EMBER & ELM
Privacy Policy

**DRAFT — attorney starting point. Not legal advice. Review and finalize with counsel (including state

wiretap / two-party-consent exposure) before launch.**

Last updated: July 9, 2026 · Operator: KlockWorks Consulting, LLC ("Ember & Elm," "we," "us") · Contact: [email protected]

Plain-language summary

Ember & Elm is a moderated, members-only (21+) community. To keep it safe, lawful, and working, **the operator

and its AI agents can access content you post or send** — for moderation, safety, legal compliance, and

operations. **We are not end-to-end encrypted, and "private" spaces are private from other members, not from our

safety and moderation systems.** We collect only what we need, restrict and log internal access, and let you

request access to or deletion of your data. If you wouldn't want it reviewed for safety, don't post it here.

1. Information we collect

provider and do not store your ID image or raw ID fields beyond what the verification step requires.

2. How we use information

To operate the Service; verify eligibility (21+); personalize your experience (including AI-agent memory of your

preferences); moderate the community and keep it safe; detect and stop fraud, attacks, and abuse; communicate

with you; process payments; comply with law; and improve the Service.

3. Access disclosure — what we and our agents can see

Ember & Elm is not end-to-end encrypted. Authorized staff and AI agents may access your content for

moderation, safety, legal compliance, and operations:

(e.g., preferences, cigars you own, avoidances) to personalize help. You can view and request deletion of what

an agent remembers about you.

Any feature called "private," "women-only" (including Ember & Iris), or "members-only" is **hidden from other

members, not from our moderation, safety, and security systems, and is not end-to-end encrypted.**

4. How we share information

We share with service providers who help us run the Service under contract — for example payment processors,

hosting/database providers, the age-verification provider, and the AI model and web-search providers that power

our agents. We may disclose information to comply with law or lawful requests, to protect safety and our

rights, and in a business transfer. We do not sell your personal information.

5. Data minimization and retention

We collect and keep only what we need for the purposes above, set retention limits, and delete or de-identify

aged content where feasible. Some data is retained longer where required by law (e.g., financial records) or to

resolve disputes and enforce our Terms.

6. Internal access controls

Not everyone on our team can see everything; access follows least-privilege and our consumer/management boundary.

Administrative and agent access to member content is logged to an immutable audit trail.

7. Security and breach notification

We maintain administrative, technical, and physical safeguards and a written incident-response plan, and will

notify affected members and regulators within the windows applicable law requires. No system is perfectly secure.

8. Your privacy rights

Depending on where you live (e.g., under CCPA/CPRA and similar state laws), you may have rights to access,

correct, delete, or port your personal information, and to limit certain uses — including a request to delete

what an AI agent remembers about you — subject to legal retention duties. To exercise rights, contact

[email protected]. We will not discriminate against you for exercising them.

9. Children

Ember & Elm is strictly 21+ and not directed to children. We do not knowingly collect data from anyone under

13 (COPPA) or permit anyone under 21 to use the Service. If we learn we have collected data from a child, we will

delete it.

10. Sensitive and special-category data

and consented to, consistent with laws such as Illinois BIPA. [Counsel to confirm before any such feature.]

sensitivity and is still subject to the access disclosure above.

11. Cookies and similar technologies

We use cookies/local storage needed to run the Service and to remember your settings. [Counsel/engineering to

list any analytics or tracking; note session-replay and similar tools raise wiretap-law exposure — see §13.]

12. International users

The Service is operated from the United States; by using it you understand your information is processed in the

U.S. [Counsel to address cross-border transfer mechanisms if you accept EU/UK users.]

13. A note on wiretap / two-party-consent laws

Several U.S. states (e.g., California's CIPA, Illinois, Florida) are two-party-consent jurisdictions with active

litigation over message interception and session replay. Real-time interception is legally distinct from storing

messages you send to the platform. This is flagged for counsel to review against where our members are located.

14. Changes to this Policy

We may update this Policy; we will post the updated version with a new "Last updated" date and, for material

changes, provide reasonable notice.

15. Contact

Privacy questions or requests: [email protected]

© Ember & Elm. *Draft for counsel review; not legal advice. Companion frameworks:

Ember-and-Elm-Access-and-Privacy-Disclosure.md, Ember-and-Elm-Lawful-by-Design.md, Ember-and-Elm-Security-Division.md.*