Privacy Notice
Last revised
Sub Zero Labs OÜ ("EmberX", "we", "us", "our") is the data controller for the personal data processed through https://emberx.ai and every service we operate under that name (the "Services"). We are registered in Estonia under register code 17449187, at Sepapaja tn 6, 15551 Tallinn, Estonia.
EmberX is an AI companion application: you exchange messages, images, voice notes and video with fictional characters generated by software. This notice explains what that means for your data. It applies alongside our Terms of Service.
It is written to satisfy the EU General Data Protection Regulation (GDPR), the UK GDPR, and comparable laws elsewhere, including the California Consumer Privacy Act.
The short version
- We ask for as little as we can. An email address is the only thing you must give us to have an account.
- We do not sell your data, and we do not sell or publish your conversations.
- Your conversations are sent to AI model providers, because that is the only way a reply can exist. They are not used to train third-party models.
- We run automated safety moderation. Content it flags may be reviewed by a person.
- We use no advertising trackers and build no profile of you for advertising. Our analytics stores nothing on your device and cannot link one visit to another. Where you arrive through a partner link we store that partner's code locally so they are credited. See section 9.
- You can delete your account at any time, and you can email support@emberx.ai to exercise any of the rights in section 10.
1. Terms used in this notice
- Personal data
- Any information relating to an identified or identifiable person — your email address, your IP address, the account identifier we assign you, and the content you send us where it identifies you.
- Processing
- Anything done with personal data: collecting, storing, using, transmitting, altering, disclosing, deleting.
- Controller
- Whoever decides why and how personal data is processed. For the Services, that is Sub Zero Labs OÜ.
- Processor
- A third party that processes personal data on our instructions and on our behalf — our hosting, storage, email, payment and AI providers. They may not use your data for their own purposes.
- Content
- What you send into the Services (messages to a companion, prompts, preferences, settings) and what the Services generate in response.
2. What we collect and why
Each row below is a distinct processing activity, the data it involves, and the legal basis we rely on under the GDPR. Where the basis is consent, you can withdraw it at any time — see section 10.
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account | Email address; the sign-in method you chose; account identifier; display name, username and avatar if you set one; account creation and last sign-in timestamps. | Performance of a contract (Art. 6(1)(b)) |
| Signing you in | Email address and one-time sign-in codes; or, if you use Google sign-in, the identifier, email address and basic profile Google returns to us. Session cookies on your device. | Performance of a contract (Art. 6(1)(b)) |
| Delivering the chat experience | Your messages to a companion and the companion's replies; the character you are talking to; conversation history and the memory derived from it. | Performance of a contract (Art. 6(1)(b)) |
| Content and companion preferences | Your onboarding choices: whether you want safe-for-work or explicit content, and the gender and style of companion you prefer. | Consent (Art. 6(1)(a)) and, where these reveal data about your sex life or sexual orientation, explicit consent (Art. 9(2)(a)) |
| Generating images, voice and video | The prompt or scene you requested, the character it involves, the generated media, and job status records. | Performance of a contract (Art. 6(1)(b)) |
| Subscriptions, tokens and payments | Subscription status and period dates; token balance and the ledger of every grant, spend, top-up and refund; payment attempt records, our own payment reference, amount, currency, outcome and timestamps. Card data is handled by our payment provider — see section 3. | Performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Safety, moderation and enforcement | Prompts and Content assessed by automated moderation; anything flagged and reviewed by a person; the action taken; associated account data and metadata such as timestamps and originating IP address. | Legal obligation (Art. 6(1)(c)); legitimate interests in preventing misuse and protecting users and the platform (Art. 6(1)(f)) |
| Age assurance | Your confirmation that you meet the minimum age, and — where we require verification — the outcome of a check and the reference the verification provider returns. We do not receive or retain identity documents. | Legal obligation (Art. 6(1)(c)); legitimate interests in keeping minors off an adult service (Art. 6(1)(f)) |
| Support | The email address you write from, what you tell us, and the account and Content we need to look at to answer you. | Legitimate interests in answering your request (Art. 6(1)(f)); performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention and debugging | Server and application logs: IP address, user agent, request paths, timestamps, error traces, rate-limit counters. | Legitimate interests in keeping the Services secure, available and working (Art. 6(1)(f)) |
| Improving the Services | Aggregated and de-identified usage patterns; failure diagnostics. We do not build advertising or behavioural profiles. | Legitimate interests in improving what we operate (Art. 6(1)(f)) |
| Legal claims and lawful requests | Whatever is within the scope of a lawful request from an authority or court, or necessary to establish, exercise or defend a legal claim. | Legal obligation (Art. 6(1)(c)); legitimate interests in defending our rights (Art. 6(1)(f)) |
If you do not provide the data marked as necessary for the contract, we cannot give you an account or provide the Services.
3. Payment data
We never see or store your full card number, expiry date or security code. Card details are captured and processed by our payment provider on their own infrastructure.
Card payments are processed by Finby, a licensed European payment institution. To process a payment they receive the data their fraud, risk and settlement obligations require — typically your name and email address, card scheme, the last four digits and issuing-country of the card, the amount, currency, IP address, and the outcome of the transaction. For that processing Finby acts as an independent controller under its own privacy policy and under financial-services law, including anti-money-laundering rules.
What comes back to us is limited: whether the payment succeeded, our own reference for it, the amount and currency, the timestamp, and — for a subscription — the token our provider gives us to charge the same payment method again on renewal. That token is not your card number and cannot be used anywhere else.
Billing on your statement is discreet: the descriptor does not name the nature of the Services.
4. Your conversations and AI processing
This section matters more than any other, so it is stated plainly.
- Your messages are sent to AI model providers. A companion's reply is produced by a large language model running on third-party infrastructure. Delivering your message to that model is the only way a reply can exist. The same is true of the prompts behind generated images, voice and video.
- We instruct our AI providers not to use your Content to train their models, and we contract with them on that basis. We cannot audit their infrastructure, and we tell you that rather than promise otherwise.
- We do not train our own foundation models on your conversations, and we do not sell, rent, publish or share your conversation content with anyone for their own purposes.
- We store your conversation history so a companion can remember you across sessions. That is a product feature, and it is why the history exists at all.
- Automated moderation reads your prompts and Content. Where it flags something, an authorised person may review that content and other content on the account. See section 5.
- Generated output can be wrong. It is produced by probabilistic models and may be inaccurate or inconsistent. Do not treat it as fact, advice, or the statement of a real person.
Do not send us data you would not want processed this way. Companions are software: they cannot verify anything and have no reason to be told anything. Never disclose your full name, home address, financial details, government identifiers, passwords, or another person's personal data — including intimate details or images of anyone other than yourself — in a conversation.
You can delete individual chats, and deleting your account deletes your conversation history, subject to section 8.
5. Safety moderation
We run automated moderation across the Services to enforce our Terms of Service and the law. It may block or alter a request before generation, and may flag Content after it.
Where something is flagged, we or an authorised provider may manually review that Content, other Content on the account, and the account's metadata, and may act on it — removing content, restricting features, or suspending or terminating the account.
We have zero tolerance for child sexual abuse material. Where we confirm it, we report the material and the associated account data to the competent authorities and to child-protection organisations, as the law requires and permits. This processing is not subject to your consent and cannot be opted out of while you use the Services.
7. International transfers
Some of the providers above are established outside the European Economic Area, principally in the United States, so your personal data may be transferred there.
Where it is, we rely on an adequacy decision of the European Commission where one covers the recipient, and otherwise on the European Commission's Standard Contractual Clauses together with technical and organisational safeguards. You can ask us for a copy of the safeguards applying to a specific transfer, redacted of commercially confidential terms — see section 12.
8. How long we keep data
We keep personal data for as long as your account exists and for as long as we need it for the purpose we collected it, unless the law says otherwise.
| Data | Retention |
|---|---|
| Account data and conversation history | For the life of the account. Deleted without undue delay when you delete your account or ask us to. We may also remove Content after a prolonged period of account inactivity, for operational and infrastructure reasons. |
| Financial and transaction records | Seven years from the end of the financial year they belong to, as required by Estonian accounting and tax law. This obligation survives account deletion. |
| Moderation records and safety reports | For as long as needed to enforce our Terms, defend against repeat abuse, and comply with reporting obligations. Records relating to reported illegal material are retained as the law requires. |
| Server and security logs | Up to 30 days, then deleted or aggregated, except where retained for a specific security investigation. |
| Data relevant to a legal claim or a lawful request | For as long as necessary to establish, exercise or defend the claim, or to comply with the request. |
Deleting your account does not withdraw the records we are legally required to retain, and does not undo a moderation report already made to an authority.
10. Your rights
Under the GDPR and equivalent laws you have the following rights over your personal data. They are free to exercise, and exercising one never counts against you.
- Access
- Get confirmation of whether we process your data, a copy of it, and information about the purposes, categories, recipients, retention periods and the source it came from.
- Rectification
- Have inaccurate data corrected and incomplete data completed. Much of this you can do yourself in settings.
- Erasure
- Have your data deleted where it is no longer needed, where you withdraw consent and no other basis applies, where you successfully object, or where it was processed unlawfully. This does not override our legal retention obligations or our need to defend a legal claim.
- Restriction
- Have processing suspended while we verify accuracy, while we assess an objection, where processing is unlawful but you do not want deletion, or where you need the data for a legal claim.
- Portability
- Receive the data you provided to us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
- Objection
- Object at any time to processing based on our legitimate interests. We stop unless we can demonstrate compelling grounds that override your rights, or we need the data for legal claims.
- Withdraw consent
- Withdraw any consent you gave — including for content preferences — at any time. Withdrawal does not affect processing that already happened, and it may mean we can no longer provide part of the Services.
- No automated decisions with legal effect
- We do not make decisions producing legal or similarly significant effects about you by purely automated means. Automated moderation may restrict an account; where it does, you can ask us to review it and we will have a person look at it.
To exercise any of these, write to support@emberx.ai from the address on your account. We may need to verify your identity. We answer within one month; if a request is complex we may extend that by up to two further months and will tell you why within the first month.
If you are in California, you also have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA. Use the same address.
11. Security, and no data from minors
Security
We apply technical and organisational measures appropriate to the risk: encryption in transit, access controls and least-privilege access to production systems, audited administrative actions, and providers selected for their own security posture. We hold no card numbers and no plaintext passwords.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority as the GDPR requires.
Minors
The Services are for adults. We do not knowingly collect personal data from anyone under 18, or under the age of majority where they live if that is higher. If we learn that an account belongs to a minor, we terminate it and delete the associated data as quickly as we can. If you believe a minor has created an account, tell us at support@emberx.ai and we will act immediately.
12. Contact us and complaints
For any question about this notice, or to exercise a right under section 10:
- Controller
- Sub Zero Labs OÜ
- Registered office
- Sepapaja tn 6, 15551 Tallinn, Estonia
- Register code
- 17449187
- support@emberx.ai
We would rather resolve a concern with you directly, so please come to us first. You always keep the right to lodge a complaint with a supervisory authority — the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), the authority in the EU country where you live or work, or the Information Commissioner's Office if you are in the UK.
13. Changes to this notice
We update this notice when our practices or the applicable law change. The revised version is posted here with a new revision date, and takes effect on posting.
Where a change is substantial, we will tell you before it takes effect — by email or in the product — and, where the change requires your consent, we will ask for it rather than assume it.