Privacy Policy
Effective June 11, 2026
Amara provides an audit layer for AI customer operations: we review AI-handled customer conversations against our customers' private policies, permissions, and compliance rules. This policy explains what we collect, how we use it, and the commitments we make. It applies to tryamara.ai and the Amara application.
Information we collect
- Account information: name, work email, and authentication identifiers when you sign in (via Google or magic link).
- Customer content: policy documents and AI conversation data that customers upload or connect for auditing. Automated redaction is applied at ingestion to strip common personal data patterns (card numbers, emails, phone numbers, government identifiers) before storage.
- Audit records: findings, risk categorizations, reviewer decisions, and audit logs generated by the service.
- Usage data: standard logs (IP address, browser type, pages viewed) used for security and service operation.
How we use information
- To provide the service: auditing conversations, generating findings and reports, and maintaining compliance-ready audit trails.
- To improve each customer's own results: reviewer decisions build that customer's private evaluation corpus, used only for that customer.
- To operate and secure the platform, including fraud prevention and debugging.
- To communicate with you about the service.
What we do not do
- We do not train foundation models on customer content.
- We do not share one customer's content, policies, or audit results with any other customer. Each organization's data is isolated at the database layer.
- We do not sell personal information.
Subprocessors
We use a small set of infrastructure providers to deliver the service: Vercel (hosting), Supabase (database and authentication), Anthropic (model inference for evaluation), Resend (transactional email), and Google (optional sign-in). Each processes data only as needed to provide their function. A current subprocessor list and our data processing agreement are available on request at dpa@tryamara.ai.
Security
Customer content is encrypted in transit and at rest. Access is restricted by role and organization-level isolation, and reviews and decisions are recorded in an immutable audit log. SOC 2 is in progress; our security pack is available to customers and prospects under NDA.
Retention
Audit-sample uploads from prospective customers are retained for 30 days after report delivery unless converted to a paid engagement. Customer data under an active agreement is retained for the duration of the agreement and deleted or returned on termination, subject to legal obligations.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing (including under GDPR and CCPA). Contact privacy@tryamara.ai and we will respond within applicable legal timelines. Where Amara processes personal data inside customer content, we act as a processor on the customer's instructions; requests may be referred to the relevant customer.
Changes
We will post updates to this policy here and update the effective date. Material changes will be communicated to account holders by email.
Contact
Amara · privacy@tryamara.ai