room is operated by Ember Sovereignty. This notice says what we collect, why, who can read it, and how to reach us. Last updated 13 September 2026.
Account. Your work email address, a display name, and the company you register or join. We verify email ownership with a sign-in link. We do not store passwords.
Content you contribute. Files and text you upload, selected records you import from connected tools, your needs and offers, generated briefs and claims, introduction decisions, and shared chat messages. We also retain content and records for existing Room workflows. Content is associated with its owning account and the permissions recorded for its use.
Records. Who approved what and when, provider calls, and disclosure and delivery events. Records are how the product works; they are retained with the Room.
Technical data. Server logs with IP addresses and request metadata, kept for security and operations.
Selected evidence is used to prepare briefs when you allow processing. Activating a brief permits the matching service to compare its approved private context with other participating companies’ approved briefs. Counterparties receive only authorized representations before acceptance; identities and a shared chat are released after both sides accept. Existing Room workflows retain their recorded permissions. We do not sell content or use it to train models.
Model providers. The processing permission names the provider and purpose. Brief generation sends selected evidence and your direction; matching uses approved private briefs; a separate review checks proposed outward content. Existing Room prompts use their declared provider and approved inputs. An external provider reads whatever is sent to it and processes it under its own terms.
Hosted execution. Ordinary Runs execute on infrastructure we operate. We do not claim operator blindness for those Runs: the service operator can technically read data processed there. Each record states the execution venue.
Connected tools. You authorize a provider connection, then a specific import scope. Some provider permissions cover more than the selection room imports; the selection screen explains this. Credentials are encrypted in the connector vault and are not included in evidence or model prompts. Google Drive’s file picker receives a short-lived access token in your browser. Optional human review of claims content requires its separate processing permission.
Email. We send sign-in links and short notices about requests, reviews, and answers waiting for you. Notices contain links, not content.
We use hosting, email delivery, and model providers as processors. Each receives only what its function needs. We disclose data when the law requires it. We do not share it with advertisers.
Account data is kept while your account is active. Disconnecting a source removes its saved credential and stops future acquisition and pending claims work that depends on it. It does not delete imported snapshots, established chats or recorded disclosures. Pausing processing stops new brief processing and discovery. Changed evidence requires fresh processing approval. Provider-side access withdrawal is detected on a subsequent API call, rather than immediately. To close your account or request deletion of saved content, contact us; we confirm what was removed and what records remain.
You can access, correct, export, or ask us to delete your personal data. Write to us through the contact form. Depending on where you live you may have additional rights under local law; we honor them.
Changes to this notice are posted here with a new date.