Legal
Privacy Policy
Last updated: 16 June 2026 · Effective: 16 June 2026
Embr is built to forget. This policy is the no-jargon version of what that actually means — what we collect, why, how long we keep it (spoiler: barely), and the controls you have. The plain-English boxes are summaries; the numbered sections are the real terms.
The short version
- We collect as little as is practical — a userid, an optional photo or email, and the technical bits a mobile app needs (device identifiers including Android ID and the advertising ID, network & crash data) to run, stay safe, and meet the rules.
- Messages are designed to disappear from view — most leave your chat seconds after they're read, the rest within 24 hours.
- We don't sell your personal data, and we don't use the private messages you send through Embr to build advertising profiles.
- We can't recover your password — not for you, not for anyone. That's deliberate.
- You can export or delete your data anytime. Links are at the bottom.
01Who we are
Embr is a product of Foxcyber Solutions Private Limited (“Foxcyber Solutions”, “we”, “us”), which operates the Embr mobile application and related services (the “Service”). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), Foxcyber Solutions Private Limited is the data controller / Data Fiduciary for personal data processed through the Service.
Operating entity: Foxcyber Solutions Private Limited, India. Questions: see Section 11.
02What we collect
You give us
- Your userid — the handle people find you by. Required.
- Your password — stored only as a one-way hash. We never see or keep the original, and we cannot recover it.
- Optional profile bits — a display photo and/or email address, only if you add them. You can use Embr with neither.
- Content you send — messages, statuses (“glimmers”), and posts in Circles. These are processed transiently to deliver them and then deleted (see Section 06).
We collect automatically
- Device & technical data — device manufacturer and model, OS version, app version, language, and timezone.
- Device identifiers — the Android device identifier (Android ID / SSAID) and the Android advertising identifier (AAID, also known as Google Advertising ID). We use these to authenticate your install, detect duplicate or abusive accounts, prevent fraud and ban evasion, attribute installs, and run analytics. We currently do not use the AAID to deliver targeted ads inside Embr and we do not share the AAID with third-party advertising networks. If we later use the AAID for advertising or attribution purposes beyond what's described here, we will update this policy and (where the law requires) seek your consent. You can reset the AAID at any time from Android Settings → Privacy → Ads, and apps targeting Android 13+ require the com.google.android.gms.permission.AD_ID permission, which our app declares for these purposes.
- Network & connection data — IP address (used to derive coarse region — country / state level — and to detect abuse), connection type, and server-side request logs.
- Push-notification tokens — Firebase Cloud Messaging (FCM) tokens so we can deliver chat and Orbit notifications to your device.
- When we collect it — the identifiers, technical data, and FCM push token above are captured on every cold start of the app, including before you create an account. This lets us count installs, attribute referrals, prevent abusive re-installs, and — once you sign up — deliver notifications without a separate registration step. Nothing collected before signup is used for advertising, sold, or shared with third-party marketing partners. If you install the app and never create an account, the install record persists only for the operational and safety purposes described in Section 06 and can be deleted on request via the Delete my data flow.
- Usage & diagnostics — feature interactions, crash logs, and performance data to keep the Service running and safe.
- Safety signals — limited metadata used to detect spam, abuse, ban evasion, and underage use.
What we don't collect: your phone number, your real or legal name, your contacts list, or precise GPS location. People can only find you by your exact userid.
03How we use your data
- To create and run your account and deliver your messages.
- To operate features — Orbit matching, Open Circles, whisper statuses, and read signals.
- To keep people safe: preventing fraud, spam, harassment, and underage access.
- To fix bugs, measure performance, and improve the Service.
- To comply with the law and enforce our Terms.
We do not use the private messages you send through Embr to build advertising profiles, and we do not sell personal data. Embr is currently ad-free; if we ever introduce advertising inside the app, we will update this policy and notify users beforehand. Any advertising would, at minimum, exclude content from private messages, and we would not "share" personal data for cross-context behavioural advertising as defined under California law without the choices the law requires.
04Legal bases (GDPR / DPDP)
- Performance of a contract — to provide the Service you signed up for.
- Consent — for optional data (photo, email) and any optional features; you can withdraw it anytime.
- Legitimate interests — for security, abuse prevention, and core analytics, balanced against your rights.
- Legal obligation — where we must process data to comply with applicable law.
Under the DPDP Act, we process personal data on the basis of your consent or for legitimate uses permitted by the Act.
05Who we share with
We share personal data only with:
- Service providers (processors) — cloud hosting, crash analytics, push-notification, and infrastructure vendors who process data on our instructions under written contract.
- Law enforcement, courts & regulators — we may disclose information, including the contents of messages stored on our servers, where we receive a valid, binding legal request (such as a summons, court order, search warrant, or formal production demand under applicable law), or where we have a good-faith belief that disclosure is necessary to investigate or prevent serious harm, abuse of children, fraud, terrorism, threats to life, or other illegal activity, or to enforce our Terms. We respond to lawful requests in the manner and within the timelines required by applicable law.
- Corporate events — a successor entity in a merger, acquisition, or restructuring, subject to this policy.
We do not sell your personal data.
06How long we keep it
Embr's app is designed so content fades from view, but for the Service to work — and for us to keep people safe and meet our legal obligations — content and metadata are processed and stored on our servers for as long as needed for those purposes:
- Messages — message content sent through Embr is stored on our servers (encrypted at rest) and is designed to fade from view in the app after delivery and reading. Stored copies may be retained for limited operational, safety, and legal-compliance purposes. We may preserve specific records when required by a binding legal request or when we reasonably believe preservation is necessary to investigate or prevent serious harm, abuse, fraud, or violation of our Terms. You should not treat Embr as a private vault — assume that anything you send may be preserved or disclosed as described in this policy.
- Statuses & Circle posts — disappear from view within 24 hours; underlying records may be retained for a short additional period for safety, abuse-investigation, and legal purposes.
- Account data (userid, optional email/photo) — kept while your account is active, and erased after deletion (see Delete account), subject to records we are required to keep.
- Safety, abuse & legal logs — limited records (including device identifiers, IP, and metadata around reported incidents) may be kept for the period required to investigate violations, respond to legal requests, prevent harm, or comply with applicable law.
07How we protect it
Your data is encrypted in transit (TLS) and encrypted at rest on our servers. We minimise what we collect, make content disappear from view quickly by design, and restrict internal access to authorised personnel on a need-to-know basis.
To deliver your messages, power features like Orbit and Circles, and run safety checks, content is briefly processed on Embr's servers before it is delivered and deleted — so messages are not end-to-end encrypted. In that short window we may access content only where strictly necessary, such as to comply with a binding legal order or to investigate serious abuse. Because we keep so little for so short a time, there is very little to expose. No method of transmission or storage is ever 100% secure, and we cannot guarantee absolute security.
Your key is yours alone. Your password is stored only as a salted hash. We cannot read it, reset it, or recover it. If you lose it, your account cannot be restored — so save it somewhere safe.
08Your rights & choices
Depending on where you live (EU/UK GDPR, India DPDP Act, California CCPA/CPRA, and similar laws), you have some or all of these rights:
AccessGet a copy of the personal data we hold about you.
CorrectionFix data that's wrong or incomplete.
ErasureAsk us to delete your account and data.
PortabilityReceive your data in a portable format.
Object / RestrictObject to or limit certain processing.
Withdraw consentPull consent for optional data at any time.
Nominate (DPDP)Nominate someone to exercise your rights if you can't.
Non-discriminationWe won't penalise you for using your rights.
Use the Delete account or Delete / export my data pages, or email us (Section 11). We respond within the timeframes required by law. You also have the right to complain to your local data protection authority or, in India, to the Data Protection Board.
09Age requirements
Embr is not for children. You must be at least 16 years old (or the minimum digital-consent age in your country) to use Embr, and at least 18 to use Orbit's stranger-matching features. Where required by the DPDP Act, we obtain verifiable parental consent before processing the data of a child, and we do not knowingly profile or serve targeted content to children. If we learn an account belongs to someone underage, we remove it.
10International transfers
We may process and store data in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards — such as Standard Contractual Clauses or equivalent mechanisms — to protect it consistent with this policy and applicable law.
For privacy questions or to exercise your rights:
- Operating entity: Foxcyber Solutions Private Limited, India
- Email: info@foxcybersolutions.co.in
- Grievance Officer (India / DPDP Act): info@foxcybersolutions.co.in
- Data Protection Officer (EU/UK): info@foxcybersolutions.co.in
We acknowledge grievances promptly and resolve them within the period required by applicable law (for the DPDP Act, ordinarily within the prescribed timeframe).
12Changes to this policy
We'll update this page when things change and revise the “last updated” date. For material changes, we'll give notice in the app. Continuing to use Embr after changes take effect means you accept the updated policy.
This Privacy Policy is published by Foxcyber Solutions Private Limited and applies to the Embr Service. Foxcyber Solutions may update this page; the current version is the one that applies.