Privacy Policy
Last updated: August 13, 2026
Translations are provided for convenience. If anything conflicts, the English version controls.
Summary
This summary is provided for convenience only and does not replace the full Privacy Policy below.
- We collect basic account, device, and website info to run Amnis.
- Amnis can process audio on your device. When Cloud is enabled or server-side AI processing is used, the audio, transcript, or personalization context needed for your request is sent securely for processing.
- We do not create voiceprints or biometric identifiers from your audio.
- The data controller depends on your billing country: Senolytic Lab 合同会社 (セノリティックラブ合同会社) (Japan) or YuniqueS Limited (all other countries, including Hong Kong).
- Payments are processed securely by Stripe or Apple; sign-in is handled by Supabase.
- We use essential cookies to run the site, plus optional analytics cookies only if you allow them.
- You can contact us to access, correct, or delete your information.
1. Data controller
The data controller depends on your billing country: Senolytic Lab 合同会社 (セノリティックラブ合同会社) for customers in Japan, and YuniqueS Limited for customers in all other countries (including Hong Kong). The entity shown on this page is based on your detected location. Your billing country at the time of subscription is the definitive determining factor.
Controller (outside Japan):YuniqueS Limited
Email:support@amnis.one
Your billing country at the time of subscription determines which entity is your data controller. If you believe the wrong entity is shown, contact us.
2. Audio data and biometric identifiers
Amnis can process audio locally on your device for transcription. When Cloud transcription is enabled or server-side AI processing is used, Amnis sends the audio or transcript needed for that request to our backend and inference providers. These providers may keep short-lived operational or security logs or caches. We do not use your content to train models without your consent. Amnis does not extract voiceprints or any other biometric identifier from your audio — transcription converts speech to text only, and no identifier capable of uniquely identifying you as a speaker is created or transmitted. If you share audio with us voluntarily (for example, in a support request), we use it solely to assist you and do not retain it beyond that purpose. Amnis does not create or process biometric data as defined under any applicable law, including GDPR Article 9, Illinois BIPA, Japan APPI, and the Australian Privacy Act.
3. Information we collect
We collect information you provide, information generated when you use the Service, and information from our payment and authentication providers.
- Account information (such as email address, account ID, sign-in events, language, and any marketing choice with its time and registration source).
- Device and app information (such as device ID, app version, platform, and language).
- Billing information from Stripe or Apple (such as subscription status, transaction or product IDs, and receipts). We do not receive full card details.
- Website technical data (such as IP address, browser type, and server logs) when you visit amnis.one.
- Download requests (email address, language, and any optional Amnis news choice with its time and download source).
- Support communications (such as emails, messages, and attachments you send us).
- Audio, transcript, and personalization content (such as dictionary entries, Smart Inserts, and per-app writing preferences) when Cloud transcription is enabled or server-side AI processing is used, including AI polishing, Assistant, or Professional Notes.
- Diagnostics (such as crash and error reports) when diagnostics sharing is enabled. This setting may be enabled initially and can be turned off in Settings.
4. On-device processing
Amnis can process audio on your device. When Cloud is enabled or server-side AI processing is used, Amnis securely sends the audio, transcript, and personalization context needed for your request to our backend and inference providers. Personalization context may include dictionary entries, Smart Inserts, and per-app writing preferences. These providers may keep short-lived operational or security logs or caches. We do not use your content to train models without your consent. If you share content with us for support, we may receive and retain it only as needed to help you.
5. How we use information
We use information to operate, secure, support, and improve the Service, and to meet legal obligations.
- Provide the Service (account access, device linking, and features).
- Authenticate users and prevent fraud, abuse, and security incidents.
- Process billing, taxes, and refunds through Stripe or Apple.
- Provide customer support and respond to your requests.
- Maintain and improve reliability and performance (for example, troubleshooting bugs).
- Send account and service emails needed to operate Amnis. Marketing email is separate and optional: it is sent only after an unchecked opt-in is explicitly selected. We record the choice, language, time, and registration or download source. Unsubscribing from marketing does not stop service emails.
- Comply with legal and accounting obligations and enforce our terms.
6. Legal bases (EEA / UK)
If you are in the EEA or UK, we process personal data under the following legal bases (as applicable):
- Contract: to provide the Service you request.
- Legitimate interests: to secure the Service, prevent fraud, and improve reliability, including operational diagnostics where permitted by law.
- Legal obligations: to comply with tax, accounting, and other laws.
- Consent: for optional features where consent is required (for example, analytics cookies or product news). You can withdraw consent at any time.
8. International data transfers
Our Japan and Hong Kong entities, together with our service providers, may process information in Japan, Hong Kong, the United States (Apple, Stripe, Supabase, Resend, hosting and Cloud inference providers), and other countries. These countries may have different data protection laws. For transfers from the EEA or UK, we rely on applicable transfer mechanisms (such as standard contractual clauses or adequacy decisions). For transfers under Japan APPI, we use appropriate safeguards; details of the legal systems and protective measures of each destination country are available on request. Contact us if you want more information.
9. Retention
We keep personal information only as long as needed for the purposes described above, such as to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements. Download-request and marketing-preference records are kept while needed for delivery and until you withdraw consent or request deletion, subject to legal requirements. For example, billing records may be retained for longer periods where required by law. You can request deletion of your account information, subject to legal requirements. Under Japan APPI, we maintain records of third-party data provisions for three years.
10. Security and breach notification
We use reasonable administrative, technical, and physical safeguards to protect personal information (for example, access controls and encryption in transit). No method of transmission or storage is 100% secure. In the event of a data breach that may create a risk of harm to you, we will notify you and the relevant regulatory authority as required by applicable law (for example, within 72 hours to EEA/UK supervisory authorities under GDPR; within approximately 3–5 business days to the Japan PPC; as soon as feasible to the Canadian OPC or CAI; and within 30 days of assessment to the Australian OAIC).
11. Your rights and choices
Depending on where you live, you may have rights regarding your personal information. We may need to verify your identity before responding. To exercise any of these rights, contact us using the details in the Contact section.
- Access / disclosure of the information we hold about you.
- Correction or update of inaccurate information.
- Deletion of information (subject to legal requirements).
- Objection to certain processing or restriction of processing (EEA/UK).
- Data portability (EEA/UK, Quebec, in certain circumstances).
- Withdrawal of consent where processing is based on consent.
- The right to lodge a complaint with your local data protection authority (EEA/UK).
- Suspension of use or third-party provision of your information on specified grounds (Japan APPI — see the Japan section below).
12. US privacy rights (CCPA / CPRA and other state laws)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you specific rights. Other US state privacy laws may provide similar rights.
- Right to know: request the categories and specific pieces of personal information we have collected about you in the prior 12 months, including sources, purposes, and third parties with whom it was shared.
- Right to delete: request deletion of personal information we have collected, subject to exceptions (for example, information needed to complete a transaction or comply with a legal obligation).
- Right to correct: request correction of inaccurate personal information we maintain.
- Right to opt-out of sale or sharing: we do not sell personal information and do not share personal information for cross-context behavioral advertising. No opt-out action is required.
- Right to limit use of sensitive personal information (SPI): we do not use SPI beyond what is necessary to provide the Service. No limit request is needed.
- Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.
- Authorized agents: you may designate an authorized agent to submit requests on your behalf by providing written authorization.
- How to submit a request: contact us by email using the details in the Contact section. We will respond within 45 days (extendable by a further 45 days with notice).
- Categories of personal information collected in the prior 12 months: identifiers (email, device ID, account ID); commercial information (subscription status, purchase records, and App Store transaction or product IDs); internet/electronic activity (app usage, website visits); and audio, transcript, or personalization content when Cloud is enabled or server-side AI processing is used. We do not collect voiceprints or other biometric identifiers — see the Audio section above.
- Shine the Light (Cal. Civil Code §1798.83): we do not disclose personal information to third parties for their direct marketing purposes.
13. Canadian privacy rights (PIPEDA and Quebec Law 25)
If you are a resident of Canada, you have rights under PIPEDA and, if you are in Quebec, under the Act respecting the protection of personal information in the private sector (Law 25 / Bill 64).
- Right to access the personal information we hold about you. We will respond within 30 days (extendable to 60 days with written notice).
- Right to correct inaccurate, incomplete, or out-of-date personal information.
- Right to withdraw consent to collection, use, or disclosure where consent is the processing basis (subject to legal or contractual requirements).
- Right to data portability (Quebec residents): receive your personal information in a structured, commonly used technological format and have it transmitted to another organization.
- Right to be informed of automated decision-making (Quebec residents): if any feature renders a decision affecting you exclusively through automated processing, you have the right to know the personal information used, the principal factors behind the decision, and to submit your views to a person who can reconsider it.
- Right to de-indexing (Quebec residents): request de-indexing or removal of hyperlinks to personal information about you where dissemination contravenes law.
- Data minimization: we collect only what is necessary for the purposes described in this policy.
- Named privacy officer: our designated Privacy Officer can be reached at the email address in the Contact section.
- Breach notification: if a breach of your personal information creates a real risk of significant harm, we will notify you and the relevant regulator (the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information for Quebec) as soon as feasible.
- To exercise any of these rights, contact us using the details in the Contact section.
14. Australian privacy rights (Privacy Act 1988)
If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to our handling of your personal information. Amnis is an APP entity for this purpose.
- Right to access: you may request access to the personal information we hold about you. We will respond within a reasonable period (typically 30 days). We may charge a reasonable cost-recovery fee in some circumstances.
- Right to correction: you may request correction of personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading. We will respond within a reasonable period.
- If we refuse an access or correction request, we will provide written reasons and information about how to make a complaint.
- Overseas recipients: we disclose personal information to overseas recipients including Apple, Stripe (United States and Ireland), Supabase (United States), hosting providers, and Cloud inference providers. We take reasonable steps to ensure overseas recipients handle information consistently with the APPs or under equivalent contractual protections.
- Notifiable Data Breaches (NDB scheme): if a data breach is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. Our NDB assessment is completed within 30 days of becoming aware of a suspected breach.
- Complaints: if you believe we have interfered with your privacy, please contact us first. If your complaint is not resolved within 30 days, you may complain to the OAIC at oaic.gov.au.
- Consumer guarantees: nothing in this policy limits any rights you have under the Australian Consumer Law.
15. Japan: additional information under APPI
This section provides additional disclosures required by Japan's Act on the Protection of Personal Information (個人情報の保護に関する法律 — APPI) as amended in 2022. The entity responsible for handling personal information for customers in Japan is Senolytic Lab 合同会社.
- Purpose of use (利用目的): (1) providing and operating the Service (account management, device activation, features); (2) processing billing and subscriptions through Stripe Japan or Apple; (3) authenticating users via Supabase; (4) responding to customer support inquiries; (5) improving the Service through aggregated analytics; (6) providing Cloud transcription and server-side AI processing, which may require transmitting audio, transcripts, or personalization context when enabled or used; (7) complying with legal obligations; (8) sending product and service communications (you may opt out at any time by contacting us).
- Voiceprints and biometric identifiers (個人識別符号): Amnis does not create, extract, or store voiceprints (声紋) or any other Personal Identifier Code from your audio. Cloud and server-side AI processing may transmit audio or transcripts when enabled or used, but no biometric identifier is created or transmitted.
- Third-party provision records (第三者提供記録): when we provide personal information to third parties, we maintain records as required by APPI Article 25 (retained for three years). When receiving personal information from third parties, we also record the source, categories, and basis as required by APPI Article 26.
- Cross-border transfers (外国にある第三者への提供): personal information may be processed in Japan, the United States (Apple; Stripe Japan, Inc.; Supabase, Inc.; hosting and Cloud inference providers), and other countries. We use appropriate safeguards. Details of the legal systems and specific protective measures of each destination country are available on request by contacting us.
- Right to request disclosure (開示請求): you may request disclosure of retained personal information we hold about you. We will respond within 30 days.
- Right to request correction or deletion (訂正・削除請求): you may request correction or deletion of inaccurate personal information. We will respond within a reasonable period (typically two weeks to one month).
- Right to request suspension of use or third-party provision (利用停止・消去・第三者提供停止請求): you may request suspension of use or cessation of third-party provision of your personal information on any of the following grounds: (a) use beyond the stated purpose or illegal collection; (b) the information is no longer needed for the purpose; (c) a data breach has occurred; or (d) continued processing is likely to harm your rights and interests. We will respond within a reasonable period.
- Breach notification (漏えい等の報告): if a breach meets the criteria under APPI (sensitive information involved, financial harm risk, malicious attack, or 1,000+ data subjects affected), we will submit a preliminary report to the Personal Information Protection Commission (PPC) promptly (approximately 3–5 business days) and notify affected individuals without delay.
- Complaint handling: for APPI-related inquiries or complaints, contact us at the email address in the Contact section. You may also file a complaint with the Personal Information Protection Commission (PPC) at ppc.go.jp.
17. Children
The Service is not intended for children. In the United States, users must be at least 13 years old. In the UK, users must be at least 13 years old. In the EEA and all other countries, users must be at least 16 years old (or the age of digital consent in their country, if higher). In Quebec, Canada, users under 14 require parental or guardian consent. We do not knowingly collect personal information from children below the applicable age threshold. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
18. Changes to this policy
We may update this Privacy Policy from time to time. We will update the date above when we do. If changes are material (for example, we change how we collect or use your data in a significant way), we will take reasonable steps to provide advance notice before the changes take effect (for example, by posting a notice on our website or sending an email). Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
19. Contact
For privacy questions, requests, or complaints, email support@amnis.one. We aim to respond within 30 days. For EU residents, you also have the right to lodge a complaint with your local data protection authority. For UK residents, with the Information Commissioner's Office (ico.org.uk). For Australian residents, with the OAIC (oaic.gov.au).