Home/Privacy

Privacy

Ember is a UK parenting product. This page explains what we collect, why, and how you stay in control. It is written for parents — not lawyers. It is not legal advice.

Who we are

Ember (emberplay.app) is the controller for personal information described here. Questions, complaints, or data requests: use our contact form (choose Privacy complaint or Access request). We aim to acknowledge privacy complaints within 30 days.

What we collect

  • Account details (email, sign-in identity from Google/Apple/email codes).
  • Child profiles you add: date of birth (to place the right age band), optional call-name, optional gender. Call-names are never required.
  • Saves, gift marks, Family ID / gift-list settings, Marketplace listings and messages.
  • Waitlist email if you join Ember Plus interest collection.
  • Optional analytics (only if you accept analytics) — product events (user id, page area, product ids, child id and age band — not call-names, not exact dates of birth, not postcodes) and, during early launch, short session recordings of how you use Ember so we can spot confusing screens. Typed fields are masked; Account, sign-in, and contact pages are not recorded. Recordings are not used for advertising.
  • Optional marketing / advertising cookies (only if you accept marketing) — used when we run paid ads or performance campaigns; pixels must not load without this switch.
  • Push subscription details if you turn on browser notifications.

Why we use it

To run your Ember account, personalise Discover and Family, share a gift list when you choose, power Marketplace, improve the product (with analytics consent), and email you about Ember Plus readiness when you join the waitlist. We do not sell personal data. We do not run ad pixels today.

Children's information

Ember is built for parents. Profiles store information about your child so ideas fit their age. Public gift links default to age labels only. Call-names appear on a public gift list only if you switch that on when sharing. We never send call-names as analytics event properties. If you accept analytics, a session recording may still show a call-name that is already visible on screen — that is why Account and sign-in pages are not recorded, and typed fields are masked.

Cookies

Essential cookies keep you signed in. Optional analytics and marketing cookies stay off until you Accept, or until you switch them on in the preference centre. Reject is offered with the same weight as Accept. Details: Cookies.

Who helps us (subprocessors)

  • Supabase — authentication, database, file storage
  • Vercel — website hosting
  • PostHog — product analytics and session recordings (only with your analytics consent)
  • OneSignal — web push (only when you turn notifications on)
  • Google / Apple — sign-in, when you choose those options
  • Google Gemini — optional Marketplace listing photo assist (not for identifying people)
  • postcodes.io — turning a UK postcode into an approximate area for Marketplace
  • Affiliate networks — purchase attribution when you follow a retailer link (on their site)

Your choices

  • Change analytics on Cookies or Account → Privacy & data.
  • Turn push off in Family reminders / Account.
  • Download a copy of your Ember data or delete your account from Account.
  • Leave the waitlist via Unsubscribe.
  • Complain to Ember via Contact, or to the ICO.

How long we keep data

We keep account and child profile data while your account is active. If you delete your account, we remove auth identity and cascaded app data. Waitlist rows you unsubscribe from are marked unsubscribed and not used for further readiness emails. Analytics and session recordings follow PostHog retention (recordings currently kept for about 30 days).

Last updated: 31 July 2026