1. Who is responsible
Embla is provided by embla.ai AB, Swedish organisation number 559499-7560, Friggavägen 2, 182 63 Djursholm, Sweden. Contact us at hello@embla.ai.
embla.ai AB is the controller of the personal information described here. This policy covers our website and mobile apps, including private practice features and public meditation sharing. It does not replace the privacy notices of services you choose to visit through external links.
2. Information we process
- Account and purchases: sign-in identifiers, contact and Profile details, plan, credit balance and subscription events. Payment providers handle payment details; do not put them in chat.
- Your practice: conversations and transcripts, chosen teacher and language, duration and soundscape, optional distress and energy check-ins, generated scripts and audio, playback activity, favourites, Journal reflections and saved Memory.
- Voice: when you start the microphone, we receive and store your recording to transcribe it. Stopping capture does not automatically send the resulting text as a chat message. A recording may remain saved even if transcription fails.
- Sharing: public recordings, titles and practice metadata, your displayed Profile name when available, and Feed likes.
- Devices and support: request and security logs, device/browser information, support correspondence, and notification subscription details, timezone and chosen reminder days if you enable reminders.
- Usage analytics: interaction events, campaign attribution and masked session replay used to understand navigation and reliability. In the current preview, analytics is enabled by default and the “I got it” notice acknowledges this. You can turn analytics off in Settings. Account identifiers can link analytics to a signed-in account.
What you choose to say can reveal sensitive information, including health or beliefs. Share only what is useful for your practice; avoid detailed medical histories or information about other people. Text remains available if you do not allow microphone access, and check-ins and reminders are optional.
3. Why we use information
We use information to authenticate you, provide the conversation and meditation you request, save your library and reflections, show sourced Insights, maintain your chosen defaults, provide optional Memory, deliver reminders, manage payments and credits, support you, and protect the service from misuse. Restricted, authorised staff may inspect relevant records for support, safety and reliability; privileged access to private records is logged. We use aggregate practice counts to understand service usage. We do not sell your personal information.
4. Legal bases and your choices
Under the GDPR, our ordinary service and account processing is based on performing our agreement with you; accounting and legally required disclosures are based on legal obligations; proportionate security, abuse prevention and reliability work relies on legitimate interests, balanced against your rights. You can turn analytics off in Settings without losing access to your account. The current preview uses an opt-out analytics setup: the “I got it” notice does not mean collection waited for your permission. Where applicable law requires prior consent for non-essential tracking, that requirement is not waived by this policy.
Sensitive information may require an additional legal condition, including explicit consent where applicable. Accepting terms or reading this policy is not, by itself, explicit consent to process health information. Contact us about sensitive-data processing or withdrawal of consent. We do not use your check-in to make a legal or similarly significant decision about you.
Practice selection uses your current conversation and, when provided, distress and energy to choose a constrained practice family. AI personalises within that family. Teacher, language, duration and soundscape affect presentation. You can skip an optional check-in or stop a practice.
5. Conversations, Memory and public sharing
Signed-in conversations are stored on our servers rather than as private text in browser storage. Completed safe conversations may contribute bounded saved Memory. Reflection-proposed Memory requires a confirm-or-dismiss choice. Memory is private, visible and deletable in Profile; it can help personalise a later relevant conversation or practice. Deleting a Memory item does not itself delete its original conversation or reflection.
Sharing makes a recording and its associated public details available to others. Turning off spoken-name use enables eligible new recordings to appear in Feed as described in Profile. Public audio can still contain personal context. Your private chat, check-in, Journal and Memory are not published with a share.
You can remove your own shares from Feed. Authorised administrators can remove public content for moderation. Account deletion removes Profile attribution but preserves active shared recordings. If retained audio identifies you, contact us to exercise your applicable rights; “shared” does not mean you lose those rights.
6. Providers and international transfers
We use service providers for authentication and subscriptions (Clerk), AI text and transcription processing (OpenAI), audio rendering and synthetic voice (including ElevenLabs through our audio worker), database and file storage (MongoDB and Google Cloud), hosting (Vercel), and optional product analytics (PostHog). They receive the information necessary for their role. The data needed for a generated voice recording can include the meditation script.
Providers and their subprocessors may process information outside your country, including outside the EEA. Where GDPR transfer rules apply, transfers require an appropriate mechanism, such as an adequacy decision or standard contractual clauses with any necessary supplementary protections. Contact us for details of the applicable arrangements and a copy of relevant safeguards. We may also disclose information when legally required, to protect rights or safety, or as part of a business transfer subject to applicable protections.
8. Retention and account deletion
We keep account and private practice records while needed to provide your account and the saved features you use, subject to deletion choices. Raw voice recordings have a scheduled expiry under the service’s configured retention period; the application default is 30 days. Deleting an account requests removal of private records and stored voice files, cancellation of the subscription and deletion of the authentication identity.
You can request account deletion at the bottom of Profile. Cleanup runs as a retryable process, so it is not necessarily immediate. Active public shares remain without account attribution as explained above. Records that must be retained for tax, accounting, legal claims or another legal obligation are retained only for that purpose and period. A hashed account marker is retained for 30 days to prevent stale requests from recreating a deleted account. Service-provider backups may take longer to expire; they must not be used to restore a deleted account into ordinary service.
Contact us for the retention period applicable to a particular record or for help removing information. We do not promise that a shared recording is anonymous merely because its Profile byline has been removed.
9. Your rights and how to contact us
Depending on applicable law, you may request access, correction, erasure, restriction, portability, or objection to processing based on legitimate interests. You may withdraw consent without affecting processing already lawfully undertaken. We may need proportionate verification to protect your account. Send requests to hello@embla.ai; please do not send identity documents unless we ask through a suitable process.
For GDPR requests, we normally respond within one month. If a lawful extension is needed, we will explain why within that period. You may complain to the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority. Additional rights available where you live remain unaffected. We do not discriminate against you for exercising them.
10. Adults, security and policy updates
Embla is for adults aged 18 or older. If you believe a child has supplied personal information, contact us so we can investigate and remove it as appropriate.
We use access controls and other technical and organisational measures to protect information. No service can guarantee absolute security. We will respond to incidents and notify affected people and authorities when legally required.
We will update this policy when practices change. Material changes will be brought to your attention, and we will seek a new choice where the law requires it. The date below identifies the current version.