EmberFold Labs

emberslate

Privacy Policy

Last updated 28 August 2026

Summary

emberslate is a media tracking app. It stores the account you create and the viewing library and community activity you add so they are available when you sign in on another device.

emberslate also uses limited product analytics. Analytics is on by default and can be turned off at any time from the control above. We do not show ads or sell, rent, or share personal data with advertisers or data brokers.

Who we are

emberslate is operated by EmberFold Labs. For questions about this policy or your personal data, contact privacy@emberfoldlabs.com.

What we collect

Account details, so you can sign in and use community features:

  • Your email address, username, and display name.
  • If you sign in with Google, the account identity Google returns. We do not receive your Google password.
  • Your account role, creation date, and whether setup has been completed.

Your library and viewing activity, which is the substance of the app:

  • Titles on your watchlist, their status, your ratings, favourites, and rewatch counts.
  • Episodes you mark as watched, including the date and time, and reactions you leave on episodes.
  • Feedback used to improve title suggestions, such as titles you have seen or are not interested in.

Community activity, where you choose to use those features:

  • Posts and replies you write, mentions, and likes you leave.
  • Accounts you follow and block.
  • Recommendations you send or receive, including any note you add.
  • Reports you submit about a post, including any reason you provide.

Settings and notification data:

  • Your sharing, mention, notification, display, and analytics choices.
  • If you enable push notifications, an Expo push token, your device platform, and your device time zone.

If you use library import, we temporarily process:

  • The import source, original file name and size.
  • The titles, provider identifiers, watch dates, ratings, favourites, and statuses needed to prepare the review step.

When usage analytics is enabled, Mixpanel receives:

  • A device-generated analytics identifier. After sign-in, it is associated with your Supabase user ID, not your email, username, or display name.
  • App version and platform, app opens, and screen views. Screen routes are reported as patterns, so title IDs, usernames, and other route values are not included.
  • Sign-up and sign-in method, profile and onboarding milestones, account role and age, and account deletion events.

Like any online service, our servers and service providers receive technical connection information such as an IP address and request metadata when a request is delivered. We do not use Mixpanel to derive location from your IP address.

What we do not collect

  • Your password in a form we can read. Supabase Auth handles password authentication and password storage.
  • Advertising identifiers. There is no advertising in the app.
  • Your precise location, contacts, camera, microphone, or photo library. A device time zone used for reminders is not precise location.
  • Your search queries in a form tied to your account. Search terms are cached globally to build the shared catalog and are not associated with your account.
  • The email, username, display name, search terms, title names, or title identifiers in product analytics events.

How we use your data

  • To create and secure your account, provide the app, sync your library, and preserve your settings.
  • To operate the community, sharing, import, recommendation, and notification features you use.
  • To understand app adoption and screen usage, diagnose product funnels, and improve the app when analytics is enabled.
  • To prevent abuse, enforce our rules, comply with law, and protect our users and services.

Usage analytics

In builds configured with Mixpanel, usage analytics is on by default. You can turn it off at any time using the switch above. Turning it off stops future analytics collection on that device and clears events waiting to be sent. Turning it on again starts with a new analytics identifier.

Turning analytics off does not automatically erase events Mixpanel already received. Contact privacy@emberfoldlabs.com if you want us to handle a request concerning previously collected analytics data.

Where your data goes

We use a small number of service providers for the purposes below:

  • Supabase — hosts our database and provides account authentication, including password storage and email delivery.
  • Mixpanel — receives the limited product analytics described above when analytics is enabled.
  • Expo, Apple, and Google — issue and deliver push notifications if you enable them. Notification delivery requires the relevant push token and message payload.
  • TMDB — supplies film and television data. Our server sends only the title, search term, or provider identifier needed for a catalog request; it does not send your identity or library.
  • JustWatch, through TMDB — supplies where-to-watch availability under the same arrangement.
  • Google — verifies your identity only if you choose to sign in with Google.

These providers may process data in countries other than the one where you live. We do not sell personal data or share it with advertisers or data brokers. We may disclose data when required by law or when reasonably necessary to protect users and the service.

What other people can see

Your display name, username, follower and following counts, and aggregate title and episode counts are public.

Your favourites, watchlist, ratings, and progress are visible to mutual follows by default. Your watch history is private by default. You can change these audiences under Settings, in Sharing.

Posts and replies are visible to the audience of the discussion room where you publish them. Recommendations and their notes are visible to the sender and recipient.

Data stored on your device

The app keeps some data on the handset itself:

  • Your sign-in session, so you are not asked to sign in every time.
  • Cached copies of your profile, watchlist, progress, and recent figures, so the app can open with no connection.
  • Episode marks waiting to be sent while you are offline.
  • Display, vibration, notification, and analytics preferences.
  • If you import a library, the system file picker may temporarily copy the ZIP into the app cache so it can be uploaded.

Account-scoped caches and queued offline actions are deleted when you sign out. Device preferences remain for the next session. The operating system may clear temporary cache files, and uninstalling the app removes its local data.

How long we keep it

Account data is kept while your account exists. Deleting your account removes the active authentication account and the account data in our database. Limited residual copies may remain temporarily in service-provider backups or logs until their normal rotation, or longer where retention is required for legal or security reasons.

An imported ZIP is read in memory by our server and is not saved as a server file. Review staging contains only the allowed library data described above. It is deleted when the import is applied or cancelled, or automatically after seven days if left unfinished. Basic import-job metadata remains with your account.

A push token is removed when you turn off push on that device, sign out, delete your account, or when the token has not been refreshed for 90 days. Analytics events already received by Mixpanel are kept according to our Mixpanel retention settings and are not automatically removed by the in-app account deletion flow.

Deleting your account

You can delete your account from inside the app under Settings, or from https://emberfoldlabs.com/emberslate/delete-account if you no longer have the app installed — that page confirms it is you by emailing your account a one-time code, then removes the account the same way Settings does. Either path removes your profile, library, progress, history, reactions, community activity, relationships, settings, imports, and push registrations from the active account database. It cannot be undone.

Neither path erases analytics events that Mixpanel already received. For anything the web page cannot resolve, or to request action on previously collected analytics, email privacy@emberfoldlabs.com from the address on the account.

Security

Traffic between the app and our production services is encrypted in transit. Access to account data is checked by the server against the signed-in session on each protected request; the app does not decide what it may read.

No system is perfectly secure, and we cannot guarantee absolute security. We limit what we collect and restrict data access to what is needed to operate the service.

Children

emberslate is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact privacy@emberfoldlabs.com and we will investigate and remove the data where required.

Your rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to the use of your personal data, and to complain to your local data protection authority. You can turn off analytics in the app and delete your account under Settings. For any other request, contact privacy@emberfoldlabs.com.

Changes to this policy

If this policy changes, the updated version will be posted here with a new date. Significant changes will be communicated in the app.

Questions about this policy or your data? Contact privacy@emberfoldlabs.com.