embase.tech

Privacy Policy

This policy explains what information Embase collects, how we use it, and your rights regarding that information.

Last updated: July 27, 2026

Introduction

Embase ("we", "our", or "us") operates the competitive intelligence platform available at embase.tech. The service is operated by a sole proprietor registered in Georgia; full legal details are available on request via support@embase.tech. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

We are committed to protecting your personal data and complying with applicable privacy laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Please read this policy carefully. If you do not agree with its terms, please discontinue use of the service.

This policy is provided in English. In the event of any conflict between translated versions and the English version, the English version shall prevail.

Information We Collect

Account information: When you register, we collect your name, email address, and organisation details. Authentication is handled by Clerk, our identity provider, which may collect additional information as described in their privacy policy.

Workspace data you add: Competitor names, domains, monitoring sources, notes, and settings you configure are stored and processed to deliver the intelligence you request. This data belongs to your organisation.

Usage data: We measure aggregate usage of our public website with Plausible, a cookieless, privacy-first analytics tool. It does not use cookies, does not track you across sites, and does not build individual profiles.

Communications: If you contact our support team or opt in to product emails, we retain those messages and your email preferences to resolve enquiries and honour your choices.

Device and log data: We automatically process IP addresses, browser type, and request timestamps for security, rate limiting, and abuse prevention. Application errors are captured by our error-monitoring tool together with technical context about the failed request.

Billing information: We store your subscription plan and billing status. Payments are handled by our payment provider; we never see or store full payment card details.

How We Use Your Information

To provide and improve the service: We use your information to operate Embase, monitor the competitors you track, generate signals, reports, and battle cards, and improve the quality and relevance of the product.

To communicate with you: We send transactional emails (account, billing, report delivery). Organisation owners who have opted in during onboarding may also receive product updates and announcements — every marketing email contains an unsubscribe link, and you can withdraw consent at any time.

For security and fraud prevention: We analyse request logs and usage patterns to detect and prevent unauthorised access, abuse, and other security incidents.

For billing: Subscription state is used to determine your plan, features, and entitlements.

To comply with legal obligations: We may process your data when required to do so by law, regulation, or valid legal process.

Legal Bases for Processing (GDPR)

Where the GDPR applies, we process your personal data on the following legal bases:

Performance of a contract: operating your account and workspace, generating the intelligence you request, billing, and sending transactional emails. Legitimate interests: securing the service, rate limiting and abuse prevention, error monitoring, and aggregate cookieless analytics — balanced against your rights and freedoms. Consent: product and marketing emails to organisation owners who opted in during onboarding; consent can be withdrawn at any time via the unsubscribe link or your settings. Legal obligation: where processing is required to comply with applicable law.

AI Processing

Embase uses large language models provided by Anthropic to analyse companies, filter and enrich signals, and generate reports and battle cards. The content sent to the model consists of company profiles, publicly sourced signals, and the workspace context needed for the requested output.

Under our API agreements, content submitted to Anthropic is not used to train their models. AI-generated content is stored in your workspace like any other workspace data and is scoped to your organisation.

Embase does not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you — the AI analyses the companies you track, not the individuals using the service.

Third-Party Processors

We work with a small set of processors to deliver the service. Each handles data only as instructed by us and under contractual obligations consistent with this policy:

Clerk — authentication, organisation management, and subscription billing (United States). Neon — encrypted PostgreSQL database hosting (Frankfurt, Germany). Railway — application hosting (Amsterdam, Netherlands). Trigger.dev — background job processing for monitoring and generation (United States). Anthropic — AI inference (United States). Resend — transactional and consent-based product email delivery (United States). Sentry — error monitoring with EU data residency (Germany). Plausible — cookieless, aggregate website analytics (European Union).

We do not sell your personal data, and we do not share your data with advertisers or data brokers.

Integrations You Connect

You may connect your workspace to third-party tools such as Slack, Microsoft Teams, or your own webhook endpoint. When you do, the content you choose to deliver (signals, digests, reports) is sent to the destination you configured, and its further handling is governed by that provider’s terms and privacy policy.

If you connect an external AI client through our MCP endpoint, that client can read your workspace data on your behalf after you authorise it. Access is scoped to your organisation, is read-only, and can be revoked at any time; the client’s own privacy policy governs what it does with the data it retrieves.

Public Web Data

To build competitor profiles and detect signals, Embase collects and analyses publicly available information about companies — websites, news, product pages, and similar public sources. This information may incidentally include personal data that appears in public materials, such as the names of founders or spokespeople quoted in news coverage.

We process such data solely to provide competitive intelligence about companies, not to profile individuals. If you believe Embase stores public-source information about you that you would like reviewed or removed, contact us at support@embase.tech.

Cookies

We use strictly necessary cookies only: they maintain your authentication session, remember your language preference, and protect authorisation flows against cross-site request forgery.

We do not use advertising cookies, cross-site tracking, or analytics cookies — our website analytics (Plausible) works entirely without cookies and collects only aggregate statistics.

Data Retention and Security

We retain your data for as long as your account or organisation is active. When you delete your account, your user record is deleted immediately; content your organisation continues to rely on (such as reports) is retained in anonymised form without any link to you. When an organisation is deleted, all of its workspace data — competitors, signals, reports, battle cards, and integrations — is deleted immediately.

Residual copies may persist in encrypted database backups for up to approximately 30 days before they expire on schedule.

All data is encrypted in transit (TLS) and at rest. Third-party credentials you connect (such as integration tokens) are additionally encrypted at the application level before storage. Access to production systems is restricted and protected by multi-factor authentication.

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where the GDPR requires it, and will inform affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

Your Rights (GDPR and CCPA)

Depending on your location, you may have the following rights regarding your personal data:

Right to access: You may request a copy of the personal data we hold about you. Right to rectification: You may ask us to correct inaccurate or incomplete data. Right to erasure: You may ask us to delete your personal data, subject to our legal obligations. Right to restriction: You may ask us to limit how we process your data in certain circumstances. Right to portability: You may request your data in a structured, machine-readable format. Right to object: You may object to processing based on legitimate interests. Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

California residents have additional rights under the CCPA/CPRA, including the right to know what personal information is collected, the right to delete, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share personal information for advertising), the right to limit the use of sensitive personal information, and the right to non-discrimination for exercising these rights. You may designate an authorised agent to submit a request on your behalf.

To exercise any of these rights, please contact us at support@embase.tech. We will respond within one month of receiving your request; where a request is complex or requests are numerous, this period may be extended by up to two further months as permitted by the GDPR, in which case we will let you know.

International Data Transfers

Your workspace data is stored in the European Union: our database runs in Frankfurt, Germany, and the application is hosted in Amsterdam, Netherlands. Some of our processors — including Clerk, Trigger.dev, Anthropic, and Resend — operate from the United States, and the service is administered from Georgia.

Where personal data is transferred out of the European Economic Area or the United Kingdom to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or on the EU–US Data Privacy Framework where the recipient is certified under it.

Children's Privacy

Embase is a business-to-business service intended for use by organisations and professionals. We do not knowingly collect personal data from anyone under the age of 16.

If we become aware that we have inadvertently collected personal data from a child under 16, we will delete it promptly. If you believe we may have collected data from a child, please contact us at support@embase.tech.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the date at the top of this page and, where appropriate, by sending an email to the address associated with your account.

Your continued use of Embase after any changes take effect constitutes your acceptance of the revised policy.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at support@embase.tech.

If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection supervisory authority — a directory of EEA authorities is available at edpb.europa.eu.