Last updated August 20, 2026
This describes how Amnesia AI LLC (“Amnesia AI,” “we,” “us”) processes personal data on behalf of business customers under GDPR, UK GDPR, and similar laws. It is incorporated by reference into our Terms of Service for customers who require one; contact us to execute a signed copy for your organization.
Where a customer submits personal data (for example, client or patient identifiers) into the service, the customer is the data controller and Amnesia AI is the data processor, processing that data only on the customer's documented instructions, as set out here and in the Terms of Service.
Personal data entered into the desktop app is encrypted on the customer's device to a key held by the confidential-computing enclave that runs the model. The encrypted request passes through our gateway, which relays it without holding a key that decrypts it, and is decrypted only inside that enclave. Our processing is therefore limited to: relaying encrypted requests, receiving the unencrypted portions of a turn described in section 3, metering (model, token counts, timestamp), and account and billing administration.
Depending on how the customer uses the service, this may include names, tax identifiers, financial account numbers, client or patient identifiers, and similar values entered into the app. Values contained in message content reach us only as ciphertext.
The following are not encrypted and do reach our gateway in readable form, because the protocol requires it: tool definitions; the names, arguments and results of tool calls in both directions, which may include file paths, URLs, shell commands and search queries; images and screenshots sent to the model; the identity of the model, the size of the request and reply, and the timing of the turn; and audio submitted for dictation. Where a customer's agent places personal data into any of those, we receive it in readable form.
Full detail is on our security architecture page. In summary:
We use the following subprocessors to operate the service:
We will notify customers of new subprocessors with material access to personal data with reasonable notice, at legal@amnesia.ai.
Where personal data is transferred outside the customer's region, we rely on appropriate safeguards, including Standard Contractual Clauses, with our subprocessors.
We will assist customers, to the extent our architecture allows, in responding to data subject access, correction, or deletion requests concerning account and billing data we hold. For data that only ever existed on the customer's own device, the customer controls it directly, including through free encrypted export.
We will notify affected customers without undue delay after becoming aware of a security incident affecting their personal data, with the information available to us at the time.
On reasonable request, and no more than once per year absent a security incident, we will make available information reasonably necessary to demonstrate compliance with this addendum.
This addendum applies for as long as we process personal data on the customer's behalf. On termination, we will delete or return the account and billing data we hold within a reasonable period, except where retention is required by law.
To execute a signed, entity-specific DPA, or with questions about this page: legal@amnesia.ai.