Ami

Privacy Policy

Last updated: 14 September 2026

Ami is a personal assistant that answers questions using data from accounts you choose to connect: email, calendar, files, and similar services. This policy describes exactly what it reads, where that data goes, and how to remove it.

Who we are

Ami is operated by an individual developer and is available at askami.xyz. For any privacy question or request, email ameerup@gmail.com.

What we collect

Account information

When you sign in with Google we store your name, email address, profile image URL, and a Google account identifier. This exists only to identify your account across sessions.

Data from services you connect

Nothing is read until you explicitly connect a service. For each one, we request read-only access and read only what is listed here. The scope column is the exact OAuth scope Ami asks for on the consent screen:

ServiceOAuth scope requestedWhat Ami reads
Google sign-inopenid, email, profileYour name, email address, profile image URL, and Google account identifier, to create and identify your Ami account.
Gmailhttps://www.googleapis.com/auth/gmail.readonlySender, subject, date, and the short preview snippet of recent messages; whether a message has an attachment; your unread count and mailbox address. Messages are requested in metadata form: full message bodies and attachments are never read or downloaded.
Google Calendarhttps://www.googleapis.com/auth/calendar.events.readonlyUpcoming event titles, times, locations, and attendee counts, on your primary calendar.
Google Drive / Docs / Sheetshttps://www.googleapis.com/auth/drive.readonlyFile names, types, and modified dates, and your storage total. For up to three recent Google Docs, the first 1,500 characters of text. One scope covers all three services: Docs and Sheets are listed through Drive’s file search and read through Drive’s plain-text export, so no separate Docs or Sheets scope is requested.
Google Contactshttps://www.googleapis.com/auth/contacts.readonlyNames and email addresses of your contacts.
Google Taskshttps://www.googleapis.com/auth/tasks.readonlyTitles, notes, and due dates of your open tasks, and the names of the lists they are on.
YouTubehttps://www.googleapis.com/auth/youtube.readonlyYour channel name and subscription list.
OutlookMail.Read, Calendars.Read, User.Read, offline_access (Microsoft Graph)Mailbox address and message counts, calendar entries.
OneDrive / OneNoteFiles.Read, Notes.Read, User.Read, offline_access (Microsoft Graph)Drive owner and storage used, notebook names.
Apple Calendar / RemindersNone — CalDAV with an app-specific password you createCalendar and reminder-list names.
CanvasNone — a personal access token you createYour name and enrolled course list.

Ami never writes, sends, deletes, or modifies anything in a connected account. All access is read-only. We request the narrowest scope each feature can work with: Calendar is requested as events-only rather than full calendar access, and Docs, Sheets and Drive share a single scope rather than three.

Check-in contact

Ami has an optional safety check-in. If you turn it on and name someone, Ami stores that person’s name and email address on its server, along with the date the app was last opened on your device and how many days of silence you chose. If the app goes unopened for that long, Ami sends that person a single email asking them to check on you.

This is the only personal information about someone other than you that Ami stores, and it exists only because the feature cannot work on the phone alone: an app that is not being opened cannot run, so the counting has to happen elsewhere. Nothing else you write down in Ami is stored on the server. The details are never used for anything else, never shared, and are deleted the moment you remove the contact or delete your account. If you never turn the feature on, no record is created at all.

How your data is used

When you ask Ami a question, relevant data from your connected services is retrieved live and included in the request sent to the AI model that writes the reply. That is the sole purpose. We do not use your data to build advertising profiles or for any other purpose.

Never used to train AI models

Google user data is never used to create, train, fine-tune, evaluate or improve any machine learning or artificial intelligence model. This applies to models operated by us and to any third-party model, including generalised or non-personalised ones.

Ami sends the relevant excerpts of your data to Perplexity AI’s Chat Completions API, which processes them solely to generate the answer to the question you asked. Perplexity’s API documentation states that it maintains a “Zero Data Retention Policy for the Chat Completions API” and that it does “not use customer data to train our models or for any purpose beyond processing the immediate request” (Perplexity API privacy & security documentation). Ami calls that API and no other model provider.

Who we share it with

To generate replies, the content described above is transmitted to Perplexity AI (privacy policy), which operates the language model. This includes email senders, subjects and snippets, calendar entries, file names, and document excerpts relevant to your question.

We also use Supabase for database hosting and Vercel for application hosting.

We do not sell your data, and we do not share it with anyone else except where required by law.

Google user data and Limited Use

Ami’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Specifically, Google user data is:

Storage and retention

Access tokens for your connected services are stored in our database so Ami can query them on your behalf. Content fetched from your services (emails, events, documents) is fetched fresh for each question and is not stored by Ami beyond the lifetime of that request.

We retain your account record and connection tokens until you disconnect the service or delete your account. Deleting the account removes both at once, with no retention period and no recovery window.

Security

In transit: all traffic to Ami, and every request Ami makes to Google and other providers, runs over HTTPS with TLS. The site is served only over HTTPS.

At rest:OAuth access and refresh tokens are encrypted at the application level before they are written to the database, using AES-256-GCM envelope encryption with a unique data key per stored value. Key material is held in the deployment’s secret manager, never in the database and never in source code, so a copy of the database alone does not yield a usable token.

Underlying storage: the database is managed by Supabase, encrypted at rest by the provider, on infrastructure that is not publicly reachable.

Access controls: application data is reachable only through the server, never directly from your browser or phone. The database blocks direct client access by default (row-level security is on with no public policies), and every query is scoped to the signed-in user. One individual developer has administrative access; no other person or company has access to your connected-account data.

Deletion: disconnecting a service deletes its stored tokens immediately, and deleting your account removes your account record, every connected service and its tokens, chats, tasks, family members and groups in a single operation, with no retention period and no recovery window.

Ami is an early-stage project run by one developer. If you find a security issue, email ameerup@gmail.com.

Your choices

Children

Ami is not directed at children under 13, and we do not knowingly collect their data.

Changes

We may update this policy. Material changes will be reflected in the “last updated” date above, and continued use after a change constitutes acceptance.

Questions? Email ameerup@gmail.com.