Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · embercopilot.ai

Ember

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-20
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

11 verified findings2 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
0
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Ember's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 11 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 11 citationsLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines the scope and purpose of the Privacy Policy, identifying the entities covered (website, SaaS platform), the company's stated commitment to privacy compliance, and the primary intended audience (healthcare organizations), thereby establishing foundational definitions for how information is collected, used, and shared.

" Ember AI is committed to protecting privacy and maintaining transparency about how information is collected, used, and shared. This Privacy Policy explains how we collect, use, and share information in connection with our website, our prop..."
📍 Privacy Policy › “Privacy Policy”Jump to exact text →
plan language
Privacy & data use

Defines 'Business Identification Data' as a collection category including company name, business address, industry, and firmographic information inferred from IP address or network signals, specifying the scope of this collection category.

" Business Identification Data Company name, business address, industry, and related firmographic information inferred from IP address or network signals"
📍 Privacy Policy › “Parties You Authorize, Access or Authenticate”Jump to exact text →
plan language
Privacy & data use

States that non-essential tracking technologies are not activated until consent is provided, and defines the categories of tracking technologies (Strictly Necessary, Analytics, Marketing & Advertising) including their purposes and activation conditions, establishing both a protective restriction on pre-consent activation and definitional classifications for each category.

" Non-essential tracking technologies are not activated until you provide consent . We categorize tracking technologies as follows: Strictly Necessary: Required for the website to function properly, including security and storing your cons..."
📍 Privacy Policy › “Customize your preferences by category”Jump to exact text →
plan language
Privacy & data use

Describes the use of B2B analytics tools that analyze IP address information and network signals to associate website visits with business organizations, and provides an opt-out mechanism via a specific URL or contact email — establishing both a data use practice and a user remedy to limit that use.

" We use certain analytics tools designed for business-to-business websites that help us understand how organizations interact with our website. These tools may analyze IP address information and other network signals to associate website vi..."
📍 Privacy Policy › “Business Identification and B2B Analytics”Jump to exact text →
plan language
Privacy & data use

States that information may be used to measure marketing effectiveness and identify potential business visitors (conditioned on consent), and to protect safety and security of the website, app, and users, establishing conditional and unconditional permitted purposes for data processing.

" To measure marketing effectiveness and identify potential business visitors to our website (with your consent) To protect the safety and security of our Website, App, and users"
📍 Privacy Policy › “To fulfill your requests and process transactions”Jump to exact text →
plan language
Subprocessors & data sharing

Describes how, after user consent, specific third-party technologies may be activated to measure marketing performance and engagement, naming the third parties and their purposes, and confirming each is loaded only after consent to the relevant category — a procedure governing conditional data sharing with named subprocessors.

" After you provide consent, we may activate third-party technologies that help us measure marketing performance and understand engagement with our website. These technologies may include: Google Ads: Used to measure advertising campaign p..."
📍 Privacy Policy › “Third-Party Tracking Technologies”Jump to exact text →
plan language
Subprocessors & data sharing

States that information may be shared with third-party service providers assisting in business operations, identifies the purpose of understanding organizational visitors, and imposes a reasonable-measures obligation on the controller to ensure recipients protect the data and use it only for stated purposes — establishing both a sharing permission and a protective data-handling requirement for subprocessors.

" To share with third-party service providers who assist us in operating our business To understand which organizations and industries are visiting our website and evaluating interest in our services. We take reasonable measures to ensure ..."
📍 Privacy Policy › “To comply with legal obligations and enforce our agreements”Jump to exact text →
Conflicting provisions (3)
  • Clause A states that non-essential tracking (including marketing and advertising) requires prior consent (opt-in), while Clause B implies an opt-out mechanism for certain advertising or identification activities, suggesting they are active by default.

    " Non-essential tracking technologies are not activated until you provide consent . We categorize tracking technologies as follows: Strictly Necessary: Required for the website to function properly, including security and storing your consent choice. Your consent choice itself is stored locally in your browser (local storage), not in a cookie. Always active. Analytics: Help us understand how visitors and their organizations interact with our website (e.g. Snitcher). Marketing & Advertising: Used to measure the effectiveness of our marketing and advertising campaigns and identify potential business visitors (e.g. Google Ads, Meta Pixel, RB2B)."
    " We use certain analytics tools designed for business-to-business websites that help us understand how organizations interact with our website. These tools may analyze IP address information and other network signals to associate website visits with business organizations. Visitors may opt out of certain advertising or identification activities by visiting https://app.retention.com/optout or by contacting us at support@embercopilot.ai ."
    Within one document
  • Clause A promises no tracking technologies or cookies are loaded until explicit user consent, while Clause B describes analytics tools that identify organizations via IP addresses and offers an opt-out, implying these activities may occur by default or without prior opt-in consent.

    " We use tracking technologies to operate our website and understand how visitors interact with it. We manage consent with our own in-house solution: no third-party tracking technology is loaded, and no tracking cookies are set, until you provide consent. When you visit our website, you will be presented with a consent banner that allows you to:"
    " We use certain analytics tools designed for business-to-business websites that help us understand how organizations interact with our website. These tools may analyze IP address information and other network signals to associate website visits with business organizations. Visitors may opt out of certain advertising or identification activities by visiting https://app.retention.com/optout or by contacting us at support@embercopilot.ai ."
    Within one document
  • Clause A states that identifying potential business visitors requires user consent, while Clause B describes this activity and offers an opt-out mechanism, implying it occurs by default rather than requiring prior consent.

    " To measure marketing effectiveness and identify potential business visitors to our website (with your consent) To protect the safety and security of our Website, App, and users"
    " We use certain analytics tools designed for business-to-business websites that help us understand how organizations interact with our website. These tools may analyze IP address information and other network signals to associate website visits with business organizations. Visitors may opt out of certain advertising or identification activities by visiting https://app.retention.com/optout or by contacting us at support@embercopilot.ai ."
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 11
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" To share with third-party service providers who assist us in operating our business To understand which organizations and industries are visiting our website and evaluating interest in our services. We take reasonable measures to ensure that any party receiving personal information from us protects that information and uses it only for the purposes outlined in this Privacy Policy."
Privacy Policy › “To comply with legal obligations and enforce our agreements”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that information may be shared with third-party service providers assisting in business operations, identifies the purpose of understanding organizational visitors, and imposes a reasonable-measures obligation on the controller to ensure recipients protect the data and use it only for stated purposes — establishing both a sharing permission and a protective data-handling requirement for subprocessors.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Ember AI is committed to protecting privacy and maintaining transparency about how information is collected, used, and shared. This Privacy Policy explains how we collect, use, and share information in connection with our website, our proprietary software-as-a-service (SaaS) platform, and your interactions with us. As a company based in the United States, Ember AI designs its privacy practices with the goal of complying with applicable privacy and data protection laws intended to safeguard personal information. Our website and services are intended primarily for healthcare organizations and other business users rather than individual consumers."
Privacy Policy › “Privacy Policy”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope and purpose of the Privacy Policy, identifying the entities covered (website, SaaS platform), the company's stated commitment to privacy compliance, and the primary intended audience (healthcare organizations), thereby establishing foundational definitions for how information is collected, used, and shared.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Customers who have signed up to access and use our App Customer's employees and contractors authorized to access and use our App By visiting our Website, you are agreeing to the terms of this Privacy Policy and the Terms of Service ."
Privacy Policy › “Visitors to our Website, who view only publicly-available content”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines additional covered user categories (customers and their authorized employees/contractors) and incorporates acceptance of both this Privacy Policy and the Terms of Service by virtue of visiting the website, creating a binding incorporation by reference obligation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This chart details the categories of Personal Data that we collect: Category of Personal Data Examples of Personal Data We Collect Categories of Third Parties With Whom We Share this Personal Data "
Privacy Policy › “Personal Data We Collect”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Introduces the structure of the personal data collection chart, defining the categories of personal data collected and the third parties with whom each category is shared, establishing the definitional framework for data collection and sharing disclosures.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Business Identification Data Company name, business address, industry, and related firmographic information inferred from IP address or network signals"
Privacy Policy › “Parties You Authorize, Access or Authenticate”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines 'Business Identification Data' as a collection category including company name, business address, industry, and firmographic information inferred from IP address or network signals, specifying the scope of this collection category.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Other Identifying Information that You Voluntarily Choose to Provide Identifying information in emails, letters, texts, or other communication you send us Any other identifying information you authorize Ember to access or elect to share with Ember"
Privacy Policy › “Parties You Authorize, Access or Authenticate”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines a residual collection category of 'Other Identifying Information Voluntarily Provided,' encompassing identifying information in user communications and any information the user authorizes or elects to share with the company, establishing the scope of voluntarily submitted personal data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We use tracking technologies to operate our website and understand how visitors interact with it. We manage consent with our own in-house solution: no third-party tracking technology is loaded, and no tracking cookies are set, until you provide consent. When you visit our website, you will be presented with a consent banner that allows you to:"
Privacy Policy › “Cookies and Tracking Technologies”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the consent management procedure for tracking technologies, stating that no third-party tracking technology is loaded and no tracking cookies are set until user consent is provided, and specifying that a consent banner is presented to visitors — establishing a procedural gate on data collection that is protective of users.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Non-essential tracking technologies are not activated until you provide consent . We categorize tracking technologies as follows: Strictly Necessary: Required for the website to function properly, including security and storing your consent choice. Your consent choice itself is stored locally in your browser (local storage), not in a cookie. Always active. Analytics: Help us understand how visitors and their organizations interact with our website (e.g. Snitcher). Marketing & Advertising: Used to measure the effectiveness of our marketing and advertising campaigns and identify potential business visitors (e.g. Google Ads, Meta Pixel, RB2B)."
Privacy Policy › “Customize your preferences by category”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that non-essential tracking technologies are not activated until consent is provided, and defines the categories of tracking technologies (Strictly Necessary, Analytics, Marketing & Advertising) including their purposes and activation conditions, establishing both a protective restriction on pre-consent activation and definitional classifications for each category.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We use certain analytics tools designed for business-to-business websites that help us understand how organizations interact with our website. These tools may analyze IP address information and other network signals to associate website visits with business organizations. Visitors may opt out of certain advertising or identification activities by visiting https://app.retention.com/optout or by contacting us at support@embercopilot.ai ."
Privacy Policy › “Business Identification and B2B Analytics”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the use of B2B analytics tools that analyze IP address information and network signals to associate website visits with business organizations, and provides an opt-out mechanism via a specific URL or contact email — establishing both a data use practice and a user remedy to limit that use.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" To measure marketing effectiveness and identify potential business visitors to our website (with your consent) To protect the safety and security of our Website, App, and users"
Privacy Policy › “To fulfill your requests and process transactions”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that information may be used to measure marketing effectiveness and identify potential business visitors (conditioned on consent), and to protect safety and security of the website, app, and users, establishing conditional and unconditional permitted purposes for data processing.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" After you provide consent, we may activate third-party technologies that help us measure marketing performance and understand engagement with our website. These technologies may include: Google Ads: Used to measure advertising campaign performance and track conversions. Loaded only after you consent to the Marketing & Advertising category. Meta (Facebook) Pixel: Used to measure the effectiveness of advertising campaigns, understand how visitors interact with our website, and track conversions from advertisements. Loaded only after you consent to the Marketing & Advertising category. RB2B (B2B Tracking): Used to identify company-level information about organizations visiting our website. RB2B and its partners may use cookies or similar technologies to associate website activity with other information they or others may have about a business contact or company domain. Loaded only after you consent to the Marketing & Advertising category. Snitcher: Used to understand, at a company level, how organizations interact with our website. Loaded only after you consent to the Analytics category. These services may collect information such as: pages visited referring website device and browser information approximate geographic location based on IP address company-level visitor information for business visitors These providers may process information according to their own privacy policies."
Privacy Policy › “Third-Party Tracking Technologies”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes how, after user consent, specific third-party technologies may be activated to measure marketing performance and engagement, naming the third parties and their purposes, and confirming each is loaded only after consent to the relevant category — a procedure governing conditional data sharing with named subprocessors.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Ember's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Ember's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Ember's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Ember requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Ember's published policies yet.

What the policies actually cover

0 topics

None of Ember's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

20
clauses
2
patterns
2
stances
privacy sharing · 2
privacy sharingHIGHPrivacy Policy › “California Privacy Rights”

The clause permits sale of personal data or information.

If you are a California resident, you have the right to: request access to personal information we collect about you request deletion of personal information request information about categories of data shared with third parties opt out of the sale or sharing of personal information (where applicable) To exercise these rights, contact us at: support@embercopilot.ai We do not knowingly sell personal information.
Open source citation
privacy sharingMEDIUMPrivacy Policy › “To comply with legal obligations and enforce our agreements”

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

To share with third-party service providers who assist us in operating our business To understand which organizations and industries are visiting our website and evaluating interest in our services. We take reasonable measures to ensure that any party receiving personal information from us protects that information and uses it only for the purposes outlined in this Privacy Policy.
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useworsensHIGH1
Team / Businesssubprocessors data sharingconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

To share with third-party service providers who assist us in operating our business To understand which organizations and industries are visiting our website and evaluating interest in our services. We take reasonable measures to ensure that any party receiving personal information from us protects that information and uses it only for the purposes outlined in this Privacy Policy.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

If you are a California resident, you have the right to: request access to personal information we collect about you request deletion of personal information request information about categories of data shared with third parties opt out of the sale or sharing of personal information (where applicable) To exercise these rights, contact us at: support@embercopilot.ai We do not knowingly sell personal information.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

20 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Ember's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Ember's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Ember's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.