Legal

Privacy Policy

Last updated: September 5, 2026

Our promise, in plain terms: We don't sell your data. We don't use your BOMs, cost figures, or other estimating content to train AI models or to serve ads. Your quotes and cost data belong to you. We host and secure them so your team can use Emura, and we do not monetize your estimating data.

1. Overview & scope

This Privacy Policy explains how Emuri, LLC ("Emuri," "we," "us," or "our") collects, uses, and protects information in connection with Emura, our web-based manufacturing cost-estimating application ("the Service"), at emura.io. It applies to visitors to our marketing site and to registered users of the Service. It should be read together with our Terms of Service.

2. Information we collect

  • Account information: your email address and the details needed to sign you in (such as sign-in method and timestamps). Passwords are handled and securely hashed by Supabase Auth — Emuri never sees or stores your password.
  • Organization & role information: the organization, site, site and folder permissions, and role (admin / estimator / viewer) associated with your account, plus any optional Organization Contact Email supplied by an administrator.
  • Estimating content: the finished goods, BOMs, materials, equipment, operations, cost figures, and parts & equipment library data you and your organization create in the Service ("Customer Data").
  • Billing information: your Stripe customer and subscription identifiers, subscription status, and renewal date. Card details are entered directly into and stored by Stripe; Emuri never sees or stores full card numbers.
  • Waitlist information: if you voluntarily join a launch or enrollment waitlist, we collect your email address solely to tell you when registration reopens.
  • Limited technical / usage data: aggregate, cookieless usage data collected via Vercel Web Analytics (see Section 4).

3. How we use information

We use the information above to:

  • Operate, secure, support, and improve the Service;
  • Authenticate users and enforce organization- and role-based access;
  • Process subscription payments and manage billing through Stripe;
  • Send transactional email — account confirmation, password reset, magic-link sign-in, and team invitations — via Resend and Supabase.
  • Send billing and service notices to the optional Organization Contact Email as a backup to the account owner's email. We do not use that address for marketing.
  • Notify people who voluntarily joined an Emura enrollment waitlist when registration reopens.

We do not sell Customer Data or account information. We do not show advertising or share your information with advertisers. We do not use Customer Data to train machine-learning or AI models, and we do not permit our subprocessors to use Customer Data to train their models — they may process it only to provide their services to us. We do not send marketing email without your consent.

4. Cookies & analytics

Emura sets only the strictly necessary cookies required to keep you signed in (session authentication). We do not use advertising or cross-site tracking cookies.

We use Vercel Web Analytics, which is cookieless and reports aggregate usage data — it does not track individuals across sites or build an advertising profile.

Because we use only essential cookies and cookieless analytics, Emura does not display a cookie-consent banner. If that ever changes, we will update this policy and provide any consent controls required by law.

5. Subprocessors

We rely on the following subprocessors to provide the Service:

  • Supabase — database hosting and authentication.
  • Vercel — application hosting, global content delivery, and cookieless analytics.
  • Stripe — payment processing and subscription billing.
  • Resend — transactional email delivery.

These are established SaaS infrastructure providers, engaged only to help us operate Emura and bound by their agreements to process data solely for that purpose.

6. Data sharing

We share information only with the subprocessors listed above, to the extent needed to operate the Service, or when required by law, legal process, or to protect the rights, property, or safety of Emuri, our customers, or others. We do not sell your information to any third party.

7. Data retention

We retain account and Customer Data while your organization's account is active. If a subscription lapses, we retain Customer Data through the grace and read-only periods described in our Terms of Service. After a prolonged period of non-payment (see Section 5 of the Terms), we reserve the right to retain or permanently delete an organization's data at our discretion, and we will make reasonable efforts to notify the organization's admins before deleting it.

If you ask us to delete your account or organization, we will delete the associated Customer Data within 30 days, other than copies in routine backups, which age out on our providers' normal backup-rotation cycle.

8. Data export & your choices

While you have access to the Service, including during the billing read-only period, you can export individual quotes you are permitted to view as Emura Quote JSON, CSV reports, or customer PDFs. Emura Quote JSON can be imported into an editable quote in Emura. There is no account-wide export or restore function. You can request access to, correction of, or deletion of your information by emailing service@emura.io. Organization admins control who is invited to the organization and what role each member holds.

9. Security & our access to data

Customer Data is transmitted over encrypted connections (HTTPS/TLS) and stored on our providers' encrypted infrastructure (encryption at rest). These protections guard your data on the network and on disk; they do not make it invisible to us.

Authorized Emuri personnel can access Customer Data when reasonably necessary to operate, support, secure, troubleshoot, or improve the Service, or to comply with the law. We limit access to these purposes and treat your estimating data as confidential.

Access to Customer Data is otherwise restricted to your organization through strict, organization-scoped access controls and role-based permissions. No method of storage or transmission is completely secure, and we do not claim any formal security certification or audit at this time.

10. Where your data is processed

Emura's database and primary infrastructure are operated in the United States, and Customer Data is stored there. To load the app quickly, some static content and requests may be routed through Vercel's global edge network, which can process such requests outside the United States; your Customer Data itself remains stored in our U.S. database.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will make reasonable efforts to notify you (for example, by email or an in-app notice). Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact

Questions about this Privacy Policy can be sent to service@emura.io. See also our Terms of Service and Contact pages.

This page is a general description of our privacy practices and is provided for convenience; it is not legal advice. Questions? Email service@emura.io.