Single-use email codes
Sign-in uses a six-digit email code rather than a reusable password. Codes expire, repeated failures are limited, and authentication responses avoid revealing whether an account exists.
See how Emelyn protects account access and workspace boundaries, approaches data handling, and gives you a direct route to report a concern.
The controls are designed to make sign-in, sessions, workspace context, and permission checks explicit rather than hidden behind a general security claim.
Sign-in uses a six-digit email code rather than a reusable password. Codes expire, repeated failures are limited, and authentication responses avoid revealing whether an account exists.
Production session tokens use Secure, HttpOnly cookies rather than local storage. State-changing requests are checked against CSRF protection.
Signed-in users can review meaningful device and activity context for active sessions and revoke another session without exposing its raw token.
The backend resolves the signed-in user's sole active organization membership and its workspace. It checks that relationship rather than trusting a workspace selection from session state, a URL, or browser-only settings.
The privacy notice remains the controlling public explanation of information collection, use, sharing, retention, and individual choices.
Emelyn may process sources, topics, brand guidance, instructions, drafts, edits, approvals, and publishing context that you provide or authorize for the service.
Optional analytics require a visitor choice. Message bodies, passwords, access tokens, private drafts, and payment details are excluded from product analytics.
We do not sell personal information or share private workflow content for unrelated targeted advertising. Retention depends on the purpose, account relationship, security and backup cycles, disputes, and legal requirements. Customer-specific commitments belong in written terms.
Connected services
Emelyn's connected-service standard is to explain required permissions, what the service can read or change, token handling, reconnection behavior, limits, failure states, and how to disconnect it. Do not send passwords or access tokens through the contact form or support email.
Email from an address we can reasonably verify and avoid placing secrets or sensitive content in the first message.