Emm AI
Emm AI - Privacy Policy
Last Updated: September 25, 2026
1. Introduction
This Privacy Policy explains how Emm AI ("we", "our", "Service") collects, uses, and protects your personal information. We are committed to protecting your privacy and handling your data transparently.
2. Data We Collect
2.1 Personal Data
- Email address (from authentication via Google, GitHub, or Sign in with Apple). If you use Sign in with Apple and choose "Hide My Email," we receive an Apple private relay address (…@privaterelay.appleid.com) instead of your personal address, and use it the same way.
- Display name (if provided by authentication provider)
- Account creation and last login timestamps
2.2 Content You Store
- Memories: notes and personal facts you and your connected AI agents create and store, with categories, tags, and creation/modification timestamps
- Standing instructions: durable guidance documents your connected AI agents read at the start of each run (for example your preferences, formatting style, and recurring task list)
- Output-wiki documents: artefacts your AI agents author on your behalf (drafts, research notes, dashboards) that you review and edit
- Recurring-run records: a log entry for each agent-run cycle (when it ran, which connected client started it, and its outcome)
2.3 Usage Data
- Service interaction logs (API calls, feature usage)
- Memory type and count statistics
- Anonymized AI agent connection information and prompt interactions
- Pseudonymized product analytics events forwarded to a third-party analytics provider (see §5.4)
- Feedback messages you submit via the in-app feedback form, which are emailed to our support address (see §5.5). Feedback is not stored in our application database.
2.4 Payment Data
- Web purchases: if you subscribe on the web, your card details are handled directly by our payment processor, Stripe (see §5.6); we never receive or store your full card number.
- iOS App Store purchases: if you subscribe through the iOS app, Apple processes the payment through the App Store and we never receive your card details. We use RevenueCat (see §5.7) to manage the subscription and reconcile your entitlement to your account; your account identifier and purchase/entitlement information are shared with RevenueCat for this purpose.
- We keep a record of your subscription status and purchase history (plan, transaction dates, and amounts), linked to your account, to provide and manage your subscription, regardless of purchase channel.
2.5 Data Sent by Connected AI Clients
- Each request from a connected AI client (Claude, ChatGPT, Cursor, or another MCP-compatible assistant) carries the content you ask it to save, search, or write; the arguments for that request; and the client's self-reported name and version.
- Some requests write state to your account: saving, updating, moving, and deleting memories, outputs, and instructions; starting and closing an agent run; claiming a one-off task; updating your actions dashboard; and a per-call usage counter used for diagnostics.
- We do not write the content of your requests — search queries, memory content, or the arguments you pass to a connected AI agent's own methods — to our server logs. Diagnostic logs may retain structural facts about a request (its length, category filters, or which argument names were present) but not the content itself.
3. How We Use Your Data
3.1 Service Provision
- Store and retrieve your memories
- Authenticate your identity
- Provide AI agent integrations via MCP
- You may at your own discretion share your memories with other users through the actor connection functionality
3.2 Service Improvement (Free Trial)
- Analyze anonymized usage patterns
- Improve AI categorization and search
- Enhance service features and reliability
3.3 AI Processing
We use AWS Bedrock, hosted in the EU (eu-central-1), to generate short descriptions, categorizations, and search embeddings for your memories. Depending on the complexity of the task, this routes to Amazon Nova Micro (simple categorization and descriptions), Anthropic Claude Haiku 4.5 (more complex cases), or Anthropic Claude Sonnet (fallback); embeddings used for semantic search are generated by Cohere Embed English v3. Your identity is not shared with the AI service, Bedrock does not train its models on your data, and your data is protected by AWS's privacy-preserving services.
4. Data Storage and Security
- Location: Amazon Web Services (AWS) DynamoDB in the EU region (eu-central-1)
- Encryption: All data transmitted via HTTPS; data is encrypted at rest
- Authentication: OAuth2 / OpenID Connect. Sign-in is by Google, GitHub, or Apple; the service stores no password for those accounts. Demo accounts used for app-store review and support use a hashed password.
- Access Control: Per-user data isolation; AI agents require explicit authorization
5. Third-Party Services
5.1 AWS
- Data storage (DynamoDB)
- AI processing (Bedrock)
- Service processing (Lambda and HTTP gateway)
5.2 Authentication Providers
- Google, GitHub, and Apple (Sign in with Apple) receive only necessary authentication requests
- We receive only email and profile information. With Sign in with Apple, this may be an Apple private relay email address if you choose "Hide My Email"
- Apple's handling of your authentication data is governed by Apple's own privacy policy
5.3 AI Agents
- Claude, ChatGPT, Cursor, and other MCP-compatible agents
- Access requires your explicit OAuth2 authorization, during which you choose an access level for that connection: Read-only (search and retrieve only) or Read/Write (the default; full access to create, update, and delete)
- You control which memory types each agent can access
- New custom memory categories are shared with all your connected agents by default; you can switch a category to Creator only in Settings → Memory & Sharing to restrict it to the connection that created it
5.4 Product Analytics (PostHog)
- We use PostHog (EU region, hosted at eu.i.posthog.com) to understand how the Service is used and to prioritize improvements
- Your account identifier is pseudonymized (GDPR Art. 4(5)) before being sent: we transmit a salted SHA-256 hash of your actor ID, never the raw ID, email, or display name
- Person properties are limited to your subscription plan and beta-tester status
- URL paths sent with events are scrubbed so the raw account ID never appears in PostHog
- Data Processing Agreement: https://posthog.com/dpa
5.5 Feedback Email Delivery (Brevo)
- Feedback you submit via the in-app form is emailed to our support address using Brevo (brevo.com, EU-based) as the transactional email provider
- The email contains the message you wrote, an optional rating, the page you were on, your account email, and an optional reply-to address you provide
- Brevo processes the email purely as transit; we hold the message in our support inbox after delivery
- Data Processing Agreement: https://www.brevo.com/legal/termsofuse/
5.6 Payment Processing — Web (Stripe)
- Paid subscriptions purchased on the web are processed by Stripe (stripe.com). Stripe collects and processes your payment details directly; we receive only your subscription status and purchase history, never your full card data.
- Data Processing Agreement: https://stripe.com/legal/dpa
5.7 App Store Subscriptions (Apple & RevenueCat)
- Paid subscriptions purchased in the iOS app are sold and billed by Apple through the App Store. Apple processes your payment and we never receive your card details; Apple's handling of your data is governed by Apple's own privacy policy.
- We use RevenueCat (revenuecat.com) to manage these App Store subscriptions and reconcile entitlements to your account. We send RevenueCat your account identifier as the subscription's app-user ID; RevenueCat receives and processes purchase, entitlement, and transaction information (such as the App Store transaction/receipt and last-seen time) on our behalf as a data processor. RevenueCat is a US-based provider.
- Privacy policy: https://www.revenuecat.com/privacy
- Data Processing Agreement: https://www.revenuecat.com/dpa
6. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Restriction: Limit how we process your data
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
To exercise these rights, use the functionality in the web interface, or contact: support@actingweb.io
Sub-processors: PostHog (eu.i.posthog.com, EU) for pseudonymized product analytics, and Brevo (brevo.com, EU) for transactional email delivery (feedback form submissions and notification emails). Payment processing for web subscriptions is handled by Stripe (stripe.com) under its data processing agreement. Subscriptions purchased in the iOS app are billed by Apple through the App Store, with subscription management and entitlement reconciliation provided by RevenueCat (revenuecat.com, US) under its data processing agreement (https://www.revenuecat.com/dpa).
7. Data Retention and Deletion
- Active accounts: Data is retained while account is active
- Account deletion: Your account and data are removed from the live service immediately; residual copies in encrypted backups are purged within 35 days as backups rotate
- OAuth2 tokens: Revoked immediately upon account deletion or when you revoke an MCP client's access. Access tokens otherwise expire after 1 hour and refresh tokens after 30 days
- Backups: Purged within standard backup rotation cycles (35 days)
- Diagnostic server logs: Retained for 30 days
8. Premium Tier Privacy Options
Premium subscribers (USD 9.95/month or USD 99/year on the web; App Store pricing as shown at purchase for iOS in-app purchases) may:
- Receive detailed data export in standard formats
9. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this Privacy Policy periodically. Significant changes will be communicated via the Service or email.
11. Contact Information
Emm AI is operated by Greger Wedel, Oslo, Norway.
For privacy-related questions or requests:
Terms of Service | Privacy Policy | Data Deletion | Support