Local work and shared projects
You can work locally without creating an account. Signing in does not publish a local project. When you explicitly share a project, Emm's relay stores and synchronizes its shared records and membership information. Other members can download the records they are authorized to access.
Revoking access stops further authorized cloud access. It does not erase files someone has already downloaded.
Your account
Emm stores a verified email address, account identifier, display name, sign-in credentials, and project memberships. We use these to identify your account, deliver invitations and recovery messages, and enforce project access.
Invitations contain the project name, inviter, and intended recipient. Treat a private invitation link like a verification email: do not forward it to someone you do not intend to give access.
Sign in with Google
Google sign-in provides your Google account identifier and email information. Emm requests identity and email scopes. It does not request access to your Gmail messages, Google Drive files, calendar, or contacts.
Emm keeps an encrypted Google refresh credential on its server to check that Google still authorizes access. Google credentials are not given to the Emm desktop app, command-line tool, or your coding agents. Emm does not receive your Google password.
Emm uses this Google information to authenticate you and enforce access. You can review or revoke Emm's access in your Google Account. Revocation can stop cloud access; it does not delete your Emm account or local projects.
After you confirm connecting Google, your Emm account requires Google for future sign-in. Email recovery and Emm passkeys cannot bypass it. Google authorization checks can pause cloud access while your local work remains available.
Passkeys
Emm stores a passkey's public credential, the name you give it, and its creation and last-used times. The private key stays with your authenticator or password manager. Emm does not receive your fingerprint, face scan, or device password.
Your password manager controls whether a passkey syncs between devices. Removing a passkey from Emm prevents it from signing in again; it does not delete your project's local files or revoke device access already granted. You can revoke that access separately in your account.
Cookies and service operations
The sign-in service uses a short-lived, host-only cookie to keep a browser authentication attempt together. Its authentication pages do not include advertising or analytics scripts.
Emm records operational events such as invitation delivery, project joining, synchronization, and active use. The relay's analytics events use identifiers and outcomes, not emails, invitation secrets, Google tokens, or project content. Service providers operate our hosting, backups, DNS, and email delivery.
Questions and requests
For questions about your data, or to request account or data deletion, contact owen@emmflow.com. Shared project records and copies held by other members may need separate handling.
This page describes Emm's account and collaboration services. Google and your password manager have their own privacy policies.