Draft — not yet in force. This page is a structural placeholder. It has not been reviewed by counsel and must not be relied on. Remove this notice in the same change that lands the final text.

Privacy Policy

Last updated: Draft · Digital Estate Media

How Emberquill collects, uses, discloses and protects personal information. Being drafted with counsel against PIPEDA (Canada) and the GDPR; the sections below list what each must cover.

1. What we collect

  • Account data: name, email, organization, role, authentication method (including Google SSO).
  • Billing data: handled by Stripe. Card numbers never reach our servers — say so plainly.
  • Connected-service data pulled on the customer's instruction: Google Search Console queries and pages, GA4 metrics, WordPress content, Ahrefs metrics.
  • Product telemetry: agent runs, credit ledger entries, funnel events, error logs.

2. AI subprocessors — disclose by name

  • Content is sent to third-party model providers to generate drafts, reviews and analyses. Name them: OpenRouter (and the models routed through it), and Google (Gemini).
  • State what is sent: page content, keywords, and configuration — not billing details, not credentials.
  • State that customer content is not used to train these providers' models, and link each provider's own terms.
  • This section is the one most likely to be read by an agency's client. It should be specific rather than generic.

3. Other processors

  • Supabase (database and authentication), Railway (hosting), Stripe (payments), Resend (transactional email), and the analytics stack once configured.
  • Where each stores data, and the transfer basis for any outside Canada/the EEA.

4. Cookies and analytics

  • The consent banner already ships on the marketing site and gates GTM/GA4 — this section is what it links to, so it must actually describe those cookies.
  • Strictly-necessary vs analytics cookies, and how to withdraw consent after granting it.

5. How we use it, and legal basis

  • Providing the service, billing, support, security, and product improvement.
  • Lifecycle and transactional email, and how marketing email consent is handled separately (CASL express vs implied consent).
  • The GDPR legal basis for each purpose.

6. Retention and deletion

  • How long each category is kept, and what happens after account closure.
  • Note the credit ledger is append-only by design — corrections are new entries, rows are never edited or deleted — and explain how that interacts with a deletion request.

7. Your rights

  • Access, correction, deletion, portability, and objection; the GDPR and PIPEDA equivalents.
  • How to exercise them and the response window.
  • Complaint route: the Office of the Privacy Commissioner of Canada, and the relevant EU supervisory authority.

8. Security

  • Encryption in transit and at rest; credentials encrypted at the application layer.
  • Access controls: per-project roles and section-level permissions.
  • Breach notification commitment.
  • Claim only what is actually operated — no certifications the business does not hold.

9. Contact

  • The privacy contact address and the legal entity's mailing address — the mailing address is also required in the footer of every commercial email under CAN-SPAM.

Questions about this page? support@emberquill.ai