Privacy Policy
How Amvio, Inc., a Delaware corporation handles personal information — what it collects, who it reaches, how long it is kept, and what you can ask us to do about it.
1. Two groups of people, treated differently
1.1 Customers are the companies that install Amvio in their product and sign in to the dashboard. For their account data, Amvio is the controller — we decide what to do with it.
1.2 End usersare the people who talk to Amvio inside a customer's product. For their data, the customer is the controller and Amvio is the processor: it is their product, their relationship, and their instructions. If you are an end user, the company whose product you were using decides what happens to your data, and this notice is written for you.
1.3 Amvio does not use one customer's data to answer anyone else's questions, does not train models on customer data, and does not sell personal information or share it for cross-context behavioural advertising.
2. What we collect from customers
2.1 Account information — your name, email address, the organisation and workspace you create, and everyone you invite.
2.2 Configuration — what your product does, who uses it, how far it will go before handing to a person, and where those handoffs go.
2.3 Knowledge you provide — documentation pages Amvio crawls, files you upload, and text you paste.
2.4 Technical data — IP address, browser and device information, and log records of requests to the service, kept for security and debugging.
3. What we collect from end users
3.1 Conversations, in full — every message either side sent, and what Amvio did about them.
3.2 Identity, only when the customer supplies it. Amvio has no way to know who anyone is unless the customer's own servers tell it, via a signed call carrying their account and user identifiers and optionally a name and email. Without that call, sessions are anonymous and stay that way.
3.3 Microphone audio, and images of the screen where screen sharing is enabled. Amvio is a voice product: a live session captures audio, and can capture still frames of whatever the user is sharing, so it can see what someone is struggling with. Both are off unless a customer turns them on, and both are sent to Google to be processed — see section 5.
3.4 What Amvio infers — which pages people get stuck on, which questions the documentation does not answer, sentiment, and signals that an account is at risk.
4. Why we process it, and on what basis
4.1 To provide the service— answering your customers, indexing your documentation, producing dashboard analysis. For customer data this is performance of our contract with you. For end user data we act on the customer's instructions as processor.
4.2 To secure the service — abuse prevention, rate limiting, audit logs, investigating incidents. Our legitimate interest in operating a safe service.
4.3 To communicate with you — service notices, billing, and support. Contract, and our legitimate interest in administering the relationship.
4.4 To comply with law — retaining records and responding to lawful requests. Legal obligation.
4.5 Where a customer enables voice or screen capture, the lawful basis for capturing an end user's audio or screen is the customer's to establish, and in most jurisdictions that means consent obtained before the session starts.
5. Who else sees it
5.1 Amvio runs on other companies' infrastructure and sends data to it in the course of working. The full list is here, with what each one receives. Three are worth stating in the policy itself, because they are not optional and not obvious.
5.2 Googlereceives the live session — microphone audio, shared screen frames, and the conversation text — because the voice model is Google's. It is the only provider that receives audio or images.
5.3 OpenAI receives every piece of knowledge you give Amvio, because all of it is embedded through OpenAI regardless of which model answers your customers.
5.4 Supabase holds everything Amvio stores: conversations, files, indexed documentation and derived signals.
5.5 We may also disclose information where required by law, to enforce our terms, or to a successor in a merger or sale — in which case this policy continues to apply until replaced with notice to you.
6. International transfers
6.1 Amvio is established in the United States and its providers process data in the United States and elsewhere. Using Amvio means personal data leaving the UK and EEA.
6.2 For transfers of EEA or UK personal data, Amvio relies on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into our Data Processing Agreement and passed down to sub-processors.
7. How long it is kept
7.1 Conversations, memory and derived signals persist for as long as the workspace exists. Durable memory across sessions is what the product is for — Amvio remembering someone six months later is the feature, not incidental retention.
7.2 Deleting an account removes its profile and its membership of every organisation.
7.3 On termination, customer data is deleted within 30 days of a written request, and within 90 days in any event, except where we must keep records to comply with law. Backups age out on their own cycle and are not restored to serve a deleted workspace.
7.4 Customers can ask us to delete a specific conversation or purge a workspace at hello@amvio.ai. There is no self-serve control for this in the dashboard today.
8. Security
8.1 Data is encrypted in transit. Workspaces are separated at the database by row-level security, so a signed-in user reaches their own organisation's rows and no others. Server-side keys are never sent to the browser and cannot be read back after generation.
8.2 The security overview describes this in full, including what Amvio has not yet done.
8.3 If a breach affects your data, we will notify you without undue delay and within 72 hours of becoming aware, with what we know and what we are doing about it.
9. Your rights
9.1 Depending on where you live you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. Exercising them never results in worse service.
9.2 California residents may request the categories and specific pieces of personal information collected, its sources, the purposes, and the categories disclosed; may request deletion or correction; and may appoint an authorised agent. Amvio does not sell personal information or share it for cross-context behavioural advertising, and does not process sensitive personal information for purposes requiring a right to limit.
9.3 UK and EEA residentsmay lodge a complaint with their supervisory authority, and in the UK with the Information Commissioner's Office.
9.4 End users: contact the company whose product you were using. They are the controller, they decide what happens to the data, and Amvio acts on their instructions — including a deletion request. If you contact us directly we will route you to them.
9.5 Customers: write to hello@amvio.ai. We will verify your identity and respond within 30 days, or tell you why we need longer.
10. Cookies
10.1 The dashboard sets cookies that keep you signed in, and nothing else. There is no advertising on this site, and no advertising or tracking cookies — which is why there is no consent banner. There is nothing to consent to beyond the cookies that make signing in work.
10.2 We count page views, using an analytics tool that sets no cookies and builds no profile of you. It records the page, the referring site and coarse device and country information, and it is run by Vercel, who already host this dashboard and are listed at /privacy/subprocessors. Nothing about it identifies you, and it is not used to follow you between sites.
10.3 The Amvio widget inside a customer's product sets no advertising or tracking cookies, and carries no analytics of its own.
11. Children
11.1 Amvio is a business product, is not directed at children, and does not knowingly collect personal information from anyone under 16. It should not be embedded in a product intended for children without the customer satisfying itself that doing so is lawful.
12. Automated decisions
12.1 Amvio scores account health and flags accounts as at risk. These are signals shown to the customer's team, not decisions taken about anyone: nothing is granted, refused or withdrawn automatically on the basis of a score, and no legal or similarly significant effect follows from one.
13. Changes to this policy
13.1 We will post the new version here with a new effective date, and for material changes give notice by email or in the dashboard at least 30 days beforehand.
Contact
Questions about any of these documents, requests about your data, and security reports all go to hello@amvio.ai.