Emra logo
Sign in
Legal

Privacy Policy

Effective Date: July 7, 2026

1. Introduction

This Privacy Policy explains how Emra Tech, Inc. ("Emra," "we," "us," or "our") handles information when you use the Emra website and web application at emra.app, our AI app builder, our collaborative workspace, and the backend-as-a-service that powers apps published on Emra (collectively, the "Services").

Emra is an AI app builder and collaborative workspace. A user describes an app in our web builder; an AI agent writes a real application, runs it in a sandbox, and publishes it as a hosted app. Apps published on Emra can use Emra's backend-as-a-service — sign-in/authentication, data collections, and file uploads — for those apps' own users. Emra is a web application hosted in the cloud; there is no Emra desktop application, and no software is installed on your device.

The data controller for personal data described in this policy (except data we process on behalf of Builders — see Section 4) is Emra Tech, Inc. You can reach us at support@emra.app.

This policy describes our practices; it is not a consent mechanism. Where applicable law requires your consent for a specific practice (for example, certain marketing or non-essential cookies), we will ask for it separately.

A. Who this policy applies to

Emra serves three groups of people, and this policy addresses each:

  • Builders — Emra's account holders, who use the builder to create and publish apps. Emra is the controller of Builder personal data.
  • Collaborators and workspace members — people who share a Builder's workspace. Emra is the controller of a member's own account data, and processes shared workspace content on behalf of the workspace that owns it. See Section 5.
  • End users of published apps — people who use an app a Builder published on Emra. For personal data a published app stores through Emra's backend, Emra acts as a data processor on the Builder's behalf as described in Section 4. Published apps do not currently offer their own end-user sign-up; until that capability launches, data a published app stores is treated as the Builder's own content, processed on the Builder's behalf.

2. Information We Collect

This section describes information Emra collects about Builders and workspace members. Personal data stored inside published apps is covered in Section 4.

A. Account and Personal Data

When you create an account or interact with us, we collect:

  • Email address and display name.
  • Authentication data. Sign-in is by email and password or by Google sign-in. Credentials are handled through our managed identity service (AWS Cognito); we do not store plaintext passwords. If you sign in with Google, we receive your name, email address, and a Google account identifier from Google, per your Google settings.
  • Account identifiers — internal account ID, workspace membership and role, and a customer reference with our payment processor if you purchase Paid Services.
  • Cookies and similar identifiers (see Section 8).

We do not collect a phone number.

B. Usage Data

We automatically collect data about how you access and use the Services ("Usage Data"), including:

  • Device and connection information: IP address, device type, operating system, browser type, and session identifiers.
  • Activity logs: pages and features visited, timestamps, system logs, error/crash reports, and performance metrics. Server-side errors are captured through our error-monitoring provider (Sentry), which may incidentally process request metadata.
  • Builder activity: actions taken in the builder, such as starting a build run, publishing, sharing, and cloning apps.
  • Site analytics: we use privacy-focused, cookieless web analytics (Vercel Web Analytics) that reports aggregated page and traffic statistics and does not track you across other websites.

C. Builder Content, AI Features, and Model Improvement

Emra's core function is to generate applications from your instructions. We collect and process the content you provide to and generate within the builder ("Builder Content"), which includes:

  • Prompts and instructions you give the AI agent describing the app you want.
  • Generated app code, configuration, and metadata the AI agent produces, and the published app bundle.
  • Files and assets you upload into the builder or attach to a build.
  • App and workspace metadata — app names, descriptions, sharing settings, and workspace member lists.

How AI providers are involved. Your prompts and app code are sent to third-party large-language-model providers (currently Anthropic and OpenAI — see Section 12) to generate your app. Under our agreements with these providers, they process this data to provide the service to us and do not use it to train their models.

How Emra uses content to improve the Services. We may use Customer Content — including Builder Content and, where a published app stores data through Emra's backend, that app's stored data and files — together with Usage Data, to provide, maintain, secure, and improve the Services, including to develop, evaluate, and improve our AI features, systems, and models, and to train them. Where feasible, we de-identify or aggregate content used for improvement.

Your opt-out. You can opt out of the use of your Customer Content (including your apps' backend contents) for AI model training by contacting support@emra.app from your account email. We will honor verified requests for future training runs within 30 days. Users in the EEA and UK also have a statutory right to object (Section 10).

If you are an end user of an app built on Emra, the Builder who operates that app is responsible for telling you how the app's data is used, including the use described here (Section 4). You can also contact support@emra.app and we will refer your request to the Builder.

D. Payment Information

When you sign up for any Paid Services, our third-party payment processor, Stripe, Inc. ("Stripe"), collects and processes your payment information — such as name, email, billing address, and card details. Emra does not store full card numbers; we retain a Stripe customer reference, your subscription state, and transaction history. Stripe's privacy policy is available here.

E. Communications and Other Information You Provide

We collect information you provide directly, such as support requests, survey responses, and feedback. We send transactional and account email through Amazon SES (see Section 12).

3. How We Use Data and Our Lawful Bases

We use data to operate, maintain, secure, and improve Emra. Where the GDPR or UK GDPR applies, our lawful basis for each purpose is listed alongside it:

  • Service delivery — account management, running build jobs, generating and publishing apps, serving published apps, and operating the backend-as-a-service. Basis: performance of a contract.
  • Collaboration — workspace membership, app share links, and cloning. Basis: performance of a contract.
  • Payments and billing — subscriptions, credits, invoicing, and tax. Basis: performance of a contract; legal obligation.
  • Transactional communication — security alerts, service and account email, and support responses. Basis: performance of a contract.
  • Service improvement and analytics — aggregated, privacy-focused site analytics, diagnostics, and performance work. Basis: legitimate interests.
  • AI feature and model improvement — as described in Section 2.C, subject to your opt-out. Basis: legitimate interests, subject to your right to object.
  • Security and abuse prevention — fraud detection, enforcing our Terms and Acceptable Use Policy, and protecting users and infrastructure. Basis: legitimate interests; legal obligation.
  • Marketing — product news and promotions; opt out any time via the unsubscribe link or support@emra.app. Basis: consent where required by law; otherwise legitimate interests with opt-out.
  • Compliance — meeting legal and regulatory obligations. Basis: legal obligation.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you.

4. Data Emra Processes on a Builder's Behalf

Apps published on Emra can use Emra's backend-as-a-service to store data and files. For personal data a published app stores through this backend, the Builder who operates the app is the controller of that data. This means:

  • Builders are responsible for the lawfulness of the data their published apps collect and store, including having any required notice, lawful basis, or consent.
  • Emra processes this data to provide the backend-as-a-service, in line with the Builder's instructions, our agreement with the Builder, and our Data Processing Addendum (DPA). As disclosed in Section 2.C, we may also use it to improve the Services — including AI model training — unless the Builder opts out; for that use, Emra acts as a controller rather than a processor.
  • Requests to access, correct, or delete personal data inside a published app are the Builder's responsibility as controller. If you contact Emra about such data, we will refer you to the relevant Builder and may assist that Builder in responding.

Our DPA, including our sub-processor list, is available on request at support@emra.app.

5. Collaboration and Sharing

Emra is a collaborative workspace. When you work in a shared workspace or share an app, some of your data becomes visible to others.

A. What others can see

  • Workspace members can view and work on the apps, prompts, generated code, files, and app metadata in the shared workspace, according to their workspace role (owner, admin, or member).
  • Recipients of an app share link can view and clone the shared app — cloning gives them a copy of the app's code and configuration in their own account. Treat a share link like handing someone the app: anyone with the link can use it while it remains valid.

B. Code vs. data — the sharing boundary

Emra's sharing model separates which app's code runs from whose data the app reads and writes. Sharing or cloning an app lets someone run or copy your app's code without giving them access to your app's stored data — a cloned app operates on the recipient's own data going forward. Review your sharing settings before sharing so you understand exactly what a recipient can see.

6. Retention of Data

We keep personal data only as long as necessary to provide the Services, comply with legal obligations, and resolve disputes.

  • Account data: retained for the life of your account, then deleted or de-identified within a reasonable period after account deletion.
  • Builder Content (prompts, generated code, published apps, uploaded files): retained while your account is active; on cancellation or non-payment, handled per the freeze-and- deletion process below.
  • Published-app data: retained on behalf of, and per the instructions of, the Builder who controls it (Section 4).
  • Usage Data and logs: generally retained for 12 months or less, then deleted or aggregated.
  • Billing records: retained as required by tax and accounting law (generally up to 7 years).
  • Backups: deleted content may persist in encrypted backups for a limited period before being purged on rotation.

Freeze and deletion on cancellation or non-payment

If your subscription is cancelled, lapses, or you stop paying, we freeze your workspace: it becomes read-only and new builds and runs are paused. During the freeze, you may still export your Customer Content (using tools we make available or by requesting an export at support@emra.app). We retain your Customer Content for a limited wind-down period after the freeze begins, and will attempt to notify you at your registered email before it becomes eligible for permanent deletion. We do not store content indefinitely, and we reserve the right to freeze, suspend, or delete accounts and content where we detect repeated non-payment, chargeback abuse, or attempts to circumvent storage, usage, or billing limits — for example, repeatedly cycling between paid and unpaid status to obtain storage or Services without paying for them.

7. International Transfers of Data

Emra is based in the United States, and information is processed and stored on servers in the United States and by our service providers (see Section 12). If you are located outside the United States, your data will be transferred to and processed in the U.S. and other countries where data-protection laws may differ from those in your jurisdiction. Where transfers of EEA, UK, or Swiss personal data require safeguards, we rely on the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum and Swiss adaptations.

8. Cookies, Analytics, and Consent

We keep tracking minimal:

  • Essential cookies only. We use cookies and similar storage to keep you signed in, to secure sign-in flows (for example, OAuth state for Google sign-in), and to remember interface preferences. The Services do not function without these.
  • Cookieless analytics. Our site analytics (Vercel Web Analytics) does not use cookies and does not track you across other websites; it gives us aggregated statistics about page visits and performance.
  • No advertising trackers. We do not run third-party advertising cookies or cross-site behavioral tracking, and we do not sell personal data.

Because we currently use only essential cookies and cookieless, non-advertising analytics, we do not show a cookie-consent banner. If we introduce non-essential cookies or trackers in the future, we will obtain any consent required by applicable law before they are set, and will update this policy. You can instruct your browser to refuse cookies, but parts of the Services will not function without the essential ones.

9. How We Secure Your Information

We implement industry-standard measures to protect data, including:

  • Encryption in transit (TLS) for connections to the Services.
  • Encryption at rest on our cloud storage providers for uploaded files and published app bundles.
  • Managed authentication via AWS Cognito; we do not store plaintext passwords.
  • Secrets management through a dedicated secrets manager rather than plaintext configuration.
  • Logical isolation of app data: each published app's data is scoped to its app and account, and a signed launch token binds a running app to the data it is authorized to read and write.
  • Access controls limiting production access to authorized personnel, and server-side error monitoring.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify you and the relevant authorities as required by applicable law.

10. Your Data Protection Rights (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, you have rights over your personal data, including:

  • Access and portability — request a copy of your data in a machine-readable format.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data.
  • Restriction — restrict certain processing.
  • Objection — object to processing based on legitimate interests — including the use of your Customer Content for AI model training (Section 2.C) — and to direct marketing (which we always honor).
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
  • Complain — lodge a complaint with your local supervisory authority (in the UK, the ICO).

To exercise these rights where Emra is the controller, contact support@emra.app from your account email; we may need to verify your identity, and we will respond within the time required by law (generally one month). If your request concerns data stored inside an app published on Emra, Emra is a processor for that data — please contact the Builder that operates the app (Section 4).

11. Children's Personal Data

The Services are intended only for adults. You must be at least 18 years old to use Emra — the sign-up flow requires you to confirm this — and by using the Services you confirm you meet this requirement. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we will delete it. Contact support@emra.app if you believe we have collected data from a minor.

12. Service Providers and Sub-Processors

We use the following third-party providers to operate the Services. They may access personal data only to perform services for us and are bound to protect it. We do not sell your personal data. We will update this section as our providers change.

  • Amazon Web Services (AWS) — cloud compute for the API and the codegen agent, object storage, managed sign-in (Cognito), secrets management, and transactional email (SES).
  • Cloudflare — serves published apps and stores app bundles and uploaded files.
  • Vercel — hosts the Emra web frontend (emra.app) and provides cookieless site analytics.
  • Stripe — payment processing and billing.
  • Anthropic and OpenAI — large-language-model APIs that power the codegen agent (process your prompts and app code; they do not train on this data — see Section 2.C).
  • Sentry — server-side error and performance monitoring.

We also disclose data:

  • For legal requirements: when compelled by law, court order, or valid governmental request.
  • To protect rights and safety: to investigate fraud or abuse, enforce our Terms and Acceptable Use Policy, or protect users.
  • In business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy's commitments.

13. Links to Third-Party Websites

The Services and apps published on Emra may contain links to other websites. We are not responsible for the privacy practices of third-party sites or of apps operated by Builders, and we encourage you to read their policies.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically. For material changes, we will give at least 30 days' notice by email and/or a prominent notice in the Services before the changes take effect; for other changes, we will post the updated policy with a new effective date. Your continued use of the Services after changes take effect constitutes acceptance of the revised policy. We will not materially expand how we use previously collected personal data without providing notice and any legally required choice.

15. U.S. State Privacy Rights (California and Others)

This section supplements the rest of this policy for residents of U.S. states with comprehensive privacy laws, including the California Consumer Privacy Act as amended ("CCPA").

A. Categories of Personal Information We Collect (Last 12 Months)

  • Identifiers: name, email, IP address, account/session identifiers. Sources: you; your devices; Google if you use Google sign-in. Purposes: Section 3. Disclosed to: the service providers in Section 12.
  • Customer records: account details, support communications, billing records (via Stripe).
  • Commercial information: subscription, credits, and transaction history.
  • Internet or network activity: usage logs, device information, aggregated site analytics.
  • Sensitive personal information: your account credential (log-in in combination with password), handled by our identity provider and used solely to authenticate you — never to infer characteristics. We do not use or disclose sensitive personal information for purposes that would trigger a "right to limit" under the CCPA.
  • We do not collect precise geolocation, biometric data, or phone numbers, and we do not knowingly collect data of anyone under 18 (Section 11).

We retain each category as described in Section 6.

B. No Sale or Sharing

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising. We use no advertising trackers (Section 8). Accordingly, there is currently no sale or sharing to opt out of — but if this ever changes, we will add a "Do Not Sell or Share My Personal Information" mechanism and honor Global Privacy Control (GPC) signals as required by law.

C. Your Rights

Depending on your state, you may have the right to know/access the personal information we collect; delete it (subject to exceptions); correct inaccuracies; portability; opt out of sale, sharing, targeted advertising, and certain profiling (not applicable today — see B); and non-discrimination for exercising your rights.

To exercise rights, contact support@emra.app from your account email. We will verify your identity (and an authorized agent's authorization, if you use one) and respond within the time your state's law requires (generally 45 days under the CCPA). If we deny your request, you may appeal by replying to our decision; if your appeal is denied, you may contact your state Attorney General. Requests about data inside a published app: Emra is a service provider/processor for that data — direct your request to the Builder that operates the app (Section 4).

D. Do Not Track / Global Privacy Control

Our Services do not respond to browser "Do Not Track" signals. Because we do not sell or share personal information, GPC signals have nothing to opt out of today; if our practices change, we will honor GPC where the law requires (see B).

16. Contact Us

If you have questions about this Privacy Policy, contact Emra Tech, Inc. at:

Email: support@emra.app