Privacy Policy
embden, operated by Introvert Labs LLC · Effective October 6, 2026
This policy explains what information embden ("the app," "we") collects when you use it, why, and what control you have over it. It covers the app as it actually works today.
Information we collect
- Account information. A username and an email address. If you sign up with a password, we store a salted hash of it, never the password itself. Every password login sends a one-time code to that email, which also confirms the address is real and reachable. If you use "Sign in with Google" or "Sign in with Apple," that provider shares your name and (if you allow it) your email. We never see your Google or Apple password.
- Date of birth. Collected once at registration solely to verify you're at least 16 (see Children's privacy below). It's never shown publicly and never used for advertising.
- Messages to businesses. If you write to a business through its page, the message, the business's replies and the time they were sent are stored so both of you can read the conversation later. The business's team sees your username and your messages, and nothing else about you. Messages you report are held for our review; we never share them with anyone but the business you wrote to. They go when your account does.
- Flight numbers you follow. If you ask to be told when a flight lands, we store that flight number, its date and your device's notification address until a few days after the flight, and check the flight's status with our flight-data provider on your behalf. We don't store the airport or your booking.
- Calendar, on your device only. On an airport page, and only if you allow it, the app looks through the calendar events around the current day for something that looks like a flight number so it can offer it to you. That search happens entirely on your phone; no calendar event, title, or attendee ever leaves the device or reaches our servers.
- Location. If you allow it, your device's GPS coordinates, used to find nearby venues, show local weather, and confirm you were actually near a place before counting a crowd report from you. Location is never stored as a standing history of everywhere you've been: nearby search and weather use your coordinates live and don't keep them. One exception is a crowd report: the coordinates you reported from are saved with that report as an anti-fraud measure, kept for up to 90 days, then deleted automatically (and deleted immediately if you delete your account). If you place yourself in a Meet up room, the point you place is rounded to roughly a city block (~110 m) before it is stored, is never shown to the other people in the room as a location, and is deleted automatically within about half a day of the room ending. If you start or join a shared plan in Plan your night with your location on, where you are is rounded to roughly a city block (~110 m) before it is stored, is used only for that plan, is never shown to the other people in it as a location, and is deleted as soon as you leave the plan, or automatically within about half a day of the plan ending, the day after the night it's for. If you tap "Spotted" on a food truck, where you tapped is rounded to roughly a city block (~110 m) and kept with that sighting, to show roughly where the truck has been; nobody else is shown who spotted it, and each sighting is deleted automatically after 30 days (and immediately if you delete your account). If you add your own food truck, we also note that you added it, until the truck has been somewhere real, so that your own taps never put it on the map from where you are. If you tap "It's gone" on a food truck, that is kept with your account only while it can count toward the truck being marked gone, and is deleted automatically within about half a day. The app also records how long a visit to a venue lasted, with no account attached to it, as a second anti-fraud signal. Those records name a venue and a duration, never a person.
- Community content. Crowd reports, votes, "confirmed accurate" taps, and written feedback you submit about a venue, tied to your account. Your username is shown beside the reports and takes you post, on that place's page, where anyone using the app can see them. You can turn that off in Settings with "Show my username on my reports." Your reports and takes then show "Someone here" instead of your name, including ones you've already posted. We can still see who posted them, so we can act on a report of abuse.
- Business information. If you claim or manage a business listing: your name, email, phone number, and any contact/hours/social-link/logo details you provide for that venue. Photos you upload for a business (a logo, a cover, gallery and product photos, or a permit photo with a claim) are stored without the location and camera details a phone writes into a photo. If you apply to list a small business, we also collect the address you trade from, including a home address if that's where you work. A home address is used only to place you in the right area; it is never shown on the public listing, and the coordinates are never sent to anyone else's device.
- Contact details on an order or enquiry. If you send an order request or enquiry to a business through embden, the name, email, and phone number you put on that form, so the business can reply. Nothing is charged through embden, and no payment details are collected.
- Payment information. If a business purchases Premium through the iPhone app, billing is handled entirely by Apple. We receive a signed transaction receipt to confirm the purchase, verified through Apple's own servers, and never see your card number. If a business purchases Premium another way, billing is handled entirely by Stripe on the same terms. We store only the resulting subscription status and Stripe's own reference IDs, never your card number.
- Push notification subscriptions. If you enable alerts for a venue, the subscription needed to deliver them: on the phone app, a push token issued by Apple through Expo; on the web, your browser's push endpoint and encryption keys.
- A device identifier. The app generates a random ID for your installation, used to attach your alert subscriptions to this device and to switch them off when you turn notifications off. It isn't Apple's advertising identifier, it isn't shared with anyone, and it goes when your account does.
- Basic device/session data. Standard web request data (IP address, browser type) that any server sees, and an authentication token stored on your device so you stay logged in.
How we use it
- To show crowd estimates, hours, and other venue information.
- To verify you're a real, nearby person before a crowd report counts, as a basic anti-abuse measure.
- To send account-related email (one-time login codes, password reset) and, if you opt in, venue alerts.
- To keep a record of what you've contributed, shown back to you on your own profile.
- To deliver your messages to the business you wrote to, and theirs back to you, and to send a notification when one arrives unless you've muted that conversation.
- To notify you about a flight you follow: when it lands, when its gate changes, and when it's running late.
- To operate the owners' desk for claimed venues, and to process Premium payments.
We do not sell your personal information, and we do not use your location or reports for advertising.
Third-party services we rely on
These providers process a limited slice of data strictly to do their specific job. We don't hand any of them your full account record:
- Google: Sign in with Google, and the map on the owners' desk website. Venue search and venue details don't use Google.
- Expo: delivery of push notifications to the phone app.
- Geoapify: OpenStreetMap's data, for parking and dog parks near you, and for turning a place name you type into a location. It receives the location you searched from, or the text you typed.
- Amazon Location Service: opening hours for a place someone opens in the app, when we hold none of its own. It receives the place's name and location, and nothing about you. Where a place's page says "Hours from a business directory," those hours came from it (see its data attribution).
- AeroDataBox: the status, gate and baggage belt of a flight you follow or look up. It receives the flight number and date, and nothing about you.
- tsawaittimes.com: security-line waits at airports. We ask by airport, and nothing about you is sent.
- Eventbrite: if you run a business and connect its Eventbrite account, we read that account's upcoming events to list them on your venue's page, and keep an encrypted access token to do it.
- Render: hosting for the service and its database.
- Sentry: crash and error diagnostics, when enabled.
- Twilio: the verification text sent to a business's own listed phone number, if you choose that way of proving you run the business.
- Apple WeatherKit: weather, when enabled, as an alternative to Visual Crossing.
- Apple: Sign in with Apple, an alternative to a password or Google for creating and logging in to your account; and, for a Premium purchase made on iPhone, processing that purchase and its receipt through the App Store.
- Visual Crossing: current and forecast weather for your searched location.
- SeatGeek: event listings for ticketed venues, when enabled (most event data is entered directly by us from official sources).
- BestTime.app: historical/live occupancy modeling for venues.
- Stripe: payment processing for a business Premium subscription purchased outside the iPhone app.
- Resend: delivery of account emails (login codes, password reset).
- SpotHero: if you tap through to reserve parking, that reservation happens on SpotHero's own site, under their own privacy policy.
Your choices and rights
- Location is opt-in and can be turned off in your device/browser settings at any time.
- Download your data. From Settings, you can export a full copy of your account, reports, votes, confirmations, recognition, saved places, step-free answers, alerts, followed flights, takes, saved events, passes, offers you saved or claimed, orders you placed, your conversations with businesses, the food trucks you spotted, said were gone or added, and any venues you manage.
- Delete your account. Also from Settings. This removes your account and personal identifiers, your messages, and any flights you follow. Your past crowd reports and takes are anonymized rather than deleted outright, so the historical data other users rely on doesn't just vanish, but they're no longer linked to you. Orders you placed stay with the business, with your name, email, and phone taken off. If you no longer have the app, see how to ask us to delete your account.
If you're in the European Economic Area or United Kingdom
The app doesn't specifically market to or target EEA/UK residents, but it's reachable from anywhere, so this section applies if you use it from there.
- Legal basis for processing. We process account information and community content because it's necessary to provide the app to you (contract). We process location and push-notification data because you affirmatively opt in each time (consent), and both can be withdrawn at any time by turning them off. We process basic device/request data and use rate-limiting/anti-abuse checks based on our legitimate interest in keeping the service secure and honest, weighed against your privacy. Where a court order or legal process requires it, we process data to comply with a legal obligation.
- No non-essential cookies or ad trackers. The app doesn't set advertising or analytics cookies today; the only client-side storage is the login token needed to keep you logged in, which is strictly necessary and doesn't require separate cookie consent under ePrivacy rules. If that changes, we'll update this section and add a consent mechanism first.
- International transfers. Our infrastructure runs in the United States, so using the app from the EEA/UK means your information is transferred to and processed in the US, a country the European Commission has not found to provide "adequate" protection under EU law. We rely on our processors' own compliance mechanisms (such as Standard Contractual Clauses) where applicable, and are reviewing this further as our EEA/UK usage grows.
- Article 27 representative. We haven't designated an EU or UK representative. We believe our processing of EEA/UK residents' data is currently occasional and unlikely to result in a risk to individuals' rights, which GDPR Art. 27(2)(a) exempts from that requirement. We're confirming this assessment with counsel as usage grows, rather than treating it as settled.
- Your GDPR rights (access, correction, erasure, restriction, portability, and objection) are all already available through Settings (export/delete) or by emailing us; we'll extend these formally as needed once the assessment above is complete.
If you're a California resident (CCPA/CPRA)
- We do not sell or share your personal information, as "sell" and "share" are defined under the CCPA/CPRA (no exchange of personal information for money, and no disclosure for cross-context behavioral advertising). There's no opt-out link to provide, because there's nothing to opt out of today.
- Right to know/access what we collect: see "Information we collect" above, or request a copy via Settings' data export or by emailing us.
- Right to delete: via Settings, or by emailing us.
- Right to correct inaccurate information: email us and we'll update it.
- Right to limit use of sensitive personal information: precise geolocation is the one "sensitive" category (per CPRA) we collect; we use it only for the purpose you provided it for (live for search and weather, with a crowd report's coordinates kept up to 90 days for fraud prevention; see above), and never sell, share, or use it to infer characteristics about you.
- Non-discrimination. We won't deny you service, charge a different price, or provide a different level of service for exercising any of these rights.
- To exercise any of these, email support@embdenapp.com from the address on your account (or have an authorized agent contact us). We'll verify the request and respond within the time CCPA/CPRA requires.
Data retention
We keep account data for as long as your account is active. Community content (reports, takes, votes, confirmations) is retained to keep venue history accurate. When you delete your account, your crowd reports and takes are kept but anonymized rather than tied to you, and your votes and confirmations are deleted with it.
Children's privacy
embden is not directed at anyone under 16, and we do not knowingly collect personal information from them. Creating an account requires a date of birth, and registration is refused for anyone under 16. If we learn that we have collected personal information from someone under 16, including through an account created with a false date of birth, we delete that account and its personal information. This includes our obligations under the U.S. Children's Online Privacy Protection Act (COPPA) with respect to children under 13. If you believe someone under 16 has created an account, contact us at support@embdenapp.com and we'll remove it.
Security
Passwords are salted and hashed, never stored in plain text. Password logins require a one-time emailed code in addition to your password. We use industry-standard encryption in transit (HTTPS) for all requests.
If a security incident results in unauthorized access to personal information, we will notify the relevant data protection authorities within the timeframe the applicable law requires (for example, within 72 hours under the EU and UK GDPR where the incident is likely to result in a risk to individuals), and we will notify affected users without undue delay where the law requires it or where we judge the risk warrants it, using the email address on the account.
Changes to this policy
If this policy changes in a meaningful way, we'll update the effective date above.
Contact us
Questions about this policy or your data? Reach us at support@embdenapp.com.