Draft for owner review — effective at launch. This page describes how our products work today. It becomes our policy when E:MERGENCE launches publicly.
Privacy Policy
Your work stays yours.
This policy explains what E:MERGENCE LLC collects when you use our websites, your E:MERGENCE account, and our apps (E:Voice, AERIS Node, AERIS OS, Charles and Roofer Buddy). It also covers what stays on your own devices, who else receives data, and how to delete it.
The short version
- E:Voice keeps your workspace on your phone. That means your conversations, AERIS Node memory, E:Docs and vault.
- Content leaves your device only when a feature needs it, and it goes to the provider or computer you chose.
- We keep what we need to run your account: email, username, sign-in and subscription records.
- We do not sell your personal information. There is no advertising in our apps and no advertising identifier.
- Our websites use Google Analytics, which sets cookies, to count visits. You can opt out (see Your choices).
- You can delete your account yourself, from the app or the web, without asking us.
1. Who we are
E:MERGENCE LLC ("E:MERGENCE", "we", "us") makes E:Voice, AERIS Node, AERIS OS, Charles and Roofer Buddy. It also runs emergencerising.com, emergencelanding.com and e-mergencefab.com. Dan Riding is the founder. For anything in this policy, write to evoice@emergencerising.com. A real person reads it.
Each app also has its own detailed notice. For E:Voice, see the E:Voice Privacy Policy and Manual chapter 10, "What leaves your phone". Where those notices are more specific about an app, they apply to that app. This page covers the whole company.
2. Our websites
When you visit one of our sites, three kinds of data are involved:
- Server logs. Our web server records each request: your IP address, browser and device type (user agent), the page you asked for, the referring page and the time. We use these logs to keep the sites running and to stop abuse.
- Google Analytics 4. Our pages load Google Analytics a moment after the page settles. It tells us how many people visit, which pages they read, roughly where they are (Google estimates the country or city from your IP address), what device and browser they use, and where they came from. We also count a few clicks: links to Google Play, app downloads, sign-up links and pricing links. Google Analytics sets first-party cookies to do this (see Cookies). We do not use it for advertising, and we do not load it on the owner's private dashboards.
- Google Fonts. Our pages load their typefaces from Google Fonts. To send the fonts, Google receives your IP address and browser details.
You can read our sites without an account. Nothing you do on a public page is tied to your identity unless you sign in.
3. Frank, the website assistant
The round Frank button on our pages opens a support chat. If you send Frank a message:
- Your message and Frank's reply are stored on our account server. They are linked to a hashed visitor identifier, and to your account if you are signed in. We use them to answer you, to limit abuse and to improve our help pages.
- Your message and the last few turns of the chat go to an OpenAI model, which writes the answer. Frank has no tools: it cannot see passwords or payment details, and it cannot change your account.
- Your browser keeps a conversation ID for the current tab session only.
We have not yet set an automatic deletion period for Frank chats. Until we do, email us and we will delete yours. Please do not type passwords, keys or payment details into Frank.
4. Your E:MERGENCE account
One account signs you in to E:Voice, AERIS OS, the Landing community and our other apps. The account service handles:
- Account and profile: email address, username, display name, profile settings, and any profile or community content you choose to post.
- Sign-in and security records: password hashes (never the password itself), session and token hashes, API and bridge credential metadata, access grants, and security and audit events. These events include IP address and user agent.
- Entitlements: your plan, subscription status and download access.
- Device continuity: if you use sync, an encrypted push token, an install-scoped device ID, app version and short "doorbell" records. A doorbell wakes your other device. It never contains your messages, memory or project content.
- Things you send us: feedback, bulletin posts, comments, uploads, AI-response reports and crash reports. The app sends a crash report only when you press Send, and it shows you the exact fields first.
We use this information to sign you in, provide downloads and paid features, connect the runtimes you authorise, operate community features, prevent abuse, fix failures and support you.
5. Payments
You pay either through Stripe on the web or through Google Play in the Android app. Stripe or Google handles your card or payment details. We never see or store your full card number. We receive the facts needed to grant access: the plan, the subscription status and dates, and the store's own purchase or customer identifiers. Stripe and Google keep their own payment, fraud-prevention and legal records under their own policies. Those records can survive the deletion of your E:MERGENCE account.
6. E:Voice on your phone
E:Voice is local-first, but it is not "fully offline". Here is what that means in practice:
| Stays on the phone | Leaves the phone, when you use the feature |
|---|---|
| Conversations, AERIS Node memory, E:Docs, vault data, voice-training corrections, profile pictures | Message content goes to the AI provider answering you, or to the runtime you paired |
| Provider keys and your pairing token, in encrypted storage behind your phone's lock | Voice audio goes to a cloud speech provider, but only if you pick one. The default recogniser runs on the device. |
| Crash details, until you choose to send a report | Photos and files, when you attach them or send them to an agent |
| Backups you export, saved or shared where you choose (not encrypted, so keep them safe) | Managed voice, dictation and image generation go through E:MERGENCE services to our voice and image providers |
E:Voice does not collect your location, contacts, calendar, SMS, call logs, health data or browsing history, or the list of apps on your phone. It has no location permission. It does not read hardware identifiers such as IMEI or Android ID. It uses no advertising identifier and includes no third-party analytics. The phone-state permission lets it pause voice when a call starts; it does not read your call log or phone numbers. If you share a contact with Android's picker, that one contact becomes message content and goes to the provider or runtime you chose.
Deleting your account (Settings → Account → E:Voice Account → Delete account) removes the server-side account. It does not erase data held only on the phone. To remove that, clear the app's storage or uninstall E:Voice.
7. AERIS Node memory
AERIS Node is the memory your agents share: projects, agents, docs, tasks, decisions and preferences, organised as a graph. It lives on your phone.
- Indexing is local by default. If you choose provider-assisted indexing, the relevant memory content goes to the provider you picked for that feature.
- You can control what agents see. You can pin, suppress, restore or delete entries one at a time. Entries the app derives rather than stores are read-only. You can limit memory to local agents, so paired external agents receive none.
- Turning AERIS Node off stops new writes but does not delete existing entries, and "Clear Context" in a chat does not delete memory either. Use Delete for that.
- Sync is optional. It needs a paid plan and a desktop you pair. It runs between your own signed-in devices. Unpairing stops future sync but does not delete what is already on the other device. Remove that copy there.
8. AERIS OS on your computer
AERIS OS is our desktop app. The first launch asks you to sign in, so that our server can confirm what your plan includes. After that, your dashboards, agent setup and any synced history are stored on your own computer. They stay there until you remove them or uninstall AERIS OS. The account service learns that the app signed in and checked your entitlement. It does not receive the contents of your desktop.
9. AI you connect yourself
E:Voice and AERIS OS can work with AI services and agent runtimes you already use, such as Claude Code, Codex, Cursor, Hermes, OpenClaw, Agent Zero, Grok, OpenAI, Anthropic, Google Gemini, OpenRouter or an endpoint you enter. Those are your own accounts with those companies. The content you send them is processed under their terms and privacy policies, and they may charge you. When you talk to an agent on your own computer, the traffic goes from your phone to that computer over your private network. E:MERGENCE is not a relay in that path. We only hand out the one-time setup code.
10. Who else receives data
We do not sell personal information, and we do not share it for cross-site advertising. We use these service providers, and each receives only what its job needs:
| Provider | What for |
|---|---|
| OVHcloud | Server hosting for our websites and account service |
| Stripe | Web subscription billing |
| Google Play | In-app subscriptions and app distribution |
| Google Analytics, Google Fonts | Website visit statistics; web typefaces |
| Firebase Cloud Messaging (Google) | Wake-up notifications for sync. Metadata only, no content. |
| Cloudflare Turnstile | Checking that sign-ups are human |
| Resend | Account emails, such as verification and password reset |
| ElevenLabs | Managed premium voices and managed dictation |
| OpenAI | Frank's website answers; managed image generation |
We may also disclose information if the law requires it, to protect people or our services from harm, or as part of a sale or reorganisation of the business. If the business changes hands, this policy would continue to apply to your data.
11. How long we keep things
- Data on your devices: it stays until you delete it. Deleting your account does not reach into your phone or computer.
- Account, profile and your content: kept while your account is active. It is deleted when you remove it or when a verified account deletion completes.
- Sessions, keys and bridge credentials: kept while in use. They are revoked when they expire, when they are replaced, or as soon as account deletion starts.
- Sync doorbells: up to 7 days.
- Crash reports: up to 90 days. AI-response reports: up to 365 days. Both are redacted on arrival. Deleting your account removes your link to them.
- Security records and server logs: kept as long as needed to protect accounts and investigate abuse.
- Google Analytics: kept for the retention period set in our Analytics property. Google allows 2 or 14 months.
- After account deletion: we keep only an opaque receipt, so you can check that the deletion finished. It contains no user ID, email or profile.
12. Your choices and rights
- Delete your account yourself: in E:Voice go to Settings → Account, or use the account deletion page. Deletion revokes access immediately. It finishes after any Stripe subscription is cancelled and your uploads are removed.
- See, correct or export your data: most account details are in your account settings. For anything else, email evoice@emergencerising.com from your account's address. We will confirm your request and reply.
- Opt out of website analytics: open any page of our site with
?ea_optout=1at the end of the address, for example emergencerising.com/?ea_optout=1. That device stops loading Google Analytics on our sites. Use?ea_optout=0to turn it back on. Blocking cookies, or using Google's opt-out browser add-on, also works. - Choose your routes: in E:Voice you choose on-device speech and voices, local-only memory indexing, and whether to pair or sync at all.
Depending on where you live, you may have legal rights to access, correct, delete or port your personal information, or to object to certain uses. We honour those requests for every user, wherever they live. You will not be treated differently for using them.
13. Cookies and browser storage
| Name | Set by | Why |
|---|---|---|
session | Account service | Keeps you signed in. It is secure and HTTP-only, and it is set only if you sign in. |
_ga, _ga_G55LR6JHL8 | Google Analytics | Tells repeat visits from new ones. Up to 2 years. |
| Turnstile | Cloudflare | Human check on the sign-up page |
emergence-theme | Our pages (local storage) | Remembers light or dark theme |
frank-conversation, frank-dismissed | Our pages (session storage) | Keeps your Frank chat, or hides Frank, for this tab only |
emergence_analytics_optout | Our pages (local storage) | Remembers that you opted out of analytics |
14. Children, security and changes
Children. Our services are not directed to children under 13, and we do not knowingly collect their information. If you think a child has given us information, email us and we will delete it.
Security. All connections to us use HTTPS. Passwords are stored as one-way hashes. Keys on your phone sit in encrypted storage backed by Android. No system is perfectly secure. If a breach affects your information, we will tell you as the law requires.
Where data is processed. Our servers are in the United States. Our service providers may process data in other countries under their own safeguards.
Changes. When we change this policy, we will update the date at the top. If a change is significant, we will also tell account holders by email or in the app before it takes effect.