← Back to home

Privacy Policy

Last updated:

Ember syncs your clipboard, images, files and notifications between your Android phone and your Mac. This policy explains what data that involves, where it goes, and the choices you have.

The short version

  • We can't see what you sync. Clipboard items, images, files and notifications are end-to-end encrypted on your devices, and the keys never leave them.
  • Local by default. Your phone and your Mac connect directly over Bluetooth or your Wi-Fi. You don't need an account, and nothing passes through our servers.
  • Cloud sync is optional. If you turn it on, we store your email address and a few sign-in records. Never your content.
  • No ads, no tracking, no selling. The apps include no analytics or third-party SDK telemetry, and we don't sell or share your personal data.
  • Delete any time. In either app, or at ember.balakumar.dev/delete-account.

Who we are

Ember is made by CoolSolve LLP (“we”, “us”). We are the controller of the personal data described in this policy. You can reach us at mail@balakumar.dev or by post:

CoolSolve LLP
Unit 101, Oxford Towers
139/88 HAL Old Airport Road, HAL II Stage
Bangalore 560008, Karnataka
India

What stays on your devices

Ember is local-first. When you pair your phone and your Mac by scanning a QR code, the two devices agree on encryption keys directly with each other (using X25519). The keys are created on your devices and never leave them.

Everything Ember syncs, including clipboard text and images, files, notifications and your replies to them, is encrypted end to end with AES-256-GCM before it leaves a device. Only your paired devices can decrypt it. When your devices can reach each other over Bluetooth Low Energy or your local Wi-Fi network, data goes straight from one to the other. It doesn't touch the internet or our servers, and you don't need an account.

Your content is kept only on your devices:

None of this is sent to us, so we can't read it, share it or lose it.

Cloud sync (optional)

Cloud sync connects your devices through our relay when they can't reach each other over Bluetooth or Wi-Fi. It's off by default and needs a free account. You sign in with your email address and a 6-digit code we email you. There's no password.

The relay only passes end-to-end-encrypted data between your two paired devices. It can't decrypt that data, and it doesn't store it. Ember uses the relay only when Bluetooth and Wi-Fi can't connect your devices. While a connection is open, the relay keeps track of it (a random room ID derived from your pairing, and when the connection started) and forgets it when the connection closes, apart from our hosting provider's request logs described below.

To run your account, we store:

What we storeWhyHow long
Your email addressTo send you sign-in codes and identify your accountUntil you delete your account
A random account ID, when you created the account, and your plan (and when it last changed)To run your account. Everyone is on the free plan today.Until you delete your account
One-time sign-in codes, stored only as a hash, with when each was created and expires and how many times it was triedTo check the code you enter and stop guessingDeleted as soon as a code is used. Unused codes expire after 10 minutes and are removed by a daily cleanup.
Session tokens that keep your devices signed in, stored only as a hash, with when each was created and expiresTo keep you signed in without asking for a new code each timeStop working the moment you sign out. Signed-out and expired tokens are deleted by the daily cleanup, and all of them are deleted right away if you delete your account.

We don't store your device names or anything you sync. Signed-in devices also hold a short-lived access token, valid for one hour, which we don't store.

Service providers and international transfers

Two companies help us run cloud sync. They process data only on our behalf.

Both are based in the United States, so your data is processed there and in other countries where they operate. We are based in India. Where the law requires it, these transfers are covered by safeguards such as the European Commission's Standard Contractual Clauses in the providers' data processing terms.

Android app permissions

Ember asks only for what each feature needs, and optional features stay off until you turn them on.

Nearby devices (Bluetooth)
To find and connect to your paired Mac. Ember doesn't use Bluetooth to work out your location.
Network access
To connect directly to your Mac over your Wi-Fi and, only if you turn on cloud sync, to reach the relay and our sign-in service.
Notifications
To show Ember's status notification and alerts about things you receive.
Running in the background
Ember runs a foreground service, and starts it when your phone boots, to keep the connection to your Mac open. Android shows a notification while it runs.
Battery optimization exemption (optional)
So Android doesn't cut the connection to your Mac to save power.
Camera (optional)
Only to scan the pairing QR code on your Mac. The QR code is decoded on your phone, and camera images are never stored or sent anywhere.
Clipboard
Ember reads your clipboard when you send it to your Mac, or when Auto-copy detects a copy. It puts text your Mac sends you onto your clipboard.
Notification access (optional)
Needed only if you turn on notification mirroring. Ember then reads your phone's notifications (the app name, title and text) so it can show them on your paired Mac, end-to-end encrypted. You choose which apps are mirrored. Ongoing notifications and ones an app marks as secret are never mirrored. If you reply to a mirrored notification on your Mac, or stop mirroring an app from there, that action is sent back to your phone, also encrypted. Nothing goes to us.
List of installed apps
So you can choose which apps' notifications to mirror. The list stays on your phone.
Accessibility service (optional, for Auto-copy)

Auto-copy sends what you copy on your phone to your Mac without you having to open Ember. It's off by default. Ember asks for your consent in the app before you can turn it on, and you then enable Ember's accessibility service in Android's settings.

When you turn it on, Ember's accessibility service watches three things in other apps to notice when you copy something:

  • taps;
  • pop-up and toolbar windows, such as the menu that appears when you select text;
  • “copied” toast messages.

It reads the text of the item you tapped and of those windows, and uses it only to detect a Copy action. When it detects one, Ember briefly opens an invisible screen to read your clipboard, because Android only lets the app in focus read it. It then sends the copied content to your paired Mac, end-to-end encrypted. Nothing is sent to us. You can turn off Auto-copy in Ember, or turn off the service in Android's accessibility settings, at any time.

Mac app permissions

Bluetooth
To connect to your paired phone.
Local Network
To connect directly to your phone over your Wi-Fi.
Notifications
To show your phone's mirrored notifications and alerts about transfers.
Clipboard
Ember watches your Mac's clipboard so it can send what you copy to your paired phone. Images are sent only if Sync Images is on.
Files
Files you choose to send (from the menu bar, by drag and drop, or with Finder's “Send to Android” service) go to your phone. Files you receive are saved to your Downloads folder.

Support and diagnostics

Ember includes no analytics and no third-party SDK telemetry. Diagnostic information leaves your devices only if you choose to send it to us, as described below.

If you contact us from the app (Feedback & support on Android, Email Support… on Mac), your email app opens a draft that includes your app version, operating system version, device model and Bluetooth status. On a Mac, it also lists how many devices are paired and a couple of settings. You can read and edit the draft before you send it.

You can also choose to share diagnostic logs (Share diagnostic logs on Android, Copy Diagnostic Logs to Clipboard on Mac). Logs describe what Ember did, such as connections, transfers and errors, and can include device names, file names and the names of apps whose notifications were mirrored. They're designed not to include the text you copy or what your notifications say. Logs stay on your devices unless you choose to send them to someone.

We use what you send us only to help you, and we keep our correspondence for as long as we need it to deal with your request and keep reasonable records.

This website

This site doesn't use cookies, analytics or trackers. If you switch between light and dark mode, your choice is saved in your browser and never sent to us. Our web host keeps standard server logs, such as IP address, browser type and the pages requested, for security and troubleshooting. If you use the delete-account page, the email address and code you enter are sent to our sign-in service to verify and delete your account.

Deleting your account

You can delete your cloud sync account at any time:

Deletion immediately removes your account record (email address, account ID, creation date and plan), all your sessions and any unused sign-in codes. Access tokens already issued to your devices stop working within one hour. Your pairings and synced content were never on our servers. To remove them, unpair your devices in Ember and uninstall the apps.

Your rights

Depending on where you live, for example in the EEA, the UK, California or India, you have rights over your personal data. You can ask us to:

You can also complain to a data protection supervisory authority, such as the one in the country where you live or work.

To make a request, email mail@balakumar.dev from the address on your account, so we can confirm it's you. We'll reply within one month. To delete your account, the quickest route is one of the self-serve options above.

Content that stays on your devices isn't processed by us at all. We don't sell or share your personal data, use it for advertising, or make decisions about you based solely on automated processing.

Children

Ember isn't directed to children under 13, or under 16 in the EEA, and we don't knowingly collect their personal data. If you think a child has created an account, contact us and we'll delete it.

Security

Synced content is end-to-end encrypted, so even our relay can't read it. Connections to our servers use HTTPS. We store sign-in codes and session tokens only as hashes. Codes expire after 10 minutes and allow only a few attempts, and code requests are rate-limited. No system is perfectly secure, but Ember is designed so that we hold as little as possible and your content never reaches us in readable form.

Changes to this policy

If we change this policy, we'll post the new version on this page and update the “Last updated” date at the top.

Contact us

Questions or requests about privacy: mail@balakumar.dev.

CoolSolve LLP
Unit 101, Oxford Towers
139/88 HAL Old Airport Road, HAL II Stage
Bangalore 560008, Karnataka
India