Ember

Privacy Policy

Last updated: 7 July 2026

Who we are

Ember is a financial-independence modelling service operated by Planespoken Ltd, a company registered in England and Wales (company number 11084007), registered office: 1 Craftsman Square, Temple Farm Industrial Estate, Southend-on-Sea, England, SS2 5RH. Planespoken Ltd is the data controller. Contact: [email protected].

What we collect

  • Account data: email address, username, password (stored as a salted scrypt hash — we never see or store the plaintext), and at least one of phone number or postcode, used solely to verify account-recovery requests.
  • Two-factor secrets: your authenticator (TOTP) secret and hashed backup codes, encrypted at rest with a key derived uniquely for your account.
  • Financial data you enter: assets, debts, pensions, income, spending, scenarios, and imported statements. This data exists so the service can do its job; we do not sell it, share it with advertisers, or use it for marketing.
  • Integration credentials you choose to add:broker/bank API keys and OAuth tokens (encrypted at rest, per-account key derivation) used only to sync the accounts you connect.
  • Audit log: a record of changes made in your account, kept so you can review your own history.
  • Sign-in events: the time, method, IP address, and browser of each successful sign-in, recorded for account security and as payment-dispute evidence. Kept for the life of your account and erased with account deletion.

What we deliberately do not do

  • No third-party analytics or ad-tech trackers. Our analytics is first-party and privacy-friendly (see “Analytics” below and the Cookie Policy). The only always-on cookies are the session and two-factor login cookies.
  • No selling or renting of personal data, ever — and your financial data is never shared with advertisers.
  • AI features send relevant slices of your data to the model provider (Anthropic) to answer your request; providers are contractually restricted from training on API data. AI features are optional.

Analytics

We use first-party, privacy-friendly analytics: anonymous page-view counts (no cookie, no personal data retained — the visitor identifier is a daily-rotating one-way hash and your IP address is never stored for analytics; it is recorded separately when you sign in, as described under “What we collect”; lawful basis legitimate interest), and — only with your consent — a first-party cookie (em_va) to recognise returning visitors (lawful basis consent). No third-party analytics or ad-tech tracking. Withdraw consent any time via the cookie banner; deleting your account also erases your analytics history.

Social listening and question research

To decide what educational content to write, we read public posts on social platforms (such as Reddit) where people ask questions about financial independence and early retirement. We do this to identify recurring FIRE-education questions to build educational content, relying on our legitimate interests (we have a written Legitimate Interests Assessment; contact us to request a summary).

We do not store what you posted or who you are. A member of our team reads public posts and writes our own generalised paraphrase of the question theme — never your username, never your words, never quotes, and never details that could single you out. Our systems have no fields for usernames or post text, and automated tests enforce that.

We keep two narrow, short-lived technical values:

  • A one-way keyed hash of a post’s web address, used only to avoid counting the same question twice. It is deleted within 90 days.
  • A link to the source post (only once this feature is enabled, and only so we can reply while the thread is still current). It is deleted within 14 days, and immediately if we reply or if you ask us to.

Rejected or archived content drafts are deleted within 12 months, and internal workflow records within 24 months. Purged data may persist in backups for up to 30 days before being overwritten; backups are never restored except for disaster recovery, and any restore is followed by a re-run of the retention purge.

Your rights. You may ask us for access to any data linked to your post, ask us to delete it (we will remove the source link and its hash, and confirm within one month), object to this processing, or complain to the UK Information Commissioner’s Office (ico.org.uk). If you believe one of our paraphrases still identifies you, tell us and we will rewrite or delete it. Contact: [email protected].

Emails we send

Account-summary emails: a monthly progress digest of your own numbers (net worth, FIRE progress) is on by default for new accounts. It contains no advertising. Every digest carries a one-click unsubscribe link, and you can switch it off any time in Settings → Account.

Marketing emails: promotional emails are sent only if you opted in; every one carries an unsubscribe link, and you can withdraw consent any time via [email protected].

Processors we rely on

  • Hosting: Hetzner Online GmbH (Germany/EU) — runs the application and database.
  • Email: Resend — delivers verification and account emails.
  • AI (optional): Anthropic — Ember’s hosted, metered Claude; you don’t supply your own key. Under Anthropic’s commercial terms, data sent through Ember’s API access is not used to train Anthropic’s models.
  • Market data: exchange-rate and price lookups (Twelve Data and our FX provider) are made server-side; your identity is not sent to those providers.
  • Network: Cloudflare proxies and protects all traffic to the service.
  • Payments (when live): Stripe processes card payments; we never see or store card numbers.

International transfers

The application and database are hosted in the EU (Hetzner, Germany) and stay there. Some processors above are US-based — email delivery (Resend), network protection (Cloudflare), AI processing (Anthropic) and, when live, payments (Stripe) — so limited personal data (such as your email address, IP address, or the content you send to AI features) can be processed outside the UK/EEA. Those transfers are protected by the providers’ standard contractual clauses / UK IDTA or, where applicable, their EU–US Data Privacy Framework certification.

Retention and deletion

Your data is retained while your account exists. Deleting your account (Settings → Danger zone) permanently and immediately erases your data — financial records, credentials, integrations, audit history — with no soft-delete or recovery window. Encrypted database backups are retained for 14 days and then destroyed, after which deleted data is gone from backups too.

Inactive free accounts. Free (Spark) accounts that stay inactive for 12 months are eligible for automatic deletion. Before any automated deletion runs we will email reminders at around 6 and 9 months of inactivity, and a final notice about a week beforehand, so you can keep your account simply by signing in. Paying accounts are never auto-deleted. Automatic deletion erases your data the same way as the self-service deletion described above.

Security

Two-factor authentication is mandatory for every account. Stored secrets are encrypted with per-account derived keys; passwords and recovery tokens are stored only as cryptographic hashes; all traffic is TLS-encrypted. No system is perfectly secure — if we become aware of a breach affecting your data we will notify you without undue delay.

Your rights

You can export your data (Reports → Export), correct it in-app, or erase it entirely via account deletion, at any time and without asking us. Depending on your jurisdiction (e.g. UK/EU GDPR) you may have further statutory rights; contact [email protected] to exercise them. UK users can also complain to the ICO (ico.org.uk).

Children

Ember is a financial-planning tool intended for adults and is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you are under 16, please do not register or send us your information. If you believe a child under 16 has provided us with personal data, contact [email protected] and we will delete it promptly.

Changes

We will update this policy as the service evolves and note material changes on this page with a new “last updated” date.