Last updated: August 19, 2026
Amani Digital LLC("we", "us", or "our") makes two kinds of product: Prism, a personal intelligence app for individuals, and the Amani Intelligence Platform, a business assessment and research platform for organizations. This Privacy Policy covers both, and explains what we collect, where it is stored, who else receives it, and what you can do about it.
Prism handles material that is personal by nature — how you are doing, your relationships, your finances, your beliefs, what you write in your journal. We have tried to describe the handling of that material plainly, including the parts that are less flattering than a marketing page would put them.
Amani Digital LLC is the data controller for the personal data described here.
Company: Amani Digital LLC
Address: 1082 W 2310 N, Pleasant Grove, UT 84062, USA
Privacy contact: privacy@amanidigital.com
We are a small US company. We have not appointed a statutory Data Protection Officer and we do not operate Binding Corporate Rules; earlier versions of this policy said otherwise and were wrong. Privacy requests go to the address above and are handled by us directly.
This differs by product, and the difference matters. Please read the row that applies to you.
Your vault is a folder on your own computer, in a location you choose. We do not upload it and we hold no copy of it.
Your vault is stored on the device in an encrypted database (SQLCipher, with AES-256-GCM applied by the app). The encryption keys are held in the iOS Keychain or Android Keystore, marked so that they do not leave the device. We hold no copy of the vault.
Two exceptions where content reaches our servers: if your local vault cannot be opened when you save a journal entry, that entry is saved to your Amani account instead so it is not lost; and if we have not enabled local-vault mode for your account, journal entries and dimension data are stored on our servers rather than on the device. Whether local-vault mode is on is a setting we control, not one you set.
If you use Prism in a browser, or completed the life assessment on the web, your answers, your ten dimension profiles, and the assembled context document are stored on our servers in our database (Supabase, hosted in the United States). This cloud copy is not end-to-end encrypted. It is encrypted in transit and at rest at the storage layer, but we are technically able to read it. It is what the desktop and MCP "import from cloud" features read from.
Assessment responses, uploaded documents, research queries, and generated reports are stored on our servers, protected by row-level security and audit logging.
Prism deliberately asks about areas that European law treats as special category data under GDPR Article 9, and that California law treats as sensitive personal information: health and wellbeing, faith and spirituality, finances, relationships and family life.
We process that material only on the basis of your explicit consent (Article 9(2)(a)), collected before the relevant questions are asked. You can withdraw consent at any time from your privacy settings or by contacting us; withdrawal stops further processing but does not undo processing already carried out.
We do not use this material for advertising, we do not sell it, and we do not disclose it to anyone except the processors listed in section 9 and anyone you explicitly share it with.
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the app, generating replies, insights and reports | Contract, Art. 6(1)(b) — plus explicit consent, Art. 9(2)(a), for special category content |
| Billing and subscription management | Contract, Art. 6(1)(b) |
| Security, abuse prevention, rate limiting, crash diagnosis | Legitimate interests, Art. 6(1)(f) |
| Product analytics and marketing communications | Consent, Art. 6(1)(a) |
| Tax, accounting and legal compliance | Legal obligation, Art. 6(1)(c) |
We do not sell your personal information, and we do not use your content to train our own models or anyone else’s.
Prism’s chat is answered in the cloud. When you send a message, we receive your message, the conversation so far, and any context attached to it — which can include excerpts retrieved from your vault, your journal, past conversations, and documents you imported. Two different things can put vault content into that request, and only one of them asks you first. On mobile, a semantic search across your vault, and generating your blueprint (which assembles every dimension you have saved), each require you to approve an on-screen card before they run. The assistant can also look things up in your vault on its own — reading your dimension files, one or all of them in full; listing your document filenames and journal titles; or pulling journal entries for “on this day” — and those lookups run and are sent to us with your message without a separate prompt. On desktop, retrieved document text is attached automatically to give the model context.
We pass that content to an AI provider to generate the reply. If you configure your own provider API key in Prism Desktop, your chat goes directly from your device to that provider instead, and we do not see it.
Depending on the feature and on provider availability, your content may be processed by Anthropic (our primary provider), Google (Gemini, used as a fallback when a call to Anthropic fails, including for Prism life content), OpenAI(embeddings, voice transcription, document summarization, and one of the advisors in the business platform’s AI Council), and xAI (an AI Council advisor and some report generation). If you supply your own key, you may also route to OpenRouter or to a local Ollama model on your own hardware.
All of these providers are used under commercial API terms that prohibit training on content submitted through the API. Providers may retain API logs for a limited period for abuse monitoring — Anthropic and OpenAI document up to 30 days — before deleting them. We have not negotiated zero-retention terms.
If you connect Prism to a third-party assistant such as Claude or ChatGPT over MCP or OAuth, whatever those tools read into that conversation is processed by that vendor under your agreement with them, not under our API terms.
Dictation in Prism Mobile and Prism Desktop runs on your device: audio is transcribed locally by a bundled speech model, is held only in memory, and is not written to disk or sent to us. On the web platform, voice transcription is performed by OpenAI (Whisper), which receives the audio. Where an in-app notice tells you audio will be sent to a cloud transcription provider, that notice governs that session.
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We do use the following processors. Not all of them apply to every product; several apply only to the business platform.
| Provider | What they receive |
|---|---|
| Supabase | Database, authentication and storage for everything we persist |
| Vercel | Hosting; request logs including IP addresses |
| Anthropic | Chat, assessment and report content sent for AI generation |
| Google (Gemini) | The same content, when a call to Anthropic fails |
| OpenAI | Text embeddings, voice audio for transcription, document summaries, and AI Council queries |
| xAI (Grok) | AI Council and report generation queries |
| Stripe | Billing email, customer identifier and subscription events |
| Resend | Recipient address and the contents of emails we send you |
| Sentry | Crash and error reports, including masked web session replays |
| Upstash | Rate-limiting keys derived from IP address and user ID |
| Cloudflare | Anti-bot challenge token and IP address at sign-up |
| Expo | App update checks: platform, app version and IP address |
| Hugging Face | Model download requests when a model has to be fetched to your device: the speech model on first dictation, and a document-search model of about 91 MB the first time you make documents searchable |
| Google (ML Kit) | On-device text recognition when you import a picture of a document. The image and the recognized text stay on your device. Whether the ML Kit runtime reports its own usage telemetry to Google is something we have not verified |
| PostHog, Google Analytics | Website analytics, only with your consent |
| Serper, Tavily, You.com | Business-platform research queries derived from your business context |
| Gamma, ElevenLabs, Google Cloud | Business-platform report content for deck, narration and image generation |
| CRM and finance connectors | Business-platform only, and only for integrations you connect yourself |
We may also disclose data to legal authorities where required by law or valid legal process, and in connection with a merger, acquisition, or sale of assets. If that happens we will tell you before your data becomes subject to a different policy.
We are based in the United States and our infrastructure and processors are primarily in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the US. We rely on the European Commission’s Standard Contractual Clauses with our processors for those transfers. We do not operate Binding Corporate Rules, and we have not appointed an Article 27 representative in the EU or UK.
| Data | How long we keep it |
|---|---|
| Prism cloud vault, journal entries and profile data | For as long as your account exists. Deleted when your account is deleted. |
| Account and subscription records | For as long as your account exists, then as required for tax and accounting |
| Business assessment data and reports | For as long as the account exists, unless your organization sets a shorter period |
| Prism Desktop chat transcripts (on your device) | Approximately 90 days, then removed by the app |
| Vault contents on your own device | Until you delete them. Deleting your account does not erase them; uninstall or delete the vault folder. |
| Audit and compliance logs | Up to 7 years, as an integrity record |
| Crash reports | Per our provider default, up to 90 days |
| Marketing data | Until you withdraw consent |
| Website analytics | Up to 2 years |
We are actively improving automated enforcement of these periods. If a specific deletion matters to you, email privacy@amanidigital.com and we will carry it out rather than waiting for an automated sweep.
Wherever you live, we extend the following to you: access to your data, correction, deletion, a portable copy, restriction of and objection to processing, and withdrawal of consent. Under GDPR these are Articles 15 to 21.
We respond within 30 days. Self-service export does not yet cover every Prism record, so for a complete copy please email us and we will assemble it.
Note that deleting your account removes data held by us. It does not reach the vault on your own device, or content you have already shared with another person.
If you live in a US state with a comprehensive privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect — you have the right to know what we collect and why, to access it, to correct it, to delete it, to obtain a portable copy, and not to be treated differently for exercising any of those rights.
Sensitive data.Several states require your affirmative opt-in before we may process sensitive data, which under those laws includes health information and religious beliefs — exactly the material Prism asks about. We treat that as the standard everywhere: we collect the categories in section 5 only after you have opted in, and you can withdraw at any time.
Appeals. If we refuse a privacy request, you may appeal by replying to our decision or writing to privacy@amanidigital.comwith "Appeal" in the subject. We will respond within 45 days with our decision and the reasons for it, and tell you how to contact your state attorney general if you disagree.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by these laws, so there is no "Do Not Sell or Share My Personal Information" mechanism to offer and no universal opt-out signal, such as Global Privacy Control, applies to us. We collect sensitive personal information — see section 5 — and use it only to deliver the service you asked for, never to infer characteristics for advertising. To exercise any right, email privacy@amanidigital.com. You may use an authorized agent.
We are not certified against SOC 2 or ISO 27001. Earlier versions of our help pages claimed SOC 2 compliance; that was incorrect and has been removed. See section 3 for the limits of on-device protection in Prism Desktop.
We use AI to generate scores, insights, summaries and recommendations from what you tell us. These are advisory. We do not make decisions producing legal or similarly significant effects about you by automated means alone. You can ask for human review of anything the system produced about you, contest it, and ask us to explain the logic involved — write to privacy@amanidigital.com.
AI processing is central to how these products work. If you withdraw consent for it, most features will stop functioning.
See our Cookie Policy for what we set and how to control it. Analytics and marketing cookies are off until you consent, and we honour browser Do Not Track signals.
Our products are for adults. They are not directed to children, and we do not knowingly collect personal data from anyone under 18. We do not knowingly collect personal data from children under 13, as defined by COPPA. In the EEA and UK, our services are not offered to anyone under 16. If you believe a child has provided us with personal data, contact privacy@amanidigital.com and we will delete it.
We may update this policy. For material changes we will notify you by email or with a prominent in-product notice before they take effect, and where the change requires your consent we will ask for it again.
Please contact us first — we would rather fix it. You also have the right to complain to a supervisory authority. In the EEA you can find yours at edpb.europa.eu; in the UK, the Information Commissioner’s Office; in California, the California Privacy Protection Agency.