Amgram

Privacy Policy

What Amgram collects, why, how long we keep it, and how to exercise your rights.

Version 1.1 · effective July 30, 2026

Who we are

Amgram is an AI assistant with a persistent memory, operated by JF Boyer, based in the Province of Québec, Canada. JF Boyer is the controller of the personal information described here, and is the person responsible for the protection of personal information for the purposes of Québec's Law 25.

For any question or request — about privacy or anything else — write to ask@amgram.ai, or see the Support page. Put "privacy" in the subject line and it gets handled as a data request rather than a support question.

This policy covers the Amgram web app, the Amgram mobile apps for iOS and Android, and the Amgram desktop app. It does not cover third-party services you choose to connect, which are governed by their own policies.

What we collect and why

Amgram remembers what you tell it so it can personalize its answers. The categories below are what that requires.

CategoryWhy we have itLegal basisHow long
Account and identity — your email address, your account identifier, the names you give your workspaces and organization, and your role.To create your account, sign you in, and keep your data separate from other users.Performance of our agreement with you.Until you delete your account.
Your conversations — the messages you write, your thread titles, and the material we derive from them so the assistant can find relevant context again.To hold the conversation and to provide the memory that is the point of the service.Performance of our agreement with you.Until you delete the thread or your account.
What Amgram remembers about you — facts and preferences drawn from your use of the service.To personalize answers without you repeating yourself.Your consent, given by using the memory features.Until you delete the memory or your account.
Documents you upload — your files, and the material we derive from them.So the assistant can read and cite your own documents.Performance of our agreement with you.Until you delete the document or your account.
Personalization signals — observations about how you work, the suggestions the service proposes, and your answers to them.To improve how the service personalizes over time.Your consent, recorded when you first answer a personalization prompt.Until you delete your account.
Connected accounts — for each third-party service you connect, the access credentials and the account identifier at that service, plus a record of connector activity.To read the data you asked the assistant to read on your behalf.Your consent, given per connection.Until you disconnect the service or delete your account.
Search queries — the query sent to a search provider when a request requires a web search.To answer questions that need current information.Performance of our agreement with you.Not retained by us beyond the request.
Usage measurement — request and consumption counts tied to your account. No message content.To measure usage, control cost, and enforce limits.Performance of our agreement with you.Until you delete your account.
Consent records — which consent you gave, its version, when, and the IP address and browser captured at that moment as proof.To be able to demonstrate that consent was given.Our legal obligation of accountability.Retained after account deletion, stripped of identifying columns — see below.
Diagnostics and administration — error reports, and logs of administrative and configuration changes.To find and fix faults, and to show who changed what.Our legitimate interest in running a secure, working service.Retained, de-identified when you delete your account — see below.

We do not collect your precise location, and we do not read your contacts, address book, photo library, or calendar. On mobile, the camera, photo, and file pickers open only when you tap to attach something, and we receive only the file you pick.

Who else receives your information

We use third-party service providers to operate Amgram. They act on our instructions, under contract, and only for the purposes above. They fall into these categories:

  • cloud infrastructure providers, for hosting, databases, authentication, and file storage;
  • artificial-intelligence model providers, which receive the content of a request in order to generate the response;
  • a web search provider, which receives a search query when a request requires one;
  • an email delivery provider, for account emails such as sign-in confirmation and password reset;
  • an error-monitoring provider, for technical diagnostics;
  • any third-party service you explicitly connect, which receives the requests we make on your behalf under your own account there.

If you installed a mobile app from an app store, that store collects its own installation and account data under its own policy. We do not receive your store account details.

We also disclose personal information where the law requires it, or to establish or defend a legal claim.

Automated processing

Amgram generates its responses using artificial-intelligence models operated by the providers described above. To produce an answer, the content of your request is transmitted to one of those providers.

Amgram personalizes automatically, which means automated processing of your information. It does not make any decision about you that produces a legal effect or a comparably significant effect: it decides what to say, not what you are entitled to.

Cookies and local storage

Amgram uses cookies that are strictly necessary to keep you signed in; without them the service cannot function. Your device also stores interface preferences locally, such as your light or dark theme.

How long we keep things

We keep your content until you delete it or delete your account. The exceptions are the accountability records described in the next section, which are kept deliberately and de-identified.

Deleting your account, and what survives

Where the control is available in the app, it is under Settings → Account. If you do not see it on the platform you are using, write to ask@amgram.ai from the address on your account and we will delete the account for you. Either way it is not a request that sits in a queue: your authentication record is destroyed and your data is erased in the same operation, and the account cannot be recovered.

What is erased: your account record, your conversations and everything derived from them, your memories and preferences, your uploaded documents, your personalization signals, your connected-account credentials and connector history, your usage records, your workspaces and organization, and your place in any feature rollout list.

What survives, and why:

  • Your consent records survive with the identifying columns removed. We are required to be able to demonstrate that consent was given; a consent log that is deleted on request proves nothing.
  • Administrative and configuration audit logs survive with your identifier set to null. They record that a change was made, not who you are.
  • A deletion receipt survives: your former account identifier, a timestamp, and the number of records removed. It contains no content, and it is the evidence the erasure took place.

Deleting your Amgram account does not cancel anything at a service you connected. Disconnect it in Amgram, or revoke Amgram's access from that service.

Backups held by our infrastructure providers are rotated on their own schedule, so an erased record can persist in a backup for a short period before it ages out. It is not restored into the live service.

Your rights

You can ask us to give you a copy of your personal information, correct it, delete it, or stop processing it, and you can withdraw a consent you gave. If you are in Québec or the European Union, you also have the rights your law gives you specifically, including access in a structured technical format and the right to be informed about automated processing.

In the app you can review and edit the preferences Amgram has recorded, remove documents you uploaded, and delete your account and everything in it. Some controls are still rolling out to all accounts. There is no self-service export yet — until there is, ask us and we will produce your data by hand.

Write to ask@amgram.ai from the email address on the account, with "privacy" in the subject line so it is not mistaken for a support question. We answer within 30 days. If we refuse a request, we will tell you why and how to challenge it.

If you are not satisfied with how we handled your request, you can complain to the Commission d'accès à l'information du Québec, or, in the European Union, to your national data protection authority.

Security

We apply technical and organizational measures appropriate to the sensitivity of the information, including encryption in transit, encryption of stored credentials, access controls that separate one account's data from another's, and restricted access to production systems.

No service is perfectly secure, and we will not pretend otherwise. If you find a vulnerability, write to ask@amgram.ai with "security" in the subject line, before disclosing it publicly. If a breach presenting a risk of serious injury affects you, we will notify you and the relevant authority as the law requires.

Where your data is processed

Your data is stored in the United States, in the East US (North Virginia) region. Our service providers may process it in other regions, which may be outside your country.

If you are in the European Union, this means your information is transferred outside the EU. Those transfers rely on the standard contractual protections our providers offer.

Children

Amgram is not intended for children. You must be at least 13 years old to create an account, and where the age of digital consent is higher — 14 in Québec, up to 16 in parts of the European Union — a parent or guardian must consent for you. We do not knowingly collect information from children below those ages; if we learn we have, we delete the account and its data.

Changes to this policy

If we change how we handle your information, we update this page and the version and effective date at the top. For changes that require it, we will tell you in the app or by email before they take effect, and where the law requires your consent, we will ask for it.

Contact

Everything reaches us at ask@amgram.ai — use "privacy" in the subject for a data request, "security" for a vulnerability. Operated by JF Boyer, the Province of Québec, Canada.

See also our Terms of Service and our Support page.