Privacy Policy
Your voice, notes, and Decision DNA belong exclusively to you.
Our Core Privacy Invariant
Your voice samples, private research notes, editorial feedback, and Decision DNA are strictly private and never used to train public foundation models. We do not sell your data, monetize your intellectual property, or harvest platform credentials.
Table of Contents
1. Introduction & Identity
HUUMANEXT EMBER ("Ember", "the Service", "we", "us", or "our") is a Creator Intelligence System developed and operated by Fifth Force (https://fifthforce.in/).
Ember is designed to serve as a quiet, personal intellectual companion that learns how a creator thinks, writes, and decides through the Creator Intelligence Loop™, Decision DNA™, and earned autonomy.
This Privacy Policy explains how we collect, process, isolate, store, and protect your information when you access our public website (https://ember.huumanext.com/) or utilize the Ember creator application.
2. Information We Collect
We collect only the data necessary to provide and compound your personal Creator Intelligence environment:
A. Account & Identity Information
When you create an account, authentication is processed via our secure identity partner (Clerk). We store your creator profile details such as name, email address, avatar, account identifier, and workspace configuration.
B. Creator Inputs, Research & Private Notes
Notes, research files, drafts, ideas, and contextual references you provide to ground your creative work. These materials are stored in tenant-isolated datastores protected by database Row-Level Security (RLS).
C. Voice & Decision DNA Data
Stylistic analyses (lexical richness, sentence rhythms, tone parameters) and decision heuristics extracted from your writing and your corrections (e.g., phrasing approved, generic clichés pruned, hooks preferred).
D. Editorial Decisions, Approvals & Rejections
Every interaction with draft proposals — including explicit approvals, modifications, and rejections — is captured to train your personal Decision DNA model.
E. Connected Platform OAuth Tokens
When you connect third-party platforms (e.g., LinkedIn, X), we receive OAuth 2.0 authorization tokens strictly within requested least-privilege scopes. We never collect, handle, or store third-party passwords. All tokens are encrypted at rest with AES-256-GCM using creator-specific Data Encryption Keys (DEKs).
F. Decision Ledger & Audit Metadata
Cryptographic SHA-256 hash chains recording timestamps, action names, policy verifications, and publication receipts to provide a tamper-evident record of all system and creator actions.
3. How Your Data Is Used
We process your data strictly for the following purposes:
- Personal Intelligence Compounding: To build and refine your private Creator Intelligence Graph and Decision DNA, ensuring future suggestions align with your instincts.
- Grounded Draft Assistance: To generate assistive draft proposals grounded in your proprietary research notes and stylistic profile.
- Governed Publishing: To execute approved publication dispatches to your connected platform accounts via official platform APIs.
- Transparency & Auditability: To generate "Why Ember Acted" explanation moments and verifiable audit trails.
- Account Administration & Security: To enforce authentication, rate limits, session management, and system health checks.
4. AI & Infrastructure Subprocessors
To generate draft suggestions and perform vector similarity search, Ember utilizes secure enterprise cloud and AI infrastructure:
- AI Model Providers (e.g., Google Cloud Vertex AI): Prompts sent for inference include only the necessary contextual notes and stylistic rules. Data transmitted to our enterprise AI providers is processed in transit under enterprise terms that explicitly prohibit using customer data for model training and enforce zero persistent data retention by the model vendor.
- Cloud Infrastructure: Primary persistent storage (PostgreSQL 17 with pgvector) and computing run within secure, regional enterprise data centers (Oracle Cloud Infrastructure).
- Email Delivery: Transactional notifications and verification messages are dispatched via Amazon Simple Email Service (SES).
5. Third-Party Platform Integrations (X, LinkedIn & Others)
Ember integrates with external publishing networks (including X and LinkedIn) strictly through official, developer-approved APIs and OAuth 2.0 PKCE authentication:
- Official APIs Only: All actions execute through canonical platform endpoints. We strictly prohibit and do not use web scraping, browser automation (e.g. Puppeteer/Selenium), or private API endpoints.
- Least-Privilege Scopes: We request only the minimal permissions required to read user profile identification and publish approved content.
- Zero Password Access: We never see or store your third-party social media passwords.
- Approval Gates: Automated publishing occurs only when you have explicitly authorized an action or granted scoped autonomy through Ember's Earned Trust protocol.
6. Security & Token Protection
We enforce defense-in-depth security across all architectural layers:
- Encryption in Transit: All HTTP communications require TLS 1.3+ encryption with HSTS enforcement.
- Encryption at Rest & Envelope Encryption: Sensitive payloads and third-party OAuth access/refresh tokens are encrypted using AES-256-GCM with unique per-creator Data Encryption Keys (DEKs).
- PostgreSQL Row-Level Security (RLS): Tenant isolation is enforced at the database layer; server sessions assert creator tenant context so that cross-tenant access is structurally impossible.
- Server-Side Authorization: All capability gating, publishing permissions, and autonomy checks are validated server-side.
7. Data Sovereignty, Portability & Cryptographic Shredding
Under our Data Sovereignty architecture, you maintain complete ownership of your creative assets and identity:
Full Portability: You can export your entire intelligence history, notes, voice profiles, and decision graph in standardized JSON-LD and Markdown formats at any time.
Permanent Deletion & Cryptographic Key Shredding: When you request account deletion, your active creator record, private notes, voice profile, and vector embeddings are deleted. To maintain ledger auditability without preserving private data, your individual Data Encryption Key (DEK) is destroyed. Cryptographic shredding ensures that all historical encrypted payloads in the immutable ledger become permanently unrecoverable mathematical noise.
8. Retention & Credential Revocation
We retain your data only for as long as your account remains active or as required to deliver the Service.
You can disconnect connected third-party platforms (LinkedIn, X) from within your Ember dashboard at any time. Disconnection immediately invalidates and wipes local OAuth tokens, terminating Ember's access to that platform.
9. Cookies, Analytics & Technical Telemetry
We use strictly necessary first-party cookies and local storage tokens solely for session authentication and interface preferences (e.g., active theme). We do not use third-party behavioral advertising cookies.
Server telemetry (OpenTelemetry request metrics, error correlation IDs) captures system performance, latency, and operational health without logging private creative content.
10. Changes to this Policy & Contact Information
We may update this Privacy Policy from time to time. When changes are made, we will revise the "Last Updated" date at the top of this document and notify active creators through the Ember interface or email.
For privacy inquiries, data export requests, or questions regarding our data governance, please contact:
Fifth Force — HUUMANEXT EMBER
Email: info@ember.huumanext.com
Phone: +91 70031 80336
Organization Website: https://fifthforce.in/
Product Website: https://ember.huumanext.com/