Privacy Policy
Last updated: July 8, 2026
Freedom by Design (“Emboulden,” “we,” “us”) is operated by Thomas Lin as a sole proprietor based in California. This policy explains what we collect when you use the free course site and the member app at emboulden.com, why we collect it, and the choices you have.
What we collect
- Account info — your email address, a display name you provide, and a hashed password (managed by our auth provider).
- Course progress — which days you mark complete, your current day, theme preference.
- Journal entries and reflections — anything you write in response to the journal prompts, plus AI-generated reflections on those entries. These are often personal in nature.
- Coach chat messages — your messages to the AI coach and its replies.
- Goals and steps — goals you create and AI-generated micro-steps for them.
- Money tool data — if you use the Money tool (Statement Analysis, Monthly Budget, Net Worth), the statements you upload and the transactions, balances, budget entries, and net-worth figures built from them. Your working copy stays in your browser by default, but using the tool automatically sends your financial data to our third-party AI provider as part of normal use — for example, when you upload a statement (a photo or PDF passes through our server so its contents can be read), when you open the Budget or Net Worth tab with data in it (including figures you typed in by hand), when quick money tips are generated or refreshed, and when a tab’s AI advisor writes or answers messages. Separately, this data reaches our database only if you click “Save to my account,” and goes to another person only if you email it. See Money tool: statements, AI, and email sharing below for exactly what that involves.
- Technical data — basic request information (IP address, user agent, timestamps) processed by our hosting and error-monitoring providers. We don’t run analytics scripts or advertising trackers.
How we use it
- To deliver the course and member app and keep your account working.
- To send transactional email (sign-up confirmation, password reset), opt-in weekly encouragement nudges if you’ve enabled them, and — if you’re in a cohort — cohort email: automated meeting reminders, meeting recaps, and messages from your facilitator. Every cohort email and weekly nudge includes an unsubscribe link — see Cohort email and unsubscribing below.
- To generate AI responses to your journal entries, goals, and coach messages.
- To read and categorize statements you upload to the Money tool, answer your questions about them, and save a private copy of your Money tool data if you choose to.
- To detect and fix bugs and abuse, and to enforce per-user limits on AI usage.
We do not sell your personal information. We do not use it for advertising.
AI processing
When you write a journal entry, send a coach message, or ask the app to generate goal steps, the text of your message is sent to our AI inference provider (currently fal.ai) so the model can produce a response. For these features, the model currently used is Google’s Gemma 3 27B, reached through fal.ai. The Money tool relies on different underlying AI models than the journal and coach features, still reached through fal.ai (see Money tool: statements, AI, and email sharing below). Refer to fal.ai’s privacy policy for their own data-handling practices.
Please don’t paste anything into the journal or coach that you wouldn’t want a third-party AI provider to process — for example, government identifiers, account credentials, or medical records.
Money tool: statements, AI, and email sharing
The Money tool (Statement Analysis, Monthly Budget, and Net Worth tabs) touches more sensitive data than the rest of the app — a bank or investment statement — so here’s exactly what happens to it.
Your working copy stays in your browser by default. Extracted transactions, budget entries, and net-worth figures live in your browser’s local storage. Ordinary use of the tool, though, automatically sends your financial data to our AI provider: a statement photo or PDF passes through our server the moment you upload it, on its way to being read (see “Reading a statement” below), and the app makes further automatic AI calls as you use it — for example, categorizing merchants after an upload, generating quick money tips when you open the Budget or Net Worth tab with data in it (even data you typed in by hand), and writing and answering AI advisor messages (see “Categorizing transactions, tips, and the chat advisor” below). What stays gated on your explicit action: this data is stored on our servers only if you click “Save to my account,” and sent to another person only if you use “Share / email.”
Reading a statement. When you upload a statement as a photo or PDF, the file itself is sent to our AI provider, fal.ai, so its vision model can read the transactions or account balances printed on it — that’s the only way it can transcribe a scanned document. That means the statement image, including whatever’s printed on it, reaches fal.ai for that one step; it isn’t redacted first, because the model has to see the actual document to read it. Every call we make to fal.ai, including this one, sends a header (X-Fal-Store-IO: 0) that, per fal.ai’s current documentation, turns off their default 30-day storage of the request and response, so the statement isn’t retained in fal’s systems afterward. If you upload a CSV export instead of a photo or PDF, it’s parsed entirely in your browser and never reaches fal.ai for this step.
Categorizing transactions, tips, and the chat advisor. These later AI calls — auto-categorizing merchants, the quick money tips, and each tab’s chat advisor — send transaction descriptions and summary figures (which can include budget and net-worth entries you typed in by hand), never the original statement file. Before the financial data we include automatically — transaction descriptions and those budget and net-worth figures — reaches fal.ai, we run it through an automated filter that looks for patterns like Social Security numbers, EINs, bank routing numbers, card numbers, and account numbers, and replaces any match with [REDACTED]. The filter is deliberately trigger-happy — tuned to over-redact rather than miss something — but it’s a pattern scan, not a guarantee: it can’t promise no personal information of any kind ever shows up in a transaction description. Dates, amounts, and categories are sent as-is, since that’s the actual data the advice is based on and isn’t the kind of identifier the filter looks for. One important exception: the messages you type to a tab’s AI advisor are sent to fal.ai as-is — the filter does not touch them. Please don’t paste anything into the chat advisor that you wouldn’t want a third-party AI provider to process — the same caution as the journal and coach above. These calls carry the same no-store header described above.
What we actually save. Raw statement files, AI chat history, and money tips are never saved on our servers — they exist only in your browser, or briefly in server memory for the length of a single AI request. If you click “Save to my account,” what we store is your derived Money tool data: the deduplicated transaction list, monthly budget targets, income, net-worth entries, and a minimal account tag (bank name, account type, last 4 digits) you enter yourself — scoped to your account so only you can read it.
Emailing a summary. If you use “Share / email” to send a budget summary to yourself or someone else (a facilitator, partner, or accountant, for example), the message and summary text go through the same redaction filter before we send it. If you attach the transaction CSV, its description column is redacted the same way (the date, amount, category, and account columns are not). We send that email through Resend, our email provider — see Subprocessors below.
Cohorts and facilitator visibility
If you join a facilitated cohort (a 10-week guided group), a designated facilitator at Emboulden can see metadata about your participation in their cohort dashboard: your display name, email, last sign-in time, how many days you’ve completed, how many journal entries you’ve written, whether you submitted one this week, how many goals you have, how many chat messages you’ve sent, and which sessions you attended. Facilitators may also record private notes about cohort members that you do not see.
Facilitators cannot read the text of your journal entries, AI reflections, or coach chat transcripts. Those remain accessible only to you.
Cohort email and unsubscribing
If you’re in a cohort, we send email tied to its meetings: automated reminders the day before and the morning of each meeting, a nudge later in the week if you haven’t written a journal entry yet, a meeting recap (notes and resources, sent by your facilitator — to the whole cohort or only to those who attended, at their choice), and messages your facilitator writes to the group.
Every one of these emails, and every weekly nudge, ends with an unsubscribe link. It opens a page — no sign-in needed; the link is unique to you — where one click sets a preference on your account that stops all cohort email and the weekly nudges. It doesn’t affect your access to the app, and it doesn’t stop truly transactional email like cohort invites or password resets. To start receiving cohort email again, email info@emboulden.com.
Subprocessors
We rely on the following service providers to operate the product:
- Supabase (Supabase, Inc., USA) — database, authentication, and storage of everything you create in the app.
- fal.ai (Features and Labels, Inc., USA) — AI inference (described above).
- Vercel (Vercel, Inc., USA) — hosting and content delivery.
- Resend (Resend, Inc., USA) — transactional email delivery.
- Sentry (Functional Software, Inc. dba Sentry, USA) — error monitoring. May receive request metadata and a user identifier if an error occurs on a route you used.
Offline storage on your device
The member app works offline as a Progressive Web App. To do that, it stores two kinds of data on the device you’re using:
- App files and lesson text — cached by a service worker so you can read lessons without a connection. This holds no personal data.
- Your offline entries and progress — if you write journal entries or mark days complete while offline, that text and those completion flags are kept in your browser’s local database (IndexedDB) on that device until they sync to our servers. They’re scoped to your account on that device and are cleared when you sign out, and when a different account signs in on the same browser.
This on-device data relies on your device and browser for protection; it isn’t separately encrypted beyond what your operating system and browser provide. If you’d rather keep nothing on the device, turn off “Save lessons & my entries on this device for offline use” in the member footer — that clears what’s stored and stops saving offline. It’s on by default and is a per-device choice.
Cookies
We use cookies set by our auth provider to keep you signed in. We use localStorage on your device to remember your theme and your offline-storage preference (and the local database described above). We do not use third-party advertising or analytics cookies.
How long we keep it
We keep your account data for as long as your account is active. You can request deletion at any time by emailing info@emboulden.com — we’ll delete your account and the rows tied to it (journal, coach messages, goals, progress, saved Money tool data) within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your data, and to object to or restrict certain processing. California residents have additional rights under the CCPA/CPRA, including the right to know what we collect, to delete, and to not be discriminated against for exercising those rights. We don’t sell personal information.
To exercise any of these rights, email info@emboulden.com. We’ll respond within a reasonable time.
Children
Emboulden is intended for adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has signed up, please email us and we’ll delete the account.
Security
Data is encrypted in transit (HTTPS). Database rows are protected by row-level security so you only read and write your own data. We follow reasonable industry practices, but no service is perfectly secure.
Changes
We may update this policy as the product evolves. We’ll update the “Last updated” date above and, for material changes, notify active members by email.
Contact
Questions, requests, or concerns: info@emboulden.com.