Legal information

Privacy Notice

Last revised

Sub Zero Labs OÜ ("EmberX", "we", "us", "our") is the data controller for the personal data processed through https://emberx.ai and every service we operate under that name (the "Services"). We are registered in Estonia under register code 17449187, at Sepapaja tn 6, 15551 Tallinn, Estonia.

EmberX is an AI companion application: you exchange messages, images, voice notes and video with fictional characters generated by software. This notice explains what that means for your data. It applies alongside our Terms of Service.

It is written to satisfy the EU General Data Protection Regulation (GDPR), the UK GDPR, and comparable laws elsewhere, including the California Consumer Privacy Act.

The short version

  • We ask for as little as we can. An email address is the only thing you must give us to have an account.
  • We do not sell your data, and we do not sell or publish your conversations.
  • Your conversations are sent to AI model providers, because that is the only way a reply can exist. They are not used to train third-party models.
  • We run automated safety moderation. Content it flags may be reviewed by a person.
  • We use no advertising trackers and build no profile of you for advertising. Our analytics stores nothing on your device and cannot link one visit to another. Where you arrive through a partner link we store that partner's code locally so they are credited. See section 9.
  • You can delete your account at any time, and you can email support@emberx.ai to exercise any of the rights in section 10.

1. Terms used in this notice

Personal data
Any information relating to an identified or identifiable person — your email address, your IP address, the account identifier we assign you, and the content you send us where it identifies you.
Processing
Anything done with personal data: collecting, storing, using, transmitting, altering, disclosing, deleting.
Controller
Whoever decides why and how personal data is processed. For the Services, that is Sub Zero Labs OÜ.
Processor
A third party that processes personal data on our instructions and on our behalf — our hosting, storage, email, payment and AI providers. They may not use your data for their own purposes.
Content
What you send into the Services (messages to a companion, prompts, preferences, settings) and what the Services generate in response.

2. What we collect and why

Each row below is a distinct processing activity, the data it involves, and the legal basis we rely on under the GDPR. Where the basis is consent, you can withdraw it at any time — see section 10.

PurposeDataLegal basis
Creating and running your accountEmail address; the sign-in method you chose; account identifier; display name, username and avatar if you set one; account creation and last sign-in timestamps.Performance of a contract (Art. 6(1)(b))
Signing you inEmail address and one-time sign-in codes; or, if you use Google sign-in, the identifier, email address and basic profile Google returns to us. Session cookies on your device.Performance of a contract (Art. 6(1)(b))
Delivering the chat experienceYour messages to a companion and the companion's replies; the character you are talking to; conversation history and the memory derived from it.Performance of a contract (Art. 6(1)(b))
Content and companion preferencesYour onboarding choices: whether you want safe-for-work or explicit content, and the gender and style of companion you prefer.Consent (Art. 6(1)(a)) and, where these reveal data about your sex life or sexual orientation, explicit consent (Art. 9(2)(a))
Generating images, voice and videoThe prompt or scene you requested, the character it involves, the generated media, and job status records.Performance of a contract (Art. 6(1)(b))
Subscriptions, tokens and paymentsSubscription status and period dates; token balance and the ledger of every grant, spend, top-up and refund; payment attempt records, our own payment reference, amount, currency, outcome and timestamps. Card data is handled by our payment provider — see section 3.Performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c))
Safety, moderation and enforcementPrompts and Content assessed by automated moderation; anything flagged and reviewed by a person; the action taken; associated account data and metadata such as timestamps and originating IP address.Legal obligation (Art. 6(1)(c)); legitimate interests in preventing misuse and protecting users and the platform (Art. 6(1)(f))
Age assuranceYour confirmation that you meet the minimum age, and — where we require verification — the outcome of a check and the reference the verification provider returns. We do not receive or retain identity documents.Legal obligation (Art. 6(1)(c)); legitimate interests in keeping minors off an adult service (Art. 6(1)(f))
SupportThe email address you write from, what you tell us, and the account and Content we need to look at to answer you.Legitimate interests in answering your request (Art. 6(1)(f)); performance of a contract (Art. 6(1)(b))
Security, abuse prevention and debuggingServer and application logs: IP address, user agent, request paths, timestamps, error traces, rate-limit counters.Legitimate interests in keeping the Services secure, available and working (Art. 6(1)(f))
Improving the ServicesAggregated and de-identified usage patterns; failure diagnostics. We do not build advertising or behavioural profiles.Legitimate interests in improving what we operate (Art. 6(1)(f))
Legal claims and lawful requestsWhatever is within the scope of a lawful request from an authority or court, or necessary to establish, exercise or defend a legal claim.Legal obligation (Art. 6(1)(c)); legitimate interests in defending our rights (Art. 6(1)(f))

If you do not provide the data marked as necessary for the contract, we cannot give you an account or provide the Services.

3. Payment data

We never see or store your full card number, expiry date or security code. Card details are captured and processed by our payment provider on their own infrastructure.

Card payments are processed by Finby, a licensed European payment institution. To process a payment they receive the data their fraud, risk and settlement obligations require — typically your name and email address, card scheme, the last four digits and issuing-country of the card, the amount, currency, IP address, and the outcome of the transaction. For that processing Finby acts as an independent controller under its own privacy policy and under financial-services law, including anti-money-laundering rules.

What comes back to us is limited: whether the payment succeeded, our own reference for it, the amount and currency, the timestamp, and — for a subscription — the token our provider gives us to charge the same payment method again on renewal. That token is not your card number and cannot be used anywhere else.

Billing on your statement is discreet: the descriptor does not name the nature of the Services.

4. Your conversations and AI processing

This section matters more than any other, so it is stated plainly.

  • Your messages are sent to AI model providers. A companion's reply is produced by a large language model running on third-party infrastructure. Delivering your message to that model is the only way a reply can exist. The same is true of the prompts behind generated images, voice and video.
  • We instruct our AI providers not to use your Content to train their models, and we contract with them on that basis. We cannot audit their infrastructure, and we tell you that rather than promise otherwise.
  • We do not train our own foundation models on your conversations, and we do not sell, rent, publish or share your conversation content with anyone for their own purposes.
  • We store your conversation history so a companion can remember you across sessions. That is a product feature, and it is why the history exists at all.
  • Automated moderation reads your prompts and Content. Where it flags something, an authorised person may review that content and other content on the account. See section 5.
  • Generated output can be wrong. It is produced by probabilistic models and may be inaccurate or inconsistent. Do not treat it as fact, advice, or the statement of a real person.

Do not send us data you would not want processed this way. Companions are software: they cannot verify anything and have no reason to be told anything. Never disclose your full name, home address, financial details, government identifiers, passwords, or another person's personal data — including intimate details or images of anyone other than yourself — in a conversation.

You can delete individual chats, and deleting your account deletes your conversation history, subject to section 8.

5. Safety moderation

We run automated moderation across the Services to enforce our Terms of Service and the law. It may block or alter a request before generation, and may flag Content after it.

Where something is flagged, we or an authorised provider may manually review that Content, other Content on the account, and the account's metadata, and may act on it — removing content, restricting features, or suspending or terminating the account.

We have zero tolerance for child sexual abuse material. Where we confirm it, we report the material and the associated account data to the competent authorities and to child-protection organisations, as the law requires and permits. This processing is not subject to your consent and cannot be opted out of while you use the Services.

6. Who we share data with

We disclose personal data only where it is needed to run the Services, where we have a legitimate interest, where you have consented, or where the law requires it. We do not sell personal data, and we do not share it with anyone for their own marketing.

These are the categories of processor we rely on, with the providers currently in use:

What they doProviderData they process
Application hosting and deliveryVercel Inc.Requests, IP address, user agent, server logs
Database and backend platformConvex, Inc.All account, chat, media-job and billing records
Media storage and deliveryCloudflare, Inc. (R2)Generated and catalog images, audio and video
Transactional emailResend, Inc.Email address and the message we send you
Product analytics (EU region)PostHog, Inc.Anonymous page views and three funnel events (which character card was opened, whether a room was opened, whether a paywall was shown), with a random device identifier. No profile is created for signed-out visitors.
Sign-in with Google (optional)Google Ireland Ltd.Identifier, email address, basic profile — only if you choose that method
Conversational AI inferenceAI model providers accessed through the Vercel AI GatewayYour messages, character persona and conversation context
Image and video generationRunware, RunPod and MuleRouterGeneration prompts and the resulting media
Card paymentsFinbySee section 3

We also disclose personal data to: our professional advisers (lawyers, accountants) where we need advice; law-enforcement, regulatory and judicial authorities where the law requires it or to protect someone's vital interests; and, in a merger, acquisition or sale of assets, to the acquirer and its advisers — in which case your data stays subject to this notice until you are told otherwise.

We may share aggregated or de-identified statistics that cannot be linked back to you.

7. International transfers

Some of the providers above are established outside the European Economic Area, principally in the United States, so your personal data may be transferred there.

Where it is, we rely on an adequacy decision of the European Commission where one covers the recipient, and otherwise on the European Commission's Standard Contractual Clauses together with technical and organisational safeguards. You can ask us for a copy of the safeguards applying to a specific transfer, redacted of commercially confidential terms — see section 12.

8. How long we keep data

We keep personal data for as long as your account exists and for as long as we need it for the purpose we collected it, unless the law says otherwise.

DataRetention
Account data and conversation historyFor the life of the account. Deleted without undue delay when you delete your account or ask us to. We may also remove Content after a prolonged period of account inactivity, for operational and infrastructure reasons.
Financial and transaction recordsSeven years from the end of the financial year they belong to, as required by Estonian accounting and tax law. This obligation survives account deletion.
Moderation records and safety reportsFor as long as needed to enforce our Terms, defend against repeat abuse, and comply with reporting obligations. Records relating to reported illegal material are retained as the law requires.
Server and security logsUp to 30 days, then deleted or aggregated, except where retained for a specific security investigation.
Data relevant to a legal claim or a lawful requestFor as long as necessary to establish, exercise or defend the claim, or to comply with the request.

Deleting your account does not withdraw the records we are legally required to retain, and does not undo a moderation report already made to an authority.

9. Cookies and similar technologies

We use no advertising cookies and no cross-site trackers. There is no behavioural profiling on the Services, and nothing here is used to target advertising.

What we set without asking is strictly necessary: the cookies and local storage that keep you signed in between page loads, hold your session securely, remember interface preferences such as your theme, and record that you confirmed you are an adult when you entered. These are exempt from the consent requirement under the ePrivacy Directive because the Services cannot work without them.

Product analytics — and what we deliberately do not do. We use PostHog (EU region) to count how visitors move through the site: which character was opened, whether a room was opened, whether a paywall was shown. It runs without storing anything on your device — no analytics cookie, nothing in local storage. The identifier lasts only as long as the page is open and is gone when you close the tab, your IP address is not recorded with the event, and no profile is created for signed-out visitors. Two visits by you are not linked to each other, and nothing here is linked to your identity.

Referral attribution. Where you arrive through a partner or affiliate link, we store that partner's code in your browser's local storage for up to 90 days so the partner who introduced you is credited if you later create an account. It records the code, the page you landed on, and a random identifier for the browser. It is not used to build a profile of you, is never combined with your chat or media activity, and is not shared with the partner as anything other than a count.

You can remove it at any time by clearing your browser's storage for this site, and blocking storage stops it being written at all — neither affects anything else about how the Services work for you.

You can clear or block cookies and storage in your browser, but you will be signed out and parts of the Services will stop working.

10. Your rights

Under the GDPR and equivalent laws you have the following rights over your personal data. They are free to exercise, and exercising one never counts against you.

Access
Get confirmation of whether we process your data, a copy of it, and information about the purposes, categories, recipients, retention periods and the source it came from.
Rectification
Have inaccurate data corrected and incomplete data completed. Much of this you can do yourself in settings.
Erasure
Have your data deleted where it is no longer needed, where you withdraw consent and no other basis applies, where you successfully object, or where it was processed unlawfully. This does not override our legal retention obligations or our need to defend a legal claim.
Restriction
Have processing suspended while we verify accuracy, while we assess an objection, where processing is unlawful but you do not want deletion, or where you need the data for a legal claim.
Portability
Receive the data you provided to us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
Objection
Object at any time to processing based on our legitimate interests. We stop unless we can demonstrate compelling grounds that override your rights, or we need the data for legal claims.
Withdraw consent
Withdraw any consent you gave — including for content preferences — at any time. Withdrawal does not affect processing that already happened, and it may mean we can no longer provide part of the Services.
No automated decisions with legal effect
We do not make decisions producing legal or similarly significant effects about you by purely automated means. Automated moderation may restrict an account; where it does, you can ask us to review it and we will have a person look at it.

To exercise any of these, write to support@emberx.ai from the address on your account. We may need to verify your identity. We answer within one month; if a request is complex we may extend that by up to two further months and will tell you why within the first month.

If you are in California, you also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA. Use the same address.

11. Security, and no data from minors

Security

We apply technical and organisational measures appropriate to the risk: encryption in transit, access controls and least-privilege access to production systems, audited administrative actions, and providers selected for their own security posture. We hold no card numbers and no plaintext passwords.

No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority as the GDPR requires.

Minors

The Services are for adults. We do not knowingly collect personal data from anyone under 18, or under the age of majority where they live if that is higher. If we learn that an account belongs to a minor, we terminate it and delete the associated data as quickly as we can. If you believe a minor has created an account, tell us at support@emberx.ai and we will act immediately.

12. Contact us and complaints

For any question about this notice, or to exercise a right under section 10:

Controller
Sub Zero Labs OÜ
Registered office
Sepapaja tn 6, 15551 Tallinn, Estonia
Register code
17449187

We would rather resolve a concern with you directly, so please come to us first. You always keep the right to lodge a complaint with a supervisory authority — the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), the authority in the EU country where you live or work, or the Information Commissioner's Office if you are in the UK.

13. Changes to this notice

We update this notice when our practices or the applicable law change. The revised version is posted here with a new revision date, and takes effect on posting.

Where a change is substantial, we will tell you before it takes effect — by email or in the product — and, where the change requires your consent, we will ask for it rather than assume it.

Related

All documents are listed on the legal information page.