Skip to main content

Privacy Policy

Last updated: August 19, 2026

Amani Digital LLC("we", "us", or "our") makes two kinds of product: Prism, a personal intelligence app for individuals, and the Amani Intelligence Platform, a business assessment and research platform for organizations. This Privacy Policy covers both, and explains what we collect, where it is stored, who else receives it, and what you can do about it.

Prism handles material that is personal by nature — how you are doing, your relationships, your finances, your beliefs, what you write in your journal. We have tried to describe the handling of that material plainly, including the parts that are less flattering than a marketing page would put them.

1. What This Policy Covers

  • Prism Desktop(macOS and Windows) — the installed app and its local vault.
  • Prism Mobile(iOS and Android) — the installed app and its on-device encrypted vault.
  • Prism on the web— account creation, billing, the life assessment, and the cloud vault at amanidigital.com.
  • Prism inside another AI assistant— when you connect Prism to Claude, ChatGPT, or a similar client over MCP or OAuth.
  • The Amani Intelligence Platform— the business assessment, research, and reporting product.
  • Our marketing website.

2. Who Is Responsible

Amani Digital LLC is the data controller for the personal data described here.

Company: Amani Digital LLC

Address: 1082 W 2310 N, Pleasant Grove, UT 84062, USA

Privacy contact: privacy@amanidigital.com

We are a small US company. We have not appointed a statutory Data Protection Officer and we do not operate Binding Corporate Rules; earlier versions of this policy said otherwise and were wrong. Privacy requests go to the address above and are handled by us directly.

3. Where Your Data Is Stored

This differs by product, and the difference matters. Please read the row that applies to you.

3.1 Prism Desktop

Your vault is a folder on your own computer, in a location you choose. We do not upload it and we hold no copy of it.

  • Your life dimensions and journal entries are saved as readable Markdown filesin that folder. They are not encrypted by the app. This makes your data genuinely yours — portable, greppable, editable in any tool — and it also means anyone with access to your computer, your user account, or your device backups can read them. We recommend enabling full-disk encryption (FileVault on macOS, BitLocker on Windows).
  • Documents you import are encrypted on disk, as are your keys and any local telemetry.
  • Your chat transcripts are stored separately from the vault, unencrypted, inside the app’s local browser storage, and are deleted after approximately 90 days. They are not covered by the vault export or vault delete controls.
  • Your sign-in tokens and any AI provider API keys you supply are stored in a permissions-restricted file in the app’s application-data folder, not in your operating system’s keychain. Your provider keys are never transmitted to us.

3.2 Prism Mobile

Your vault is stored on the device in an encrypted database (SQLCipher, with AES-256-GCM applied by the app). The encryption keys are held in the iOS Keychain or Android Keystore, marked so that they do not leave the device. We hold no copy of the vault.

Two exceptions where content reaches our servers: if your local vault cannot be opened when you save a journal entry, that entry is saved to your Amani account instead so it is not lost; and if we have not enabled local-vault mode for your account, journal entries and dimension data are stored on our servers rather than on the device. Whether local-vault mode is on is a setting we control, not one you set.

3.3 Prism on the web, and the cloud vault

If you use Prism in a browser, or completed the life assessment on the web, your answers, your ten dimension profiles, and the assembled context document are stored on our servers in our database (Supabase, hosted in the United States). This cloud copy is not end-to-end encrypted. It is encrypted in transit and at rest at the storage layer, but we are technically able to read it. It is what the desktop and MCP "import from cloud" features read from.

3.4 Device sync and sharing

  • Device sync, where enabled, uploads your dimension files to our relay as ciphertext we cannot read. We do receive, in readable form, the associated metadata: which vault and which dimension, a version number, which device made the change, its approximate size and timing, and your account and IP address at sync time. That metadata tells us which areas of your life you are tracking and how often, even though it does not tell us what you wrote.
  • Sharing a dimension with a person (a coach, partner, or contact) is end-to-end encrypted to that recipient. Our relay carries only ciphertext.
  • Sharing into a team or workspace is different: that path sends the decrypted dimension content to our servers, where it is stored in readable form so the workspace can use it. Do not treat a team share as private from us.

3.5 The business platform

Assessment responses, uploaded documents, research queries, and generated reports are stored on our servers, protected by row-level security and audit logging.

4. Information We Collect

4.1 You provide

  • Account information: name, email address, and (for business accounts) phone number, company, and job title.
  • Personal life content (Prism): your answers across the ten life dimensions, journal entries, documents you import, and your conversations with Prism.
  • Business content (platform): assessment responses, business documents, and research queries.
  • Payment information: handled by Stripe. We receive your billing email, a Stripe customer identifier, and subscription status. We never see your full card number.
  • Voice: see section 7.
  • Communications: support requests, feedback, and reports you send about AI responses.

4.2 Collected automatically

  • Usage and device data: pages and features used, browser and operating system, and IP address, in our server and hosting logs.
  • App checks:the apps contact us on launch to confirm your subscription and which features are enabled for you, and contact Expo’s update service to check for a new version. Both requests carry your IP address, and the subscription check is tied to your account.
  • Crash and error reports: see section 8.
  • Cookies and analytics: see our Cookie Policy.

4.3 Device permissions the apps ask for

  • Microphone (Prism Mobile and Desktop):for dictation. The audio is transcribed on your device — see section 7.3.
  • Photos and camera (Prism Mobile): your photo library, so you can import a document by choosing a picture of it, and the camera, so you can scan the pairing QR code shown on another device. When you import a picture, the text in it is read by an on-device text recognizer (Google ML Kit). The image is processed on the handset and is not uploaded to us. The text it produces is saved into your vault like any other document, which means it can afterwards be retrieved into a chat and sent to an AI provider along with your message.
  • Notifications (Prism Mobile): reminders, only if you turn them on. They are scheduled by your own device on a repeating daily trigger and fire locally. We do not send push notifications and we do not hold a push token for you.

5. Sensitive and Special Category Data

Prism deliberately asks about areas that European law treats as special category data under GDPR Article 9, and that California law treats as sensitive personal information: health and wellbeing, faith and spirituality, finances, relationships and family life.

We process that material only on the basis of your explicit consent (Article 9(2)(a)), collected before the relevant questions are asked. You can withdraw consent at any time from your privacy settings or by contacting us; withdrawal stops further processing but does not undo processing already carried out.

We do not use this material for advertising, we do not sell it, and we do not disclose it to anyone except the processors listed in section 9 and anyone you explicitly share it with.

6. How We Use Your Information, and Our Legal Basis

PurposeLegal basis (GDPR)
Providing the app, generating replies, insights and reportsContract, Art. 6(1)(b) — plus explicit consent, Art. 9(2)(a), for special category content
Billing and subscription managementContract, Art. 6(1)(b)
Security, abuse prevention, rate limiting, crash diagnosisLegitimate interests, Art. 6(1)(f)
Product analytics and marketing communicationsConsent, Art. 6(1)(a)
Tax, accounting and legal complianceLegal obligation, Art. 6(1)(c)

We do not sell your personal information, and we do not use your content to train our own models or anyone else’s.

7. AI Processing and Voice

7.1 What leaves your device

Prism’s chat is answered in the cloud. When you send a message, we receive your message, the conversation so far, and any context attached to it — which can include excerpts retrieved from your vault, your journal, past conversations, and documents you imported. Two different things can put vault content into that request, and only one of them asks you first. On mobile, a semantic search across your vault, and generating your blueprint (which assembles every dimension you have saved), each require you to approve an on-screen card before they run. The assistant can also look things up in your vault on its own — reading your dimension files, one or all of them in full; listing your document filenames and journal titles; or pulling journal entries for “on this day” — and those lookups run and are sent to us with your message without a separate prompt. On desktop, retrieved document text is attached automatically to give the model context.

We pass that content to an AI provider to generate the reply. If you configure your own provider API key in Prism Desktop, your chat goes directly from your device to that provider instead, and we do not see it.

7.2 AI providers

Depending on the feature and on provider availability, your content may be processed by Anthropic (our primary provider), Google (Gemini, used as a fallback when a call to Anthropic fails, including for Prism life content), OpenAI(embeddings, voice transcription, document summarization, and one of the advisors in the business platform’s AI Council), and xAI (an AI Council advisor and some report generation). If you supply your own key, you may also route to OpenRouter or to a local Ollama model on your own hardware.

All of these providers are used under commercial API terms that prohibit training on content submitted through the API. Providers may retain API logs for a limited period for abuse monitoring — Anthropic and OpenAI document up to 30 days — before deleting them. We have not negotiated zero-retention terms.

If you connect Prism to a third-party assistant such as Claude or ChatGPT over MCP or OAuth, whatever those tools read into that conversation is processed by that vendor under your agreement with them, not under our API terms.

7.3 Voice

Dictation in Prism Mobile and Prism Desktop runs on your device: audio is transcribed locally by a bundled speech model, is held only in memory, and is not written to disk or sent to us. On the web platform, voice transcription is performed by OpenAI (Whisper), which receives the audio. Where an in-app notice tells you audio will be sent to a cloud transcription provider, that notice governs that session.

8. Crash Reports and Product Telemetry

  • Crash and error reporting is provided by Sentry. On the web it captures errors, stack traces, breadcrumbs, and a masked session replay of the moments around an error. In Prism Mobile it captures crashes only, configured not to attach personal identifiers. Web Sentry traffic is routed through our own domain, which means content blockers will not see or block it.
  • Product telemetryin Prism Desktop is off unless you turn it on. When on, it uploads a small set of aggregate signals such as session length, dimension coverage, and engagement indicators — not the contents of your vault. Uploads already made remain with us unless you delete your account data.
  • Some events are written to our hosting provider’s logs with your user identifier attached.

9. Service Providers and Third Parties

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We do use the following processors. Not all of them apply to every product; several apply only to the business platform.

ProviderWhat they receive
SupabaseDatabase, authentication and storage for everything we persist
VercelHosting; request logs including IP addresses
AnthropicChat, assessment and report content sent for AI generation
Google (Gemini)The same content, when a call to Anthropic fails
OpenAIText embeddings, voice audio for transcription, document summaries, and AI Council queries
xAI (Grok)AI Council and report generation queries
StripeBilling email, customer identifier and subscription events
ResendRecipient address and the contents of emails we send you
SentryCrash and error reports, including masked web session replays
UpstashRate-limiting keys derived from IP address and user ID
CloudflareAnti-bot challenge token and IP address at sign-up
ExpoApp update checks: platform, app version and IP address
Hugging FaceModel download requests when a model has to be fetched to your device: the speech model on first dictation, and a document-search model of about 91 MB the first time you make documents searchable
Google (ML Kit)On-device text recognition when you import a picture of a document. The image and the recognized text stay on your device. Whether the ML Kit runtime reports its own usage telemetry to Google is something we have not verified
PostHog, Google AnalyticsWebsite analytics, only with your consent
Serper, Tavily, You.comBusiness-platform research queries derived from your business context
Gamma, ElevenLabs, Google CloudBusiness-platform report content for deck, narration and image generation
CRM and finance connectorsBusiness-platform only, and only for integrations you connect yourself

We may also disclose data to legal authorities where required by law or valid legal process, and in connection with a merger, acquisition, or sale of assets. If that happens we will tell you before your data becomes subject to a different policy.

10. International Data Transfers

We are based in the United States and our infrastructure and processors are primarily in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred to the US. We rely on the European Commission’s Standard Contractual Clauses with our processors for those transfers. We do not operate Binding Corporate Rules, and we have not appointed an Article 27 representative in the EU or UK.

11. Data Retention

DataHow long we keep it
Prism cloud vault, journal entries and profile dataFor as long as your account exists. Deleted when your account is deleted.
Account and subscription recordsFor as long as your account exists, then as required for tax and accounting
Business assessment data and reportsFor as long as the account exists, unless your organization sets a shorter period
Prism Desktop chat transcripts (on your device)Approximately 90 days, then removed by the app
Vault contents on your own deviceUntil you delete them. Deleting your account does not erase them; uninstall or delete the vault folder.
Audit and compliance logsUp to 7 years, as an integrity record
Crash reportsPer our provider default, up to 90 days
Marketing dataUntil you withdraw consent
Website analyticsUp to 2 years

We are actively improving automated enforcement of these periods. If a specific deletion matters to you, email privacy@amanidigital.com and we will carry it out rather than waiting for an automated sweep.

12. Your Rights

Wherever you live, we extend the following to you: access to your data, correction, deletion, a portable copy, restriction of and objection to processing, and withdrawal of consent. Under GDPR these are Articles 15 to 21.

How to exercise them

  • Email privacy@amanidigital.com. This is the reliable route and covers all of your data across every product.
  • In-app controls cover part of your data: Prism Desktop and Mobile can export or delete your local vault, and the web account offers deletion with a 30-day grace period.

We respond within 30 days. Self-service export does not yet cover every Prism record, so for a complete copy please email us and we will assemble it.

Note that deleting your account removes data held by us. It does not reach the vault on your own device, or content you have already shared with another person.

13. US State Privacy Rights

If you live in a US state with a comprehensive privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect — you have the right to know what we collect and why, to access it, to correct it, to delete it, to obtain a portable copy, and not to be treated differently for exercising any of those rights.

Sensitive data.Several states require your affirmative opt-in before we may process sensitive data, which under those laws includes health information and religious beliefs — exactly the material Prism asks about. We treat that as the standard everywhere: we collect the categories in section 5 only after you have opted in, and you can withdraw at any time.

Appeals. If we refuse a privacy request, you may appeal by replying to our decision or writing to privacy@amanidigital.comwith "Appeal" in the subject. We will respond within 45 days with our decision and the reasons for it, and tell you how to contact your state attorney general if you disagree.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by these laws, so there is no "Do Not Sell or Share My Personal Information" mechanism to offer and no universal opt-out signal, such as Global Privacy Control, applies to us. We collect sensitive personal information — see section 5 — and use it only to deliver the service you asked for, never to infer characteristics for advertising. To exercise any right, email privacy@amanidigital.com. You may use an authorized agent.

14. Security

  • Encryption in transit (TLS 1.3) and at rest at the storage layer.
  • Row-level security in our database, and hash-chained audit logging.
  • Optional multi-factor authentication.
  • End-to-end encryption for device sync payloads and person-to-person dimension shares.
  • On-device encryption of the Prism Mobile vault.

We are not certified against SOC 2 or ISO 27001. Earlier versions of our help pages claimed SOC 2 compliance; that was incorrect and has been removed. See section 3 for the limits of on-device protection in Prism Desktop.

15. Automated Processing

We use AI to generate scores, insights, summaries and recommendations from what you tell us. These are advisory. We do not make decisions producing legal or similarly significant effects about you by automated means alone. You can ask for human review of anything the system produced about you, contest it, and ask us to explain the logic involved — write to privacy@amanidigital.com.

AI processing is central to how these products work. If you withdraw consent for it, most features will stop functioning.

16. Cookies

See our Cookie Policy for what we set and how to control it. Analytics and marketing cookies are off until you consent, and we honour browser Do Not Track signals.

17. Children

Our products are for adults. They are not directed to children, and we do not knowingly collect personal data from anyone under 18. We do not knowingly collect personal data from children under 13, as defined by COPPA. In the EEA and UK, our services are not offered to anyone under 16. If you believe a child has provided us with personal data, contact privacy@amanidigital.com and we will delete it.

18. Changes

We may update this policy. For material changes we will notify you by email or with a prominent in-product notice before they take effect, and where the change requires your consent we will ask for it again.

19. Complaints

Please contact us first — we would rather fix it. You also have the right to complain to a supervisory authority. In the EEA you can find yours at edpb.europa.eu; in the UK, the Information Commissioner’s Office; in California, the California Privacy Protection Agency.

20. Contact Us

Amani Digital LLC

1082 W 2310 N, Pleasant Grove, UT 84062, USA

Privacy: privacy@amanidigital.com