Embedder

Privacy Policy

Effective Date · August 21, 2026

Embedder Tech Inc., a Delaware corporation ("Embedder", "we", "our", or "us"), describes in this Privacy Policy how we collect, use, store, share, and protect your information when you use the "Services." The Services include our websites at https://embedder.com and https://app.embedder.com, and all applications, services, and related software we make available through those websites, the Free Tier, an Evaluation Period, or a paid agreement.

1. Scope and Acceptance

This Privacy Policy applies to everyone who accesses or uses the Services, including Free Tier access, Evaluation Period access, and access under a paid, commercial, or enterprise agreement. It describes the personal data we handle as a controller, meaning data for which we decide how and why it is processed, such as account details, website and application telemetry, and information about prospective customers.

Content processed on a customer's behalf. Where we process personal data contained in content submitted under a signed Master Services Agreement ("MSA"), Order Form, or Data Processing Agreement ("DPA"), we act as a processor on that customer's behalf. That customer determines how such data is used, and that customer's own privacy notice governs its personnel and end users. Where such an agreement and this Privacy Policy conflict as to that content, the agreement controls.

This Privacy Policy does not set the commercial terms of paid, commercial, or enterprise access to the Embedder Platform. Those terms are governed solely by a separate MSA, Order Form, or other written agreement signed by both you and Embedder. For the privacy terms that accompany paid access, please contact us at [email protected].

By accessing or using our Services, you acknowledge that you have read this Privacy Policy. This acknowledgment is not consent where applicable law requires separate consent, which we request through our privacy controls or another affirmative mechanism.

If you provide personal information about another person, you are responsible for having authority to provide it and for giving any notice or obtaining any consent required by law.

2. Information We Collect

2.1 Account Information

When you create an account or use our Services we collect:

  • Name, email address, and authentication credentials
  • Profile picture and basic profile information (when provided through OAuth)
  • Company or organization information (for team and enterprise accounts)
  • Account preferences, settings, and your communications with us

2.2 Uploaded Content

When you use the Services, we process the content you provide, which may include source code and firmware, hardware datasheets and technical documentation, project files and build configurations, and any other files or data you provide. Embedder orchestrates between you and third-party AI providers: we process snippets of your code and documentation to construct requests, transmit them to the AI providers, and process the responses. For documents you upload for reference (such as datasheets and reference manuals), we generate and store vector embeddings (mathematical representations of your content) that enable our AI features to provide context-specific assistance for your projects.

You are responsible for ensuring that you have the necessary rights, licenses, and permissions to upload any third-party documentation, datasheets, or other materials to the Services, including materials subject to confidentiality or non-disclosure obligations.

2.3 API Usage and Telemetry

We collect telemetry about your use of the Services, including API endpoint calls and timing metrics, token usage and model selections, error logs and performance metrics, feature usage patterns, and AI conversation history.

2.4 Automatically Collected Information

  • Device information: browser type, operating system, device identifiers
  • Network information: IP address and approximate geographic location
  • Usage data: pages viewed, navigation paths, click patterns
  • Cookies and similar technologies (see Section 11)
  • Log data: timestamps, system events, diagnostic information

2.5 Information We Receive From Third Parties

We may receive personal information about you from the following third-party sources:

  • Identity providers: if you sign in using an OAuth or similar identity provider, we receive the profile information that provider makes available to us based on your account settings, such as your name, email address, profile picture, and account identifier.
  • Payment and billing providers: Stripe may provide us with customer, billing, transaction-status, and payment-method information associated with your account and purchases.
  • Business-data and visitor-identification providers: Unify may match device, network, and website-activity signals with commercial business datasets. Depending on what the provider makes available, we may receive a business visitor's name, work email address, employer, job title, professional profile information, and company-level details. The provider may compile its datasets from data partners, commercial business databases, professional-network sources, and publicly available sources.

We combine this information with information described elsewhere in this section for the purposes described below. In the European Economic Area, United Kingdom, and Switzerland, optional visitor-identification providers are not loaded unless you consent through our privacy controls.

3. How We Use Your Information

  • Service provision: to provide, operate, and maintain the Services.
  • AI features: to process your uploaded documents, generate embeddings, and enable context-aware AI assistance for your projects.
  • Service improvement: to analyze telemetry, understand usage patterns, and improve the Services and user experience.
  • Customer support: to respond to inquiries and troubleshoot issues.
  • Communications: to send service updates, security alerts, technical notices, and support messages.
  • Marketing, analytics, and advertising: to measure website and campaign performance, understand how visitors engage with our website, identify prospective business customers, personalize business outreach, and measure advertising conversions. In the European Economic Area, United Kingdom, and Switzerland, we load optional third-party analytics, advertising, and visitor-identification technologies only with your consent.
  • Security: to detect, prevent, and address technical issues, security threats, fraud, or abuse.
  • Legal compliance: to comply with applicable laws and lawful requests.

We may use your content to operate, maintain, troubleshoot, evaluate (including internal quality evaluations, or "evals"), develop, and improve the Services. We do not sell Uploaded Content or use it for advertising.

4. Legal Bases for Processing in the EEA and UK

If the EU GDPR or UK GDPR applies to our processing, we rely on the legal bases described below. The basis that applies depends on the context in which we process the information.

PurposeCategories of personal informationLegal basis
Service provision, account administration, AI features, and customer supportAccount Information, Uploaded Content, API Usage and Telemetry, and communications with usContractual necessity: processing is necessary to perform our contract with you or to take steps at your request before entering into a contract.
Service communications and operationsAccount Information, API Usage and Telemetry, and communications with usContractual necessity and legitimate interests: we have a legitimate interest in administering customer relationships and keeping users informed about service, support, and operational matters.
Service improvement, internal evaluations, product telemetry, and first-party measurementAccount Information, Uploaded Content where permitted, API Usage and Telemetry, device information, usage data, and log dataLegitimate interests: we have a legitimate interest in operating, debugging, evaluating, measuring, and improving the Services, provided those interests are not overridden by your rights and interests. We also rely on consent where required for cookies or browser storage used for these purposes.
Security and prevention of fraud and abuseAny categories relevant to the security eventLegitimate interests: we have a legitimate interest in protecting the Services, our users, and our business. We also rely on compliance with law where processing is necessary to meet a legal or regulatory obligation.
Optional third-party analytics, advertising, direct marketing, and visitor identificationAccount and contact information, device information, network information, usage data, and information from business-data and visitor-identification providersConsent: in the EEA and UK, we rely on your consent where required for these activities. You may withdraw consent at any time.
Legal compliance and legal claimsAny categories relevant to the obligation or claimCompliance with law and legitimate interests: where a legal obligation does not apply, we have a legitimate interest in establishing, exercising, or defending legal claims and responding to lawful requests.
Corporate transactionsAny categories relevant to the transactionLegitimate interests: we have a legitimate interest in evaluating and carrying out a financing, merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.

When we process personal data in Uploaded Content solely on a customer's behalf, we act as that customer's processor and process the data under our agreement with the customer. The customer determines the applicable legal basis.

5. AI Processing and Model Providers

Our Services use third-party AI models from Anthropic (Claude) and OpenAI (GPT). When you use AI features, your prompts, code, uploaded documents, and embeddings may be transmitted to these providers in order to generate responses or embedding vectors.

Each provider has its own privacy policy; we recommend reviewing them.

Our AI features generate suggestions for your review and do not produce decisions that have legal or similarly significant effects on you within the meaning of Article 22 of the GDPR.

Sensitive content: do not upload highly sensitive, regulated, or third-party-confidential information unless you have evaluated the risks and have an enterprise agreement with us that addresses such use. Unless a signed agreement expressly authorizes it, do not submit personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for identification, health data, data concerning a person's sex life or sexual orientation, or data concerning criminal convictions or offenses. If you submit such data on behalf of another person, you are responsible for establishing an appropriate legal basis and providing any required notices.

6. Service Providers and Sub-processors

We engage the following third parties to deliver the Services. Depending on the processing involved, they may act as our processor or sub-processor, or as an independent controller subject to their own privacy notice. Where they process personal data on our behalf, written agreements restrict their use of the data to the services they provide to us.

CategoryProviderServiceInformation typically involved
Hosting and infrastructureGoogle Cloud Platform (GCP)Primary hosting, Cloud SQL, Cloud Storage, Memorystore, and Secret Manager. Production workloads run in us-central1.Service data, Uploaded Content, account information, and telemetry as needed to host the Services.
Hosting and infrastructureCloudflareEdge network, DNS, CDN, WAF, Zero Trust Access, and Cloudflare Tunnel.IP addresses, request and device metadata, and data transmitted through the edge network.
AI inference and embeddingsAnthropicClaude AI inference.Prompts, code, documents, and related context submitted to generate requested Output.
AI inference and embeddingsOpenAIGPT AI inference and embedding generation.Prompts, code, documents, and related context submitted to generate requested Output or embeddings.
Product operationsStripeCustomer, billing, and payment operations.Account, contact, billing, transaction-status, and payment-method information.
Product operationsLoopsLifecycle and product email.Contact, account, communication-preference, and email engagement information.
Website analytics and advertisingGoogleGoogle Analytics 4 traffic measurement and Google Ads conversion measurement.Device, network, online-activity, and advertising identifiers, subject to the consent controls described below.
Website visitor identificationUnifyWebsite-intent measurement, visitor identification, and lead generation.Device, network, website-activity, professional, and company information, subject to the consent controls described below.
Internal operationsGoogle WorkspaceCorporate email, documents, and collaboration.Account, contact, support, security, or operational information placed in the service by our personnel.
Internal operationsSlackInternal communications and collaboration.Account, contact, support, security, or operational information placed in the service by our personnel.
Internal operationsLinearProject planning, issue tracking, and operational coordination.Support, issue, security, and operational information placed in the service by our personnel.
Internal operationsGitHubSource-code hosting, software collaboration, and development workflows.Development, issue, security, and operational information placed in the service by our personnel.
Internal operationsDrataCompliance automation.Metadata about systems and personnel.
Internal operationsIru (formerly Kandji)Workforce-device management.Workforce-device, system, and personnel metadata.

In the EEA, UK, and Switzerland, Google Analytics, Google Ads, and Unify are not loaded until you consent through our privacy controls. See our Cookie Policy for details about the technologies, available storage periods, and your choices.

Providers categorized as internal operations do not, in normal use, receive Uploaded Content.

We will update this list when we add or remove a sub-processor. Customers under signed agreements receive advance notice of material sub-processor changes per the terms of their agreement.

Data Processing Agreement. Customers who process personal data through the Services may request our Data Processing Agreement ("DPA"), which covers our role as a processor and our use of sub-processors. Request one at [email protected].

7. Data Sharing and Disclosure

We do not sell personal information for money, and we do not sell Uploaded Content or use it for advertising. We use advertising, analytics, and visitor-identification services as described above. Some U.S. state privacy laws may classify the disclosure of identifiers and online-activity data to those services as "selling" or "sharing" personal information, even though no money changes hands. Where applicable, you may opt out using the "Do Not Sell or Share" or "Privacy Choices" control made available through the Services, or by enabling a Global Privacy Control signal. See our Cookie Policy for more information.

We may otherwise share your information only:

  • With the service providers and sub-processors listed in Section 6, subject to the terms described there.
  • When required by law, court order, subpoena, or other legal process, or to establish, exercise, or defend legal claims.
  • To investigate, prevent, or take action regarding suspected fraud, abuse, or violations of our Terms of Service.
  • In connection with a merger, financing, acquisition, or sale of assets; we will notify you of any such transfer that affects your information.
  • With your explicit consent for a specific purpose.
  • As aggregated or de-identified data that cannot reasonably be used to identify you.

When we maintain information in de-identified form, we maintain and use it without attempting to reidentify it, except to test whether our deidentification processes comply with applicable law.

8. Data Security

We implement organizational and technical measures appropriate to the risk:

  • Encryption of data in transit using TLS, and encryption at rest using provider-managed keys at GCP.
  • Authentication and least-privilege access controls for personnel; production access is brokered through single sign-on with multi-factor authentication.
  • Logging of administrative actions and access to production systems, with retention controls described in Section 9.
  • Vulnerability management and dependency-scanning processes that target remediation timelines based on severity.
  • Self-hosted Sentry error monitoring and performance tracing used to diagnose reliability and security issues.

No system is perfectly secure. If you believe your account or data has been compromised, contact us at [email protected].

9. Data Retention

We retain information for as long as we need it to provide the Services and to meet legal obligations.

Account and uploaded content: retained while your account is active. When you delete your account, we deactivate it immediately and complete erasure of account records and uploaded content across our primary database and sub-processors within 45 days, subject to legal-hold and backup-rotation exceptions described below. Backups containing deleted data age out under the schedule in this section and are not restored to production except in the event of a disaster-recovery incident, in which case re-deletion is performed.

  • Marketing and prospect records: retained while you remain a customer or active business prospect and for as long as reasonably necessary to manage that relationship, measure our outreach, and meet legal obligations. If you opt out of marketing, we may retain a minimal suppression record for as long as needed to honor your choice.
  • Website analytics and visitor-identification records: retained for as long as reasonably necessary to measure site and campaign performance, maintain attribution, and manage prospective-customer relationships. We determine that period based on the date of your last interaction, the length of our sales cycle, applicable provider settings, your consent or opt-out status, and legal requirements; after that, we delete or aggregate the records where reasonably feasible.
  • Cookies and browser-storage identifiers: retained for the periods described in our Cookie Policy, unless you clear them or change your privacy choices sooner.
  • Database backups: we keep up to 30 most-recent automated backups of our primary database and 7 days of point-in-time recovery transaction logs. Backups roll forward and old backups age out automatically.
  • Application and telemetry logs: retained for approximately 14 days in our default log store. Specific operational logs may be retained for shorter or longer periods as configured.
  • Audit logs: retained for 730 days under bucket-locked, write-once storage to support security investigations and compliance.
  • Legal holds: data may be retained longer where required for legal, regulatory, or legitimate business purposes.

10. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request correction of inaccurate or incomplete personal information.
  • Deletion: request deletion of your personal information, subject to legal exceptions.
  • Portability: request a copy of your data in a structured, commonly used, machine-readable format.
  • Objection: object to certain processing of your personal information, including for marketing purposes.
  • Restriction: request that we restrict processing in certain circumstances.
  • Withdraw consent: where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.

Direct marketing: you may object to our use of your personal information for direct marketing at any time by using the unsubscribe link in a marketing email or emailing [email protected]. After you opt out, we may still send non-marketing messages necessary to provide or administer the Services.

To exercise any of these rights, email us at [email protected]. We will acknowledge your request promptly and respond substantively within one month for requests from the European Economic Area, the United Kingdom, and Switzerland (extendable by up to two additional months for complex or numerous requests, with notice to you), and within 45 calendar days for requests from California or other jurisdictions where that timeline applies. We may need to verify your identity before responding.

Declining to provide information: some personal information is required to create and secure an account, provide requested Services, process a transaction, or comply with law. If you do not provide information identified as required, we may be unable to create your account, provide the relevant Service, complete the transaction, or respond to your request. Other information is optional.

10.1 California Privacy Rights

This subsection applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), applies to us. The table below summarizes the categories of personal information we collected, the sources and purposes of collection, and our disclosure practices during the 12 months preceding this Privacy Policy's effective date. The examples reflect the information described in Sections 2, 3, 6, and 7.

Category and examplesSourcesPurposesDisclosed for business purposes toSold or shared with
Identifiers and customer-record information, such as name, email, account identifiers, IP address, employer, and billing detailsYou; identity and payment providers; Unify; and automatic collectionService delivery, account administration, billing, security, analytics, advertising, and business outreachInfrastructure, AI, payment, email, analytics, advertising, visitor-identification, and professional service providers described in Sections 6 and 7Google and Unify
Commercial and professional information, such as transaction status, employer, job title, and professional profile informationYou; Stripe; Unify; and public sourcesBilling, customer administration, analytics, lead generation, and business outreachPayment, operations, analytics, visitor-identification, and professional service providersUnify
Internet or other electronic network activity, such as pages viewed, navigation paths, clicks, device identifiers, logs, and product telemetryAutomatic collection from our website and ServicesService delivery, security, debugging, analytics, advertising, attribution, and visitor identificationInfrastructure, analytics, advertising, visitor-identification, and security providersGoogle and Unify
Approximate geolocation, such as city, state, or region inferred from an IP addressAutomatic collection and service providersSecurity, regional privacy controls, analytics, advertising, and visitor identificationInfrastructure, analytics, advertising, and visitor-identification providersGoogle and Unify
Customer content and communications, such as Uploaded Content, AI conversations, and support requestsYou and users authorized by your organizationService delivery, AI features, support, security, and service improvement as described in this PolicyInfrastructure, AI, support, security, and professional service providers as necessaryNone
Inferences about professional interests or likely business interest in our ServicesWebsite activity; Unify; and commercial business datasetsAnalytics, lead generation, and personalized business outreachAnalytics, advertising, visitor-identification, and operations providersUnify
Sensitive personal information, such as account credentials and information voluntarily included in Uploaded ContentYou and users authorized by your organizationAccount authentication, security, and providing requested ServicesInfrastructure, identity, AI, and security providers as necessary to provide the ServicesNone

We do not sell personal information for money. As described above, disclosures of identifiers, professional information, internet activity, approximate location, and related inferences to advertising and visitor-identification providers may be considered "selling" or "sharing" under the CCPA. We do not sell or share Uploaded Content. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.

Subject to applicable exceptions, California residents may:

  • Request the categories and specific pieces of personal information we collected about them; the categories of sources, purposes, and recipients; and our sale or sharing practices.
  • Request deletion or correction of personal information we maintain about them.
  • Opt out of the sale or sharing of personal information using the "Do Not Sell or Share" control made available through the Services or a Global Privacy Control signal.
  • Exercise these rights without receiving discriminatory treatment.

To submit an access, deletion, correction, or limitation request, email [email protected] or write to the postal address in Section 15. Because we operate exclusively online and have a direct relationship with users, we provide these online and postal request methods instead of a toll-free telephone number. We may verify your request using information associated with your account or information we already maintain. If we cannot verify a request, we may deny it and explain why.

An authorized agent may submit a request on your behalf. We may require signed permission or a valid power of attorney, verify the agent's identity and authority, and ask you to confirm directly that you authorized the request, as permitted by law.

We do not have actual knowledge that we sell or share personal information of consumers under 16. We do not offer financial incentives related to the collection, sale, or sharing of personal information.

Global Privacy Control: we honor Global Privacy Control (GPC) signals from your browser as an opt-out of advertising and visitor-identification tracking globally.

Do Not Track: some browsers send a "Do Not Track" (DNT) signal. We do not currently respond to DNT signals. DNT is distinct from GPC, which we honor as described above.

EU/UK residents: under the GDPR and UK GDPR, you have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data violates applicable law. If you are in the EEA, you can find your supervisory authority in the European Data Protection Board member list. If you are in the UK, you may contact:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: +44 303 123 1113
Website: ico.org.uk/make-a-complaint

11. Cookies and Tracking

We use cookies and similar technologies to maintain your login session, remember your preferences, analyze usage, and detect abuse. You can control cookies through your browser settings; disabling some cookies may impair functionality. Where required by law, we ask for your consent before setting non-essential cookies. For details about the cookies we use, the categories they fall into, and how to manage your preferences, see our Cookie Policy.

12. International Data Transfers

Embedder is a US-based company and our production systems are hosted in the United States (GCP, region us-central1). If you access the Services from outside the United States, your information will be transferred to and processed in the United States. For transfers from the European Economic Area, the United Kingdom, and Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) with our service providers and sub-processors, supplemented by additional safeguards as required. You may request more information about the transfer mechanism that applies to your personal information, including a copy of the relevant contractual safeguards, by emailing [email protected]. We may redact information that is confidential or unrelated to the safeguards.

13. Children's Privacy

Our Services are intended only for adults who are at least 18 years old. We do not knowingly collect or process personal information from anyone under 18. If we learn that we have collected such information, we will take appropriate steps to delete it.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. You are responsible for regularly reviewing this Privacy Policy. If we make material changes, we will notify you by email (if provided) or through the Services at least 30 days before they take effect.

15. Contact

Privacy and data-subject requests: [email protected].
Security reports: [email protected].
Our Chief Information Security Officer oversees our privacy program as our privacy lead. We have not designated that role as a statutory Data Protection Officer.

Embedder Tech Inc.
2261 Market Street STE 95828
San Francisco, CA 94114
United States

16. European Union Representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact in the European Union.

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit: https://app.prighter.com/portal/embedder