Privacy Policy
Last updated: 16 September 2026
Ember ("Ember", "we", "us") is a referral relationship management tool operated by Win More Clients and
Vitalspark.ai. This policy explains what data Ember accesses, how we use it, how we store and protect it,
and the choices you have. It covers data you give us directly and data we access, with your permission,
from third parties such as Google and Microsoft.
Google Limited Use disclosure. Ember's use and transfer to any other app of information received
from Google APIs will adhere to the
Google
API Services User Data Policy, including the Limited Use requirements.
1. The data we access
Data you provide
- Your account details (name, email, business) and the contacts, notes, and referral activity you add.
- Content you create in Ember, such as messages you draft and details about your relationships.
Google account data (only if you connect Google)
If you choose to connect a Google account, you grant Ember access to the following scopes, and only these.
Ember requests them to run the referral features you turn on, and nothing else.
| Google scope | Why Ember needs it |
.../auth/userinfo.email, openid, profile |
To identify the mailbox you connected and show it back to you ("Connected as you@example.com"). |
.../auth/gmail.modify |
Ember watches your incoming mail for referral introductions (someone connecting you with a new
person), reads those messages so it can capture the referral for you, marks or labels a message once it
has been handled so the same one is not processed twice, and sends a reply or follow-up
from your own address when you choose to. Ember does not permanently delete your email. A
narrower scope is not sufficient, because Ember must both read incoming mail and mark what it has handled. |
.../auth/calendar.events |
To read your upcoming events so Ember can show your next meetings and prepare a short pre-call brief,
and to add follow-up or meeting holds only when you ask it to. Ember does not modify or delete
events it did not create. |
Microsoft account data (only if you connect Outlook)
If you connect a Microsoft account, Ember uses the delegated Microsoft Graph permissions
Mail.ReadWrite, Mail.Send, and Calendars.ReadWrite for the same
purposes described above, and nothing else.
2. How we use Google and Microsoft data
- Incoming mail is analyzed to detect referral introductions and the follow-up they need. To do
this, the text of a candidate message is processed by our AI provider (Anthropic) solely to identify
referrals for you; this processing is transient and governed by contract, and the message text is not
retained by the AI provider.
- Sending is used only to deliver a message you composed or approved inside Ember, from your own
address. Ember never sends on its own except through an automation you have explicitly configured, and it
stops immediately when you pause automation for a contact.
- Calendar is used to display your upcoming meetings, generate a brief for the person you are about
to meet, and add follow-up holds you request.
- We do not use Google or Microsoft user data for advertising.
- We do not sell Google or Microsoft user data, and we do not transfer it to others except as needed
to provide a feature you requested (such as the AI analysis above), for security or legal reasons, or in
aggregated/anonymized form that cannot identify you.
- We do not use your email or calendar content to train AI models, and our AI provider does not
train its models on it.
- Humans at Ember do not read your Google or Microsoft user data except (a) with your explicit consent,
(b) where necessary for security, abuse prevention, or to comply with applicable law, or (c) where the data
is aggregated and anonymized and used for internal operations.
3. How we store and protect it
- OAuth access and refresh tokens are held in an encrypted, access-controlled store and are never
readable by other customers or exposed to your browser.
- Ember is strictly per-customer isolated. Every record belongs to exactly one customer account and is
enforced by row-level security. One customer's data is never readable by another.
- We retain the minimum needed to run the features you use. Ember does not copy your mailbox into
its database: for a message relevant to your referrals it keeps only a short snippet and basic metadata
(sender, subject, date). The full message text is fetched transiently for analysis and then discarded.
4. Sharing and subprocessors
We use a small number of service providers to operate Ember: cloud hosting and database infrastructure,
and an AI provider (Anthropic) that analyzes candidate messages to detect referrals as described above. These
providers process data on our behalf under contract and only as needed to run the service. We do not share
Google or Microsoft user data with any provider for that provider's own purposes, and our AI provider does
not train on your data.
5. Your choices and how to revoke access
- You can disconnect Google or Microsoft at any time inside Ember, which removes the stored tokens.
- You can also revoke Ember's access directly at
myaccount.google.com/permissions
(Google) or in your Microsoft account security settings.
- To request deletion of your Ember account and associated data, contact us at the address below.
6. Children
Ember is a business tool and is not directed to anyone under 18.
7. Changes
We will update this page when our practices change and revise the "last updated" date above.
8. Contact
Questions about this policy or your data: privacy@emberrms.com.