Legal
Privacy Policy
The most private thing you own should stay that way. This policy explains, in plain words, what Ember does and doesn't do with data.
Privacy at a glance
- Your conversations stay on your phone. Ember's companion is designed to run on-device by default. Your words are stored on your device and encrypted there under a key derived from your recovery kit — held by you, not by us.
- We cannot read your conversations. Nothing leaves your device unless you opt in. If you turn on sync/backup, what leaves is end-to-end encrypted — we store only ciphertext we cannot decrypt.
- The cloud is off until you switch it on. Two features can send data off your device, and both are off by default: encrypted sync/backup, and optional cloud assistance. Nothing else leaves. See the box below.
- Nothing is sold. Ever. No ads, no data brokers, no "partners", no exceptions.
- You can delete everything. Erase on-device instantly, and request deletion of any account or encrypted backup — see Delete my data.
- Ember is non-clinical and 18+. Ember provides emotional wellbeing support through the menopause transition — a private space to reflect, build coping habits and feel heard. It is not a medical device and does not diagnose, treat or manage menopause or any medical condition. It is not directed at children.
1. Who we are
Wellnetix Ltd is the data controller for the Ember app and this website under the UK GDPR and, where it applies, the EU GDPR.
- Controller: Wellnetix Ltd, United Kingdom.
- Contact for privacy matters: nimind@wellnetixltd.com
- We have not designated a statutory Data Protection Officer; privacy matters are handled directly by the team at the contact address above.
2. What this policy covers
It covers the Ember mobile app for iOS and Android (currently in private early access) and the ember.wellnetixltd.com website, including the early-access sign-up and contact forms. It does not cover third-party services you reach through signposting (for example, your GP's booking system or a crisis line) — those have their own policies.
3. What we collect — and what we deliberately don't
Your data goes to the cloud only when you opt in.
By default, everything stays on your device — your conversations and diary never touch our servers. There are exactly two features that can send data off your device, and both are off until you turn them on:
- Encrypted sync/backup — your content leaves only as end-to-end encrypted data. We store ciphertext we cannot read.
- Cloud assistance — a single exchange is sent to a cloud model, transiently, to help write one reply. Not retained afterwards.
Turn either off at any time. Neither is required to use Ember. Full detail in §3.3 and §3.4.
3.0 What we collect & where it's stored — at a glance
Every item Ember touches, what it is, where it lives, whether it ever leaves your device, and how long it's kept. The detailed sections follow.
-
App conversations & memory Your device
- What it is
- Your chat with the companion and what it remembers for you.
- Where it lives
- On your device, encrypted at rest under your recovery-kit key.
- Leaves device?
- No — unless you turn on sync/backup (then end-to-end encrypted).
- Retention
- Until you delete it or uninstall. Not retained by us.
-
Wellbeing diary Your device Off by default
- What it is
- Entries and tags you write yourself — your own words, never scores, stages or forecasts.
- Where it lives
- On your device. The diary is opt-in and off unless you enable it.
- Leaves device?
- No — unless you sync (end-to-end encrypted), or you export a copy for your GP yourself (assembled on-device; never uploaded to us).
- Retention
- Until you delete the entry or the diary.
-
On-device model files Download to device
- What it is
- The language-model files the app downloads after install so it can run locally.
- Where it lives
- Cached on your device. The download is a plain file transfer, integrity-checked before use.
- Leaves device?
- None of your content. The fetch sees only standard technical request data (IP address, app version) — the model comes to your words, not the other way round.
- Retention
- Cached until you uninstall; delivery logs kept up to 90 days.
-
Cloud assistance Opt-in · transient
- What it is
- A single conversation exchange sent to a cloud model to help generate one reply.
- Where it lives
- Processed transiently by a contracted AI inference provider — only if you switch cloud assistance on.
- Leaves device?
- Yes, when enabled — encrypted in transit (TLS). Never used to answer a crisis or medical/HRT question.
- Retention
- Not retained after the reply; minimal security/abuse logs up to 90 days; never used for training.
-
Encrypted sync & backup Opt-in · E2E
- What it is
- A copy of your on-device content, encrypted on your device before it leaves.
- Where it lives
- On our servers as end-to-end encrypted blobs, plus minimal metadata (account identifier, timestamps, sizes). We cannot decrypt the content.
- Leaves device?
- Yes, when enabled — as ciphertext only.
- Retention
- Until you delete it or close your account.
-
Account email Opt-in · our servers
- What it is
- Your email address and sign-in credentials — only if you claim an account for sync/backup/restore.
- Where it lives
- On our servers, encrypted at rest. Unlike your conversations, we can process this to sign you in and run those features.
- Leaves device?
- Yes, if you create an account. Ember works fully without one.
- Retention
- For the life of the account; erased when you delete it.
-
Website waitlist & contact Your email to us
- What it is
- The early-circle sign-up and contact form: your email address, and any message you send.
- Where it lives
- The website stores nothing — both forms open your own email app and send a message to us. We hold what you email us, in our inbox.
- Leaves device?
- Only what you choose to email us.
- Retention
- Until you unsubscribe or ask us to remove it, or the early-access programme ends.
-
Server & security logs Our infrastructure
- What it is
- Standard web-server and security logs — IP address, user agent, pages requested — needed to run and protect the service.
- Where it lives
- With our cloud hosting provider. No conversation content, no decryption capability.
- Leaves device?
- Standard technical request data only.
- Retention
- Up to 90 days.
3.1 In the app: your conversations, journal and reflections
- Stored: on your device only, by default. Content is encrypted at rest using client-side encryption under a key derived on your device and held by you (with a recovery kit you control).
- Collected by us: no. We do not receive, read, mine, or train on your conversations. There is no server-side copy we can decrypt.
- Crisis and HRT-related moments are recognised and handled on-device. We do not build risk profiles, and no "flag" about you is sent to us or anyone else.
3.2 In the app: the on-device model
When you first set up Ember, the app downloads the language-model files it needs to run locally. That download is a plain file transfer: our cloud infrastructure sees standard technical request data (IP address, app version) needed to deliver the files, and no conversation content — the model comes to your words; your words don't go to the model.
3.3 In the app: optional cloud assistance
If a reply needs more capability than your device can provide, Ember can — only if you have turned cloud assistance on — send that exchange to a cloud model to generate the response. When it is used:
- the exchange is encrypted in transit (TLS);
- it is processed transiently to answer the request and is not retained afterwards, aside from minimal security and abuse-prevention logs kept for up to 90 days — and it is not used for training;
- the processing is carried out by an AI inference provider engaged only for this purpose (see section 6);
- cloud assistance is off by default, clearly labelled in the app, and can be switched off at any time.
3.4 In the app: optional sync & backup
If you enable sync or backup, your content leaves your device only as end-to-end encrypted data encrypted under your key. We store the encrypted blobs and the minimal metadata needed to run the service (account identifier, timestamps, data sizes, device registrations). We cannot decrypt the content. Encrypted backups are kept until you delete them or close your account.
3.5 In the app: optional account
Ember works without an account. If you claim an account (for sync, backup or restore), we collect your email address and the credentials needed to sign you in, to operate those features.
3.6 On the website
- Early-access sign-up: your email address, used only to contact you about Ember early access. Unsubscribe anytime.
- Contact form / email: your email address and the message you send, used to reply to you.
- Cookies and analytics: none. See section 10.
- Server logs: our cloud hosting provider keeps minimal web-server logs (IP address, user agent, pages requested) for security and reliability, retained for up to 90 days.
3.7 What we deliberately do not do
- No sale or sharing of personal data for advertising. No ad SDKs, no data brokers.
- No wearables, no sensor tracking, no location tracking. Region-aware crisis signposting uses your device's locale/region setting on-device; it is not reported to us.
- No third-party advertising or cross-app tracking identifiers.
- No scores, stages or forecasts about your body — Ember doesn't generate them at all.
4. Purposes and legal bases (UK GDPR / GDPR)
-
Early-access email Website
To invite you to Ember early access and send occasional updates about it.
Consent · Art. 6(1)(a) — withdraw anytime via unsubscribe.
-
Contact messages Website
To respond to your enquiry.
Legitimate interests · Art. 6(1)(f) — responding to people who write to us.
-
Account email + authentication data App · optional
To provide sign-in, sync, backup and restore.
Contract · Art. 6(1)(b)
-
Encrypted sync/backup blobs + minimal metadata App · optional
To provide the sync and backup you switch on. Content is end-to-end encrypted; we cannot read it.
Contract · Art. 6(1)(b)
-
Cloud-assistance exchange content App · optional · transient
To generate a reply when on-device capability isn't enough and you've turned cloud assistance on.
Consent · Art. 6(1)(a) — and, as conversation content may include health information, the app asks for your explicit consent (Art. 9(2)(a)) when you enable it.
-
Model download + server logs App + website
Delivering files, keeping services secure and working.
Legitimate interests · Art. 6(1)(f)
Special-category data: what you write in Ember may include health information. By design it stays on your device under your key; where any of it transits our systems (cloud assistance, sync) it does so encrypted and/or transiently as described above, on the basis of your explicit consent.
5. Storage, encryption and retention
- On your device: your conversations and journal stay on the device under your key until you delete them or uninstall the app; they are not retained by Wellnetix. You can export or erase everything in the app at any time (uninstalling is subject to your OS backups).
- Encrypted backup/sync (if you enable it): kept until you delete it or close your account. We cannot decrypt it at any point.
- Cloud-assistance content: processed transiently to answer the request and not retained afterwards, aside from minimal security and abuse-prevention logs kept for up to 90 days.
- Operational/server logs: minimal, kept for up to 90 days for security and reliability.
- Early-access email address: kept until you unsubscribe or ask us to remove it, or the early-access programme ends.
- Support correspondence: kept as long as needed to handle your query and for a short period after.
6. Sharing and sub-processors
We never sell personal data. We share it only with service providers who process it for us under contract, and only what each needs:
-
Cloud hosting & infrastructure
Runs this website and stores end-to-end encrypted sync/backup data we cannot decrypt. Sees server logs and encrypted blobs plus minimal service metadata.
-
Email delivery
Carries early-access and support correspondence to and from nimind@wellnetixltd.com.
-
AI inference provider
Engaged only if you turn on cloud assistance; processes exchange content transiently. Otherwise, all processing is on-device.
-
Apple & Google
App distribution via the App Store and Google Play. Their standard install/crash ecosystems apply per your device settings — see section 11.
We keep a current list of sub-processors and will provide it on request at nimind@wellnetixltd.com. We use no advertising networks and no data brokers, and we do not sell personal data.
We may also disclose data if the law genuinely requires it. Because conversation content is encrypted under your key, we could not hand over readable conversations even if asked.
7. International transfers
We aim to keep personal data in the UK/EEA. Where a provider processes data outside the UK/EEA, we rely on UK adequacy regulations or the appropriate safeguards, such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.
8. Your rights
Under the UK GDPR / GDPR you can: access the personal data we hold about you; rectify it; erase it; restrict or object to processing; receive a portable copy; and withdraw consent at any time (without affecting earlier processing). Write to nimind@wellnetixltd.com and we'll respond within one month.
8.1 Deleting your data — you choose what goes
Different data lives in different places, so you get to choose what to remove. Your on-device data is instant and in your hands; for anything you stored with us, you pick whether to close your account too. There's a step-by-step version, with a ready-to-send request, on the Delete my data page.
-
Fastest · On your device Immediate
Your conversations and diary live on your device. The app's in-app erase controls delete entries — or everything — immediately, on-device, without asking us. Uninstalling removes the app's data too (subject to your own OS backups). Because we can't read this data, this route is entirely in your hands.
-
Option A · Account and all cloud data In-app or request
Closes your account and erases the cloud copy. If you claimed an account and turned on sync/backup, ask us to delete it (in-app where available, or by email). We delete the account and the key that unlocks your encrypted backups, which renders those backups permanently unreadable. A short reversal window (about 14 days) guards against deletion made in distress; after that it's final. We complete erasure requests within one month. Your on-device copy is separate — clear it with the “Fastest” route above.
-
Option B · Only cloud data, keep account By request · one month
Erases the synced/backup copy on our servers while your account stays open — and your on-device copy stays on your phone, so you keep using Ember as before. There's no self-serve button for this yet, so we do it on request and confirm within one month. Want to keep a copy? Because the full data already lives on your device, export it in the app first (assembled on-device, never uploaded to us), then send the request — you keep the complete copy while the cloud version is removed.
-
Website data By request
If you joined the early circle or emailed us, we hold your email address (and any message) in our inbox — the website itself stores nothing. Ask us to remove it and we will, and confirm when it's done, within one month.
To make a request, use the Delete my data page or write to nimind@wellnetixltd.com marked "Data deletion request". So we can find the right data, tell us which option applies (A, B, or website email) and — for an account — the email address you signed up with. We may need to confirm your identity before acting. We respond within one month (UK GDPR).
You can complain to the UK Information Commissioner's Office at ico.org.uk (or your local EU supervisory authority). We'd appreciate the chance to put things right first.
9. Children
Ember is for adults. The app and early access are 18+ only, the app asks you to confirm this during onboarding, and neither the app nor this website is directed at children. If you believe a minor has provided us personal data, contact us and we will delete it.
10. Cookies, analytics and crash reporting
- This website uses no cookies and no analytics. The only thing it stores in your browser is a single localStorage entry remembering your light/dark theme choice; it never leaves your browser. See the Cookie notice.
- The app ships with no third-party advertising or analytics SDKs.
- Crash reporting: the app includes no third-party crash-reporting SDK. Your operating system (Apple or Google) may collect crash reports subject to your own device settings; any such reports are content-free.
11a. Apple App Store — "App Privacy" disclosures
This is the declaration Ember makes on the App Store; it is checked against every build we ship:
-
Health & Fitness Not collected
Conversations stay on-device / end-to-end encrypted; we cannot access them, so they are not "collected" under Apple's definition.
-
Contact Info → Email Address Conditional
Collected only if you claim an account; linked to you; used for App Functionality only. No tracking, no marketing use without separate consent.
-
User Content Not collected
End-to-end encrypted sync blobs are inaccessible to us.
-
Identifiers, Usage Data, Diagnostics Not collected
No analytics or crash-reporting SDK ships in the app.
-
Location, Contacts, Browsing, Purchases, Financial, Sensitive Info Not collected
Ember has no use for any of these, and never asks.
-
Data used to track you None
No tracking across apps or websites; no App Tracking Transparency prompt needed.
11b. Google Play — Data Safety alignment
This is how Ember answers Google Play's Data Safety form; it is checked against every build we ship:
-
Does the app collect or share user data?
Collects: optional email (account). Shares with third parties: none for advertising or marketing. Optional cloud assistance processes conversation text transiently via a contracted provider, only when the user turns it on.
-
Health & personal-info categories Not collected
On-device / end-to-end encrypted — not collected by Wellnetix.
-
Data encrypted in transit? Yes
TLS everywhere.
-
Can users request deletion? Yes
In-app erase (immediate, on-device) and account deletion including server-side encrypted blobs. See Delete my data.
-
Ads / tracking SDKs None
The app ships with no advertising or tracking SDKs.
-
Independent security review Not claimed
We do not claim an independent security review, and won't until one has actually happened.
12. Security
Security is built into the architecture, not bolted on: client-side encryption with user-held keys and a recovery kit; end-to-end encryption for anything that syncs, so we store only ciphertext we cannot decrypt; TLS for everything in transit; no plaintext server-side copies of your conversations; and least-access controls on the small amount of operational data we do hold. These are the protections the app is built and held to. Ember is in private early access, and we are completing on-device verification of the key-storage layer before general release; we do not claim an independent security audit, and won't until one has actually happened (see §11b). No system is perfect — if we ever discover a breach affecting your personal data, we will notify you and the ICO as the law requires.
13. Changes to this policy
If we change this policy, we'll update it here with a new effective date, and for material changes we'll tell you in the app or by email before they take effect. We will never quietly weaken the commitments above — in particular, "on your device", "under your key" and "never sold" are load-bearing.
14. Contact
Wellnetix Ltd, United Kingdom · nimind@wellnetixltd.com · wellnetixltd.com