Privacy Policy
Last updated: July 2026
1. Information We Collect
Account Information: When you register, we collect your name, email address, and organization name. Passwords are hashed and never stored in plain text.
Business Information: During onboarding, you provide business details including services, pricing, brand voice, and knowledge base content. This information is used exclusively to power your AI employees.
Usage Data: We collect information about how you interact with the platform to improve our services, including page visits, feature usage, and AI interaction counts.
Customer Interaction Data: Conversations between your website visitors and Amara are stored to enable lead capture, conversation history, and service improvement.
2. How We Use Your Information
Your information is used to:
- Power your AI employees (Amara, Kofi, Nia) with your business context
- Manage your account, subscription, and billing
- Send essential service communications (account confirmations, security alerts)
- Improve platform performance and features
- Provide customer support
3. Data Isolation
Your business data is completely isolated from other customers. All database queries are filtered by your organization and business identifiers. No other customer can access your data, conversations, leads, or knowledge base.
4. AI and Data Processing
Your knowledge base entries and conversation history are sent to AI language models to generate responses, qualify leads, and create content. We do not use your data to train public AI models. AI processing is done through our secured API infrastructure.
5. Data Retention
Your data is retained for as long as your account is active. If you cancel your subscription, your data remains available for export for 30 days. After 30 days, data is scheduled for deletion. Audit logs may be retained for up to 12 months for security purposes.
6. Data Sharing
We do not sell your data. We may share data with: payment processors (Stripe) for billing, AI service providers for generating responses, and as required by law. All third-party processors are bound by data processing agreements.
7. Your Rights
You have the right to: access your data, correct inaccurate data, export your data, request deletion of your data, and object to specific processing activities. Contact us to exercise these rights.
8. Security
We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest (AES-256), password hashing (bcrypt), and role-based access controls. See our Security page for more details.
9. Contact
For privacy inquiries, contact us at [email protected].