Account data
| Data | Where it is processed |
|---|---|
| Account email and verified-email state | Cloudflare Workers / D1 |
| Sign-in email and code delivery | Resend |
| Session | Necessary browser cookie and Cloudflare D1 |
| Anti-abuse counters | Cloudflare D1; keyed email/IP hashes |
| Beta access and safe quota metadata | Cloudflare D1 |
| Installer download response starts, release and requesting account | Cloudflare D1; private installer objects in R2 |
| Random installation ID, account association, first/last app version and timestamps | Cloudflare D1; no hardware identifier or hostname |
| Desktop session | Only hashed tokens in Cloudflare D1; operating system encryption on the computer |
Quota metadata includes opaque operation identity, operation status, timestamps, a routing label and numeric credit/file-size limits. It does not contain customer or project names, file names or paths, signals, issue text, findings, model prompts or responses.
Download history records response starts, including resumed transfers; it does not prove a completed download or installation. New platform product telemetry, in-app feedback and hosted model access are not enabled in this phase.
Engineering data
Raw ASC logs, DBC databases and specifications stay local by default. This website has no engineering upload endpoint. The existing desktop engine may send selected context to an explicitly configured AI provider; account sign-in does not enable that mode or change its boundaries.
The Beta email request form still prepares a draft locally. Only sending the draft through your email application transmits it. Keep confidential engineering material out of account and support emails.
Retention and deletion
Codes are unusable after five minutes; browser and desktop sessions expire within seven days. Desktop access tokens last at most 15 minutes; refresh rotates credentials without extending the fixed session expiry. An operator-run cleanup removes expired authentication/anti-abuse/device-session records. Download starts, historical terminal usage for superseded grants and access audit records are eligible for cleanup after 90 days. Current-grant usage is retained for cumulative credits and safe retries, including invitation extensions; unknown operation states remain until resolved. Account, installation associations, current invitation access and its necessary usage records remain until deletion is requested and verified. This phase does not have automatic deletion scheduling.
Desktop sign-out removes usable credentials from this computer. If offline, an encrypted revocation retry remains until the service confirms revocation or the session expires. Local installation identity and the local-work access marker remain; sign-out does not remove local engineering files.
Email beta@embedvera.com from your account address to request deletion. Verified account deletion also removes its downloads, devices and device sessions. Provider delivery/hosting records and email correspondence have separate retention. See Privacy and Security for details.