Last updated July 22, 2026
This describes what Amnesia AI LLC (“Amnesia AI,” “we,” “us”) collects when you use our desktop app, gateway, and account dashboard, and what our architecture makes it impossible for us to see even if we wanted to.
Amnesia AI masks names, identifiers, and other sensitive values on your device before any text is sent to an AI model. Our servers meter usage (which model, how many tokens, when) but are architecturally unable to log message content: the masking happens locally, and the passphrase that protects your local database never leaves your machine. We separately hold ordinary account and billing information needed to run the business, described below.
When you create an account: your email address, name (if provided), and authentication credentials, handled through our authentication provider (Supabase).
Subscription and credit-purchase billing is handled directly by Stripe. We receive confirmation of payment and plan status; we do not receive or store your full card number.
Our gateway, which proxies requests to AI model providers, records which account and model were used, token counts, and timestamps, for metering and abuse prevention. It does not log message content, masked or unmasked: that is enforced in code, not policy.
Crash and error reports (via Sentry) may include stack traces and basic device information to help us fix bugs. These reports are engineered to exclude message content and masked values.
If you email support, sales, or any other @amnesia.ai address, we keep that correspondence to respond to you and improve the product.
Message history, masked stand-ins, and audit receipts live in an encrypted local database on your device (SQLCipher, with per-column XChaCha20-Poly1305 authenticated encryption on top). The encryption key is derived from your passphrase on-device and never reaches our servers, so we cannot decrypt this data even under legal compulsion limited to what we hold. Account and billing records are stored with our infrastructure providers under encryption at rest and in transit.
We do not sell personal data. We share the minimum necessary with:
Encrypted export and import of your local data are free on every plan, verifiable with a standalone open-source verifier: your data leaves with you whenever you want, in a format we do not control. You can request access to, correction of, or deletion of the account and billing data we hold by emailing privacy@amnesia.ai. Depending on where you live, you may have additional rights under GDPR, UK GDPR, CCPA/CPRA, or similar laws, including the right to lodge a complaint with your local data protection authority.
We keep account and billing records for as long as your account is active and as needed to meet legal, tax, and accounting requirements afterward. Usage metadata used for metering is retained for the current and prior billing cycle, then aggregated or deleted. Local device data is retained entirely under your control, on your device.
Our infrastructure providers operate in the United States and may process data in other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers of personal data.
Amnesia AI is intended for professional use and is not directed at children under 16. We do not knowingly collect personal information from children.
We will update the date at the top of this page when this policy changes, and post material changes here before they take effect.
Questions about this policy: privacy@amnesia.ai. For our data-processing terms as a business customer, see our Data Processing Addendum.