Privacy Policy
Last updated: August 16, 2026
This policy explains what Ember does with your information — including anything it reads from your Google account. It is written to be read, not to be survived. If something here is unclear, write to [email protected] and it will be fixed.
The short version. Ember runs on hardware in your own home. Your voice, your transcripts and anything it reads from your Google account are stored on that hardware and nowhere else. Nothing is sold, nothing is shared with advertisers or data brokers, and nothing is used to train anyone's models.
Who this policy is from
Ember is an independent, self-hosted voice assistant. It is not operated as a hosted service: the software runs on a computer you control, in your own home, on your own network. Throughout this policy, “Ember” means that software and the people who maintain it, and “you” means the person who installed and runs it.
Contact for any privacy question, complaint or deletion request: [email protected].
What Ember collects
Information you speak or type
When you use the wake word and talk to Ember, the audio is processed to work out what you said, and the resulting text is used to answer you. Ember keeps a history of these conversations so it can follow context and so you can read back what was said.
Information from your Google account
Ember only reads what you have explicitly granted, and only the following:
| What is accessed | Why | Kept? |
|---|---|---|
| Your basic profile — name, email address, profile picture, and your Google account identifier | To sign you in and to tell household members apart, so one person's settings and history are not mixed with another's. | Stored locally for as long as your account is connected. |
| Google Calendar — your calendars and the events on them, and the ability to create or change events when you ask | To answer questions about your schedule (“what's next?”, “am I free Thursday?”) and to add or move events by voice. | Read when you ask. Not copied into a separate database. A short cache may be held in memory to avoid re-asking Google for the same day repeatedly. |
| YouTube — search, video details, and your own playlists and subscriptions | To find and play videos and music on a screen or speaker in your home, and to reach things from your own library when you ask for them. | Read when you ask. Not copied into a separate database. |
| An access token and refresh token issued by Google | So Ember can keep the connection working without asking you to sign in again every time. | Stored on your own hardware until you disconnect the account. |
Ember does not request access to your email, your contacts, your files, your photos, your location history, or anything else not listed above.
How Ember uses this information
Only to do the thing you asked it to do. Specifically:
- To understand your request and answer it.
- To read from and, where you have permitted it, write to your calendar.
- To find and play media you asked for.
- To keep enough conversation history that a follow-up question makes sense.
Ember does not use it:
- for advertising, ad targeting, or personalised ads of any kind;
- to build a profile of you for sale or transfer to anyone;
- to train, fine-tune or improve any machine-learning model, ours or anyone else's;
- for any purpose you did not ask for when you connected the account.
Google API Services — Limited Use
Ember's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means Google user data is used only to provide or improve the features you asked for, is never transferred to others except as needed to provide those features or as required by law, is never used for advertising, and is never read by a human except with your explicit permission, for security purposes, or where the law compels it.
YouTube API Services
Ember uses YouTube API Services to search for and play media. By using the YouTube features of Ember, you are agreeing to be bound by the YouTube Terms of Service.
Google's own handling of your information is described in the Google Privacy Policy, which is separate from this one and which Ember does not control.
You can revoke Ember's access to your data at any time:
- through Google's security settings page at security.google.com/settings/security/permissions, or
- through your account permissions page at myaccount.google.com/permissions, or
- from inside Ember itself, by disconnecting the account.
Revoking access stops Ember reading anything further immediately, and Ember deletes the stored tokens for that account.
Where your data is stored
On your hardware. Ember is self-hosted: the server component runs on a machine in your home, and conversation history, settings and Google tokens are written to that machine's own storage. There is no Ember-operated cloud database holding a copy.
The practical consequence is that the security of this data is mostly in your hands — see Security below — and that deleting it is something you can do directly, without asking anyone.
Who your data is shared with
Nobody, with two narrow and necessary exceptions:
- Google, when you have connected a Google account — because reading your calendar means asking Google for it. That traffic goes between your hardware and Google directly.
- A language model provider, if you have configured Ember to use a hosted model rather than a local one. In that case the text of your request is sent to that provider so it can be answered. Ember can be run entirely on local models, in which case nothing leaves your network at all. Which mode you are in is your choice and is shown in the app's settings.
Your information is never sold, rented, bartered, or handed to advertisers, analytics companies or data brokers. There is no arrangement under which that could happen.
How long it is kept
- Conversation history is kept until you delete it. Ember provides a way to clear it, and because it is a file on your own machine, you can also simply remove it yourself.
- Google tokens are kept until you disconnect the account or revoke access at Google, at which point they are deleted.
- Calendar and YouTube content is read to answer a request and is not retained afterwards beyond short-lived in-memory caching.
Security
Ember stores credentials with file permissions restricted to the account that runs it, and talks to Google over encrypted connections only. Because the software runs on hardware you control, the remaining protections — who can log in to that machine, whether it is exposed to the internet, whether it is kept up to date — are yours to set. Running Ember only on your local network, or behind a private network overlay, is the recommended configuration.
No system is perfectly secure, and this policy does not promise one is. If you find a vulnerability, please report it to [email protected].
Your rights
You can, at any time and without giving a reason:
- see what is stored, since it is on your own machine;
- delete any or all of it;
- disconnect a Google account and have its tokens erased;
- ask [email protected] for help doing any of the above.
If you are in a jurisdiction with statutory data rights — such as Canada's PIPEDA, the EU or UK GDPR, or similar — those rights apply, and the address above is the route to exercising them. A request will be answered within 30 days.
Children
Ember is not directed at children under 13, and accounts are not knowingly connected for them. A household device may of course be heard by a child; that audio is treated exactly like any other — processed on your own hardware and never sent to an advertiser.
Changes to this policy
If this policy changes, the date at the top of the page changes with it. A change that materially widens what Ember collects or what it does with it will be announced in the app before it takes effect, not slipped in.
Contact
[email protected] — questions, complaints, deletion requests, and security reports all go to the same place, and a person reads them.