Last updated 1 August 2026.
Emdee is operated by Geoffrey Kimpyneck, sole trader, Geneva, Switzerland. Contact: hello@emdeeapp.com
Emdee is subject to the Swiss Federal Act on Data Protection (FADP) and, for users in the European Union, to the GDPR.
If you use Emdee without an account, we collect nothing about your documents. The editor runs in your browser. Your files stay on your machine, in your browser's local storage or in the files you open from your own disk. Nothing is sent to us, and there is nothing for us to keep.
You only give us data when you deliberately create an account and turn on cloud sync.
Nothing about you or your documents reaches our servers.
The only exception is what any web server necessarily sees when you load a page: your IP address, your browser's user agent, and the pages requested. We use these to keep the service running and to prevent abuse, and they are kept only for the short rotation period of our hosting provider's logs.
| What | Why | Legal basis |
|---|---|---|
| Your email address | Identifying your account, sending sign-in codes | Performance of the contract |
| Your display name | Showing it in the app. Comes from Google or GitHub if you sign in that way, otherwise you choose it | Performance of the contract |
| Your documents, if you enable cloud sync | Storing them and synchronising them across your devices | Performance of the contract |
| Your subscription status and billing period | Knowing whether your plan is active | Performance of the contract |
| Access tokens you create for AI assistants | Letting your assistant reach your documents. We store a hash, never the token itself | Performance of the contract |
| Server logs (IP address, user agent) | Security, diagnostics, abuse prevention | Legitimate interest |
We do not build advertising profiles, we do not sell data, and we do not use your documents to train anything.
The file converter at /converter processes your file entirely in memory and returns the
Markdown to your browser. The uploaded file is never written to disk on our side and never
stored. Once the response is sent, nothing remains.
We use a small number of providers. This is the complete list.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and authentication: your account, documents and tokens | Paris, European Union |
| Railway | Application hosting | United States |
| Stripe | Payment processing. Stripe is also the legal seller of Emdee Pro (see Terms) | United States, European Union |
| Brevo | Transactional emails, such as your sign-in codes | European Union |
| Cloudflare | DNS, and forwarding email sent to our contact address | United States |
We do not use any AI provider. Emdee sends nothing to Anthropic, OpenAI or anyone comparable. This is worth stating plainly, because the opposite is common.
Emdee Pro lets you connect an AI assistant, such as Claude, to your documents.
When you do, it is your assistant that reads your documents, using an access token you created, under your own account with that provider. We do not send your documents to the assistant, and we have no relationship with it. What the assistant does with what it reads is governed by your agreement with that provider, not by this policy.
You can revoke any access token at any time from Emdee, which immediately cuts that access.
Your documents and account data are stored in the European Union (Supabase, Paris).
Some of our providers are based in the United States, as shown in the table above. Transfers to them rely on the safeguards those providers offer, in particular the European Commission's Standard Contractual Clauses and, where applicable, the EU–U.S. and Swiss–U.S. Data Privacy Frameworks.
You can ask us to access, correct, delete or export your data, to restrict or object to its processing, and — if you are in the EU — to lodge a complaint with your supervisory authority. In Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Two of these you can exercise yourself, immediately, without asking anyone:
.zip of everything, in
plain Markdown. That is your right to portability, available at any time.For anything else, write to hello@emdeeapp.com.
Data is encrypted in transit. Access to your documents is enforced at the database level by row-level security, so a request that is not yours is refused by the database itself rather than by application code. Access tokens are stored as SHA-256 hashes and can be revoked at any time. Payment card details never reach our servers: they go directly to Stripe.
No system is perfect, and we do not claim otherwise.
Emdee stores data in your browser to work: your open documents in local mode, your preferences (theme, panel state), and your session if you are signed in. These are not advertising cookies, and we use no analytics or third-party tracker today. If that ever changes, this page will say so before it happens.
If we change this policy in a way that matters, we will say so on this page and, for anything significant, by email to account holders.
hello@emdeeapp.com