Privacy Policy

embden, operated by Introvert Labs LLC · Effective October 6, 2026

This policy explains what information embden ("the app," "we") collects when you use it, why, and what control you have over it. It covers the app as it actually works today.

Information we collect

How we use it

We do not sell your personal information, and we do not use your location or reports for advertising.

Third-party services we rely on

These providers process a limited slice of data strictly to do their specific job. We don't hand any of them your full account record:

Your choices and rights

If you're in the European Economic Area or United Kingdom

The app doesn't specifically market to or target EEA/UK residents, but it's reachable from anywhere, so this section applies if you use it from there.

If you're a California resident (CCPA/CPRA)

Data retention

We keep account data for as long as your account is active. Community content (reports, takes, votes, confirmations) is retained to keep venue history accurate. When you delete your account, your crowd reports and takes are kept but anonymized rather than tied to you, and your votes and confirmations are deleted with it.

Children's privacy

embden is not directed at anyone under 16, and we do not knowingly collect personal information from them. Creating an account requires a date of birth, and registration is refused for anyone under 16. If we learn that we have collected personal information from someone under 16, including through an account created with a false date of birth, we delete that account and its personal information. This includes our obligations under the U.S. Children's Online Privacy Protection Act (COPPA) with respect to children under 13. If you believe someone under 16 has created an account, contact us at support@embdenapp.com and we'll remove it.

Security

Passwords are salted and hashed, never stored in plain text. Password logins require a one-time emailed code in addition to your password. We use industry-standard encryption in transit (HTTPS) for all requests.

If a security incident results in unauthorized access to personal information, we will notify the relevant data protection authorities within the timeframe the applicable law requires (for example, within 72 hours under the EU and UK GDPR where the incident is likely to result in a risk to individuals), and we will notify affected users without undue delay where the law requires it or where we judge the risk warrants it, using the email address on the account.

Changes to this policy

If this policy changes in a meaningful way, we'll update the effective date above.

Contact us

Questions about this policy or your data? Reach us at support@embdenapp.com.