests | 24 months after the matter closes, longer if needed to establish or defend a legal claim. |
Deleting your account is done by email today: write to hello@emberblocks.com from the address on the account. Workspace owners can delete apps and data sources from the workspace at any time.
10.How we protect data
- All traffic is encrypted in transit (TLS). Data at rest is encrypted by Supabase.
- Data-source credentials (Airtable tokens, Postgres connection strings, webhook secrets) are encrypted with AES-256-GCM under a key derived separately for each workspace, and are never returned to the browser after you save them.
- Every table is protected by row-level security, so a workspace can only reach its own data; internal counters and credentials are reachable only by the server.
- Sign-in uses one-time email links or Google; we never store passwords.
- IP addresses used for rate limiting are stored only as one-way hashes.
- Access to production is limited to the operator and protected by multi-factor authentication.
One deliberate exception you should know about: files uploaded to apps are stored in a public bucket. Their URLs are long and unguessable, but anyone who has a URL can open the file without signing in. Do not upload files that must stay confidential, and tell your app users the same.
No system is perfectly secure. If a breach affects your personal data in a way that is likely to put you at risk we will tell you and the Hellenic Data Protection Authority as GDPR requires.
11.Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you and get a copy;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”), subject to records we must keep by law;
- Restrict processing while a dispute about the data is resolved;
- Port the data you gave us to another provider in a machine-readable form (your apps and Ember DB data can also be exported as CSV from the product);
- Object to processing based on legitimate interest, including product emails, at any time;
- Withdraw consent where processing rests on it (analytics cookies, waitlist), without affecting what happened before;
- Complain to a supervisory authority (see below).
To exercise a right, email hello@emberblocks.com from the address on your account, or tell us how we can verify it is you. We answer within one month; for complex requests we may take up to two months more and will tell you why. Requests are free unless they are clearly unfounded or excessive.
Our lead supervisory authority is the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr. You may also complain to the authority where you live or work in the EEA. We would appreciate the chance to resolve the matter first.
If you are an app user of a customer’s app, address these rights to that customer; we will assist them. If you write to us we will forward your request to the customer where we can, and act on it ourselves where the law requires.
12.Processing on behalf of our customers
This section applies between Emberblocks and each customer (the workspace owner and its organisation) for the personal data the customer stores in, syncs to or collects through the Service (“Customer Data”). It is the data processing agreement required by Article 28 GDPR, and it forms part of the Terms of Service.
- Roles. The customer is the controller of Customer Data and decides its purposes and means. We are the processor and act only on the customer’s documented instructions, which are: the Terms, this policy, and the settings the customer chooses in the product. We will tell the customer if we believe an instruction breaks the law.
- Nature and purpose. Hosting, storing, displaying, syncing, transforming and transmitting Customer Data so the customer’s apps, workflows, emails, documents and public links work as configured, for the life of the customer’s account.
- Types of data and data subjects. Whatever the customer chooses to put into their apps, typically business contact details, records about the customer’s staff, clients, suppliers or operations, and the accounts of the people the customer invites as app users.
- Confidentiality. Only people who need access to run and support the Service have it, and they are bound by confidentiality. We look at Customer Data only to operate the Service, to support the customer at their request, to enforce the Terms, or as the law requires.
- Security. The measures in section 10, including the public-bucket caveat for uploads.
- Sub-processors. The customer authorises the sub-processors in section 6 and the mechanism there for changes. We hold each sub-processor to obligations no less protective than these, and remain responsible for them.
- Transfers. As described in section 7.
- Assistance. We help the customer respond to data-subject requests (the product exposes search, edit, export and delete for every record), and, taking account of the nature of the processing, with security, breach notification, impact assessments and consultations with authorities. We notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
- Deletion. When the customer deletes an app, a data source or a workspace, or when the account ends, Customer Data is deleted as described in section 9. Before that the customer can export it as CSV. We keep nothing afterwards unless EU or Greek law requires it.
- Information and audit. We make available the information reasonably needed to show compliance with this section, and answer reasonable written security questionnaires no more than once a year. Any on-site audit needs 30 days’ notice, a mutually agreed scope, and is at the customer’s cost.
What we expect from the customer. The customer is responsible for having a lawful basis for the Customer Data they collect, for the privacy notice their app users see, for not storing special-category data or data about children without appropriate measures, for what they expose through public links (which anyone with the link can open), and for the content of emails and documents their workflows send.
13.Children
The Service is for business and professional use and is not directed at anyone under 18. We do not knowingly collect personal data from children as controller. If you believe a child has created an account, write to hello@emberblocks.com and we will delete it. Customers who build apps used by minors are responsible for the safeguards that requires.
14.Emails we send
Service emails (sign-in links, invitations, app transfers, trial and billing notices, security alerts, and messages your workflows send) are part of running the Service and cannot be switched off while you have an account.
Product emails (onboarding tips, new features, launch news) go to account holders and waitlist subscribers. Every one carries an unsubscribe link; one click stops them. You can also object by emailing us. We do not share our lists with anyone for their own marketing.
15.Links to other sites and apps built by others
The Service links to third-party sites (documentation, provider terms, the sources you connect), and customers’ apps may link anywhere they like. Those sites have their own privacy policies, and we are not responsible for them. An app built on Emberblocks belongs to the customer who published it, even when it carries a “Powered by Emberblocks” badge.
16.Automated decision-making and profiling
We do not make decisions about you by automated means that have legal or similarly significant effects. Plan limits and rate limits are applied automatically, but they concern usage of the Service, not you as a person, and you can always contact us if one seems wrong. Ember generates drafts on request; it does not evaluate people.
17.Changes to this policy
We update this policy when the Service, our providers or the law change. The date at the top always shows the current version. For material changes (a new category of data, a new purpose, a new sub-processor for Customer Data) we will also email account holders or show a notice in the product before the change takes effect. Continuing to use the Service after that means you accept the updated policy; if you do not, stop using the Service and ask us to delete your data.
18.Contact
Apostolos Papadopoulos, trading as Emberblocks
Filippou 2, 546 30 Thessaloniki, Greece
hello@emberblocks.com
For privacy requests, put “Privacy request” in the subject line so we can prioritise it. We aim to acknowledge within five business days and to answer within one month.