LastEmber ("LastEmber," "we," "us," or "our") is a minimalist Moment-preservation app that lets people leave one carefully chosen Moment in the world every few days, and receive quiet emotional resonance from strangers. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using LastEmber, you agree to the practices described here.
LastEmber uses Sign in with Apple exclusively. We do not support email/password registration, and we do not request your name, email address, phone number, or contacts. Apple provides us with a stable, anonymous identifier for your account; we do not receive or store your real Apple ID email unless you explicitly choose to share it through Apple's relay service, and even then we do not use it for marketing.
When you publish a "Moment," we store:
If you enable location access, LastEmber records only a city-level, coarse location when you publish a Moment — never your precise GPS coordinates, and never your real-time location while browsing. If location is enabled, any coordinate used for place-based visualization is further obfuscated with a random offset of 2–5 km around your city center before being stored. You can use LastEmber fully with location access turned off; this only disables city context and related place features for your Moments.
We record limited interaction signals required to operate the app's core mechanics:
| Purpose | Data Used | Legal basis where GDPR/UK GDPR applies |
|---|---|---|
| Operating core app functionality (publishing, Resonance distribution, drafts, account access) | Account identifier, Content, optional city context, interaction signals | Performance of a contract; legitimate interests in operating the App |
| Content moderation and platform safety | Content, reports, automated safety-classifier results, moderation logs | Legitimate interests in user safety and abuse prevention; legal obligations where applicable |
| Preventing abuse, spam, and scripted access | Anonymous account identifier, request frequency, device integrity signals, security logs | Legitimate interests in security and fraud prevention |
| Moment Guardianship subscription entitlement (if purchased) | App Store transaction identifier, subscription period/status, entitlement-sync metadata | Performance of a contract; legal obligations for transaction records where applicable |
| Optional notifications and city context | Push token; optional coarse city context | Your consent or device permission, which you may withdraw in iOS Settings |
We do not sell your personal information, and we do not use your content or coarse location for targeted advertising.
To keep LastEmber safe, every post is automatically screened by an AI-based content safety filter (for spam, links, contact information, QR codes, and clearly harmful content) before it can be distributed publicly. We also operate a reporting and blocking system: reports are reviewed by automated systems and, where necessary, human moderators within 24 hours. See our Community Guidelines for details.
Depending on your region, you may have additional rights. To exercise these rights, contact us using the details below. We may need to verify that the request comes from the account holder before acting on it.
Where GDPR, UK GDPR, or similar law applies, you may have the right to request access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent for optional features. You may also lodge a complaint with your local data protection authority. We do not use your data for solely automated decisions that produce legal or similarly significant effects.
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you. Depending on your state, you may have rights to know, access, delete, correct, obtain a portable copy of, or appeal a decision about your personal information. You may use an authorized agent where applicable law allows it, subject to verification.
You may request access to or correction of personal information we hold about you. You may also contact us to complain about how we handle personal information; we will review and respond within a reasonable time. If unresolved, you may contact your local privacy regulator, such as the Office of the Australian Information Commissioner or the Office of the Privacy Commissioner in New Zealand.
LastEmber is not directed at children under 13 (or the minimum age required by your country of residence). If your country requires a higher age for digital consent, you must meet that higher age or use the App only with valid parental/guardian consent. We do not knowingly collect personal information from children. If you believe a child has used LastEmber to create an account, please contact us so we can remove the associated data.
LastEmber is available worldwide, and your data may be processed on servers located outside your country of residence, including through Apple and Google/Firebase infrastructure. Where required, we rely on adequacy decisions, standard contractual clauses, data-processing agreements, or comparable safeguards provided by our infrastructure providers to protect data transferred internationally.
| Service | Purpose |
|---|---|
| Apple — Sign in with Apple | Authentication |
| Google Firebase (Firestore, Cloud Storage, Cloud Functions, Firebase Cloud Messaging) | Backend data storage, server logic, push-token delivery, moderation processing, and cached translation task orchestration |
| Google Cloud Translation | Translation of Moment text and city names through Cloud Functions when a cached translation is not yet available |
We do not embed third-party advertising or analytics SDKs that track users across apps.
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above, and where appropriate, communicated in-app.
For users in Japan, this policy identifies the purpose of use, categories of personal information, security controls, contact point, and overseas processing providers. We process personal information only within the purposes stated in this policy, except where Japanese law permits otherwise. Requests for disclosure, correction, suspension of use, or deletion may be sent to the contact address below.
If you are a resident of the Republic of Korea, the Personal Information Protection Act ("PIPA") requires the following itemized disclosure in addition to the general terms above:
| Item | Disclosure |
|---|---|
| Personal information collected | Anonymous Sign in with Apple identifier; content you publish (text/photo); coarse, city-level location (only if you enable it); interaction logs (seen Moments, Resonance/Connection records); reports you submit; blocked-account list |
| Purpose of collection and use | Operating core app functionality, content moderation and platform safety, abuse/spam prevention, premium subscription entitlement |
| Retention period | Public Moments: 30 days in public circulation (see Section 5). Account-related data: retained until you delete your account, then permanently erased per our Account Deletion Policy, except where retention is required by law |
| Provision to third parties | We do not provide your personal information to any third party for their own purposes. Data is processed only by our infrastructure provider (Google Firebase) strictly to operate the App, as described in Section 9 |
| Entrusted processing / overseas processing | Apple and Google/Firebase may process data outside Korea for authentication, cloud hosting, server logic, push notifications, and translation support, as described in Sections 8 and 9 |
| Right to refuse consent | You may decline to provide optional information (e.g., location); declining only disables the related optional feature and does not prevent you from using the App. You cannot use the App without the minimum information needed for Sign in with Apple authentication |