Privacy Policy
Last updated: September 14, 2026
EmberPact is a private home for the agreements you and your partner make. This policy explains what data the EmberPact mobile app and website collect, why, and what control you have over it. The short version: the words of your agreements, goals, reflections, and journals are end-to-end encrypted on your device, your Pact is stored in the EU, and we do not sell it. Optional document import has a separate consent step and is described below.
Who we are
EmberPact is operated by Wingmen Oy, a Finnish company, Business ID 2521554-2, Tunturikatu 14 B 48, 00100 Helsinki, Finland. Wingmen Oy is the data controller for the personal data described in this policy. You can reach us at [email protected].
What we collect
Account data.
- Email address and a password (stored as a hash, never in plain text)
- Your first name, used to address you and your partner inside the app
- Account identifiers, email verification status and temporary verification codes
- App-generated device identifiers, public encryption keys and encrypted key envelopes used to pair and approve your devices
Your pact, in two layers.
- Encrypted content: the text of your agreements, goals, actions, reflections, journals and drawn Pact signatures is encrypted on your device before it is sent to us. Our servers store only the encrypted form. A database leak, an administrator, or our hosting provider cannot read what you wrote.
- Readable structure: to make the app work (sync, reminders, charts), the server can read non-text structure: entry types, statuses, dates, who an item is assigned to, category tags, relationship dates, meeting schedules, review activity and relationship vital score numbers. These details can still be personal and sensitive.
Subscription status.
- Your plan, purchase platform, payer identifier and expiry date, so we can unlock paid features. Payment itself is handled by Apple and Google (see below).
Technical data.
- Server logs, including IP addresses, request paths, timestamps, browser or app information and errors, used for security and troubleshooting.
We do not request location or contact access, collect advertising identifiers, or connect to Apple Health or Health Connect. The app contains no advertising. You may choose to include sensitive information in your Pact or in a document you import.
Support and feedback.
If you contact us or use the feedback form, we receive your message and any email address you provide. Feedback is stored on our server and forwarded to our support mailbox. Support messages are readable by us and are outside the Pact's end-to-end encryption. Please include only the information needed to resolve your issue.
End-to-end encryption, honestly
Encryption keys are generated on your device and stored in your device's secure storage (the Keychain on iOS). The key that protects your couple's words is shared between your two approved devices in sealed form; our server relays it without receiving the decryption key. Data is sent over HTTPS. This design protects stored words against a database leak and ordinary administrator or hosting-provider access. It does not protect against a compromised device or a malicious app update. The readable structure described above remains visible to us. We cannot recover your encrypted words if all devices holding your keys are lost.
How we use your data
- To provide the service: accounts, pairing, sync between you and your partner, reminders (performance of contract)
- To manage subscriptions and unlock paid features (performance of contract)
- To keep the service secure and fix problems (legitimate interest)
- To answer messages you send us (legitimate interest)
- To process optional document imports you explicitly request (consent)
- To meet applicable legal and accounting obligations (legal obligation)
We never sell your data, and we never use the content of your pact for advertising or to train AI models. Optional document import sends only the text you explicitly choose to share.
Optional document import
You can choose one document to help draft your existing agreements. The app extracts text locally from XLSX, DOCX or PDF and lets you review and edit it before sending. Only after your explicit consent does that text pass through our API to Anthropic to produce suggestions. EmberPact and Anthropic can read the text during this step, which is outside end-to-end encryption. The original file is not uploaded. We do not log or save the plaintext.
Our server saves the result encrypted for the importing phone so an interrupted request can be recovered. Your phone converts the suggestions into drafts encrypted with your couple's key. Both partners review and reveal their drafts before adding agreed wording to the Pact. Import records are deleted with the shared Pact.
Anthropic may retain inputs and outputs for up to 30 days, or longer for safety or legal reasons under its commercial terms. See Anthropic's data retention policy. You can keep using the wizard without importing a document. You can decline before sending, or contact us to withdraw consent for future processing. Withdrawal cannot undo a completed import or processing that was lawful before withdrawal.
Sharing with your partner
EmberPact is built for two. Your shared pact, including its encrypted content, is by design accessible to your partner on their device. Reflections you write during guided sessions stay private to you inside the app until you choose to reveal them.
App permissions
- Camera: used only to scan your partner's QR code when pairing your devices. Scanning happens on your device; no photos or video are stored or uploaded.
- Notifications: reminders for your rituals and agreements are scheduled locally on your device. You can turn them off in system settings at any time.
- Files: the system file picker gives access only to the document you choose for import. Text is extracted on your device; the original file is not uploaded.
Payments and service providers
- Apple App Store and Google Play process all payments. We never see your card details. Their own privacy policies apply to the purchase itself.
- RevenueCat manages purchase and subscription entitlements. It receives an app user identifier, which is linked to your EmberPact account after sign-in, purchase information and technical data such as device type, operating system and app activity timestamps. We do not send it your Pact's words, name or email address. See RevenueCat's privacy policy.
- Our app servers and database are in the European Union. Disaster-recovery backups are stored with Amazon Web Services in Frankfurt, Germany. Hosting providers process stored data and technical logs to operate this infrastructure.
- Cloudflare handles website traffic and network protection, including request metadata.
- Email delivery and mailbox providers process verification emails and support messages.
- Anthropic processes document text only when you choose the optional import described above. RevenueCat, Anthropic, Apple, Google and email providers may process data outside the EU or EEA, including in the United States. International transfers are subject to applicable data protection requirements and the relevant provider agreements. Contact us for details of the safeguards that apply to your data.
We may disclose data we can access when required by law or when necessary to investigate abuse or protect people's rights and safety. We cannot provide decryption keys we do not hold.
Website
The website serves public information without advertising or analytics cookies. Fonts are served from our site. Hosting and network providers receive the technical request data described above. Following a store or other external link takes you to that provider's site, where its privacy policy applies.
Retention and deletion
We keep your data for as long as your account is active. Either partner can end the shared pact at any time from inside the app. Ending it deletes the server copy: the encrypted content, the readable structure, and the key envelopes. Sync stops and the other partner is notified. Ending a Pact also clears the initiating phone's copy. Copies already on your partner's device remain under their control. Ending a Pact does not delete your account or cancel a store subscription.
Support messages and technical logs are retained for handling requests, troubleshooting, security and any related disputes. We review their continued need when handling a deletion request. Records needed for legal, accounting or fraud-prevention purposes may be retained for as long as those obligations require; we explain any applicable exception when responding.
Deleted data may remain in disaster-recovery backups for up to 730 days. These backups are used for recovery only. If a backup is restored, subsequent deletion requests are reapplied. Store providers may retain their own transaction records under their policies.
Request account and data deletion
In the app, open You, then Delete account. If you are still setting up your account, open Account at the bottom of the setup screen. Enter your password and confirm the deletion. We sign you out after accepting the request and clear this phone's local Pact data. Processing usually takes a few minutes; we email confirmation within one month. Deletion requests cannot be undone.
You can also email [email protected] from the email address on your account with the subject "Delete my Emberpact account". You can request deletion without reinstalling or signing in to the app. We verify ownership before deleting account data. Never send your password or encryption keys.
The request covers your account details and associated personal data, including device registrations, stored Pact content, import records and identifiable feedback. Deleting an active shared Pact stops sync for both partners. We cannot erase copies already on your partner's device. The backup and legal-retention exceptions above still apply. We respond to privacy requests within one month and explain any lawful extension. You can also use this address to request deletion of specific data without deleting your account.
Deleting your account does not cancel an Apple or Google subscription. Manage or cancel it in your App Store or Google Play subscription settings.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted
- Restrict or object to processing
- Receive your data in a portable format
- Lodge a complaint with a supervisory authority, in Finland the Office of the Data Protection Ombudsman (tietosuoja.fi)
To exercise any of these rights, email [email protected]. Note that we cannot read or recover the encrypted words of your pact; only your devices hold the keys.
Children
EmberPact is made for adult couples and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
If we change this policy in a way that matters, we will update this page and note it in the app. The date at the top always shows the latest revision.
Contact
Questions about your data or this policy: [email protected].