Emberlodge — Privacy Policy

Effective: ⚠️ TO BE SET on publication Last updated: 12 August 2026 Applies to: the Emberlodge apps for Windows and Android, and the Emberlodge web app.

⚠️ DRAFT — not yet legal advice. This is written from what the code actually does, verified against the live database on 12 August 2026. It still needs a lawyer's eye before you publish it, and the ⚠️ placeholders below must be filled in. See PRIVACY-NOTES.md for the open questions and the evidence behind each claim.

1. Who we are

Emberlodge is made by Three Blades Data, a sole trader based in Australia.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The small-business exemption does not apply to us: it lifts for an organisation that both provides a health service and holds health information, and a symptom and medication tracker is a health service under the Act's broad definition.

2. Emberlodge is not a medical device

Emberlodge helps you record and remember things about your own health. It does not diagnose, treat, cure or prevent anything, and it is not a substitute for a doctor, pharmacist or any other health professional.

If something about your health worries you, talk to an actual doctor.

3. What we collect

Everything below is information you type into the app. We do not buy data about you, and we do not collect anything from other sources.

Account

Your email address, and a display name if you give one. Passwords are handled by our authentication provider and are never visible to us.

Health information — the sensitive part

Everyday use

Tasks and to-do lists, routines, time-tracking entries and client names, reading and content lists, streaks, timers, and reminders.

Your conversations with Kuro

The messages you exchange with the in-app assistant are stored so the conversation persists between sessions. See §5 for what happens to them.

Technical

Notification tokens for the device you enable reminders on, your app settings, and a per-day count of assistant calls for cost control. That counter records a number and a date — never the content of anything.

If the app breaks

When Emberlodge stops unexpectedly, it writes down what went wrong — the time, the version, the device, and the technical detail of the error — on your device only. This is kept so that "it stopped working" can be turned into something answerable.

That record can contain text the app was handling at the moment it broke, which may include health information: a note you captured, a check-in answer, the name of a medication. So it is treated as health information, and:

If you do send us a report, we use it only to fix the fault and delete it once that is done.

If you connect a calendar or email account

Access tokens for Google or Microsoft, and the account's email address, so the app can show your calendar. We store the tokens; the calendar and mail content itself is fetched when needed and not copied into our database.

4. Where your information is stored

Your data is stored in Australia. Our database is hosted by Supabase in their Sydney region (ap-southeast-2). Row-level security is enforced at the database, so one account cannot read another's rows.

5. Who else sees it, and when

We do not sell your information, ever. We do not use it for advertising, and we do not build profiles for anyone else. Information leaves our database only in the situations below.

WhoWhat reaches themWhereWhy
SupabaseEverything in §3🇦🇺 SydneyHosts the database and accounts
AnthropicYour chat messages, and health details only when you ask a question that needs them (see below)🇺🇸 USAPowers the in-app assistant
GoogleSign-in details if you use Google sign-in; calendar/mail content if you connect it; notification delivery🇺🇸 USASign-in, calendar, push notifications
MicrosoftSign-in and calendar content, if you connect an account🇺🇸 USASign-in and calendar
VercelWeb app page requestsVariesHosts the web app
Weather providerYour approximate locationVariesLocal forecast

Being specific about the assistant

This matters, so plainly: your health data is not sent to the AI provider with every message. Each request carries a fixed instruction sheet, your first name, and today's date.

But the assistant can look things up when your question requires it. If you ask "when is my next dose?" or "how has my mood been this week?", it retrieves those records — and that retrieved information is then sent to the AI provider as part of answering you. The same applies if you ask it to read your clipboard, a file, or your email.

So: routine use does not send your health records overseas. Asking the assistant about them does. If you would rather that never happened, do not ask the assistant about your health data — every feature that records it works without the assistant.

Voice

Cross-border disclosure

Sending information to the providers marked 🇺🇸 above means it is handled outside Australia, where privacy laws differ from ours. By using the assistant, sign-in, or a connected calendar, you consent to that. We take reasonable steps to use reputable providers, but we cannot guarantee an overseas recipient will handle information the way Australian law requires.

6. Your consent

Health information is sensitive information under the Privacy Act, and we collect it only with your consent. You give that consent when you choose to enter it — every health field in Emberlodge is optional, and the app works as a reminder tool without any of them.

You can withdraw consent at any time by deleting the information or your whole account (§8). Withdrawing consent does not undo anything already done, but it stops any further use.

7. What we do not do

8. Getting at, fixing and deleting your information

You can see everything. The app exports your check-in history to a file you choose.

You can correct anything. Every record can be edited or deleted in the app.

You can delete everything. Settings → "Delete all my data" erases your records from this device and from our database. It takes two deliberate presses, and local data is wiped even if the network is down.

Deleting your account removes everything: your records, the three internal tables the app itself cannot reach (an API usage counter, your connected-account tokens, and reminder bookkeeping), and the login itself. The app tells you which of those succeeded rather than assuming — if the login could not be removed, it says so and tells you to contact us.

To ask for anything above, or if you cannot use the in-app tools, contact us at the address in §1. We will respond within 30 days.

Step-by-step instructions, and the full list of what is erased, are on our account deletion page.

9. If there is a data breach

We are covered by the Notifiable Data Breaches scheme. If we discover a breach likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as soon as practicable. Our response plan is written down, so that what happens next does not depend on how the day is going.

10. How we protect it

No system is perfectly secure, and we will not pretend otherwise.

11. Where Emberlodge is offered

Emberlodge is offered in Australia only. It is built around Australian privacy law and that is the regime it is designed for.

We do not target the European Union or the United Kingdom, and we do not claim to meet the GDPR. If you are in the EU or UK, please do not create an account — cycle and mental-health data is "special category" information there, with obligations we have not set out to meet and would rather not pretend to.

12. Children

Emberlodge is not intended for anyone under 16, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

13. How long we keep it

We keep your information while your account exists. Delete it, and it goes from our live database immediately; backups roll off within ⚠️ TO BE SET — confirm your host's backup retention days.

14. Changes to this policy

If we change it, we will update the date at the top, and tell you in the app for anything that materially affects you.

15. Complaints

Contact us first — details in §1 — and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au · 1300 363 992.