Privacy Policy

Last updated: 28 September 2026

EMRules is the controller of the personal data described here. Contact: [email protected].

What we collect. Your name, email address and password (stored as a hash), or the profile a sign-in provider shares (Google or Microsoft: name and email). Your organization's name and members. Sign-in sessions, with IP address and browser. API keys and a count of API requests for limits and billing. Billing records held by Stripe. Error reports that may include technical details of a failed request.

Why. To provide the service and your account (contract), to bill you (contract and legal obligation), to secure the service and fix errors (legitimate interest), and to send account email such as verification and password reset (contract). We do not sell personal data, show advertising or use your data to train models.

Payments. Payments are processed by Stripe. Your card details go directly to Stripe and never reach our servers.

Who processes it for us. Supabase (database and file storage), Contabo (servers), Stripe (payments), Resend (email delivery), Sentry (error reports), and Google or Microsoft if you choose them for sign-in. Some of these providers process data outside the European Economic Area under standard contractual clauses.

Cookies and storage. One strictly necessary cookie keeps you signed in. Your light or dark mode choice is kept in your browser's local storage. We use no analytics or advertising cookies.

How long. Account data is kept while the account is open and deleted within 30 days of closing it, except billing records kept as tax law requires. Error reports are kept for up to 90 days.

Your rights. You can access, correct, delete or export your data, object to or restrict its processing, and complain to your data protection authority. Write to [email protected].

Changes. We will post changes here and email account holders about material ones.