Privacy Policy

Last updated: July 8, 2026

Freedom by Design (“Emboulden,” “we,” “us”) is operated by Thomas Lin as a sole proprietor based in California. This policy explains what we collect when you use the free course site and the member app at emboulden.com, why we collect it, and the choices you have.

What we collect

How we use it

We do not sell your personal information. We do not use it for advertising.

AI processing

When you write a journal entry, send a coach message, or ask the app to generate goal steps, the text of your message is sent to our AI inference provider (currently fal.ai) so the model can produce a response. For these features, the model currently used is Google’s Gemma 3 27B, reached through fal.ai. The Money tool relies on different underlying AI models than the journal and coach features, still reached through fal.ai (see Money tool: statements, AI, and email sharing below). Refer to fal.ai’s privacy policy for their own data-handling practices.

Please don’t paste anything into the journal or coach that you wouldn’t want a third-party AI provider to process — for example, government identifiers, account credentials, or medical records.

Money tool: statements, AI, and email sharing

The Money tool (Statement Analysis, Monthly Budget, and Net Worth tabs) touches more sensitive data than the rest of the app — a bank or investment statement — so here’s exactly what happens to it.

Your working copy stays in your browser by default. Extracted transactions, budget entries, and net-worth figures live in your browser’s local storage. Ordinary use of the tool, though, automatically sends your financial data to our AI provider: a statement photo or PDF passes through our server the moment you upload it, on its way to being read (see “Reading a statement” below), and the app makes further automatic AI calls as you use it — for example, categorizing merchants after an upload, generating quick money tips when you open the Budget or Net Worth tab with data in it (even data you typed in by hand), and writing and answering AI advisor messages (see “Categorizing transactions, tips, and the chat advisor” below). What stays gated on your explicit action: this data is stored on our servers only if you click “Save to my account,” and sent to another person only if you use “Share / email.”

Reading a statement. When you upload a statement as a photo or PDF, the file itself is sent to our AI provider, fal.ai, so its vision model can read the transactions or account balances printed on it — that’s the only way it can transcribe a scanned document. That means the statement image, including whatever’s printed on it, reaches fal.ai for that one step; it isn’t redacted first, because the model has to see the actual document to read it. Every call we make to fal.ai, including this one, sends a header (X-Fal-Store-IO: 0) that, per fal.ai’s current documentation, turns off their default 30-day storage of the request and response, so the statement isn’t retained in fal’s systems afterward. If you upload a CSV export instead of a photo or PDF, it’s parsed entirely in your browser and never reaches fal.ai for this step.

Categorizing transactions, tips, and the chat advisor. These later AI calls — auto-categorizing merchants, the quick money tips, and each tab’s chat advisor — send transaction descriptions and summary figures (which can include budget and net-worth entries you typed in by hand), never the original statement file. Before the financial data we include automatically — transaction descriptions and those budget and net-worth figures — reaches fal.ai, we run it through an automated filter that looks for patterns like Social Security numbers, EINs, bank routing numbers, card numbers, and account numbers, and replaces any match with [REDACTED]. The filter is deliberately trigger-happy — tuned to over-redact rather than miss something — but it’s a pattern scan, not a guarantee: it can’t promise no personal information of any kind ever shows up in a transaction description. Dates, amounts, and categories are sent as-is, since that’s the actual data the advice is based on and isn’t the kind of identifier the filter looks for. One important exception: the messages you type to a tab’s AI advisor are sent to fal.ai as-is — the filter does not touch them. Please don’t paste anything into the chat advisor that you wouldn’t want a third-party AI provider to process — the same caution as the journal and coach above. These calls carry the same no-store header described above.

What we actually save. Raw statement files, AI chat history, and money tips are never saved on our servers — they exist only in your browser, or briefly in server memory for the length of a single AI request. If you click “Save to my account,” what we store is your derived Money tool data: the deduplicated transaction list, monthly budget targets, income, net-worth entries, and a minimal account tag (bank name, account type, last 4 digits) you enter yourself — scoped to your account so only you can read it.

Emailing a summary. If you use “Share / email” to send a budget summary to yourself or someone else (a facilitator, partner, or accountant, for example), the message and summary text go through the same redaction filter before we send it. If you attach the transaction CSV, its description column is redacted the same way (the date, amount, category, and account columns are not). We send that email through Resend, our email provider — see Subprocessors below.

Cohorts and facilitator visibility

If you join a facilitated cohort (a 10-week guided group), a designated facilitator at Emboulden can see metadata about your participation in their cohort dashboard: your display name, email, last sign-in time, how many days you’ve completed, how many journal entries you’ve written, whether you submitted one this week, how many goals you have, how many chat messages you’ve sent, and which sessions you attended. Facilitators may also record private notes about cohort members that you do not see.

Facilitators cannot read the text of your journal entries, AI reflections, or coach chat transcripts. Those remain accessible only to you.

Cohort email and unsubscribing

If you’re in a cohort, we send email tied to its meetings: automated reminders the day before and the morning of each meeting, a nudge later in the week if you haven’t written a journal entry yet, a meeting recap (notes and resources, sent by your facilitator — to the whole cohort or only to those who attended, at their choice), and messages your facilitator writes to the group.

Every one of these emails, and every weekly nudge, ends with an unsubscribe link. It opens a page — no sign-in needed; the link is unique to you — where one click sets a preference on your account that stops all cohort email and the weekly nudges. It doesn’t affect your access to the app, and it doesn’t stop truly transactional email like cohort invites or password resets. To start receiving cohort email again, email info@emboulden.com.

Subprocessors

We rely on the following service providers to operate the product:

Offline storage on your device

The member app works offline as a Progressive Web App. To do that, it stores two kinds of data on the device you’re using:

This on-device data relies on your device and browser for protection; it isn’t separately encrypted beyond what your operating system and browser provide. If you’d rather keep nothing on the device, turn off “Save lessons & my entries on this device for offline use” in the member footer — that clears what’s stored and stops saving offline. It’s on by default and is a per-device choice.

Cookies

We use cookies set by our auth provider to keep you signed in. We use localStorage on your device to remember your theme and your offline-storage preference (and the local database described above). We do not use third-party advertising or analytics cookies.

How long we keep it

We keep your account data for as long as your account is active. You can request deletion at any time by emailing info@emboulden.com — we’ll delete your account and the rows tied to it (journal, coach messages, goals, progress, saved Money tool data) within 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your data, and to object to or restrict certain processing. California residents have additional rights under the CCPA/CPRA, including the right to know what we collect, to delete, and to not be discriminated against for exercising those rights. We don’t sell personal information.

To exercise any of these rights, email info@emboulden.com. We’ll respond within a reasonable time.

Children

Emboulden is intended for adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has signed up, please email us and we’ll delete the account.

Security

Data is encrypted in transit (HTTPS). Database rows are protected by row-level security so you only read and write your own data. We follow reasonable industry practices, but no service is perfectly secure.

Changes

We may update this policy as the product evolves. We’ll update the “Last updated” date above and, for material changes, notify active members by email.

Contact

Questions, requests, or concerns: info@emboulden.com.