Last updated 5 September 2026
Ember is built by Poxi AS, a company registered in Norway, and Poxi AS is the data controller for everything below. This page says what the app collects, why, where it is kept and how to get rid of it. It is written to be read rather than to be survived.
The short version: Ember keeps what you write down so it can show it back to you on your next phone. It runs no ads, sells nothing to anybody, and the only outside services it talks to are the five named further down.
The app makes an account on your first open so your habits have somewhere to live, before you have typed anything at all. That account holds a generated identity and, if you give one, an email address and a name you choose. Passwords are stored hashed and we cannot read them.
An email address is what makes the account recoverable. Without one, the account lives on that device and is gone with it.
Habits, tasks, tags, shopping items, ritual steps, Deep Focus sittings, meditation lengths, and the day by day record of what you finished. That record is the app: it is what draws the wall, counts a streak and pays a reward.
A friends ember holds the first names you typed into it and the days you reached each of them. Ember never reads your contacts, asks for no permission to, and wants no last names, numbers or addresses: the names are words you wrote, exactly like the name of a habit.
It is stored against your account so the same fire shows up when you sign in somewhere else. Nobody reads it but you, except where a paragraph below says otherwise.
If you turn the step counter on, the app reads daily step totals: from Apple Health on iPhone, from the phone’s own step sensor on Android. It asks first, it reads nothing until you allow it, and it reads nothing else from Health: no heart rate, no workouts, no sleep, no weight.
Daily totals are stored against your account so a day’s steps can pay their logs once and only once. Health data is never used for advertising or marketing, is never sold, and is never shared with any third party. Turning the permission off in your phone’s settings stops the reading immediately.
On each open the app notes the platform, the app version, the handset model and the operating system version, and stores them on your account. It is how we know which builds still need to work. It is not an advertising identifier and it is not used to recognise you anywhere else.
The bell at the end of a meditation and the chime at the end of a Deep Focus sitting are scheduled by your phone, on your phone. There is no push service behind them, no device token leaves the app, and we cannot see whether one was delivered or opened.
When you add a task without choosing a tag, the app guesses where it belongs. To do that it sends the task’s title, your tag names, and the titles of a few tasks you have already filed, to OpenRouter, which passes them to a classification model. That model answers which of your tags the task belongs under and cannot write text at all. No email address, no account identifier and nothing else from your record goes with them.
Choosing a tag yourself when you write the task means the call is never made. Tasks you have already filed are never re-sent on their own account.
Ember uses AppsFlyer to tell which advert, link or post an install came from, so a small team can stop paying for the ones that do not work. AppsFlyer receives device and network identifiers, your IP address, coarse device information such as the handset model and language, and the identifier of your account, so a report can be matched to an account, never to a name.
It also receives a few in-app events: the install itself, the first run finishing, the membership screen being opened, and, once the store has confirmed it, a membership being bought or renewed.
On iPhone this includes Apple’s advertising identifier only if you allow tracking when the system asks; say no and it is not collected, and you can change the answer at any time under Settings, Privacy & Security, Tracking. AppsFlyer processes all of this on our behalf as a data processor, and passes the result, which advert an install came from, to the network that ran the advert, so that network can be paid and can stop showing it to people who already have the app. Their own privacy policy is at appsflyer.com/legal/services-privacy-policy. Nothing you write in the app is sent to them, no Health data is sent to them ever, and if you want what they hold about you erased, write to us and we will have it done.
Apple and Google take the payment for a membership, and never pass us a card number. Between them and the app sits RevenueCat, which keeps the subscription’s status: it receives the identifier of your account and the receipt Apple or Google issues for a purchase, and it is what our server asks when it decides whether the cap is off for you. Once a purchase is confirmed, RevenueCat also tells AppsFlyer about it, so the sale can be counted against the advert that led to it.
Anything you post on the ideas and bugs board is public to other players, along with the name on your account. Treat it as writing on a wall. The occasional in-app survey is optional, and skipping it changes nothing about the app.
Your rows live in a PocketBase database hosted on Railway in Amsterdam, in the EU. The app’s server runs on Vercel in Frankfurt. Those two, OpenRouter for filing tasks, AppsFlyer for measuring installs and RevenueCat for memberships are the only processors involved. Apple and Google handle every membership payment and never pass us a card number.
We do not sell personal data, and there is no advertising network inside the app.
Your record is kept until you delete it. Settings, then Delete account, removes the account and the rows attached to it. Posts already on the ideas board stay so the threads still make sense, with the name taken off them.
If anything is unclear or you want a copy of what is held, write to filip@poxi.co and a person will answer.
Under the GDPR you can ask for a copy of your data, ask for it corrected, ask for it deleted, ask for it in a portable form, or object to a particular use of it. The lawful bases are the contract between us for running the app, your consent for step counts and for tracking, and our legitimate interest in keeping the thing working and knowing which adverts paid off.
If we get it wrong you can complain to the Norwegian Data Protection Authority, Datatilsynet, or to the authority where you live.
Ember is not made for children under 13, and we do not knowingly keep an account for one. In the EEA, anyone under 16 needs a parent or guardian’s consent. If a child’s account exists, write to us and it will be deleted.
If this policy changes in a way that matters, the date at the top changes and the app says so before the change takes effect. Small corrections just get the new date.