Privacy Policy
Version 1.9 — effective 27 August 2026
This policy explains how Emblemry handles personal data when you browse the site, submit a badge, file a report, contact us, or use account and paid features.
At a glance
- A free badge is public by design. If it passes publication review, its image and selected brief details appear at a public address and may appear in the gallery.
- A paid badge is private. It is not placed in the gallery or licensed to the public.
- Badge briefs and generated images are processed by AI services. Do not submit personal, sensitive, confidential, or third-party private information.
- Emblemry measures how the service is used with PostHog on its EU Cloud. Those events carry the name of a page and, for two of them, a one-word outcome. By default the measurement stores nothing on your device; a separate, optional choice lets PostHog keep a cookie and also switches on session replay, page-speed scores, and error reports.
- Emblemry does not identify visitors, build profiles of them, or use advertising trackers or automatic event capture. Session replay runs only after you allow storage, and everything you type is replaced with asterisks in your browser before a recording leaves it.
- You can object to a publication decision or ask for a public badge to be removed through the contact page.
- The controller is the operator named in the Imprint. The privacy contact is shown at the end of this page.
1. Who is responsible
Malte Hedderich, trading as Emblemry, is the controller for the processing described in this policy. The full postal address is in the Imprint.
Some providers, such as Polar when it acts as merchant of record, process information for their own legal duties as separate controllers. Those cases are identified below.
2. Data you give us
Badge briefs
A brief can contain:
- style, title, and subject;
- ordered motifs and things to avoid; and
- palette direction, framing, and a direction note.
The suitability check reads every submitted field. If a brief is rejected, Emblemry does not save it as an accepted brief, although OpenAI processes it to return the decision. If it is accepted, Emblemry stores the brief and the technical record needed to generate the badge.
Do not put personal data, special-category data, secrets, confidential business information, or private information about another person in a brief. A badge is not a place for private material.
Reports and messages
A badge report contains the badge address, the rule you selected, your note, the rules version, and, if you choose to provide them, your name and email address. Your identity and note are not displayed with the badge. A report can be read by an authorised human reviewer.
If you contact Emblemry, we process your contact details, message, attachments, and the reply history.
Account data
Sign-in uses Firebase Authentication with Google and Apple as identity providers. Depending on what the provider supplies and what you choose to share, Emblemry may receive:
- a Firebase user ID and provider user ID;
- a verified email address, including an Apple private-relay address;
- a display name and profile image; and
- sign-in timestamps, session and token information, IP address, user agent, and security events.
Emblemry does not receive your Google or Apple password. Google and Apple also process the sign-in under their own notices. The Emblemry account record links the Firebase user ID to private badges, runs, the credit balance, purchase history, acceptance records, and service messages. Public pages do not show a maker name, account, or profile.
Payment and credit data
Polar Software Inc. provides checkout as merchant of record for one-time credit purchases. Polar collects the payment and billing information required for the transaction. This can include your name, email, country, postal code or billing address, business details, VAT or tax number, payment method information, and fraud-prevention data. Polar processes that buyer and transaction data as a separate controller under its Privacy Policy.
Emblemry receives only the information needed to fulfil and reconcile the purchase, such as Polar customer, checkout, order, refund, and event identifiers, the credit pack, price, currency, tax totals, payment and refund status, and limited buyer details made available by Polar. Emblemry does not receive or store complete payment-card details.
Emblemry records each purchased credit lot and the price actually paid so credits can be granted exactly once and any required refund can be calculated. Purchase and credit events are kept in a ledger to prevent duplicate grants, charges, releases, or refunds.
3. Data created when Emblemry provides the service
Emblemry creates and stores:
- an accepted-brief record and a readable badge slug;
- compiled art direction, the exact generated prompt, prompt and model versions, and provider request identifiers;
- item, attempt, and delivery records;
- source, diagnostic, transparent, review, and delivered image files;
- quality-gate measurements, errors, retry and cancellation status, and publication-review results;
- model-call traces holding the prompt, the input content, the generated image, model and token metadata, latency, and errors;
- creation time, style and display metadata, and download count;
- the global free-pool day and the badge slugs claimed from it;
- badge reports submitted by visitors.
What becomes public
For a released free badge, the public badge page and gallery can show the image, title, derived slug, subject, motifs, style, framing, palette mood, creation time, and download count. The badge can be cached by Cloudflare and downloaded or copied by anyone under the Badge License.
Avoid entries, direction notes, prompts, provider identifiers, and reporter details are not public display fields.
Free badges that fail or time out are not delivered. A badge withheld by publication review is not listed, and its image is not delivered. The existing creation-status address may still show the badge title, status, grounds, and redress information, but it does not serve the image or public provenance.
Private work
Paid badges are tied to the signed-in account. They are stored privately, never held by any shared cache, and skip public-gallery review; only your own signed-in browser keeps a copy, for at most thirty minutes. Emblemry and its processors still access them as needed to generate, secure, support, and deliver the service.
4. Why we process data and the legal basis
| Purpose | Data | Legal basis under the GDPR |
|---|---|---|
| Check, generate, deliver, and, for a free badge, publish the requested badge | Brief, prompt, images, badge and run records | Article 6(1)(b), to provide the service you request |
| Operate the global free pool | UTC day and claimed badge slugs | Article 6(1)(b), to provide the free service; Article 6(1)(f), our interest in controlling cost and abuse |
| Review public material, enforce the service rules, handle reports, and provide redress | Brief, image, decision, report, reviewer record | Article 6(1)(f), our and the public's interests in a safe and lawful gallery; Article 6(1)(c) where a legal duty applies |
| Protect and debug the service | Request metadata, security logs, errors, attempts, diagnostic files, and model-call traces | Article 6(1)(f), our interest in security, reliability, fraud prevention, and claim handling |
| Answer an inquiry or rights request | Contact and request records | Article 6(1)(b) where the request concerns a contract; otherwise Article 6(1)(f), our interest in answering and documenting requests; Article 6(1)(c) where required |
| Measure how the service is used | Page name, page-open duration, one-word product outcomes, campaign tags from Emblemry's own links, and the technical context PostHog adds; with consent, session recordings, page-speed scores, and error reports | Article 6(1)(f), our interest in knowing whether the service works, for the measurement that stores nothing; Article 6(1)(a), your consent, for the optional storage and the replay, scores, and reports it switches on |
| Create and secure an account | Firebase and identity-provider data, account and session record | Article 6(1)(b), to provide account features; Article 6(1)(f), for security and abuse prevention |
| Provide private work, credits, downloads, export, and deletion tools | Account, private content, credit and activity records | Article 6(1)(b), to perform the account and paid-service terms |
| Process purchases, refunds, invoices, tax, and accounting | Polar and purchase records | Article 6(1)(b), contract performance; Article 6(1)(c), financial and tax duties; Article 6(1)(f), fraud prevention and legal claims |
| Send essential service messages | Email address, event and delivery status | Article 6(1)(b) or 6(1)(f), depending on the message |
Providing the fields marked as required in the composer is necessary to request a badge. Optional brief fields and reporter contact details are optional. Allowing analytics storage is optional too, and refusing it does not reduce the service.
5. AI processing and automated review
Emblemry uses OpenAI's Responses API to check briefs, compile art direction, and review public badges. It uses the Images API to generate badge artwork. The finished public image and relevant brief content are sent to OpenAI for publication review.
Private badges do not go through that publication-review step.
Responses requests are made with store=false and without tools. OpenAI states that API data is not used to train its models by default. store=false is not a promise of zero retention. OpenAI's default abuse-monitoring logs may include prompts, responses, and generated content for up to 30 days, unless a longer period is required by law. Emblemry does not claim zero-data retention or EU-only OpenAI processing.
Each of these provider calls is also recorded as a trace in a tracing service that Emblemry runs itself on Google Cloud in europe-west1. A trace holds the same content as the provider request it describes, including brief text and the generated image, together with the model, token counts, latency, and any error. Emblemry uses these traces to diagnose failures and to track model cost. A trace carries no visitor identity and is not used to profile anyone.
There are three automated checks:
- The suitability check can reject a brief before generation. It identifies the field and gives correction guidance. You may edit and submit again.
- OpenAI applies its provider moderation while generating the image.
- Publication review decides whether a free badge is fit for a public gallery. It fails closed. If the review is unavailable, uncertain, or negative, the badge is not published or delivered and its place in the free pool remains spent.
These checks do not decide employment, creditworthiness, insurance, or access to an essential public service. You can correct and resubmit a brief after a suitability rejection. If a publication decision or later moderation action appears wrong, use the contact page to request human review. A report does not automatically remove a badge or change its ranking.
6. Service providers and other recipients
| Recipient | Role and purpose |
|---|---|
| OpenAI Ireland | AI suitability, direction, image generation, and public-image review; processor under the OpenAI DPA |
| Google Cloud | Cloud Run API, Firestore, Cloud Tasks, private object storage, the self-hosted model-call tracing service, IAM, security, and operations; processor under the Google Cloud Data Processing Addendum |
| Cloudflare | Frontend hosting, content delivery, caching, traffic security, and request processing; processor under the Cloudflare Customer DPA |
| PostHog | Product measurement on its EU Cloud, as described in section 8 and in the Cookie Policy; processor under the PostHog data-processing agreement |
| Google-hosted email | Receives, stores, and transmits messages sent to Emblemry's general, legal, and privacy mailboxes |
| Public visitors and downstream recipients | Display, caching, downloading, and reuse of released free badges |
| Authorised reviewer and professional advisers | Reports, rights requests, disputes, security, accounting, and legal claims, limited to what is needed |
| Authorities | Where disclosure is required by law or necessary to establish, exercise, or defend legal claims |
| Firebase Authentication | Account authentication and security; Firebase Authentication operates from United States data centres |
| Google and Apple | Identity providers that process sign-in data under their own terms and privacy notices |
| Polar Software Inc. | Merchant of record, checkout, payment, fraud prevention, tax, refunds, and invoices; a US-based separate controller for buyer and transaction data it handles as merchant |
| Amazon Web Services | Amazon SES in eu-west-1 (Ireland) delivers essential export and refund messages; processor for the address, message, and delivery status |
Emblemry does not sell personal data and does not use it for behavioural advertising.
7. International transfers
Firestore, Cloud Run, Cloud Tasks, the badge bucket, and the model-call tracing service are configured in europe-west1 in Belgium. Emblemry's PostHog project is on PostHog's EU Cloud, which stores its data in the European Union. Cloudflare's network is global. An EU storage region does not mean that support, security, CDN, or all provider operations stay in the EEA.
OpenAI, Cloudflare, Google Cloud, PostHog, Firebase Authentication, Google, Apple, Polar, Amazon SES, and the Google-hosted email service, together with their subprocessors, may process data outside your country. Polar Software Inc. is established in the United States. Firebase Authentication processes data in the United States. PostHog is established in the United States, and its support and operations staff may access EU Cloud data from there. Amazon SES is configured in eu-west-1 (Ireland), although provider support and subprocessors can involve transfers outside the EEA.
OpenAI Ireland acts as Emblemry's processor under the OpenAI DPA. Google Cloud, Firebase Authentication, the Google-hosted email service, Amazon SES, Cloudflare, and PostHog process data under their applicable data-processing terms. These agreements use the EU Standard Contractual Clauses where needed. Identity providers and Polar apply the safeguards described in their own notices for processing they perform as separate controllers. Emblemry also relies on an applicable adequacy decision and the additional safeguards described in the relevant agreement where available.
8. Cookies, device storage, and analytics
Emblemry uses PostHog on its EU Cloud to measure how the service is used. It records a page view, how long each page stayed open, how far down each page was scrolled, and four product steps: a brief checked, a badge started, a badge image downloaded, and a badge link copied. Each event carries the name of one of nine fixed pages and, for two of them, a single word describing the outcome. A badge page is always reported as /b/[slug]; the real badge address is derived from text a visitor wrote and is never sent. Brief content, images, page titles, form values, report contents, and contact details are never sent as event fields either; what a session recording can show, where you have allowed one, is described below.
Alongside that, an event carries a fixed technical list: browser, operating system, device type, language, time zone, and — so that Emblemry can tell whether anyone is finding the service — the host name of the site that linked you here and the name of the search engine, where there was one. The full referring address, your search terms, the raw browser identification string, screen dimensions, and every advertising click identifier are not sent; of the campaign parameters, only the five utm_ tags that Emblemry itself wrote into a link are. Section 3 of the Cookie Policy lists this in full.
Measurement requests do not go to PostHog directly. The browser sends them to this site's own /relay address, and Emblemry's frontend forwards them to PostHog's EU Cloud, passing along the network address each request came from — the input of the daily hash described next. Emblemry's PostHog project is configured to discard that address once received.
By default this measurement stores nothing on your device and reads nothing from it. PostHog counts the events against a hash it computes on its own servers, rotates daily, and never returns to your browser. Emblemry does not identify visitors and creates no person profile.
You can separately allow PostHog to keep a cookie and browser storage holding an identifier it generates, so that a repeat visit is counted as a repeat visit. The same consent switches on three further kinds of measurement: session replay, which records the pages of a visit as they appeared — badge content and addresses included — with everything you type replaced by asterisks in your browser before the recording leaves it; four page-speed scores per page; and error reports naming what broke and where in Emblemry's code. All of it is optional and reversible from Cookie settings in the footer of every page. Refusing or withdrawing prevents the PostHog cookie and the persistent identifier and stops the replay, scores, and reports; it does not stop the storage-free measurement, which that choice does not control and which section 1 of the Cookie Policy describes together with how to object to it.
Emblemry also sets two strictly necessary cookies after sign-in. The session cookie carries the Firebase session, cannot be read by page scripts, and lasts for at most fourteen days unless you sign out or it is revoked sooner. The signed-in cookie beside it holds a single marker that a session exists, so the page can show your account menu without waiting on a request; page scripts can read it, and it names nobody and grants nothing. Infrastructure can still use strictly necessary security mechanisms. The Cookie Policy lists every entry and how it is checked.
The model-call traces described in section 5 are not analytics. They are server-side records of Emblemry's own requests to the AI provider, they measure the generation pipeline rather than your browsing, and they involve no cookie, no device storage, and no page or event tracking.
9. Retention
Emblemry does not promise a deletion period that the service cannot enforce.
| Category | Retention |
|---|---|
| Accepted briefs, live badge records, prompts, attempts, and current image objects | Emblemry does not delete these on a schedule. Public badges remain until Emblemry removes them or accepts a verified removal request. |
| Noncurrent Cloud Storage object versions | Deleted after 30 days under the current bucket lifecycle rule. This does not delete the live version. |
| Source and diagnostic files for failures | Emblemry does not delete these on a schedule. They are kept to diagnose generation failures. |
| Model-call traces | Deleted after 30 days under the tracing service's retention policy. Its cleanup runs weekly, so a trace can persist a few days past that point. |
| Publication decisions and badge reports | Publication decisions become eligible for deletion after 12 months. Badge reports normally become eligible for deletion after six months. When a report prompts a takedown, its deadline is extended to match the cited decision. Firestore typically deletes an eligible record from the live database within 24 hours. Recovery copies can retain it for up to seven further days. |
| Free-pool records and download counts | Emblemry does not delete these on a schedule. |
| Google Cloud infrastructure and security logs | Logs in the _Default bucket are retained for 30 days. Logs in the _Required bucket are retained for 400 days. Cloudflare Workers invocation logs are disabled. |
| Contact and rights-request messages | Until the request is resolved, then as needed for follow-up, legal duties, or legal claims. |
| PostHog analytics events | Deleted after 12 months. |
| PostHog session recordings | Deleted after 30 days, on a schedule separate from the 12 months for events. |
| Firebase authentication data | Until the Firebase user is deleted. Firebase states that logged IP addresses are kept for a few weeks and other authentication data is removed from live and backup systems within 180 days after deletion starts. |
| Account and private product data | While the account exists. Account deletion removes the Firebase account, private badges, unused credits, and ordinary product data, subject to backup processing and the exceptions below. |
| Billing and credit records | Purchase-lot and order records are kept for statutory accounting, tax, fraud prevention, refund, and legal-claim periods. Polar applies its own retention duties as merchant of record under its privacy notice. |
| Essential emails | Until the message has served its operational purpose, then only as needed for support, security, legal duties, or legal claims. No marketing list is created. |
10. Account export, deletion, and public removal
The account menu provides:
- an export of account information, accepted briefs, purchase history, acceptance records, and the badge files available to the account;
- account deletion; and
- access to cookie and tracking settings.
Deleting an account removes the Firebase account, private badges, unused credits, and ordinary product records. It does not create a voluntary refund unless mandatory law requires one. Emblemry retains billing records and other limited records where required by law or needed for fraud prevention and legal claims.
Public badges do not identify their maker. A badge stays public unless you make a removal request and Emblemry can reasonably verify that you created the badge or hold the relevant rights. Removing a badge clears Emblemry's edge cache and stops future hosting. It cannot recall downloaded files, browser or third-party copies, or cancel licences already granted, except where mandatory law requires a different result.
11. Your rights
Subject to the GDPR and its limits, you can ask Emblemry to:
- give you access to your personal data and a copy of it;
- correct inaccurate data;
- erase data;
- restrict processing;
- provide portable data you supplied where the right applies;
- stop processing based on legitimate interests where your situation gives you a right to object, which includes the storage-free measurement described in section 8;
- stop direct marketing, although Emblemry does not send marketing messages; and
- request human review of a publication decision or later moderation action.
You do not need to ask for the analytics choice. Under Article 7(3) GDPR you can withdraw consent to analytics storage yourself, at any time, from Cookie settings in the footer of every page, as easily as you gave it. Withdrawal does not affect processing that was lawful before it.
Use the privacy contact shown below or the contact page. Emblemry may ask for information needed to verify your identity and authority, especially for an anonymous public badge. Emblemry will not ask for more identification than the request requires.
An account login can verify account-scoped requests.
You may complain to a data-protection authority. The operator's usual authority is the Hessian Commissioner for Data Protection and Freedom of Information. You may also contact the authority where you live or work or where you believe an infringement occurred.
12. Security
Emblemry uses access-controlled cloud services, encrypted network connections, private object storage, and short-lived asset links. Public badges are intentionally cacheable. No online service can promise absolute security.
Private data is owner-scoped and paid images are served with private responses that no shared cache may hold; only the owner's own browser keeps them, briefly.
13. Children
Emblemry is not directed at young children. A person who cannot enter the relevant contract independently must use the service only with a parent or legal guardian. Emblemry does not use age verification unless a feature expressly says otherwise.
14. Changes to this policy
The version and effective date appear at the top. Material changes are published before they take effect.
Before adding a new recipient or a new processing purpose, Emblemry checks the deployed data flow and updates this policy first.
15. Contact
For privacy questions or to exercise a right, use the privacy contact displayed below. General product and moderation requests can also be sent through the contact page.
Privacy contact: Open the contact page for privacy inquiries