Privacy Policy
Last updated 2 August 2026
This Privacy Policy explains what data Embelumy processes when you use the platform to analyze marketplace account problems and manage recovery cases, why we process it, and the controls you have over it. It is maintained by Embelumy and applies to the Embelumy web application and its connected integrations.
1. Data we process
Depending on the features you use, Embelumy may process:
- Marketplace account information — the store names, marketplace, region and seller identifiers you add to your workspace so cases can be attributed to the right account.
- Connected mailbox data — when you connect a mailbox (for example Gmail), we read messages that match marketplace-related searches and import them as account events. We store the original message content, headers, timestamps and sender information required to build your account timeline.
- Marketplace API data — when you authorize a marketplace API connection (for example Amazon SP-API), we import account health, performance notifications, policy violations, compliance requests, listings, inventory, order and payment summaries, appeals and related records needed to keep your digital twin current.
- Uploaded documents — files you upload for analysis (PDF, DOCX, TXT) and the text extracted from them.
- AI-generated analyses — investigation reports, evidence scores, recovery strategies, drafts and reasoning chains produced from your data.
- Recovery history — cases, timelines, tasks, outcomes and the account intelligence profile that records how your account has performed over time.
- User profile information — your name, email address, authentication identifiers, workspace settings and subscription status.
2. Why we process it
We process this data to operate the service you asked for: importing and classifying account events, producing recovery analyses, scoring evidence, generating drafts, maintaining your account intelligence profile, authenticating you, supporting you, and securing the platform against abuse. We do not sell your data and we do not use your marketplace content to build products for other customers.
3. AI processing
To produce analyses, relevant excerpts of your case content — email text, extracted document text and imported marketplace records — are sent to our AI model providers for inference. Providers process this content solely to return the requested output. AI outputs are stored in your workspace and are visible only to your account.
4. Security commitments
- Data is encrypted. All traffic to and from Embelumy is encrypted in transit with TLS, and data at rest in our database and file storage is encrypted.
- Credentials are never exposed to the browser. OAuth flows, token exchanges and integration calls run server-side. Access tokens, refresh tokens and API secrets are never sent to, or stored in, the browser.
- Marketplace API tokens are securely stored. Marketplace and mailbox credentials are encrypted with authenticated encryption (AES-GCM) before being written to storage and are decrypted only inside server-side code that executes an authorized request for your account.
- Access is scoped to your workspace. Row-level security policies restrict every record to the workspace that owns it, and integration tables are readable only by server-side code.
5. Your controls
- Disconnect integrations at any time. From the Integrations page you can revoke any mailbox or marketplace API connection. Revoking a connection stops all further syncing and deletes the stored credentials for that connection.
- Request deletion of your data. You may request deletion of your account and all associated cases, events, documents and analyses by contacting us at the address below. We action verified deletion requests within 30 days, except where we must retain limited billing records to meet legal obligations.
- Access and export. You may request a copy of the personal data we hold about you.
6. Retention
Imported events, documents and analyses are retained for as long as your workspace is active, because recovery work depends on account history. When you delete a case, its documents and analyses are deleted with it. When you close your account, workspace data is deleted after a 30-day grace period.
7. Service providers
Embelumy relies on infrastructure and AI providers to deliver the service: cloud hosting and managed database, authentication, email delivery, AI model inference, and the marketplace and mailbox providers you choose to connect. Each provider receives only the data necessary to perform its function and is bound by contractual confidentiality and security obligations.
8. Changes to this policy
We will update this page when our processing practices change and revise the “last updated” date above. Material changes affecting how your data is used will be communicated by email.
9. Contact
Privacy questions, access requests and deletion requests: privacy@embelumy.com.