
Privacy Policy
Last updated: October 5, 2026
This Privacy Policy explains what information EmberChat collects, how we use it, and the choices you have. EmberChat is designed to collect as little personal data as possible. We do not require an email address, a phone number, or a password to use the service.
EmberChat (“EmberChat,” “we,” “us,” or “our”) operates the EmberChat applications and related services (collectively, the “Service”).
Data controller
The Service is operated by Evil Unicorn Oy, a limited company (osakeyhtiö) registered in Finland.
- Business ID: 3314508-9
- Email: support@emberchat.live
Evil Unicorn Oy is the data controller for personal data processed through the Service.
Summary
- Your identity is a cryptographic public key — we never receive or store your private key, and there are no passwords, email addresses or phone numbers.
- The only profile data we hold is what you choose: a display name, an avatar, and an optional bio. For your daily flame and achievements we also note on which days you were active — never what you wrote.
- Messages and media you send are stored on our servers in the EU so they can be delivered and displayed.
- To keep EmberChat safe we use automated tools (media scanning, a text filter, rate limits and, in rooms that invite it, the room bot Sparky) and an AI assistant for support. People review every decision that matters, and you can ask for a review.
- We do not use advertising, analytics or cross-app tracking, and we do not sell your data.
Information we collect
Public key (your identity)
EmberChat authentication is passwordless. You hold an ed25519 keypair on your device. To log in, your device signs a one-time challenge we issue, and we verify the signature against your public key. We store this public key as your account identifier. Your private key never leaves your device and is never transmitted to us.
Profile information
You may provide, and we store:
- a display name you choose;
- an avatar image (optional);
- a short bio (optional).
None of this is required to be your real name or to identify you offline. If you have no avatar, the app draws a cartoon picture for you on your device; no outside service is contacted for it.
Messages and media
Text messages, images, and videos you send through rooms and inboxes are stored on our servers so they can be delivered to other participants and shown when they open a room. Uploaded media is processed on our servers (for example, resizing and cropping pictures and generating video preview frames) and stored in object storage we control.
Video views. When you play a video, we record the view with a one-way, salted hash of your account instead of your name, so we can count views and unique viewers. Only the person who posted the video and our moderators see these counts. Uploaded videos are converted to a standard format with the uploader's display name shown in the picture; the originally uploaded file is not kept.
Links and embeds. When a message contains a link, our server may fetch a preview (title and picture) from that site; your device does not contact it. Players and media from other sites (such as YouTube, Vimeo, TikTok, Instagram, Imgur or Tenor) are only loaded when you tap them. Once you do, that site receives your request directly and its own privacy policy applies. YouTube videos are played through YouTube's privacy-enhanced mode.
Realtime voice and video
Voice and video calls are carried over LiveKit, which we run on our own servers. When you join a call, our server issues a token scoped to that room, and your audio/video streams flow through our media server to the other participants. EmberChat does not record calls.
A room owner or admin can stream a room's call to an external destination (for example a streaming service), where it may be recorded by the receiver. When this is happening, everyone in the room sees a red LIVE indicator next to the room name and a notice when the stream starts. If you do not want to be streamed, leave the room while the indicator is shown.
Push notification tokens
If you enable notifications, we store a device push token so we can deliver out-of-app alerts. Depending on your platform, this token is issued by Apple Push Notification service (APNs), Firebase Cloud Messaging (FCM), or the Web Push service in your browser. You can disable notifications at any time in your device or browser settings.
Flame and achievements
To show your daily flame (how many days in a row you have been active) and your achievements, we record which days you were active and whether you sent a message or a reaction on that day. We do not record how many messages you sent or what they said, and opening the app alone does not count. We also store your current and longest streak, your streak freezes, the achievements you have earned and when, and your time zone (so a “day” is your own calendar day). This information is used only to show you your flame and achievements — never for analytics or advertising. Your flame and achievements are shown on your profile to other users; you can hide them in My Account. The evening streak reminder is off by default and is sent only if you switch it on.
Operational data
To run the Service reliably and securely, our servers process technical data such as your IP address, connection times, and your account identifier and display name in server logs. Logs never contain your messages or login credentials, and they are rotated automatically, normally within a few days. We use Redis to cache media and link previews for performance. Sessions are held in server memory and are dropped when the server restarts — at which point your client transparently re-authenticates.
Abuse-prevention signals
To stop people who have been banned from simply creating a new account, each time you log in we store two one-way, salted hashes: one of a random identifier created by the app when it is installed (or by your browser), and one of the network address you connect from (for IPv6, only the network part). The hashes cannot be turned back into the identifier or the address. We use them only to show our moderators when a new account shares an app install or network with a banned account. They are never used to ban anyone automatically, for advertising, or to track you across other apps or websites, and they are deleted automatically 30 days after they were last seen, or immediately when you delete your account.
Support email
If you email us (for example support@emberchat.live or abuse@emberchat.live), we receive your email address and whatever you write. Incoming mail is received by our email provider, Resend, and read and sorted by our support assistant (see below) before a person answers. Support mail is deleted from the support inbox after 30 days unless it is needed for an open case.
Safety, moderation and automated tools
EmberChat is for adults and does not allow illegal content, harassment or pornography. To enforce this at scale we use the following tools. They support our moderators; they do not replace them.
- Media scanning. Every uploaded picture and video is checked before others see it. An image-classification model running on our own servers rates how explicit it is, so mature pictures can be blurred and prohibited ones refused. To detect known child sexual abuse material we calculate a perceptual hash (a short fingerprint that cannot be turned back into the picture) and compare it with Project Arachnid, run by the Canadian Centre for Child Protection. Only the fingerprint is sent, never the picture.
- Text filter. Messages, bios, user names and room names are checked against a list of prohibited terms. Depending on the term, a message is blocked, or held for a moderator to look at.
- Limits. New accounts cannot post links or media or message strangers during their first hour, and everyone has a message rate limit, to slow down spam.
- Reports. Any message, profile or room can be reported in the app. Reports and the automated flags above go to our moderators, who decide what happens. Account bans are always decided by a person.
If you think an automated decision (a blocked message or upload, or a limit) was wrong, email support@emberchat.live and a person will review it. Where the law requires it, we report illegal content, in particular child sexual abuse material, to the competent authorities and child-protection organisations.
Sparky, the room bot
Sparky is EmberChat's room bot. It is only in rooms whose owner or a Room Admin has invited it, and it is always shown with a BOT badge, so you know when it is reading along. The room owner can remove it at any time in the room settings.
In those rooms Sparky:
- answers when someone mentions @Sparky or replies to it;
- checks messages against the room rules and the Terms of Service (for example harassment, hate, threats, scams, sharing someone's private information, risks to children, and illegal activity). What it finds goes to our moderators as a report, with its reasoning.
To do this, the text of messages in that room, the display names of their senders and a few earlier messages for context are sent to AI models through our provider OpenRouter (see Service providers). Pictures and videos are not sent; they are checked by our media scanning. Sparky does not keep a copy of the conversation: it holds the last few messages of a room in memory only while it runs.
In clear-cut cases Sparky may also act on its own: it can hide a message (a moderator can restore it) and mute the writer in that room for a limited time (10 minutes, then 1 hour, then 24 hours for repeats within a week). It never acts against the room's owner, admins or moderators, and it cannot ban anyone, remove anyone from a room or delete messages for good. Every action Sparky takes goes to our moderators, who can undo it. If you think Sparky got it wrong, email support@emberchat.live and a person will review it.
AI support assistant
Our support and moderation assistant, Emberley, uses Google's Gemini AI model. It reads and sorts support email, drafts replies, and helps our moderators look up the reports and account information needed to handle a case. The content of those emails and case details are therefore processed by Google on our behalf. Emberley does not take moderation decisions on its own: a person approves every action.
What we deliberately do not collect
- No passwords — there are none.
- No phone numbers, and no email address unless you email us.
- No advertising identifiers, no analytics or tracking SDKs, and no cross-app or cross-site tracking.
- We do not sell, rent, or trade your personal data to anyone.
How we use information, and why
- To authenticate you, operate your account and deliver your messages, media and calls, and to let Sparky answer you when you talk to it, and to keep your flame and achievements — to provide the Service you asked for (GDPR Art. 6(1)(b)).
- To send push notifications you have switched on (your consent, Art. 6(1)(a)).
- To keep the Service secure and safe: logs, rate limits, media scanning, the text filter, Sparky's checks in rooms that invited it, abuse-prevention signals, moderation and support — our legitimate interest in a safe service for everyone (Art. 6(1)(f)).
- To comply with legal obligations, such as reporting child sexual abuse material (Art. 6(1)(c)).
Service providers
We share data only with providers that operate parts of the Service for us, under agreements that let them use it only on our instructions and never for their own advertising:
- Hetzner Online (Germany) — servers, file storage and backups.
- Cloudflare — DNS and delivery of our website and web app; it sees your IP address when you load them.
- Apple (APNs), Google (Firebase Cloud Messaging) and your browser's Web Push service — push notifications.
- Resend — sending and receiving email.
- OpenRouter — routes Sparky's requests to AI model providers. We only allow providers that keep no copy of the content and do not use it to train models.
- Google (Gemini) — our AI support assistant.
- Project Arachnid (Canadian Centre for Child Protection) — receives image fingerprints only, as described above.
Our moderators receive short alerts through Telegram; these alerts never contain personal data.
Where your data is processed
Your account, messages, media, calls and backups are stored and processed on servers in the European Union (Germany). Some providers above may process data outside the EU: Google, Apple, Cloudflare, Resend and OpenRouter (with the AI model providers it routes to) in the United States and elsewhere, and Project Arachnid in Canada (fingerprints only). For these transfers we rely on the European Commission's adequacy decisions (for Canada, and for companies certified under the EU–U.S. Data Privacy Framework) or on the Commission's Standard Contractual Clauses.
Data retention
- Your account and content are kept for as long as your account is active.
- When you delete your account (see Account & Data Deletion), we immediately delete your account record, profile, the messages you posted in rooms, the pictures and videos you uploaded, your push tokens, your flame and achievements, and your abuse-prevention signals. Rooms you created stay for their members, without you as the owner, and messages you sent to other people's inboxes stay with the recipient without your name.
- Flame and achievements (active days, streaks, achievements, time zone): kept while your account is active, because some achievements count your active days in total.
- Backups are kept for 7 days, so deleted data disappears from them within a week.
- Abuse-prevention signals: 30 days after they were last seen.
- Text-filter records (which term matched): 90 days.
- Reports and moderation records (reports, moderator decisions, warnings, bans and room closures): 12 months after the case is closed or the ban or closure has ended, so repeated abuse can be recognised and decisions reviewed. Open cases and bans that are still in force are kept until they end.
- Room mutes (by moderators or Sparky): 12 months after the mute ended. Sparky's reports and actions are moderation records (see above).
- Support email: 30 days in the support inbox, longer only for an open case.
- Server logs: rotated automatically, normally within a few days.
Age requirement
EmberChat is intended for adults. You must be at least 18 years old to use the Service, because rooms are created and moderated by users rather than by us.
Our Terms of Service prohibit sexually explicit material, harassment, illegal content, and other abusive content, and we remove such content and suspend the accounts responsible. Every message and user profile can be reported from within the app, and reports are reviewed within 24 hours.
We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has provided us information, contact us at support@emberchat.live.
Your rights and choices
- You can edit your display name, avatar, and bio at any time in the app.
- You can disable push notifications in your device or browser settings.
- You can delete your account and associated data — see Account & Data Deletion.
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing (including processing based on our legitimate interests, such as automated moderation), to receive your data in a portable format, and to withdraw consent at any time. To exercise any of these rights, contact us at support@emberchat.live. You also have the right to lodge a complaint with a supervisory authority; in Finland this is the Data Protection Ombudsman (tietosuoja.fi).
Security
Because identity is a keypair held on your device, there is no password database to breach. We protect data in transit with encrypted connections (WSS/HTTPS) and take reasonable measures to protect data at rest. No system is perfectly secure, but minimizing the data we hold is our first line of defense.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide notice within the Service.
Contact
Questions about privacy? Email support@emberchat.live.
