You note what happened, who with, and how it went. Four taps on a good night, one if you're tired. Positions, pace, where you were, whether anyone finished — all optional, all yours to skip.
If your partner uses Ember too, you each pick exactly what crosses over: a cycle, a moment, or nothing at all. Plenty of couples run it as two private logs for months. That works fine.
What Ember doesn't do: streaks, badges, weekly targets, or telling you how you compare to other people your age.
Phase bands run under the dates as continuous ribbons — period, predicted window, higher and lower fertility — with cycle day numbers below. Tap a date and the day opens inline: what you logged, who it was with, nothing hidden behind a sheet.
If your partner shares their cycle, their layer replaces yours rather than stacking on top. Two sets of bands at once would just be a colour mess.
Priya can see your cycle and nothing else. Sam is a name and a colour that never leaves your account. Nobody can see who else is on your list — not the names, not the number.
Ember will tell you your evenings have been busier since mid-July, that it's mostly at home and mostly unhurried, and that lately initiation has been pretty mutual. It won't tell you what any of that says about you.
Not enough logged yet? The card says so plainly instead of inventing a trend from three data points.
Ember (com.leapsnine.ember) is a personal intimacy and wellness journal developed by leapsnine. It is not a medical device, and nothing in the app — including cycle tracking — is medical advice. This policy describes exactly what data Ember handles, how it is protected, and what control you have over it.
Account. Ember signs you in with your Google account through Firebase Authentication. We receive your Google account's basic profile (name, email address, profile photo) and a unique user ID, used only to identify your account.
Onboarding details. Your year of birth (used once to confirm you are 18 or older) and an optional gender selection (used only to decide whether to offer the cycle-tracking module).
Content you log. Everything you record is stored under your account and, by default, visible to no one but you: moments (date and time plus any optional details — partner, pace, place, position, who initiated, protection, how it finished, a private satisfaction rating, a private note), partner profiles you create, place labels you type, cycle data if you enable that module, and messages and nudges exchanged with a linked partner. A partner you add locally is never contacted and never knows they are in the app. Ember never collects GPS or map data — a place is only ever a label you wrote.
Recovery and key material. Ember stores the encrypted (wrapped) keys needed to make your content recoverable on a new device. These are useless without your device or your recovery code (see section 3).
No GPS or location data, ever. No advertising, no ad identifiers. No third-party analytics or tracking SDKs — Ember's insights are computed on your device from your own data and are never uploaded. No contact-list access; linking with a partner uses a short invite code you share yourself. Nothing is sold or shared with third parties for marketing — Ember has no business model; it is a personal-use app.
Ember encrypts your sensitive content on your device before it is uploaded (AES-256-GCM). Encrypted fields include your notes, satisfaction ratings, place labels, cycle notes, free-text entries, chat message bodies, and every shared projection. The encryption keys are protected by a master key that exists in only two places: your device's hardware keystore, and a backup copy encrypted under your recovery code (a code only you have, derived with Argon2id).
This means the developer, Google, or anyone with access to the database cannot read your notes, ratings, labels, or messages. It also means that if you lose both your device and your recovery code, that content is gone — no one can recover it for you. The app tells you this when it shows you your recovery code.
To keep the app functional (calendars, filters, reminders), some structural fields are stored unencrypted: timestamps, internal category IDs (for example, which pace or protection option was chosen), references between records, and which accounts are linked. These are IDs and dates, not your words — but you should know they exist.
Sharing exists only if you explicitly link with another Ember user via an invite code, and it is opt-in at every level. Nothing is shared by default: each moment has a per-moment share toggle, off unless you turn it on (or change the default for that link). A shared moment exposes only date, pace, place label, position, who initiated, protection, and how it finished — your satisfaction rating and notes are never shared, under any setting. Cycle sharing is a separate opt-in.
Shared data is a copy (a projection): un-sharing or deleting a moment removes it from your partner's view; unlinking freezes what was already shared as read-only history and cuts off everything else. No partner can ever see anything about any other partner in your app. Chat messages are end-to-end encrypted with a key negotiated between the two devices (X25519); the server stores only ciphertext and the public halves of the handshake.
Ember runs entirely on Google Firebase; there is no other server and no other recipient of your data: Firebase Authentication (Google sign-in), Cloud Firestore (the database, stored in Google Cloud region asia-southeast1, Singapore), Cloud Functions (small server routines for invite codes, linking, unlinking, notification delivery, and account deletion), Firebase Cloud Messaging (push notifications), and Firebase App Check / Play Integrity (verifies requests come from the genuine app).
Google processes this data as a service provider under the Google Cloud terms and Google's privacy policy. Because of the encryption described in section 3, Google stores your content but cannot read the encrypted fields either.
Push notifications are deliberately generic. The notification payload never contains message text, partner names, or anything about your activity — the app fetches details locally after you unlock it. You can disable notifications entirely in system settings.
Database access rules enforce that private data is readable only by its owner and shared data only by the two linked accounts. Optional biometric/PIN lock on every app open. Optional screenshot blocking (on by default). App Check ensures only the genuine app can talk to the backend. Client-side encryption as described in section 3.
Your data is kept until you delete it. You can delete any individual moment, partner, place, message thread, or cycle entry in the app; revoke sharing at any time (removes the shared copies); and unlink from a partner at any time. Delete all my data (in Settings) permanently removes every record you own — content, keys, everything you ever shared into any link — and deletes your account. This is irreversible. Start fresh (after losing your recovery code) wipes your encrypted content while keeping your account and links; no one is notified.
There are no backups retained beyond Google Cloud's standard operational infrastructure; deleted documents are gone.
Everything beyond a moment's date is optional — every field can be skipped. Cycle tracking is optional and can be turned off. Linking is optional; the entire app works with no linked partner. You can view or regenerate your recovery code in Settings (regenerating invalidates the old one). And you can export nothing by accident: Ember has no share or export buttons on insight or content screens.
Ember is for adults. You must be 18 or older to use it; onboarding asks your year of birth and blocks the app otherwise. We do not knowingly collect data from anyone under 18.
If Ember's data practices change, this policy will be updated and the effective date revised. Material changes will be called out in the app before they take effect.
Questions or requests about your data: praveesh4u@gmail.com.