Last updated August 20, 2026
This describes what Amnesia AI LLC (“Amnesia AI,” “we,” “us”) collects when you use our desktop app, gateway, and account dashboard, and what our architecture makes it impossible for us to see even if we wanted to.
Your messages are encrypted on your device to a key held by the confidential-computing enclave that runs the model, so our gateway relays them without holding a key that decrypts them. Our servers meter usage (which model, how many tokens, when). Some parts of a turn are not encrypted and do reach our gateway readable, listed under "What our gateway can see" below. The passphrase protecting your local database never leaves your machine. We separately hold ordinary account and billing information needed to run the business, described below.
When you create an account: your email address, name (if provided), and authentication credentials, handled through our authentication provider (Supabase).
Subscription and credit-purchase billing is handled directly by Stripe. We receive confirmation of payment and plan status; we do not receive or store your full card number.
Our gateway, which relays requests to the enclave, records which account and model were used, token counts, and timestamps, for metering and abuse prevention. It does not log the content of your messages, which it cannot decrypt.
Encryption covers the content of your messages. It does not cover the actions the agent takes on your behalf, which must reach our gateway readable in order to function. On every turn that involves them, the gateway can see:
Web search queries additionally leave our infrastructure in the clear to our search provider, described under "Who we share data with."
Crash and error reports (via Sentry) may include stack traces and basic device information to help us fix bugs. These reports are engineered to exclude message content.
If you email support, sales, or any other @amnesia.ai address, we keep that correspondence to respond to you and improve the product.
Message history and attestation reports live in an encrypted local database on your device (SQLCipher, with per-column XChaCha20-Poly1305 authenticated encryption on top). The encryption key is derived from your passphrase on-device and never reaches our servers, so we cannot decrypt this data even under legal compulsion limited to what we hold. Account and billing records are stored with our infrastructure providers under encryption at rest and in transit.
We do not sell personal data. We share the minimum necessary with:
Encrypted export and import of your local data are free on every plan, verifiable with a standalone verifier binary: your data leaves with you whenever you want, in a format we do not control. You can request access to, correction of, or deletion of the account and billing data we hold by emailing privacy@amnesia.ai. Depending on where you live, you may have additional rights under GDPR, UK GDPR, CCPA/CPRA, or similar laws, including the right to lodge a complaint with your local data protection authority.
We keep account and billing records for as long as your account is active and as needed to meet legal, tax, and accounting requirements afterward. Usage metadata used for metering is retained for the current and prior billing cycle, then aggregated or deleted. Local device data is retained entirely under your control, on your device.
Our infrastructure providers operate in the United States and may process data in other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers of personal data.
Amnesia AI is intended for professional use and is not directed at children under 16. We do not knowingly collect personal information from children.
We will update the date at the top of this page when this policy changes, and post material changes here before they take effect.
Questions about this policy: privacy@amnesia.ai. For our data-processing terms as a business customer, see our Data Processing Addendum.