Privacy Policy
Last updated: September 2026
This policy covers the data Embarko holds about you, our customer. Data that your own app collects from its visitors is yours, not ours — see Your app's own data below and, if you are subject to the GDPR, our Data Processing Agreement.
What we collect
- Account identity. Your email address or phone number, verified through our authentication provider, plus the company you belong to and your role in it. Sign-in is by one-time code, so we never hold a password for you.
- Your app's source and configuration. The archive you deploy, the app name, the version string, and the environment variables and secrets you set.
- Deploy and build records. Timestamps, which token was used, build logs, and whether the deploy succeeded — kept so you can debug a failure and so we can investigate abuse.
- Runtime logs and metrics. Your app's own output plus resource usage (CPU, memory, storage, bandwidth), used to run the app, enforce plan limits, and bill usage.
- Request metadata for your live app. Path, referrer, coarse country, status code, and user agent class, used for the analytics we show you, for abuse prevention, and for reliability work.
- Billing details. Your plan, subscription state, and invoice history. Card details go directly to our payment processor and are stored there, not with us.
- Support correspondence. The emails you send us and our replies.
- Website analytics. Our marketing pages and console load Google Tag Manager, which sets analytics cookies and records page views and coarse device and location information. It is used to understand how people find and use Embarko.
What we do not do
- We do not sell your personal data, and we do not share it for anyone else's marketing.
- We do not read the data your app stores in order to profile you or your visitors.
- We do not use your source code or your app's data to train AI models.
How we use what we collect
- To run the service: building and serving your app, routing its domain, issuing certificates, restoring backups, and keeping the platform up.
- To bill you: measuring usage against your plan and processing payment.
- To contact you: sign-in codes, deploy and incident notices, billing messages, and occasional product announcements you can unsubscribe from. We do not sell your address on.
- To protect the platform: rate limiting, fraud and abuse investigation, and responding to reports about content hosted with us.
- To improve Embarko: aggregate usage patterns, error rates, and the analytics described above.
Who we share it with
We use service providers to operate Embarko — hosting and compute, storage, authentication, transactional email, billing and payments, and website analytics. Each processes data on our instructions under its own agreement with us. The current list, with purposes and locations, is in our DPA.
We also disclose data where the law requires it, and where we need to in order to investigate a credible abuse or security report.
How long we keep it
- Account and company records: for as long as your account exists.
- Apps, their data, and their backups: until you delete the app or close the account.
- Build and deploy logs, runtime logs, and raw request records: [retention window], after which analytics survive only as aggregated counts.
- Invoices and billing records: for as long as tax and accounting law requires us to keep them, currently [retention period].
- After you close your account, we delete your apps and their data within [deletion window]. Backups age out on their own schedule within [backup window].
Where your data is held
Embarko's infrastructure runs in [primary region(s)]. Where personal data moves outside the region it was collected in, we rely on [transfer mechanism — e.g. Standard Contractual Clauses].
Your app's own data
Whatever your app collects from its visitors — accounts, uploads, database rows — belongs to you. We hold it because we run the app, and we access it only to operate the service: to keep the app running, to restore a backup, to answer a support request you have made, or where we are legally required to.
If your app collects personal data, you are the controller of it and you need your own privacy notice for your visitors. This policy is not it.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, export it, delete it, or object to some uses of it. Email hello@embarko.ai and we will respond within [response window]. You can also complain to your local data protection authority; ours is [lead supervisory authority].
Changes
We may update this policy. The date at the top of the page changes when we do, and we will email account holders about material changes.
Contact
Privacy questions go to hello@embarko.ai. Embarko is operated by [legal entity name and registered address].