Privacy Policy
Effective date: March 26, 2026 · Last updated: April 4, 2026
This Privacy Policy explains how Emvara (“Emvara,” “we,” “us,” or “our”) collects, uses, and protects personal information when you visit emvara.ai, sign in to the Emvara platform at app.emvara.ai, or otherwise interact with our services. Emvara is operated by Fluenik, LLC.
1. Scope
This policy applies to personal information collected through:
- emvara.ai — our public-facing website, marketing pages, and waitlist/contact forms.
- app.emvara.ai — the Emvara platform, including the login screen, dashboard, AI assistant, integrations, automations, AI memory, workspaces, and account management.
- Waitlist and contact form submissions — forms on emvara.ai used to join waitlists, request access, subscribe to product updates, and contact our team.
- Third-party integrations — when you connect external services (such as Gmail, Google Calendar, Jira, HubSpot, Slack, and others) to Emvara via OAuth 2.0 or OAuth 1.0a, data exchanged through those connections is also covered by this policy. This includes health and fitness integrations (such as Fitbit, Oura Ring, and Strava) that may transmit health-related data such as activity metrics, heart rate, sleep, and body composition.
2. Accountability and Privacy Contact
Emvara is operated by Fluenik, LLC, a Michigan limited liability company in the United States. Fluenik, LLC is responsible for personal information under its control. For privacy questions, requests, or complaints, contact us at:
- Privacy Contact: Fluenik, LLC Privacy Officer
- Email: [email protected]
- Request label: Please include “Privacy Request” in the subject line so we can route your inquiry promptly.
3. Information We Collect
Account registration and login (app.emvara.ai)
When you create an account or sign in to Emvara, we collect:
- Email address and password-derived authentication data (your password is immediately hashed using industry-standard algorithms; we never store or transmit your plaintext password) to authenticate your identity.
- Two-factor authentication (2FA) data if you enable 2FA on your account, including TOTP secret keys (encrypted at rest).
- Session tokens — short-lived access tokens and refresh tokens stored in your browser to maintain your authenticated session. These are not used for tracking or advertising.
- Name and profile information you provide when setting up or updating your account.
- Usage and activity data within the platform, such as workspace actions, configuration changes, integration connections, and feature interactions, to support your account and improve the product.
- Server, application, and security logs — we and our infrastructure providers maintain logs that may include IP address, request metadata, timestamps, device/browser information, and related technical data for security, debugging, fraud prevention, and service reliability.
AI assistant conversations and memory
When you use the Emvara AI assistant, we collect and store:
- Conversation history — the text of messages you send and AI responses generated during your sessions. You can permanently erase a conversation's chat log at any time by starting a new chat with the agent or meeting room.
- AI memory — contextual information the AI extracts and retains across sessions to provide personalized assistance (such as your preferences, project context, and recurring tasks). You can disable AI memory entirely at any time from your account settings, and you can view and delete individual memories.
- Timestamps for sessions, messages, and AI-generated actions.
Third-party integrations
When you connect external services to Emvara (such as Gmail, Google Calendar, Jira, HubSpot, Slack, Notion, Linear, GitHub, and others), we collect:
- OAuth 2.0 tokens (encrypted at rest) to authenticate with the connected service on your behalf.
- Integration metadata — the type of integration, connection status, and permissions granted.
- Data retrieved from connected services — such as emails, calendar events, tasks, contacts, issues, and other records, as needed to provide AI assistant functionality. This data is processed in real time and/or cached temporarily to enable features you have configured.
You can disconnect any integration at any time from your account settings. When you disconnect, we revoke the OAuth token and cease accessing data from that service. Cached data from disconnected integrations is deleted within 30 days of disconnection.
Health and fitness integrations
When you connect health and fitness services (such as Fitbit, Oura Ring, Strava, WHOOP, Withings, or Garmin Connect) to Emvara, your AI assistant may access health-related data including:
- Activity data — steps, distance, calories burned, active minutes, workouts, and exercise sessions.
- Biometric data — heart rate, heart rate variability (HRV), resting heart rate, blood oxygen saturation (SpO2), breathing rate, skin temperature, and body temperature.
- Sleep data — sleep duration, sleep stages (deep, light, REM, awake), sleep scores, and sleep efficiency.
- Body composition — weight, body mass index (BMI), body fat percentage, and muscle mass.
- Recovery and stress data — readiness scores, stress levels, recovery metrics, and Body Battery.
How health data is processed: Health data is retrieved from connected services on demand when you interact with your AI assistant. Emvara does not maintain a separate database of your health data. Health information may appear in AI conversation history when you ask your assistant about your health or fitness metrics. This conversation data is subject to the same retention and deletion policies as all other conversations (see Section 13).
Health data is not logged: Health metrics retrieved from connected services are not written to application logs, error monitoring systems, or analytics platforms. Error reports from health integrations are scrubbed of health-related values before transmission to our error monitoring provider.
Legal basis: Health data is processed based on your explicit consent, which you provide when you connect a health integration and authorize data access. You may withdraw consent at any time by disconnecting the integration from your account settings. Under the EU General Data Protection Regulation (GDPR), health data is “special category” data processed under Article 9(2)(a) (explicit consent). Under the Washington My Health My Data Act and similar state laws, we obtain consent before collecting consumer health data.
No sale or sharing: We do not sell, share, or disclose health data to third parties for advertising, marketing, or any purpose other than providing the Emvara AI assistant service to you. Health data is sent to our AI provider (Microsoft Azure OpenAI Service) solely to generate responses to your questions, subject to the same contractual protections described in Section 4.
Promotional emails
We send promotional emails about our products and updates only with your consent. You may unsubscribe at any time using the link in our emails or by contacting us.
We retain your email address for marketing purposes until you unsubscribe or request deletion.
We use third-party email delivery providers to send communications.
We do not use phone numbers for marketing communications unless explicitly stated.
Waitlist, contact forms, and mailing-list subscriptions
When you submit a waitlist form, contact form, or subscribe to product updates on emvara.ai, we collect:
- Contact details such as email address and, if provided, name and phone number.
- Message content from contact form submissions.
- Subscription metadata such as list membership, consent status (including optional promotional-email consent), and subscribe/unsubscribe timestamps.
- Technical and anti-abuse data such as IP address, browser/device metadata, and captcha verification status when anti-spam checks are enabled.
You can unsubscribe at any time using the unsubscribe link in promotional emails or by contacting [email protected]. We may retain minimal suppression-list data (such as email address and unsubscribe status) to honor opt-out requests and comply with legal obligations.
Contact form submissions
Legal basis: We process contact form submissions based on our legitimate interest in responding to inquiries, or your consent where applicable.
Purpose: We use this information solely to respond to your request and communicate with you.
Retention: We retain contact form submissions for up to 1 month unless required longer for an active support matter, security issue, dispute, or legal obligation.
Your rights: You may request access, correction, or deletion of your submitted data at any time by contacting us.
Through emvara.ai (public website)
On our public-facing website, we collect limited information automatically, including IP address, browser type, device information, and page-visit data. This data is used for security, network management, performance monitoring, and privacy-friendly web analytics.
Specifically, our public website uses Cloudflare for CDN and security services (which processes IP addresses and sets strictly necessary cookies for bot protection), and Umami (self-hosted) for cookie-free, privacy-friendly web analytics (which processes anonymized page-visit data without setting cookies or tracking individuals across sites; all analytics data is processed on our own infrastructure). If you enable the optional anti-spam check on a form, hCaptcha may also process IP address and device information as described in Section 9 below.
4. AI Features and Data Processing
Emvara's AI assistant uses third-party language model providers to process your messages and generate responses. Our current AI provider is:
- Microsoft Azure OpenAI Service
When you use Emvara's AI features, your messages and relevant context may be processed by this provider in accordance with its privacy policy and contractual data protection terms. Do not submit sensitive personal information (such as payment card numbers, government ID numbers, or passwords) through chat or assistant conversations.
Emvara does not use your conversations, integration data, or any customer personal data to train our own generalized AI models. We also use provider controls and contractual terms intended to prevent customer content from being used to train third-party generalized AI models. Specifically: when customer content is submitted through Emvara via Microsoft Azure OpenAI Service (as configured in our production environment), that content is not used by Microsoft to train generalized models, subject to the applicable Microsoft Products and Services DPA. Azure OpenAI Service may retain limited content for short periods for abuse monitoring and safety purposes as described in its data processing terms. If our provider's terms or our configuration change materially, we will update this policy.
Automations configured through Emvara (such as scheduled tasks, triggered workflows, and integration actions) execute on your behalf based on rules and instructions you define. Emvara logs automation activity for transparency and debugging purposes.
5. Data Roles
Fluenik, LLC acts in different data-protection roles depending on the category of personal data and purpose of processing:
Emvara as controller: For account registration and administration, website visitor data, waitlist and contact form submissions, billing and payment data, security and abuse-prevention logging, error diagnostics, product usage analytics, direct marketing communications, and compliance and legal obligations, Fluenik, LLC acts as an independent data controller and determines the purposes and means of processing.
Emvara as processor: For customer content that you submit to Emvara through integrations and AI assistant conversations (such as emails, calendar events, CRM records, and project management data), Fluenik, LLC acts as a data processor on your behalf, processing that content to provide the services you have configured. You, as the account holder, determine the purposes for which this customer content is processed within Emvara.
Mixed-role processing: Some data may be processed in both roles. For example, conversation history and AI memory are processed as a processor to deliver the service you direct, and also as a controller for limited purposes such as maintaining service continuity, security monitoring, debugging, and enforcing our terms. Automation logs are similarly retained as a processor to provide transparency into actions taken on your behalf, and as a controller for diagnostics, security, and compliance purposes.
If you are a customer that requires Article 28 GDPR processor terms, our Data Processing Agreement is available at /data-processing-agreement.
6. Service Providers and Vendors
The following third-party service providers process personal data on our behalf or as part of providing Emvara. A full list with transfer mechanism references is published at /subprocessors.
- DigitalOcean — application hosting, managed PostgreSQL database, and managed Redis. Processes account data, conversation data, integration metadata, and all platform data stored at rest.
- AWS (Amazon S3) — object storage for file attachments and static assets. Processes uploaded files and knowledge-base documents.
- Microsoft Azure OpenAI Service — AI model hosting and inference. Processes conversation messages and context sent for AI response generation.
- Cloudflare — CDN, DDoS protection, bot management, and DNS. Processes IP addresses, request headers, and sets strictly necessary security cookies on page load across both emvara.ai and app.emvara.ai.
- Sentry — error monitoring and application diagnostics. Receives error reports and associated technical context (such as stack traces, request metadata, and browser/device information) when application errors occur on app.emvara.ai.
- Proton — email communications. Processes email addresses and message content for transactional and support email delivery (such as account verification, password resets, and privacy request responses).
- hCaptcha (Intuition Machines, Inc.) — anti-spam verification on contact and waitlist forms (consent-gated; not loaded unless the user enables it). Processes IP address and device interaction data when activated. See Section 9 for details.
- Umami (self-hosted) — cookie-free, privacy-friendly web analytics on emvara.ai, hosted on our own DigitalOcean infrastructure. Processes anonymized page-visit data (page URL, referrer, browser, OS, and country derived from IP address, which is discarded after processing). Does not track individuals across sites or sessions and does not set cookies. No analytics data is sent to any third party.
7. EU/EEA/UK Article 13 Privacy Notice
If you are in the EU, EEA, or UK, this section provides Article 13 GDPR transparency for personal information we collect directly from you through app.emvara.ai and emvara.ai.
- Controller: Fluenik, LLC (acting as controller for account, website, security, diagnostics, analytics, and compliance data; and as processor for customer content used to deliver the service, as described in Section 5).
- Controller contact: [email protected]
- Purposes and legal bases:
- Performance of contract (Article 6(1)(b)): providing and operating the Emvara platform, processing conversations, maintaining AI memory, executing automations, and connecting integrations under your account agreement.
- Legitimate interests (Article 6(1)(f)): securing our services and preventing abuse; error monitoring and diagnostics; product usage analytics; maintaining service continuity and debugging; enforcing our terms.
- Consent (Article 6(1)(a) and Article 9(2)(a)): sending promotional emails and product updates where you opt in; loading optional hCaptcha anti-spam verification when you enable it; processing health data from connected fitness integrations (special category data under Article 9) with your explicit consent.
- Legal obligation (Article 6(1)(c)): complying with applicable legal, regulatory, and accounting requirements.
- Recipients: hosting providers (DigitalOcean), object storage (AWS S3), security and CDN (Cloudflare), anti-spam verification (hCaptcha, consent-gated), AI/language model provider (Microsoft Azure OpenAI Service), error monitoring (Sentry), email communications (Proton), self-hosted web analytics (Umami, on our own infrastructure), and professional advisors where required.
- International transfers: our core services are hosted in the United States, and your information may be transferred to or accessed from the United States or other countries where our subprocessors operate. Where required, we rely on recognized transfer safeguards such as adequacy decisions (including the EU-U.S. Data Privacy Framework where applicable) and/or Standard Contractual Clauses (including required UK and Swiss transfer addenda).
- Retention: see Section 13 for specific retention periods by data category.
- Your rights: subject to applicable law, you may request access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent.
- Complaint route: you may lodge a complaint with your local supervisory authority. A directory of EU supervisory authorities is available via the EDPB: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
- Automated decision-making: we do not use solely automated decision-making that produces legal or similarly significant effects in relation to account access. AI-generated suggestions and automations are provided as tools under your control and do not constitute automated individual decision-making under GDPR Article 22.
8. California Notice at Collection (CCPA/CPRA)
At or before the point of collection, we provide this notice describing the categories of personal information collected, the purposes for collection or use, whether personal information is sold or shared, and retention periods.
- Categories collected: identifiers (name, email address, session ID, IP address); authentication credentials (password hash, 2FA tokens); professional information (workspace name, job title if provided); internet/network activity information (browser/device metadata, page interactions, integration connection logs); mailing-list subscription data (list membership, consent/opt-in status, unsubscribe status, and related timestamps); communications content (messages you send to the AI assistant); and integration data (emails, calendar events, tasks, contacts, and other records retrieved from connected third-party services at your direction).
- Sensitive personal information: if you connect health and fitness integrations, we may process health-related data (such as heart rate, sleep, and activity metrics) as described in Section 3. This data is collected only with your explicit consent when you authorize the integration, is not stored in a separate health database, and is subject to the same conversation retention policies described in Section 13. Please do not submit payment card numbers, government ID numbers, or similar data through the AI assistant or form fields.
- Business purposes: authenticating and operating your account; providing AI assistant services including conversation processing, memory, and automations; connecting to and retrieving data from third-party integrations at your direction; managing waitlists and mailing lists; sending product updates where you opt in; protecting services against spam and abuse; error monitoring and diagnostics; maintaining unsubscribe and suppression lists; maintaining business records; web analytics; and complying with legal obligations.
- Sold or shared: we do not sell personal information and do not share it for cross-context behavioral advertising.
- Retention by category: see Section 13 for specific retention periods by data category.
- Right to know, delete, correct, and opt out: California residents may exercise their rights under the CCPA/CPRA by contacting us at [email protected]. You may also designate an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization and may separately verify your identity. We will verify your identity before processing requests. We will not discriminate against you for exercising your privacy rights.
9. Cookies and Tracking Technologies
We use a small number of cookies and similar technologies to support security and functionality. We do not use advertising cookies.
- Session tokens — short-lived tokens stored in your browser (localStorage) after login to maintain your authenticated session on app.emvara.ai. These are functional, not tracking cookies, and are cleared when you sign out or your session expires.
- Cloudflare cookies (__cf_bm and related __cf_ prefixed cookies, strictly necessary) — our sites are served through Cloudflare, which automatically sets essential cookies to manage bot protection, security, and network performance. These cookies are set on page load, do not track you across sites, and are not used for advertising. They are governed by the Cloudflare Privacy Policy.
- Umami (no cookies, self-hosted) — we use Umami on emvara.ai for privacy-friendly web analytics, hosted on our own DigitalOcean infrastructure. Umami does not set any cookies, does not use personal identifiers, and is configured to avoid identifying individual visitors. It processes anonymized page-visit data (page URL, referrer, browser, OS, and country derived from IP). The IP address itself is discarded after processing and is not stored. No analytics data is sent to any third party.
- hCaptcha cookies (optional, consent-gated) — our contact and waitlist forms optionally use hCaptcha to protect against spam and automated abuse. The hCaptcha widget is not loaded, and no hCaptcha cookies are set, unless you explicitly enable the anti-spam check by clicking the “Enable anti-spam check” button on the form. If you enable it, hCaptcha may set cookies (such as hc_accessibility and hmt_id) and may collect IP address, device information, and interaction data for security and anti-bot purposes. These cookies and data collection are governed by hCaptcha's own policies, which describe broader data uses than our summary here; for full details, see the hCaptcha Privacy Policy and hCaptcha Terms of Service. If you do not enable the anti-spam check, no hCaptcha cookies are placed. You may disable the anti-spam check at any time before submitting, which resets and removes the widget.
10. How We Use Information
- Authenticate and operate your Emvara account.
- Provide, maintain, and improve the Emvara AI assistant platform, including conversation processing, AI memory, automations, and integrations.
- Connect to and retrieve data from third-party services you authorize via OAuth 2.0 to enable AI assistant functionality.
- Manage waitlists and mailing lists and send product updates where you opt in.
- Respond to support requests and account communications.
- Monitor errors and application performance for diagnostics and reliability.
- Analyze anonymized website usage through privacy-friendly analytics.
- Protect against fraud, abuse, and unauthorized access.
- Comply with legal obligations.
Most of the processing described above is necessary to perform our contract with you (providing the Emvara service) or is carried out under our legitimate interests in operating, securing, and improving our services. Where we rely on consent as the legal basis — specifically for promotional emails, product-update newsletters, and optional hCaptcha anti-spam verification — you may withdraw consent at any time by using the unsubscribe link in promotional emails, disabling the anti-spam check, or by contacting our Privacy Officer. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
Creating an account or submitting a form does not, by itself, constitute consent for all purposes. Account-related and service-delivery processing is based on our contractual relationship and legitimate interests, not consent.
11. Sharing of Information
We do not sell personal information. We do not share personal information with third parties for advertising or marketing purposes. We may share information with service providers that help operate our infrastructure (hosting, security, AI processing, error monitoring, email delivery, and analytics), subject to contractual confidentiality and security obligations. See Section 6 for a description of each service provider and the data it processes.
Third-party integrations: When you connect external services to Emvara, data flows between Emvara and those services as necessary to provide the functionality you have configured. Emvara accesses only the data and permissions you authorize. We do not sell integration data or share it with any other party.
AI providers: Your messages and relevant context are sent to our AI provider (Microsoft Azure OpenAI Service) solely to generate AI responses. This provider processes data under contractual terms that prohibit training on customer content, as described in Section 4.
Mailing lists and waitlists: Subscription data may be processed by service providers that support email delivery and list management on our behalf, subject to contractual confidentiality and security obligations. We do not sell this data and do not share it for cross-context behavioral advertising.
We may also share information where required by law or to enforce our rights.
Our current subprocessor list, including transfer mechanism references, is published at /subprocessors.
If you are a customer and need Article 28 processor terms, our DPA is available at /data-processing-agreement.
12. California Do Not Track Disclosure (CalOPPA)
Some browsers include a “Do Not Track” (DNT) setting. Because there is no universal standard for interpreting DNT signals, our website does not currently respond to DNT signals in a uniform way. We do not knowingly allow third-party advertising networks to collect personal information on our properties for cross-site behavioral advertising.
13. Data Retention
We retain personal information only for as long as needed for the purposes described in this policy, including legal, accounting, and operational requirements. The following retention periods apply:
- Account data (name, email, profile, authentication credentials) — retained for the duration of your account. After account deletion, retained in backups for up to 30 days, after which it is permanently deleted.
- Conversation history — chat messages with AI agents and Meeting Room conversations are automatically deleted after 7 days on free accounts and 30 days on personal and business accounts. You can also permanently erase a conversation's chat log at any time by starting a new chat with the agent or meeting room. After account deletion, any remaining conversation data is deleted within 30 days.
- AI memory — retained for the duration of your account to provide personalized assistance. You can disable AI memory entirely or delete individual memories at any time from your account settings. When disabled, no new memories are created. After account deletion, AI memory data is deleted within 30 days.
- Integration data and cached content — OAuth tokens are retained while the integration is connected. Cached content from connected services (emails, calendar events, tasks, etc.) is deleted within 30 days of disconnection or account deletion.
- Health and fitness data — health metrics from connected fitness integrations (Fitbit, Oura, Strava, WHOOP, Withings, Garmin) are retrieved on demand and are not stored in a separate health database. Health data may appear in conversation history, which is automatically deleted after 30 days (or 7 days for free accounts). When you disconnect a health integration, we immediately stop retrieving data from that service.
- Automation logs — retained for the duration of your account for transparency, debugging, and audit purposes. Deleted within 30 days of account deletion.
- Security and diagnostic logs — retained for up to 90 days for security monitoring, error diagnostics, and abuse prevention, unless a longer period is required for an active investigation or legal obligation.
- Request logs (server/application audit logs stored in OpenSearch) — automatically deleted after 90 days via an index lifecycle policy.
- Contact form submissions — retained for up to 1 month unless required longer for an active support matter, security issue, dispute, or legal obligation.
- Waitlist and mailing-list records — retained while you remain subscribed. After unsubscribe, we retain minimal suppression-list records (email address and opt-out timestamp) for as long as needed to honor your opt-out and comply with anti-spam laws.
- Web analytics data (Umami, self-hosted) — anonymized and aggregated; no personal data is retained.
14. Data Security
We apply reasonable technical and organizational safeguards designed to protect personal information, including:
- Encrypted transmission (HTTPS/TLS) for all data in transit.
- Hashed password storage using industry-standard algorithms.
- Encryption at rest for OAuth tokens, 2FA secrets, and other sensitive credentials.
- Role-based access controls and least-privilege principles.
- Managed PostgreSQL and managed Redis on DigitalOcean App Platform with automated backups.
- Cloudflare DDoS protection and bot management.
No system can be guaranteed 100% secure. We cannot guarantee absolute security of information transmitted over the internet.
15. Hosting Infrastructure
Emvara is hosted on DigitalOcean App Platform in the United States, with managed PostgreSQL for database services and managed Redis for caching and session management. Static assets and object storage use Amazon S3. All infrastructure providers are listed on our subprocessors page.
16. Access, Correction, and Challenge Process
You may request access to personal information we hold about you, request corrections, or challenge our compliance with applicable privacy laws by contacting our Privacy Officer at [email protected].
- We may need to verify your identity before processing requests.
- We aim to respond within timelines required by applicable law, including Canadian privacy laws where they apply.
- If you are not satisfied with our response, you may escalate concerns to the appropriate privacy regulator, such as the Office of the Privacy Commissioner of Canada or a relevant provincial or national data protection authority.
17. Regional Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or limit use of your personal information. Submit requests by contacting us at [email protected].
If you receive promotional emails from us, you can unsubscribe at any time by using the unsubscribe link in the message.
For California residents, please see our California Notice at Collection above for CCPA/CPRA-specific rights and procedures.
For EU/EEA/UK residents, please see our Article 13 Privacy Notice above for GDPR-specific rights and procedures.
For Canadian visitors, rights and obligations may vary by jurisdiction, including federal law (PIPEDA) and applicable provincial private-sector privacy laws.
18. Children's Privacy
Emvara services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us at [email protected] so we can delete it promptly.
19. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. If we make material changes, we will provide notice through the Emvara platform or by email where practicable.
Where a material change involves a new use of personal data that requires consent under applicable law, we will obtain that consent before the new use takes effect. Your continued use of our services after non-material updates constitutes acceptance of the revised policy; for material changes, we will notify you and, where required, seek your consent.
20. Contact
For privacy questions or requests:
See also:
← Back to Home