Privacy Policy

Last updated: July 2026

1. Information We Collect

Account Information: When you register, we collect your name, email address, and organization name. Passwords are hashed and never stored in plain text.

Business Information: During onboarding, you provide business details including services, pricing, brand voice, and knowledge base content. This information is used exclusively to power your AI employees.

Usage Data: We collect information about how you interact with the platform to improve our services, including page visits, feature usage, and AI interaction counts.

Customer Interaction Data: Conversations between your website visitors and Amara are stored to enable lead capture, conversation history, and service improvement.

2. How We Use Your Information

Your information is used to:

  • Power your AI employees (Amara, Kofi, Nia) with your business context
  • Manage your account, subscription, and billing
  • Send essential service communications (account confirmations, security alerts)
  • Improve platform performance and features
  • Provide customer support

3. Data Isolation

Your business data is completely isolated from other customers. All database queries are filtered by your organization and business identifiers. No other customer can access your data, conversations, leads, or knowledge base.

4. AI and Data Processing

Your knowledge base entries and conversation history are sent to AI language models to generate responses, qualify leads, and create content. We do not use your data to train public AI models. AI processing is done through our secured API infrastructure.

5. Data Retention

Your data is retained for as long as your account is active. If you cancel your subscription, your data remains available for export for 30 days. After 30 days, data is scheduled for deletion. Audit logs may be retained for up to 12 months for security purposes.

6. Data Sharing

We do not sell your data. We may share data with: payment processors (Stripe) for billing, AI service providers for generating responses, and as required by law. All third-party processors are bound by data processing agreements.

7. Your Rights

You have the right to: access your data, correct inaccurate data, export your data, request deletion of your data, and object to specific processing activities. Contact us to exercise these rights.

8. Security

We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest (AES-256), password hashing (bcrypt), and role-based access controls. See our Security page for more details.

9. Contact

For privacy inquiries, contact us at [email protected].