Ember

Privacy Policy

Last updated: 13 August 2026

Who we are

Ember is a financial-independence modelling service operated by Planespoken Ltd, a company registered in England and Wales (company number 11084007), registered office: 1 Craftsman Square, Temple Farm Industrial Estate, Southend-on-Sea, England, SS2 5RH. Planespoken Ltd is the data controller. Contact: [email protected].

What we collect

  • Account data: email address, username, password (stored as a salted scrypt hash — we never see or store the plaintext), and at least one of phone number or postcode, used solely to verify account-recovery requests.
  • Two-factor secrets: your authenticator (TOTP) secret and hashed backup codes, encrypted at rest with a key derived uniquely for your account.
  • Financial data you enter: assets, debts, pensions, income, spending, scenarios, and imported statements. This data exists so the service can do its job; we do not sell it, share it with advertisers, or use it for marketing.
  • Integration credentials you choose to add:broker/bank API keys and OAuth tokens (encrypted at rest, per-account key derivation) used only to sync the accounts you connect.
  • Audit log: a record of changes made in your account, kept so you can review your own history.
  • Sign-in events: the time, method, IP address, and browser of each successful sign-in, recorded for account security and as payment-dispute evidence. Kept for the life of your account and erased with account deletion.

What we deliberately do not do

  • No third-party analytics or ad-tech trackers. Our analytics is first-party and privacy-friendly (see “Analytics” below and the Cookie Policy). The only always-on cookies are the session and two-factor login cookies.
  • No selling or renting of personal data, ever — and your financial data is never shared with advertisers.
  • AI features send relevant slices of your data to the model provider (Anthropic) to answer your request; providers are contractually restricted from training on API data. AI features are optional.

Analytics

We use first-party, privacy-friendly analytics: anonymous page-view counts (no cookie, no personal data retained — the visitor identifier is a daily-rotating one-way hash and your IP address is never stored for analytics; it is recorded separately when you sign in, as described under “What we collect”; lawful basis legitimate interest), and — only with your consent — a first-party cookie (em_va) to recognise returning visitors (lawful basis consent). No third-party analytics or ad-tech tracking. Withdraw consent any time via the cookie banner; deleting your account also erases your analytics history.

Social listening and question research

To decide what educational content to write, we read public posts on social platforms (such as Reddit) where people ask questions about financial independence and early retirement. We do this to identify recurring FIRE-education questions to build educational content, relying on our legitimate interests (we have a written Legitimate Interests Assessment; contact us to request a summary).

We do not store what you posted or who you are. A member of our team reads public posts and writes our own generalised paraphrase of the question theme — never your username, never your words, never quotes, and never details that could single you out. Our systems have no fields for usernames or post text, and automated tests enforce that.

We keep two narrow, short-lived technical values:

  • A one-way keyed hash of a post’s web address, used only to avoid counting the same question twice. It is deleted within 90 days.
  • A link to the source post (only once this feature is enabled, and only so we can reply while the thread is still current). It is deleted within 14 days, and immediately if we reply or if you ask us to.

Rejected or archived content drafts are deleted within 12 months, and internal workflow records within 24 months. Purged data may persist in backups for up to 30 days before being overwritten; backups are never restored except for disaster recovery, and any restore is followed by a re-run of the retention purge.

Your rights. You may ask us for access to any data linked to your post, ask us to delete it (we will remove the source link and its hash, and confirm within one month), object to this processing, or complain to the UK Information Commissioner’s Office (ico.org.uk). If you believe one of our paraphrases still identifies you, tell us and we will rewrite or delete it. Contact: [email protected].

Emails we send

Account-summary emails: a monthly progress digest of your own numbers (net worth, FIRE progress) is on by default for new accounts. It contains no advertising. Every digest carries a one-click unsubscribe link, and you can switch it off any time in Settings → Account.

Marketing emails: promotional emails are sent only if you opted in; every one carries an unsubscribe link, and you can withdraw consent any time via [email protected].

Processors we rely on

  • Hosting: Hetzner Online GmbH (Germany/EU) — runs the application and database.
  • Email: Resend — delivers verification and account emails.
  • AI (optional): Anthropic — Ember’s hosted, metered Claude; you don’t supply your own key. Under Anthropic’s commercial terms, data sent through Ember’s API access is not used to train Anthropic’s models.
  • Market data: exchange-rate and price lookups (Twelve Data and our FX provider) are made server-side; your identity is not sent to those providers.
  • Network: Cloudflare proxies and protects all traffic to the service.
  • Payments (when live): Stripe processes card payments; we never see or store card numbers.

International transfers

The application and database are hosted in the EU (Hetzner, Germany) and stay there. Some processors above are US-based — email delivery (Resend), network protection (Cloudflare), AI processing (Anthropic) and, when live, payments (Stripe) — so limited personal data (such as your email address, IP address, or the content you send to AI features) can be processed outside the UK/EEA. Those transfers are protected by the providers’ standard contractual clauses / UK IDTA or, where applicable, their EU–US Data Privacy Framework certification.

Retention and deletion

Your data is retained while your account exists. Deleting your account (Settings → Danger zone) permanently and immediately erases your data — financial records, credentials, integrations, audit history — with no soft-delete or recovery window. Encrypted database backups are retained for 14 days and then destroyed, after which deleted data is gone from backups too.

Inactive free accounts. Free (Spark) accounts that stay inactive for 12 months are eligible for automatic deletion. Before any automated deletion runs we will email reminders at around 6 and 9 months of inactivity, and a final notice about a week beforehand, so you can keep your account simply by signing in. Paying accounts are never auto-deleted. Automatic deletion erases your data the same way as the self-service deletion described above.

Security

Two-factor authentication is mandatory for every account. Stored secrets are encrypted with per-account derived keys; passwords and recovery tokens are stored only as cryptographic hashes; all traffic is TLS-encrypted. No system is perfectly secure — if we become aware of a breach affecting your data we will notify you without undue delay.

Your rights

You can export your data (Reports → Export), correct it in-app, or erase it entirely via account deletion, at any time and without asking us. Depending on your jurisdiction (e.g. UK/EU GDPR) you may have further statutory rights; contact [email protected] to exercise them. You also have the right to complain to us about how we handle your personal data, and to complain to a supervisory authority — see Complaints below.

Complaints

You can complain directly to us about anything to do with how we collect, use, store or delete your personal data. You do not have to go to a regulator first, and complaining to us does not affect your right to go to one afterwards.

How to complain. Email [email protected] with “Data protection complaint” in the subject line. So we can deal with it properly, please tell us: the email address on your account, what happened, when it happened, and what you would like us to do about it. If you would rather write to us, our registered office address is in Who we are above. If you need to complain in another format because of a disability or accessibility need, say so and we will accommodate it.

What we will do. We will acknowledge your complaint within 30 days of receiving it, tell you who is handling it, investigate it, and respond with the outcome without undue delay. If we need longer than a month to resolve it, we will tell you why and keep you updated.

If you are not satisfied. UK users can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or by post to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Users elsewhere in the UK/EU may complain to their own national supervisory authority.

Children

Ember is a financial-planning tool intended for adults and is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you are under 16, please do not register or send us your information. If you believe a child under 16 has provided us with personal data, contact [email protected] and we will delete it promptly.

Changes

We will update this policy as the service evolves and note material changes on this page with a new “last updated” date.