Privacy Policy
Last updated: 14 September 2026
Ami is a personal assistant that answers questions using data from accounts you choose to connect: email, calendar, files, and similar services. This policy describes exactly what it reads, where that data goes, and how to remove it.
Who we are
Ami is operated by an individual developer and is available at askami.xyz. For any privacy question or request, email ameerup@gmail.com.
What we collect
Account information
When you sign in with Google we store your name, email address, profile image URL, and a Google account identifier. This exists only to identify your account across sessions.
Data from services you connect
Nothing is read until you explicitly connect a service. For each one, we request read-only access and read only what is listed here. The scope column is the exact OAuth scope Ami asks for on the consent screen:
| Service | OAuth scope requested | What Ami reads |
|---|---|---|
| Google sign-in | openid, email, profile | Your name, email address, profile image URL, and Google account identifier, to create and identify your Ami account. |
| Gmail | https://www.googleapis.com/auth/gmail.readonly | Sender, subject, date, and the short preview snippet of recent messages; whether a message has an attachment; your unread count and mailbox address. Messages are requested in metadata form: full message bodies and attachments are never read or downloaded. |
| Google Calendar | https://www.googleapis.com/auth/calendar.events.readonly | Upcoming event titles, times, locations, and attendee counts, on your primary calendar. |
| Google Drive / Docs / Sheets | https://www.googleapis.com/auth/drive.readonly | File names, types, and modified dates, and your storage total. For up to three recent Google Docs, the first 1,500 characters of text. One scope covers all three services: Docs and Sheets are listed through Drive’s file search and read through Drive’s plain-text export, so no separate Docs or Sheets scope is requested. |
| Google Contacts | https://www.googleapis.com/auth/contacts.readonly | Names and email addresses of your contacts. |
| Google Tasks | https://www.googleapis.com/auth/tasks.readonly | Titles, notes, and due dates of your open tasks, and the names of the lists they are on. |
| YouTube | https://www.googleapis.com/auth/youtube.readonly | Your channel name and subscription list. |
| Outlook | Mail.Read, Calendars.Read, User.Read, offline_access (Microsoft Graph) | Mailbox address and message counts, calendar entries. |
| OneDrive / OneNote | Files.Read, Notes.Read, User.Read, offline_access (Microsoft Graph) | Drive owner and storage used, notebook names. |
| Apple Calendar / Reminders | None — CalDAV with an app-specific password you create | Calendar and reminder-list names. |
| Canvas | None — a personal access token you create | Your name and enrolled course list. |
Ami never writes, sends, deletes, or modifies anything in a connected account. All access is read-only. We request the narrowest scope each feature can work with: Calendar is requested as events-only rather than full calendar access, and Docs, Sheets and Drive share a single scope rather than three.
Check-in contact
Ami has an optional safety check-in. If you turn it on and name someone, Ami stores that person’s name and email address on its server, along with the date the app was last opened on your device and how many days of silence you chose. If the app goes unopened for that long, Ami sends that person a single email asking them to check on you.
This is the only personal information about someone other than you that Ami stores, and it exists only because the feature cannot work on the phone alone: an app that is not being opened cannot run, so the counting has to happen elsewhere. Nothing else you write down in Ami is stored on the server. The details are never used for anything else, never shared, and are deleted the moment you remove the contact or delete your account. If you never turn the feature on, no record is created at all.
How your data is used
When you ask Ami a question, relevant data from your connected services is retrieved live and included in the request sent to the AI model that writes the reply. That is the sole purpose. We do not use your data to build advertising profiles or for any other purpose.
Never used to train AI models
Google user data is never used to create, train, fine-tune, evaluate or improve any machine learning or artificial intelligence model. This applies to models operated by us and to any third-party model, including generalised or non-personalised ones.
Ami sends the relevant excerpts of your data to Perplexity AI’s Chat Completions API, which processes them solely to generate the answer to the question you asked. Perplexity’s API documentation states that it maintains a “Zero Data Retention Policy for the Chat Completions API” and that it does “not use customer data to train our models or for any purpose beyond processing the immediate request” (Perplexity API privacy & security documentation). Ami calls that API and no other model provider.
Who we share it with
To generate replies, the content described above is transmitted to Perplexity AI (privacy policy), which operates the language model. This includes email senders, subjects and snippets, calendar entries, file names, and document excerpts relevant to your question.
We also use Supabase for database hosting and Vercel for application hosting.
We do not sell your data, and we do not share it with anyone else except where required by law.
Google user data and Limited Use
Ami’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Specifically, Google user data is:
- used only to provide and improve the features you request;
- never transferred to others except as needed to provide those features (see Perplexity AI above), for security purposes, or to comply with applicable law;
- never used to develop, train, or improve generalised or non-personalised AI or machine learning models;
- never used for advertising;
- never sold;
- never read by humans, unless you give explicit consent for a specific issue, it is required for security or legal reasons, or the data has been aggregated and anonymised.
Storage and retention
Access tokens for your connected services are stored in our database so Ami can query them on your behalf. Content fetched from your services (emails, events, documents) is fetched fresh for each question and is not stored by Ami beyond the lifetime of that request.
We retain your account record and connection tokens until you disconnect the service or delete your account. Deleting the account removes both at once, with no retention period and no recovery window.
Security
In transit: all traffic to Ami, and every request Ami makes to Google and other providers, runs over HTTPS with TLS. The site is served only over HTTPS.
At rest:OAuth access and refresh tokens are encrypted at the application level before they are written to the database, using AES-256-GCM envelope encryption with a unique data key per stored value. Key material is held in the deployment’s secret manager, never in the database and never in source code, so a copy of the database alone does not yield a usable token.
Underlying storage: the database is managed by Supabase, encrypted at rest by the provider, on infrastructure that is not publicly reachable.
Access controls: application data is reachable only through the server, never directly from your browser or phone. The database blocks direct client access by default (row-level security is on with no public policies), and every query is scoped to the signed-in user. One individual developer has administrative access; no other person or company has access to your connected-account data.
Deletion: disconnecting a service deletes its stored tokens immediately, and deleting your account removes your account record, every connected service and its tokens, chats, tasks, family members and groups in a single operation, with no retention period and no recovery window.
Ami is an early-stage project run by one developer. If you find a security issue, email ameerup@gmail.com.
Your choices
- Disconnect a service at any time from the Connections page. This deletes its stored tokens immediately.
- Revoke access from Google directly at myaccount.google.com/permissions.
- Delete your account and all associated data at askami.xyz/delete-account, or from Settings in the iPhone and Android apps. Deletion is immediate and permanent: the account record, every connected service and its stored tokens, your chats, tasks, family members and groups are removed in one operation, and every session ends with them. There is nothing to request and nobody to email.
Children
Ami is not directed at children under 13, and we do not knowingly collect their data.
Changes
We may update this policy. Material changes will be reflected in the “last updated” date above, and continued use after a change constitutes acceptance.
Questions? Email ameerup@gmail.com.