Privacy Policy

What we collect, what we don't, and what you can ask us to do about it.

Short version: we collect what you type into our forms or send us by email, what you choose to connect (Google, GitHub), the standard server logs every host keeps, and one anonymous step counter. We don't sell it. We don't track you across the web. We don't run advertising pixels. If you want your data deleted, email us and we'll do it — the only records we must keep are the payment ones the law requires (Section 5).

Effective: September 6, 2026 · Last updated: September 6, 2026 · Governing law: State of Oregon, USA.

1. Who is collecting your data

Emaration LLC, an Oregon limited liability company doing business as Emaration.AI, with a principal place of business in Astoria, Oregon, USA. When this page says "we," "us," or "Emaration," we mean Emaration LLC.

You can reach us at human@emaration.ai.

2. What we collect

Four categories: what you type, what you connect, what the server logs, and one anonymous counter. Each one is broken out below rather than summarized, because a short list here is only reassuring if it is the whole list.

2.1 Information you give us directly

The free account asks for the least: your email, and — all optional — your name, your website (or a tick that you don't have one), your industry, and how many locations you have.

The full audit intake asks for a great deal more, and it is worth seeing plainly. Across its steps it can collect:

  • Your business: name, category, your industry in your own words, service area, and your website address.
  • Your market: up to three competitors you name, and the buyer-intent questions you want to be found for.
  • Your numbers, if you choose to share them: monthly revenue band, average order value, customer lifetime value, conversion rate, and marketing budget. Every one of these is optional — the intake has a "share numbers" choice and a "don't know" option, and skipping them changes what we can measure, not whether we will work with you.
  • Your brand and your site: personality and guardrails in your own words, color preferences, a reference site you like, what your site must do, what you want featured, which integrations it uses, your review sources, and your social links.
  • Links you paste: Google Drive, Dropbox or SharePoint links to your own materials. We only ever see what those links let us see.
  • A free-text answer about what you want fixed.

When you email us, we receive your email address and whatever you wrote. If you become a member, we also hold your account record, your sign-in tokens, your saved reports, and the decisions you approve.

2.2 Accounts you connect

Some of the work needs read or write access to systems that are yours, not ours — and one of the two ways to sign in uses an account of yours as well. You grant each of these in their interface, not by handing us a password, and you revoke it there too:

  • Google Analytics 4 and Search Console: read-only, so we can measure. You connect them from your member portal; until you do, those features render a "not connected" state and read nothing.
  • Sign in with Google: a member who presses "Continue with Google" instead of using the emailed sign-in link approves it on Google's own consent screen. Google sees your IP address and the ordinary request details any browser sends, and learns you are signing in to Emaration; we send it nothing about you, because at that point we do not know who you are. It sends back your email address and its confirmation that the address is verified. We ask for the basic profile scope too, so Google may return a name and picture — our code reads neither, and we store nothing Google returns. It never creates an account: an email that is not already a member's is refused. The emailed link is always there and involves Google not at all.
  • GitHub: if you want approved fixes delivered into your own code, you install our GitHub App and choose the repositories. We store the installation id — which grants nothing on its own — and mint a token that expires in about an hour and reaches only the repositories you picked. We read those repositories to place the change and leave it there as a proposal for you to review. Nothing is merged; accepting or closing it is yours.

2.3 Standard server logs

Like every web server on earth, our host records the IP address, browser type, referring page, and timestamp for each request. We use this only for debugging and abuse detection. We do not link these logs to identifiable people for advertising purposes.

2.4 One anonymous funnel counter

Each page carries a step name ("saw pricing", "started the form"), and the browser posts that step and a timestamp back to us so we can count how many people reach each stage. It sends no identifier, no cookie, and not even the page's address — just the step. It counts what actually happened and never estimates the rest. It does not fire at all if your browser sends Do Not Track or Global Privacy Control, or if you have JavaScript off.

2.5 What we do NOT collect

  • We do not run third-party advertising pixels (no Meta pixel, no LinkedIn Insight tag, no Google Ads conversion pixel on this marketing site).
  • We do not use session-replay tools, and we do not track you across other websites. The funnel counter in 2.4 is the only measurement of any kind on this site, it is first-party, and it cannot follow you anywhere.
  • We do not sell, rent, or trade any data to anyone.
  • We do not collect protected categories of personal information (race, religion, health, sexual orientation, etc.) unless you volunteer them, in which case we still don't sell them.

3. Why we collect it

Three reasons:

  • To answer you. If you fill out the form, the only reason we have your data is to reply — we aim to do that within one business day — and run the audit you asked for.
  • To deliver the work. If you become a client, we need your data to send invoices, deliver findings, and stay in touch.
  • To keep the site working. Server logs help us debug, prevent abuse, and keep the form from being overrun by bots.

4. Who we share it with

Only the vendors that do a job for us, and the law when it compels us. The detail:

4.1 Vendors that process data for us

We use a small number of vendors who see your data only to do their job. The ones that touch personal data:

  • Hosting, DNS and edge storage (Cloudflare): serves this website, runs the code, and processes form submissions. Also the human-check on our forms, and the on-site assistant, which sees the question you type into it.
  • Our database (Neon, serverless Postgres): where your account, your intake answers, your contact details and your reports actually live. This is the main store of personal data we hold, and leaving it off this list was an omission we have since fixed.
  • Transactional email (Resend): delivers sign-in links, notifications and acknowledgements, and receives your email address and the full message. MailChannels is a fallback wired in code but not provisioned — we have no record of a message being delivered that way, and the register below says so.
  • Business email and files (Google Workspace): to receive and send email, and to share working files.
  • Payments (Stripe): membership billing and any one-off purchase. Card details go to Stripe directly and never reach our servers — we keep the customer and subscription identifiers, the price, and the status.
  • Accounting (Intuit QuickBooks): invoicing for paid engagements, when that connection is configured.
  • Working tools (Notion for project notes and drafts; Make.com for routing between systems we run): notes and drafts that reference your business, and the metadata that moves between our own tools.
  • Call tracking (CallRail): only if you ask us to set up call tracking for you — it is never part of onboarding. It would receive your callers' phone numbers and, if you turn recording on, the calls.
  • AI vendors (Anthropic for the writing we do; Anthropic, OpenAI, Perplexity, Google Gemini and xAI Grok as the answer engines we measure against): the measurement engines receive the buyer-intent questions on your prompt panel and nothing else — not your domain, which we match against their answers on our side.
  • GitHub: only if you connect it, and only for the repositories you choose. See Section 2.2.
  • Sign in with Google (Google LLC): only if you use "Continue with Google" rather than the emailed sign-in link. See Section 2.2 for exactly what crosses.
  • Security-header scan (Mozilla): our free scan at /tools/security-scan passes the hostname typed into it to Mozilla's HTTP Observatory, which does the scanning. That hostname is the only thing we send — along with the request metadata any HTTP client sends, which comes from our server rather than your browser — and the tool needs no account.

Ahrefs and Screaming Frog are on the register too; they read only public web pages, never personal data. Each of these vendors has its own privacy commitments and is limited to using your data to provide the service to us. The full register — every vendor, what it receives, where it sits, and what we have and have not verified about it — is at emaration.ai/sub-processors. That page is the canonical list; this one is the summary, and an automated test keeps the register honest against our own compliance records.

4.2 Legal requests

If a court order, subpoena, or law enforcement request legally compels us to share data, we will comply, and we will tell you about it unless we are legally prohibited from doing so.

4.3 Business changes

If Emaration is ever acquired or merged, your data may transfer to the successor entity. The successor is bound by this policy unless you are notified and given a chance to opt out.

5. How long we keep it

We delete nothing on a timer of our own. Data stays until you ask us to delete it (Section 7.4), and then it goes. Two exceptions: server logs, which our host rotates on its own schedule, and the payment and invoice records the law requires us to keep, for as long as it requires.

  • Form submissions from people who don't become clients: kept until you ask us to delete them. This page used to promise deletion after twelve months; nothing in our systems enforced that, so we have stopped saying it.
  • Client records: kept until you ask us to delete them, except the payment and invoice records the law requires us to keep.
  • Server logs: rotated by our host; we do not set that schedule, so we do not quote a number for it.
  • Email correspondence: kept as long as the relationship needs it, and deleted when you ask.

6. Cookies and tracking

No tracking cookies, no analytics cookies, no advertising cookies. This site writes two first-party cookie-equivalents in localStorage: your accessibility preferences (theme, font, text size, motion), and a single date that stops a phone intro video from replaying more than once a day. Neither identifies you. The funnel counter in Section 2.4 sets nothing in your browser — no cookie, no storage.

The pages with a form also load Cloudflare's Turnstile human-check from challenges.cloudflare.com — the site's only third-party embed. The full breakdown of both storage keys and that embed lives on our Cookie Policy page.

6.1 Strictly necessary cookies on the member portal

Signing in to the member portal at members.emaration.ai sets the cookies below. Each one keeps you signed in or protects that sign-in; none tracks you and none is shared with anyone. Two are set on .emaration.ai so that our other subdomains recognize the same sign-in; the rest are readable only by the portal host that set them. Signing out expires em_session and em_member.

Cookies the member portal sets at sign-in, with purpose, scope, lifetime and attributes.
NameWhat it holds and whyDomain and pathLifetimeAttributes
em_sessionYour signed sign-in token — the one identity every emaration.ai subdomain recognizes..emaration.ai, path /14 daysHttpOnly; Secure; SameSite=Lax
em_csrfA random token the portal's own pages echo in a request header, so a form posted from another site cannot act as you. Readable by page scripts — that is how it does its job. If it is missing, a product subdomain may re-issue it for the length of the browser session..emaration.ai, path /14 daysSecure; SameSite=Lax; not HttpOnly
em_memberThe emailed sign-in token itself, for the portal host only.members.emaration.ai only, path /14 daysHttpOnly; Secure; SameSite=Lax
em_mfa_okProof that this sign-in cleared your second factor, so the code is not asked for again.members.emaration.ai only, path /14 daysHttpOnly; Secure; SameSite=Lax
em_mfa_pendingA ticket that carries you from the sign-in link to the second-factor prompt.members.emaration.ai only, path /10 minutesHttpOnly; Secure; SameSite=Lax
em_mfa_enrollWhile you enroll an authenticator app, the sealed secret being enrolled, so your confirmation code can be checked.members.emaration.ai only, path /15 minutesHttpOnly; Secure; SameSite=Lax
em_nextThe page you were heading to when we asked you to sign in, so you land there afterwards. Used once, at sign-in.members.emaration.ai only, path /30 minutesHttpOnly; Secure; SameSite=Lax
em_social_stateA one-time value for a "Continue with Google" round trip, checked when Google sends you back.members.emaration.ai only, path /10 minutesHttpOnly; Secure; SameSite=Lax
em_gh_connectA one-time value that binds a GitHub App connection to the browser that started it.members.emaration.ai only, path /api/github/30 minutesHttpOnly; Secure; SameSite=Lax

An automated test in our build reads the code that sets these cookies and fails if the portal sets one this table does not name, or with a scope, lifetime or attribute the table misstates.

7. Your rights

Depending on where you live, you may have specific legal rights about your data. We honor all of them for all of our users, regardless of jurisdiction.

7.1 Oregon Consumer Privacy Act (effective July 2024)

You have the right to know what data we have about you, correct it, delete it, get a portable copy, and opt out of any sale or targeted advertising. (We don't sell or use your data for targeted advertising, see Section 2.5, but the right exists regardless.)

7.2 California Consumer Privacy Act / CPRA

You have the same set of rights under California law: access, correction, deletion, portability, and opt-out of sale. We do not sell data. We do not knowingly collect data from California residents under 16 without verifiable consent.

7.3 EU / UK (GDPR)

If you are in the EU or UK, you have the right to access, rectify, erase, restrict processing, port your data, and object to processing. The legal basis we rely on is (a) consent when you submit the form, (b) contract when you become a client, and (c) legitimate interest for server logs and abuse prevention.

7.4 How to exercise any of these rights

Email human@emaration.ai with what you want. The law that applies to you sets the deadline for our answer — usually thirty days — and we meet it. Where no law sets one, thirty days is our aim, and we try for much sooner. We do not charge a fee for the first request in any twelve-month period.

8. Children's privacy

This site is for businesses and the adults running them. We do not knowingly collect data from anyone under sixteen. If you believe a minor has submitted data, email us and we will delete it.

9. How we protect your data

Reasonable technical and organizational measures, the same standard you would expect from any small professional services firm:

  • TLS encryption for all traffic between your browser and our site.
  • Strong unique passwords and two-factor authentication on every administrative account.
  • Limited access: only the founders see form submissions and client data.
  • Vendor selection biased toward companies with serious security commitments (Cloudflare, Google Workspace, Stripe).

If we ever experience a data breach affecting your personal information, we will notify you within seventy-two hours of becoming aware of it, by email and through a notice on this site.

10. Changes to this policy

If we change this policy in a way that materially reduces your privacy protections, we will email everyone who has given us an email address and update the "Last updated" date at the top of this page at least thirty days before the change takes effect. Less-than-material changes get an updated date and that's it.

11. Contact

Questions, requests, or just want to confirm what we have on you? Email human@emaration.ai. A human answers every one — we aim to respond within one business day.

Emaration LLC dba Emaration.AI · Astoria, Oregon, USA · human@emaration.ai