Embedder Tech Inc., a Delaware corporation ("Embedder", "we", "our", or "us"), describes in this Privacy Policy how we collect, use, store, share, and protect your information when you use the "Services." The Services include our websites at https://embedder.com and https://app.embedder.com, and all applications, services, and related software we make available through those websites, the Free Tier, an Evaluation Period, or a paid agreement.
1. Scope and Acceptance
This Privacy Policy applies to everyone who accesses or uses the Services, including Free Tier access, Evaluation Period access, and access under a paid, commercial, or enterprise agreement. It describes the personal data we handle as a controller, meaning data for which we decide how and why it is processed, such as account details, website and application telemetry, and information about prospective customers.
Content processed on a customer's behalf. Where we process personal data contained in content submitted under a signed Master Services Agreement ("MSA"), Order Form, or Data Processing Agreement ("DPA"), we act as a processor on that customer's behalf. That customer determines how such data is used, and that customer's own privacy notice governs its personnel and end users. Where such an agreement and this Privacy Policy conflict as to that content, the agreement controls.
This Privacy Policy does not set the commercial terms of paid, commercial, or enterprise access to the Embedder Platform. Those terms are governed solely by a separate MSA, Order Form, or other written agreement signed by both you and Embedder. For the privacy terms that accompany paid access, please contact us at [email protected].
By accessing or using our Services, you acknowledge that you have read this Privacy Policy. This acknowledgment is not consent where applicable law requires separate consent, which we request through our privacy controls or another affirmative mechanism.
If you provide personal information about another person, you are responsible for having authority to provide it and for giving any notice or obtaining any consent required by law.
2. Information We Collect
2.1 Account Information
When you create an account or use our Services we collect:
- Name, email address, and authentication credentials
- Profile picture and basic profile information (when provided through OAuth)
- Company or organization information (for team and enterprise accounts)
- Account preferences, settings, and your communications with us
2.2 Uploaded Content
When you use the Services, we process the content you provide, which may include source code and firmware, hardware datasheets and technical documentation, project files and build configurations, and any other files or data you provide. Embedder orchestrates between you and third-party AI providers: we process snippets of your code and documentation to construct requests, transmit them to the AI providers, and process the responses. For documents you upload for reference (such as datasheets and reference manuals), we generate and store vector embeddings (mathematical representations of your content) that enable our AI features to provide context-specific assistance for your projects.
You are responsible for ensuring that you have the necessary rights, licenses, and permissions to upload any third-party documentation, datasheets, or other materials to the Services, including materials subject to confidentiality or non-disclosure obligations.
2.3 API Usage and Telemetry
We collect telemetry about your use of the Services, including API endpoint calls and timing metrics, token usage and model selections, error logs and performance metrics, feature usage patterns, and AI conversation history.
2.4 Automatically Collected Information
- Device information: browser type, operating system, device identifiers
- Network information: IP address and approximate geographic location
- Usage data: pages viewed, navigation paths, click patterns
- Cookies and similar technologies (see Section 11)
- Log data: timestamps, system events, diagnostic information
2.5 Information We Receive From Third Parties
We may receive personal information about you from the following third-party sources:
- Identity providers: if you sign in using an OAuth or similar identity provider, we receive the profile information that provider makes available to us based on your account settings, such as your name, email address, profile picture, and account identifier.
- Payment and billing providers: Stripe may provide us with customer, billing, transaction-status, and payment-method information associated with your account and purchases.
- Business-data and visitor-identification providers: Unify may match device, network, and website-activity signals with commercial business datasets. Depending on what the provider makes available, we may receive a business visitor's name, work email address, employer, job title, professional profile information, and company-level details. The provider may compile its datasets from data partners, commercial business databases, professional-network sources, and publicly available sources.
We combine this information with information described elsewhere in this section for the purposes described below. In the European Economic Area, United Kingdom, and Switzerland, optional visitor-identification providers are not loaded unless you consent through our privacy controls.
3. How We Use Your Information
- Service provision: to provide, operate, and maintain the Services.
- AI features: to process your uploaded documents, generate embeddings, and enable context-aware AI assistance for your projects.
- Service improvement: to analyze telemetry, understand usage patterns, and improve the Services and user experience.
- Customer support: to respond to inquiries and troubleshoot issues.
- Communications: to send service updates, security alerts, technical notices, and support messages.
- Marketing, analytics, and advertising: to measure website and campaign performance, understand how visitors engage with our website, identify prospective business customers, personalize business outreach, and measure advertising conversions. In the European Economic Area, United Kingdom, and Switzerland, we load optional third-party analytics, advertising, and visitor-identification technologies only with your consent.
- Security: to detect, prevent, and address technical issues, security threats, fraud, or abuse.
- Legal compliance: to comply with applicable laws and lawful requests.
We may use your content to operate, maintain, troubleshoot, evaluate (including internal quality evaluations, or "evals"), develop, and improve the Services. We do not sell Uploaded Content or use it for advertising.
4. Legal Bases for Processing in the EEA and UK
If the EU GDPR or UK GDPR applies to our processing, we rely on the legal bases described below. The basis that applies depends on the context in which we process the information.
| Purpose | Categories of personal information | Legal basis |
|---|---|---|
| Service provision, account administration, AI features, and customer support | Account Information, Uploaded Content, API Usage and Telemetry, and communications with us | Contractual necessity: processing is necessary to perform our contract with you or to take steps at your request before entering into a contract. |
| Service communications and operations | Account Information, API Usage and Telemetry, and communications with us | Contractual necessity and legitimate interests: we have a legitimate interest in administering customer relationships and keeping users informed about service, support, and operational matters. |
| Service improvement, internal evaluations, product telemetry, and first-party measurement | Account Information, Uploaded Content where permitted, API Usage and Telemetry, device information, usage data, and log data | Legitimate interests: we have a legitimate interest in operating, debugging, evaluating, measuring, and improving the Services, provided those interests are not overridden by your rights and interests. We also rely on consent where required for cookies or browser storage used for these purposes. |
| Security and prevention of fraud and abuse | Any categories relevant to the security event | Legitimate interests: we have a legitimate interest in protecting the Services, our users, and our business. We also rely on compliance with law where processing is necessary to meet a legal or regulatory obligation. |
| Optional third-party analytics, advertising, direct marketing, and visitor identification | Account and contact information, device information, network information, usage data, and information from business-data and visitor-identification providers | Consent: in the EEA and UK, we rely on your consent where required for these activities. You may withdraw consent at any time. |
| Legal compliance and legal claims | Any categories relevant to the obligation or claim | Compliance with law and legitimate interests: where a legal obligation does not apply, we have a legitimate interest in establishing, exercising, or defending legal claims and responding to lawful requests. |
| Corporate transactions | Any categories relevant to the transaction | Legitimate interests: we have a legitimate interest in evaluating and carrying out a financing, merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards. |
When we process personal data in Uploaded Content solely on a customer's behalf, we act as that customer's processor and process the data under our agreement with the customer. The customer determines the applicable legal basis.
5. AI Processing and Model Providers
Our Services use third-party AI models from Anthropic (Claude) and OpenAI (GPT). When you use AI features, your prompts, code, uploaded documents, and embeddings may be transmitted to these providers in order to generate responses or embedding vectors.
Each provider has its own privacy policy; we recommend reviewing them.
Our AI features generate suggestions for your review and do not produce decisions that have legal or similarly significant effects on you within the meaning of Article 22 of the GDPR.
Sensitive content: do not upload highly sensitive, regulated, or third-party-confidential information unless you have evaluated the risks and have an enterprise agreement with us that addresses such use. Unless a signed agreement expressly authorizes it, do not submit personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for identification, health data, data concerning a person's sex life or sexual orientation, or data concerning criminal convictions or offenses. If you submit such data on behalf of another person, you are responsible for establishing an appropriate legal basis and providing any required notices.
6. Service Providers and Sub-processors
We engage the following third parties to deliver the Services. Depending on the processing involved, they may act as our processor or sub-processor, or as an independent controller subject to their own privacy notice. Where they process personal data on our behalf, written agreements restrict their use of the data to the services they provide to us.
| Category | Provider | Service | Information typically involved |
|---|---|---|---|
| Hosting and infrastructure | Google Cloud Platform (GCP) | Primary hosting, Cloud SQL, Cloud Storage, Memorystore, and Secret Manager. Production workloads run in us-central1. | Service data, Uploaded Content, account information, and telemetry as needed to host the Services. |
| Hosting and infrastructure | Cloudflare | Edge network, DNS, CDN, WAF, Zero Trust Access, and Cloudflare Tunnel. | IP addresses, request and device metadata, and data transmitted through the edge network. |
| AI inference and embeddings | Anthropic | Claude AI inference. | Prompts, code, documents, and related context submitted to generate requested Output. |
| AI inference and embeddings | OpenAI | GPT AI inference and embedding generation. | Prompts, code, documents, and related context submitted to generate requested Output or embeddings. |
| Product operations | Stripe | Customer, billing, and payment operations. | Account, contact, billing, transaction-status, and payment-method information. |
| Product operations | Loops | Lifecycle and product email. | Contact, account, communication-preference, and email engagement information. |
| Website analytics and advertising | Google Analytics 4 traffic measurement and Google Ads conversion measurement. | Device, network, online-activity, and advertising identifiers, subject to the consent controls described below. | |
| Website visitor identification | Unify | Website-intent measurement, visitor identification, and lead generation. | Device, network, website-activity, professional, and company information, subject to the consent controls described below. |
| Internal operations | Google Workspace | Corporate email, documents, and collaboration. | Account, contact, support, security, or operational information placed in the service by our personnel. |
| Internal operations | Slack | Internal communications and collaboration. | Account, contact, support, security, or operational information placed in the service by our personnel. |
| Internal operations | Linear | Project planning, issue tracking, and operational coordination. | Support, issue, security, and operational information placed in the service by our personnel. |
| Internal operations | GitHub | Source-code hosting, software collaboration, and development workflows. | Development, issue, security, and operational information placed in the service by our personnel. |
| Internal operations | Drata | Compliance automation. | Metadata about systems and personnel. |
| Internal operations | Iru (formerly Kandji) | Workforce-device management. | Workforce-device, system, and personnel metadata. |
In the EEA, UK, and Switzerland, Google Analytics, Google Ads, and Unify are not loaded until you consent through our privacy controls. See our Cookie Policy for details about the technologies, available storage periods, and your choices.
Providers categorized as internal operations do not, in normal use, receive Uploaded Content.
We will update this list when we add or remove a sub-processor. Customers under signed agreements receive advance notice of material sub-processor changes per the terms of their agreement.
Data Processing Agreement. Customers who process personal data through the Services may request our Data Processing Agreement ("DPA"), which covers our role as a processor and our use of sub-processors. Request one at [email protected].
7. Data Sharing and Disclosure
We do not sell personal information for money, and we do not sell Uploaded Content or use it for advertising. We use advertising, analytics, and visitor-identification services as described above. Some U.S. state privacy laws may classify the disclosure of identifiers and online-activity data to those services as "selling" or "sharing" personal information, even though no money changes hands. Where applicable, you may opt out using the "Do Not Sell or Share" or "Privacy Choices" control made available through the Services, or by enabling a Global Privacy Control signal. See our Cookie Policy for more information.
We may otherwise share your information only:
- With the service providers and sub-processors listed in Section 6, subject to the terms described there.
- When required by law, court order, subpoena, or other legal process, or to establish, exercise, or defend legal claims.
- To investigate, prevent, or take action regarding suspected fraud, abuse, or violations of our Terms of Service.
- In connection with a merger, financing, acquisition, or sale of assets; we will notify you of any such transfer that affects your information.
- With your explicit consent for a specific purpose.
- As aggregated or de-identified data that cannot reasonably be used to identify you.
When we maintain information in de-identified form, we maintain and use it without attempting to reidentify it, except to test whether our deidentification processes comply with applicable law.
8. Data Security
We implement organizational and technical measures appropriate to the risk:
- Encryption of data in transit using TLS, and encryption at rest using provider-managed keys at GCP.
- Authentication and least-privilege access controls for personnel; production access is brokered through single sign-on with multi-factor authentication.
- Logging of administrative actions and access to production systems, with retention controls described in Section 9.
- Vulnerability management and dependency-scanning processes that target remediation timelines based on severity.
- Self-hosted Sentry error monitoring and performance tracing used to diagnose reliability and security issues.
No system is perfectly secure. If you believe your account or data has been compromised, contact us at [email protected].
9. Data Retention
We retain information for as long as we need it to provide the Services and to meet legal obligations.
Account and uploaded content: retained while your account is active. When you delete your account, we deactivate it immediately and complete erasure of account records and uploaded content across our primary database and sub-processors within 45 days, subject to legal-hold and backup-rotation exceptions described below. Backups containing deleted data age out under the schedule in this section and are not restored to production except in the event of a disaster-recovery incident, in which case re-deletion is performed.
- Marketing and prospect records: retained while you remain a customer or active business prospect and for as long as reasonably necessary to manage that relationship, measure our outreach, and meet legal obligations. If you opt out of marketing, we may retain a minimal suppression record for as long as needed to honor your choice.
- Website analytics and visitor-identification records: retained for as long as reasonably necessary to measure site and campaign performance, maintain attribution, and manage prospective-customer relationships. We determine that period based on the date of your last interaction, the length of our sales cycle, applicable provider settings, your consent or opt-out status, and legal requirements; after that, we delete or aggregate the records where reasonably feasible.
- Cookies and browser-storage identifiers: retained for the periods described in our Cookie Policy, unless you clear them or change your privacy choices sooner.
- Database backups: we keep up to 30 most-recent automated backups of our primary database and 7 days of point-in-time recovery transaction logs. Backups roll forward and old backups age out automatically.
- Application and telemetry logs: retained for approximately 14 days in our default log store. Specific operational logs may be retained for shorter or longer periods as configured.
- Audit logs: retained for 730 days under bucket-locked, write-once storage to support security investigations and compliance.
- Legal holds: data may be retained longer where required for legal, regulatory, or legitimate business purposes.
10. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate or incomplete personal information.
- Deletion: request deletion of your personal information, subject to legal exceptions.
- Portability: request a copy of your data in a structured, commonly used, machine-readable format.
- Objection: object to certain processing of your personal information, including for marketing purposes.
- Restriction: request that we restrict processing in certain circumstances.
- Withdraw consent: where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.
Direct marketing: you may object to our use of your personal information for direct marketing at any time by using the unsubscribe link in a marketing email or emailing [email protected]. After you opt out, we may still send non-marketing messages necessary to provide or administer the Services.
To exercise any of these rights, email us at [email protected]. We will acknowledge your request promptly and respond substantively within one month for requests from the European Economic Area, the United Kingdom, and Switzerland (extendable by up to two additional months for complex or numerous requests, with notice to you), and within 45 calendar days for requests from California or other jurisdictions where that timeline applies. We may need to verify your identity before responding.
Declining to provide information: some personal information is required to create and secure an account, provide requested Services, process a transaction, or comply with law. If you do not provide information identified as required, we may be unable to create your account, provide the relevant Service, complete the transaction, or respond to your request. Other information is optional.
10.1 California Privacy Rights
This subsection applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), applies to us. The table below summarizes the categories of personal information we collected, the sources and purposes of collection, and our disclosure practices during the 12 months preceding this Privacy Policy's effective date. The examples reflect the information described in Sections 2, 3, 6, and 7.
| Category and examples | Sources | Purposes | Disclosed for business purposes to | Sold or shared with |
|---|---|---|---|---|
| Identifiers and customer-record information, such as name, email, account identifiers, IP address, employer, and billing details | You; identity and payment providers; Unify; and automatic collection | Service delivery, account administration, billing, security, analytics, advertising, and business outreach | Infrastructure, AI, payment, email, analytics, advertising, visitor-identification, and professional service providers described in Sections 6 and 7 | Google and Unify |
| Commercial and professional information, such as transaction status, employer, job title, and professional profile information | You; Stripe; Unify; and public sources | Billing, customer administration, analytics, lead generation, and business outreach | Payment, operations, analytics, visitor-identification, and professional service providers | Unify |
| Internet or other electronic network activity, such as pages viewed, navigation paths, clicks, device identifiers, logs, and product telemetry | Automatic collection from our website and Services | Service delivery, security, debugging, analytics, advertising, attribution, and visitor identification | Infrastructure, analytics, advertising, visitor-identification, and security providers | Google and Unify |
| Approximate geolocation, such as city, state, or region inferred from an IP address | Automatic collection and service providers | Security, regional privacy controls, analytics, advertising, and visitor identification | Infrastructure, analytics, advertising, and visitor-identification providers | Google and Unify |
| Customer content and communications, such as Uploaded Content, AI conversations, and support requests | You and users authorized by your organization | Service delivery, AI features, support, security, and service improvement as described in this Policy | Infrastructure, AI, support, security, and professional service providers as necessary | None |
| Inferences about professional interests or likely business interest in our Services | Website activity; Unify; and commercial business datasets | Analytics, lead generation, and personalized business outreach | Analytics, advertising, visitor-identification, and operations providers | Unify |
| Sensitive personal information, such as account credentials and information voluntarily included in Uploaded Content | You and users authorized by your organization | Account authentication, security, and providing requested Services | Infrastructure, identity, AI, and security providers as necessary to provide the Services | None |
We do not sell personal information for money. As described above, disclosures of identifiers, professional information, internet activity, approximate location, and related inferences to advertising and visitor-identification providers may be considered "selling" or "sharing" under the CCPA. We do not sell or share Uploaded Content. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.
Subject to applicable exceptions, California residents may:
- Request the categories and specific pieces of personal information we collected about them; the categories of sources, purposes, and recipients; and our sale or sharing practices.
- Request deletion or correction of personal information we maintain about them.
- Opt out of the sale or sharing of personal information using the "Do Not Sell or Share" control made available through the Services or a Global Privacy Control signal.
- Exercise these rights without receiving discriminatory treatment.
To submit an access, deletion, correction, or limitation request, email [email protected] or write to the postal address in Section 15. Because we operate exclusively online and have a direct relationship with users, we provide these online and postal request methods instead of a toll-free telephone number. We may verify your request using information associated with your account or information we already maintain. If we cannot verify a request, we may deny it and explain why.
An authorized agent may submit a request on your behalf. We may require signed permission or a valid power of attorney, verify the agent's identity and authority, and ask you to confirm directly that you authorized the request, as permitted by law.
We do not have actual knowledge that we sell or share personal information of consumers under 16. We do not offer financial incentives related to the collection, sale, or sharing of personal information.
Global Privacy Control: we honor Global Privacy Control (GPC) signals from your browser as an opt-out of advertising and visitor-identification tracking globally.
Do Not Track: some browsers send a "Do Not Track" (DNT) signal. We do not currently respond to DNT signals. DNT is distinct from GPC, which we honor as described above.
EU/UK residents: under the GDPR and UK GDPR, you have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data violates applicable law. If you are in the EEA, you can find your supervisory authority in the European Data Protection Board member list. If you are in the UK, you may contact:
Information Commissioner's OfficeWycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: +44 303 123 1113
Website: ico.org.uk/make-a-complaint
11. Cookies and Tracking
We use cookies and similar technologies to maintain your login session, remember your preferences, analyze usage, and detect abuse. You can control cookies through your browser settings; disabling some cookies may impair functionality. Where required by law, we ask for your consent before setting non-essential cookies. For details about the cookies we use, the categories they fall into, and how to manage your preferences, see our Cookie Policy.
12. International Data Transfers
Embedder is a US-based company and our production systems are hosted in the United States (GCP, region us-central1). If you access the Services from outside the United States, your information will be transferred to and processed in the United States. For transfers from the European Economic Area, the United Kingdom, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with our service providers and sub-processors, supplemented by additional safeguards as required. You may request more information about the transfer mechanism that applies to your personal information, including a copy of the relevant contractual safeguards, by emailing [email protected]. We may redact information that is confidential or unrelated to the safeguards.
13. Children's Privacy
Our Services are intended only for adults who are at least 18 years old. We do not knowingly collect or process personal information from anyone under 18. If we learn that we have collected such information, we will take appropriate steps to delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. You are responsible for regularly reviewing this Privacy Policy. If we make material changes, we will notify you by email (if provided) or through the Services at least 30 days before they take effect.
15. Contact
Privacy and data-subject requests: [email protected].
Security reports: [email protected].
Our Chief Information Security Officer oversees our privacy program as our privacy lead. We have not designated that role as a statutory Data Protection Officer.
2261 Market Street STE 95828
San Francisco, CA 94114
United States
16. European Union Representative
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact in the European Union.
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit: https://app.prighter.com/portal/embedder