Below, we explain how we process your personal data in connection with your use of our App and website in accordance with Article 13 of the General Data Protection Regulation (GDPR).
I. Data controller
Embrace Life Technologies S.P.A.
Bozner Str. 5B, 39044 Neumarkt, Italy
info[at]embracelifetech.com
+39 333 40 31 158
II. Data Protection Officer
Our Data Protection Officer is available to answer any questions about the processing of your personal data and your data protection rights:
datenschutz[at]amami.online
III. Purposes and legal bases of data processing
We process your personal data for the following purposes:
App:
- Providing the App’s features (registration, creation of a user profile).
Legal basis: Article 6(1)(b) GDPR (performance of a contract). - Social login (optional login via Google/Apple/Facebook – transfer of profile data to simplify registration).
Legal basis: Article 6(1)(a) GDPR (consent). - Notifications and in-app messages (if enabled).
Legal basis: Article 6(1)(a) GDPR (consent). - Analytics and crash reporting (improving App performance, troubleshooting)
Legal basis: Article 6(1)(f) GDPR (legitimate interest) - Backend operation and system security (storage of user IDs, JWT tokens, login logs, and IP addresses for authentication and abuse detection).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in operational security and protection against abuse). - System diagnostics and troubleshooting (creation of system logs to identify and resolve technical problems).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in the proper operation of the system). - Regional analysis of usage (App only). From your device’s IP address, our security service provider Cloudflare determines an approximate location – country, region, city, and postal code – and transmits it to our servers. We assign it to your user profile and analyze it together with the information you provide in the App in order to understand the regional distribution of usage, to develop our offering further, and to examine regional differences in relationship satisfaction and partnership quality. Your device’s location services are not accessed; the information is correspondingly imprecise. We do not include the IP address itself in this analysis. Only the current value is stored; it is overwritten each time you log in and deleted no later than 24 months after the last update. We do not use this information for advertising. You may object to this processing under Article 21(1) GDPR.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in designing our offering to meet demand), for the research purpose additionally in conjunction with Article 89(1) GDPR.
App and website:
- Security and stability (e.g. server log files, error analysis, protection against abuse).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in operational security). - Content delivery network and attack prevention (Cloudflare). Cloudflare is deployed upstream of our servers as a reverse proxy (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA). All data traffic between your device and our servers passes through this infrastructure and is checked there for attacks. Cloudflare also accelerates the delivery of content and handles DNS resolution. In doing so, connection data such as IP address, time of the request, address accessed, and information about browser and device is processed; on the website, technically necessary cookies for detecting automated access are also set. Cloudflare acts for us as a processor pursuant to Article 28 GDPR. Further information: https://www.cloudflare.com/privacypolicy/
Legal basis: Article 6(1)(f) GDPR (legitimate interest in the security and availability of our offering).
IV. Categories of personal data
App:
- Account data: (user) name, email address, password, date of birth, language preference
- Usage data:
- User identifiers: Internal user ID (account ID), JWT tokens for authentication
- Login activity: Login timestamps, logging of failed login attempts
- IP addresses: Stored during the most recent login and in system logs
- System logs: Events such as failed logins, errors, and system warnings
- Anonymized analytics data: Aggregated usage statistics that cannot be linked to an individual
- Google services (Analytics & Crashlytics):
Please note: This data is processed both internally and transferred to Google.- Device information: Operating system and version, device model, brand and category, CPU architecture, RAM, and storage space
- App data: App version, bundle version, app store (download source), new/existing user status
- Location data: Country, region, city, continent, subcontinent (based on IP address)
- User data: Age group (18-24, 25-34, etc.), gender, interests, language
- Technical data: Platform (iOS/Android/Web), browser (for Web), jailbreak/root status
- Crash identification: RFC 4122 UUID for crash deduplication, crash timestamp
- Error details: Exception classes and messages, signal names and codes, stack traces with function names
- System status: Background/foreground status, screen orientation, proximity sensor status
- Memory details: Current RAM and storage usage, loaded libraries with names, UUIDs, and memory addresses
- Thread information: Instruction pointer for all running threads
Website:
- Usage data:
- Server log files: IP address, timestamp, pages accessed, referrer URL, browser type and version, operating system
- Cookie data: Cookies that are technically necessary for the website to function (WordPress test cookie used to check whether browser cookies are enabled; deleted at the end of the session; contains no personal data)
V. Recipients of the data
App:
- IT service providers: We use external service providers for the technical provision and maintenance of the App:
- Bliss Applications, Lda (Portugal) – https://www.blissapplications.com/privacy-policy
- Push notification services: If you enable notifications, technical data will be transferred to the following providers:
- Firebase Cloud Messaging (Google LLC, USA) – https://policies.google.com/privacy
- Apple Push Notification Service (Apple Inc., USA) – https://www.apple.com/privacy/
- Analytics and crash reporting: To improve App performance and troubleshoot errors, we use:
- Google Analytics & Crashlytics (Google LLC, USA) – https://policies.google.com/privacy
- Social login providers: If you use social login, profile data will be transferred by the following providers:
- Google LLC (USA) – https://policies.google.com/privacy
- Apple Inc. (USA) – https://www.apple.com/privacy/
App and website:
- IT service providers: We use external service providers for technical provision and maintenance:
- Cipix Internet B.V. (Netherlands) – https://cipix.nl/nl/privacy-cookiebeleid
- Limitis GmbH (Italy) – https://limitis.com/privacy-cookies/
- Cloudflare, Inc. (USA) – https://www.cloudflare.com/privacypolicy/
- Internal processing: Your data is processed exclusively by authorized employees of our company who are subject to confidentiality obligations.
Your data will not be shared with third parties for advertising purposes.
VI. Data transfers to third countries
Where technical service providers located outside the EU/EEA are used (e.g. cloud services), this will only take place if an adequacy decision by the European Commission or appropriate safeguards (Standard Contractual Clauses) are in place.
VII. Retention periods
App:
- Account data: For as long as the user account exists
- Quiz answers: Permanently in anonymized form for statistical purposes (without any link to you as an individual)
- Analytics data: Retention period in accordance with Google’s Privacy Policy: https://policies.google.com/privacy
- Crash reports: Until the problem has been resolved
- JWT tokens: Until the token expires or you log out
- Login logs: 90 days for security analysis
- System logs (errors, warnings): 30 days; up to 90 days for security-related events
- Account deletion: After your account is deleted, all personal data will be anonymized within 30 days, unless statutory retention obligations apply.
App and website:
- Server log data (including IP addresses): 30 days for security and error analysis
VIII. Technical and organizational measures
SSL or TLS encryption
- The website and App use SSL/TLS encryption to protect data transmission. On the website, you can recognize the encryption by “https://” and the padlock icon in your browser.
- Protection against third parties: Encrypted data cannot be read by unauthorized parties during transmission.
IX. Requirement to provide data
App:
Certain data (e.g. username, email address, password, date of birth) is required to use the App. All other information is voluntary but may improve the App’s functionality.
Website:
You are not required to provide any personal data to use the website.
X. Automated decision-making / profiling
No automated decision-making or profiling within the meaning of Article 22 GDPR takes place.
XI. Your rights
You have the right:
- to access the data we store about you (Article 15 GDPR),
- to rectify inaccurate data (Article 16 GDPR),
- to erasure (Article 17 GDPR),
- to restrict processing (Article 18 GDPR),
- to data portability (Article 20 GDPR),
- to object to processing (Article 21 GDPR),
- to withdraw consent you have given (Article 7(3) GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
The competent supervisory authority for Bolzano, Italy:
Garante per la protezione dei dati personali
Piazza di Monte Citorio n. 121
00186 ROME
Italy
Telephone: (+39) 06.696771
Fax: (+39) 06.69677.3785,
Email: [email protected]
Website: https://www.garanteprivacy.it/
XII. Privacy Policy AmaMi AI Companion
This Privacy Policy explains how we process your personal data when you use the AI-powered chat “AmaMi AI Companion” in the AmaMi app. It supplements the general Privacy Policy of the AmaMi app, which applies to all other features; you can find it at any time in the App and at amami.online/en/privacy-policy.
2. What data we process
When you use the AmaMi AI Companion, we process:
- Chat content: All messages you enter into the chat, as well as the AI-generated responses. Because the AmaMi AI Companion is intended for personal reflection on questions of relationships and life, your entries may contain special categories of personal data within the meaning of Article 9(1) GDPR – in particular information about your health (e.g., pregnancy, mental well-being) and about your sex life and intimate life. You alone decide which of this information you provide.
- Technical usage data: Time of the messages, session identifier (pseudonymous), technical metadata for providing the service (e.g., error logs).
- Record of consent: Time and version of the consent you have given, linked to your user account.
Within the chat, we do not process any location data and do not read any other content from your device.
3. Purposes and legal bases
3.1 Operation of the chat
We process your chat entries in order to generate responses for you and to continue the conversation. For this purpose, we transmit the conversation history to our AI service provider (see Section 4).
Your conversation history is also stored linked to your user account so that you can view it in the App at any time and continue the conversation across multiple sessions. You can delete the history yourself in the App at any time. This history is used solely for display in your App and to continue the conversation – it is neither read nor evaluated by us.
Legal basis: Your explicit consent, Article 6(1)(a) and Article 9(2)(a) GDPR. You give it before first using the chat. Without this consent, the AmaMi AI Companion cannot be used; all other features of the App are available to you regardless.
3.2 Quality assurance without conversation content
To safeguard the quality and stability of the service, we process technical metrics without conversation content: response times, error messages, conversation length and time, the model version used, and – if you provide them – your ratings of individual responses (e.g., thumbs up/down). The content of your messages is neither stored nor evaluated in this process.
Legal basis: Our legitimate interest in a functioning, secure service, Article 6(1)(f) GDPR. You may object to this processing on grounds relating to your particular situation (Article 21 GDPR, see Section 7).
3.3 Establishment, exercise, and defense of legal claims
If a specific legal dispute emerges – for example, if claims against us are announced or asserted, if a complaint has been lodged with a supervisory authority, or if court proceedings are imminent – we will retain the conversation histories concerned and the associated data by way of exception to the regular deletion rules and use them to resolve the dispute. Conversations are not stored as a precautionary measure for this purpose.
Legal basis: Our legitimate interest in legal defense, Article 6(1)(f) GDPR, in conjunction with Article 9(2)(f) GDPR (necessity for the establishment, exercise, or defense of legal claims in the specific case).
3.4 Record of consent
We store when and in which version you gave your consent in order to comply with our obligation to demonstrate compliance.
Legal basis: Legal obligation, Article 6(1)(c) in conjunction with Article 7(1) GDPR.
No training: Your conversations are not used to train AI models, either by us or by our AI service provider.
4. Recipients and processors
4.1 AI service provider Anthropic
To generate the responses, we transmit your chat entries and the previous conversation history to Anthropic Ireland, Limited (Dublin, Ireland), the operator of the AI model Claude. Anthropic processes this data exclusively on our behalf on the basis of a data processing agreement pursuant to Article 28 GDPR and does not use it to train its models.
Transfer to third countries: Processing may take place on servers in the USA. The transfer is safeguarded by the EU Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR, which form part of our data processing agreement with Anthropic. You can request a copy of the safeguards using the contact details given in Section I.
4.2 Hosting of the technical metrics
We store the technical metrics (Section 3.2) using the software Langfuse, which we host ourselves on our own servers. No external service provider is used for this.
No transfer to any other third parties takes place unless we are legally obliged to do so.
5. Retention and deletion
- Chat history in the App (linked to your account): Remains stored so that you can view and continue your conversation – until you delete it in the App, withdraw your consent under Section 3.1, or your account is deleted.
- Technical metrics and ratings (without conversation content): Deletion or full aggregation after 12 months.
- Record of consent: Up to three years after withdrawal of consent or deletion of your account (limitation period).
6. Withdrawal of your consent
You may withdraw your consent at any time with effect for the future by e-mail to datenschutz[at]amami.online. After withdrawal, the AmaMi AI Companion will no longer be available to you and your stored conversation histories will be deleted – unless individual histories are required for a legal dispute that has already become specific (Article 17(3)(e) GDPR); in that case, their processing will be restricted and they will be deleted once the reason no longer applies. The withdrawal does not affect the lawfulness of the processing carried out up to that point.
7. Your rights
You have the following rights vis-à-vis us with regard to your personal data:
- Access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), and data portability (Article 20);
- Objection (Article 21 GDPR) to processing based on Article 6(1)(f) GDPR, on grounds relating to your particular situation;
- Complaint to a supervisory authority (Article 77 GDPR), for example to the Garante per la Protezione dei Dati Personali (Italy, www.garanteprivacy.it) or to the supervisory authority of your habitual residence.
To exercise your rights, an informal message to the contact details given in Section I is sufficient.
8. No automated decision-making
The AmaMi AI Companion generates AI-created texts as prompts for conversation. No automated decision-making with legal effect or similarly significant impact within the meaning of Article 22 GDPR takes place. In particular, no profiles are created from your conversations and no decisions about you or your user account are derived from them.
9. Requirement to provide data
You are neither legally nor contractually obliged to provide personal data in the chat. Without your consent, only the use of the AmaMi AI Companion is not possible; you can use the rest of the App without restriction.
10. Changes to this Privacy Policy
We adapt this Privacy Policy when our data processing or the legal situation changes. We will inform you of material changes in the App. You can find the latest version at any time in the App and at amami.online/en/privacy-policy.
XIII. Changes to this Privacy Policy
We revise this Privacy Policy whenever our data processing activities change or for other reasons that make an update necessary. You can always find the latest version on this website.
Last updated: September 9, 2026
Information about changes to the App’s Terms of Use can be found in our Terms of Use at this link.