Privacy Policy

Privacy Policy

Embage is currently in private beta. This policy explains how we handle information submitted through the marketing website and early access forms.

1. Introduction and Scope

Welcome to Embage. This Privacy Policy describes how Embage, Inc. ('Embage', 'we', 'us', or 'our') collects, uses, discloses, and protects your information when you visit our website (https://embage.com), sign up for our private beta, request early access, or use our secure, AI-powered voice and chat receptionist platform. We are committed to protecting your personal data and ensuring enterprise-grade security.

2. Information We Collect

We collect information you provide directly to us, including your name, work email address, company name, contact messages, and early access form submissions. For registered accounts on our platform, we collect authentication credentials (managed via Better Auth) and billing configurations (processed securely through Dodo Payments). Embage also collects customer-provided business data uploaded to initialize your AI agents, including knowledge base files (PDFs, text, web pages) and structured datastore record configurations (leads, feedback logs, ticket schemas).

3. How We Use Your Information

We use the collected data to run, support, and improve the Embage platform, respond to early access requests, initialize, train, and ground AI voice and chat agents based on your uploaded business datasets, process transactions via Dodo Payments, and debug system metrics. We analyze telemetry and product usage parameters (via PostHog) to optimize latency, resolve bugs, and occasionally communicate platform announcements, system upgrades, or beta milestones.

4. Subprocessors and Data Sharing

Embage does not sell your contact information or agent training data to third parties. We share data only with trusted subprocessors necessary to deliver our services: Cloudflare (hosting, Workers infrastructure, and CDN), Turso (tenant database hosting), Better Auth (authentication services), Dodo Payments (merchant of record, subscription billing, and payment processing), Google Gemini / Vercel AI SDK (LLM model inference), and PostHog (telemetry). All data shared with model inference APIs is governed by strict privacy agreements preventing models from training on customer data.

5. Tenant Isolation and Security

Embage is designed with a security-first architecture. We enforce strict database-per-tenant isolation to ensure that customer data, integrations, configurations, and records are segregated at the database level and never mixed or leaked between organizations. Sensitive credentials, third-party integration tokens, and API keys are encrypted at rest using industry-standard AES-256 encryption. All communication between the client, backend workers, and LLMs is encrypted in transit via TLS.

6. Cookies and Tracking Technologies

We use cookies, local storage, and similar technologies (such as ModeWatcher for persisting layout theme states) to preserve user sessions, secure platform operations, and remember workspace selections. You can adjust your browser cookie settings at any time, though disabling essential session cookies may limit platform functionality.

7. GDPR, CCPA, and User Rights

Depending on your location (including the EEA and California), you possess key rights under the GDPR and CCPA. These include the right to access the personal data we store, request rectification of inaccurate records, request deletion of your information, restrict or object to certain processing, and export a portable copy of your account data. To request data updates, deletions, or export copies, please contact our support email.

8. Changes to this Policy

We may update this Privacy Policy periodically to reflect additions to our features, changes in our subprocessor list, or updates to global data protection laws. We will publish changes on this page and notify active users of significant policy updates.