Privacy Policy — Amplifiers
Controller: INNOVALISTA S.R.L. ("SC INNOVALISTA SRL"), a Romanian limited liability company (societate cu răspundere limitată), Trade Register no. J38/730/2020, VAT/CUI RO43097137, registered office Aleea Narciselor 2, Bl. C28, Sc. G, Ap. 14, Râmnicu Vâlcea, Vâlcea County, Romania. Trading as "AI Blew My Mind" and "Amplifiers".
Service: Amplifiers — the AI-assistant connector at mcp.getamplifiers.com and mcp.aiblewmymind.com; the Review Room at app.getamplifiers.com; the account and marketing site at getamplifiers.com; and our sign-in service at auth.aiblewmymind.com to the extent it serves Amplifiers.
Version: v1.2 · Effective date: 2026-08-24 · Last updated: 2026-08-24
Contact: support@aiblewmymind.com
The short version
Amplifiers is something you add to an AI assistant. You keep using Claude, ChatGPT, or whichever assistant you already use; we give it a catalogue of expert-built prompts, tools and image workflows it can call on your behalf.
That shapes everything below. We are not in your conversation. We only ever see the specific calls your assistant makes to us — one at a time, with only the information that call needs.
What we get: your email and an account identifier when you sign in; the specific request your assistant sends on each call (a search phrase, a tool's input, an image prompt); anything you deliberately upload or save; a record of which files we hold for you; and a per-action record for billing and abuse prevention.
What we never get: your chat history. What you and the assistant said before or after the call. Anything on your computer you didn't explicitly upload. Your name (unless you give it to Stripe when paying).
What we keep, honestly: more than you might assume. Because Amplifiers lets you come back to an image session days later and keep refining it, we store the prompt text you wrote for image generation and for long-running research tools. Section 7 lists every retention period we actually run — including the two places where we currently keep things forever because we have not built cleanup for them yet, and the two financial records we keep on purpose even after you leave. We would rather tell you that than round it up to something nicer.
Two things worth knowing up front:
- Generated images live at public links. An image you generate is stored at a long, unguessable web address that needs no login. It is not listed or searchable anywhere, but anyone you send the link to can open it. Treat it like an unlisted YouTube video, not a private file.
- We use advertising measurement on our website (
getamplifiers.com) — the Meta Pixel, plus a first-party cookie recording the ad click that brought you. None of it runs inside Amplifiers itself. In the EEA, the UK and Switzerland we ask first: nothing advertising-related is loaded, set or read until you choose, and declining costs you nothing — the site and the service work exactly the same either way. Change your mind whenever you like from Cookie settings. Outside those countries we load it by default. See §10, which explains exactly what that means and how to stop it either way.
We do not sell your personal data, and we do not train any AI model on your data.
Your controls: browse, open and delete anything in your library — every image you've generated, every reference you've uploaded — one item at a time, and deleting really does remove the file, not just the listing; hand someone a link to one item that stops working after ten minutes; erase your entire account (30-day grace period, cancellable); sign out of every device at once if you think your account is compromised; delete any API key you gave us; and change or withdraw your cookie choice at any time from Cookie settings on our website (§10). All self-service. See §8.
§1. Who this policy applies to
INNOVALISTA S.R.L. is the data controller for everything described here. We are established in Romania, in the European Union.
1.1 What this covers
- Signing in, and staying signed in.
- Everything you do with Amplifiers through your AI assistant.
- The interactive panels we render inside the assistant (image sessions, reference uploads, style galleries).
- The Review Room at
app.getamplifiers.com, including feedback left by people you share a link with. - Your account pages and your subscription.
- Visits to our marketing site at
getamplifiers.com. - Emails we send you.
1.2 What this does not cover
- The AI assistant you use. Claude, ChatGPT, Claude Desktop, Cowork, or anything else. Those are separate products with their own privacy policies, run by Anthropic, OpenAI, or whoever else. Your conversation lives there, not here.
- The AI Blew My Mind newsletter at
aiblewmymind.com, which has its own policy. - Our other apps. Our sign-in service also signs people into other things we build; what it holds for those is covered by their policies.
- Sites you point our tools at. If you ask a tool to read a LinkedIn page or a YouTube video, that site's own policies govern that site.
§2. How Amplifiers actually works — and what that means for your data
This is the section that matters most. Rather than list abstract categories, here is what physically happens.
2.1 The connection
You connect Amplifiers to your assistant once. That runs a standard sign-in (OAuth) at auth.aiblewmymind.com, and your assistant is issued a token.
After that, every single request your assistant makes to us carries that token and nothing else about you. We check the token, do the one thing that was asked, and reply. We hold no session, no conversation state, and no memory of your assistant's other messages. If your assistant makes three calls in a chat, we see three unrelated requests.
We receive the network metadata any web request carries — including the IP address your assistant's servers connect from, which for Claude.ai or ChatGPT is their infrastructure, not your home connection. We do not store it in our application database.
2.2 Example: "What can Amplifiers do for YouTube?"
Your assistant calls our search with an intent — a short sentence it writes describing what you're after, e.g. "user wants a tool to pull the transcript from a YouTube video they shared."
What happens: we send that sentence to Google to turn it into a numeric representation of its meaning, match it against our catalogue, and return the best matches.
What we store: the intent sentence as written, what you filtered on, and which results we returned and how they ranked.
Why we store it — and why it isn't tracking. The intent is a task description, not a record of your activity. It is written by the assistant to describe a goal, and it almost never contains personal information — it's the difference between "find a tool for pulling YouTube transcripts" and anything about you. We keep it for exactly one purpose: to see whether our search returned the right amplifier. When someone searches for something we have and we fail to surface it, that log is the only way we find out. It is read in aggregate to fix ranking. It is not used to build a profile of you, it is not used for advertising, and it is not shared with anyone.
Because the intent is written by an AI, we cannot promise it never contains something personal — if you say "help me write a message to my doctor about my back", that shape of sentence may reach us. So we bound it: the search log is deleted automatically after 90 days. It is also deleted immediately if you erase your account.
2.3 Example: "Get me the transcript of this video"
Your assistant calls a tool with its input — here, a video URL.
What leaves us: we call the vendor behind that tool (for this one, ScrapeCreators) with only that input plus our own vendor credential. The vendor does not receive your name, your email, your account identity, or anything from any other call you've made.
What we store: a usage record — what you ran, which vendor, whether it worked, and what it cost us. What you typed is not stored for tools that finish immediately.
The exception: slow tools. A few tools (deep research, finance research, business-name clearance) can take minutes, so we run them in the background for you to come back to. For those we store the request — which includes what you asked, e.g. your research question — so it survives a restart and you can collect the result. Today those records are kept for as long as your account exists (§7).
2.4 Example: "Make me a logo"
You go through an image prompt's interview, optionally pick a style, optionally upload a reference image, and generate.
What leaves us: the final assembled prompt text, and any reference images, go to Google or, if you selected it, OpenAI. That's it — no identity, no other prompts, no other images.
What we store:
- The generated image. It sits at a long, random, unguessable web address that requires no login. It isn't listed, indexed or browsable, and there's no way to find it by guessing — but if you share the link, whoever has it can view it. We do it this way so the image renders directly in your chat.
- The prompt text you wrote. This is deliberate: it's what lets you reopen a session and say "same thing but warmer" days later. It is stored against your account and nobody else can read your sessions.
- Reference images you upload, kept private — reachable only through short-lived links we generate for you or for the image model, never at a public address.
- A usage record with the vendor and what the call cost us. No prompt text and no image in the usage record.
We also keep a record of which files are yours, so that "delete this" and "erase everything I have" can be answered from a list rather than a guess. It holds no prompt text and no image content. §8.2 explains what it does for you.
2.5 Example: sharing work for feedback (Review Room)
If you use the Creative Feedback Loop, we create a session at app.getamplifiers.com and give you two links: one for reviewers, one for you as owner. Each is a long random code — the code is the access; reviewers do not create accounts and do not sign in.
About your reviewers: if someone leaves a comment, we store the display name they typed (we do not verify it), their comment text, where on the image they pinned it, and a token stored in their browser so they can edit or delete their own comment. Their comments are visible to anyone holding either link. If you share a review link, you are sharing it — please only send it to people you mean to.
Feedback sessions expire 30 days after creation, and the links to the shared work are valid for 30 days. Note that a link already handed out cannot be un-issued: revoking a session stops the Review Room page from working, but a direct link someone already copied keeps working until it expires.
2.6 Example: sending someone one image from your library
From your library you can hand someone a link to a single item. That link is deliberately weak, and the weakness is the point.
What we mint: a random link that stops working ten minutes after you create it, and after 50 openings, whichever comes first. We store the link, which item it points at, when it expires and how many times it has been opened — nothing about whoever you send it to.
How it's served: the link points at our own domain and we stream the file through it. It never redirects to a storage address, so there is no durable URL for anyone to keep. When the ten minutes are up the link is dead, including for anyone who already had it. Spent links are deleted shortly afterwards.
What we do not offer: a permanent public link. There is no "publish this" button and no setting that turns one on. If you want someone to keep a copy, download the file and send it to them yourself — then it's yours to control, not a link we're holding open.
The one thing this does not undo: an image you generated already sits at a public address (§2.4), and if you have pasted that address somewhere, the ten-minute share link has no bearing on it. Delete the image (§8.1) to remove the file itself.
2.7 What never reaches us
- Your conversation with the assistant. Not the messages before the call, not the ones after, not the assistant's reasoning.
- Anything on your device. Only files you explicitly choose in an upload panel.
- Your browsing. We set no analytics or advertising cookies inside Amplifiers.
- Your card details. Payment happens on Stripe's own pages; we never see the number.
- Your API keys in readable form outside a single call. Keys you give us are encrypted at rest and decrypted only for the moment a call needs one.
§3. What we store
Described by category rather than field by field. Where a category contains something you'd reasonably want flagged — your IP address, text you wrote — it is called out.
| Category | What it covers | Why |
|---|---|---|
| Your account | your email address and an account identifier | signing you in; tying your data to you |
| Sign-in security records | a record of sign-ins, sign-ups, password resets and sign-outs — each with the IP address the request came from — and the tokens that keep you signed in | detecting account compromise; letting you revoke access |
| API keys you choose to give us | your own AI-vendor keys, encrypted | making calls to those vendors on your behalf instead of ours |
| What you save and create | your saved prompts; your image sessions, including the prompt text you wrote; the images you generate; reference images you upload, kept private | your library, and being able to reopen and iterate on work across devices |
| A record of which files are yours | for each file we hold for you, that it is yours and where to find it. No prompt text, no file contents | listing your library, deleting the right item, and erasing all of it when you leave (§8.2) |
| Share links you create | the link, which item it points at, its ten-minute expiry, and how many times it was opened. Nothing about the person you sent it to | serving that item for ten minutes, then refusing (§2.6) |
| What you asked us to do | search phrases your assistant sends (§2.2); and, for tools that take minutes, the request you submitted — including research questions and image prompts | returning results; improving search; letting you collect a result later |
| Service and billing records | a per-action record of what ran, which vendor, whether it worked and what it cost us; your credits, quotas and entitlements; your subscription status. Your name, billing address and card details are held by Stripe, not by us | billing, quota, abuse prevention, incident response |
| Email records | which service emails we've sent you, your preferences, and an unsubscribe or bounce entry. Our audit record stores a one-way hash of your address, never the address itself | sending you the mail you should get, and not sending you mail you shouldn't |
| Review Room sessions | the work you shared, your reviewers' typed display names, their comments and pin positions, your verdicts | running the review |
| Account-erasure records | that you requested erasure, when it's scheduled, whether it was cancelled or completed | honouring the request and giving you the grace period |
| Diagnostics | error traces and performance measurements, with secrets automatically stripped and no prompt content or images | keeping the service running and diagnosing failures |
| Website and advertising data | if you take the quiz on getamplifiers.com: your answers, the recommendation, and the email address you type in if you submit one. Separately, advertising measurement events collected by Meta, and a first-party cookie recording the Google Ads click that brought you (attr_gclid) — see §10 | showing you your result, sending you what you asked for, and measuring whether our ads work |
| The cookie choice you made | a random identifier for that choice (consent_id), which categories you allowed, when you chose, which policy version you were shown, and the two-letter country your request came from. No IP address, no user agent, no email address, and no link to your account | being able to show that we asked for consent and what you answered, as consent law requires (§10) |
What we deliberately do not collect
- Your IP address in the Amplifiers service. We do not write it to any Amplifiers record. (It is recorded in our sign-in security log — see the second row above. We're calling that out rather than hiding it behind a general statement.) On our website we do derive a two-letter country code from your IP — to decide whether you must be asked for cookie consent, and stored on the record of your answer. The IP itself is not stored there.
- Your chat history. We never receive it.
- What you type into tools that run immediately. Forwarded to the vendor, not stored.
- Any prompt or image content in our diagnostics. See §9.
- Special-category data. We don't ask for it and don't knowingly process it.
§4. Why we're allowed to process it
| What we're doing | Legal basis (GDPR Art. 6) |
|---|---|
| Running the service you connected — your library, image sessions, tool calls, and requests you leave running | Contract, Art. 6(1)(b) |
| Recording which stored files are yours (§3) | Contract, Art. 6(1)(b) — we cannot show you your library, delete one item, or erase all of it without knowing which files are yours |
| Billing, credits, quotas, subscription management | Contract, Art. 6(1)(b); legal obligation for accounting records, Art. 6(1)(c) |
| Keeping payment and funnel-purchase records after you erase your account (§7) | Legal obligation, Art. 6(1)(c) — Romanian tax and accounting law; and legitimate interests, Art. 6(1)(f), for defending a disputed payment |
| The marketing-site quiz: your answers, and an email address if you give us one (§3) | Consent, Art. 6(1)(a) — you choose to take the quiz and to submit an address; withdraw by asking us to delete it, or by erasing your account |
| Service emails (account changes, incidents, erasure confirmations) | Contract, Art. 6(1)(b) |
| Security, abuse prevention, rate limiting, sign-in audit logging including IP | Legitimate interests, Art. 6(1)(f) — keeping accounts safe and the service available and non-abusive |
| Diagnostics and error tracing | Legitimate interests, Art. 6(1)(f) — keeping the service working |
| Search-quality logging (§2.2) | Legitimate interests, Art. 6(1)(f) — making the product find the right thing. Bounded by 90-day deletion and never used to profile you |
| Email suppression records retained after account deletion | Legitimate interests, Art. 6(1)(f) — not re-mailing someone who asked us to stop |
| Storing API keys you give us | Consent, Art. 6(1)(a) — you choose to add one; delete it to withdraw |
Advertising measurement on our website — including /upgrade, the paywall page your assistant links you to (§10) | Consent, Art. 6(1)(a). In the EEA, the UK and Switzerland we ask before anything is set or read, and you can withdraw from Cookie settings on any page. Outside those countries we load it by default and offer the opt-out routes in §10 — which is explicit about that difference |
| Keeping a record of the cookie choice you made (§10) | Legal obligation, Art. 6(1)(c) — consent law requires us to be able to demonstrate that you consented. It is deliberately not consent-based: a record of you saying "no" cannot be conditional on you saying "yes", which is why it is written when you reject as well as when you accept |
| Responding to lawful requests | Legal obligation, Art. 6(1)(c) |
We do not train AI models on your data. Not our own, and we do not license your content to anyone for training. Prompts and reference images go to Google or OpenAI only for the single call you triggered, and are handled under those vendors' published terms (§5).
We do not profile you. Nothing about your usage feeds an automated decision that legally or significantly affects you. The only automated ranking we do is deciding which amplifier best matches a search.
§5. Who else sees your data
| Vendor | What they do | What they get | Where |
|---|---|---|---|
| Supabase | our database and file storage | everything Amplifiers stores — your account, library, sessions, images, usage, credits, feedback | Germany (EU) — see the note below |
| Global Internet Solutions SRL (globalis.ro) | the physical server running Amplifiers | traffic in transit; the server's disks | Romania (EU) |
| Cloudflare | DNS for our domains | DNS lookups. Cloudflare does not proxy Amplifiers traffic — it is not in the request path and does not see your requests | global |
| Vercel | hosts getamplifiers.com | web requests to the marketing and account site, including IP and user agent | United States (served from EU edge) |
| image generation; interpreting search intents | per call: the prompt text and reference images you supplied, or the search intent sentence. Never your name, email, identity, or anything from another call | United States / Google global | |
| OpenAI | alternative image generation, when you select it | per call: the prompt text and reference images you supplied. Nothing else | United States |
| ScrapeCreators | the majority of our data tools (social, video, search platforms) | per call: only what you passed to that tool, plus our credential | see vendor |
| You.com | web search, deep research and finance research tools | per call: your query. Nothing else | United States |
| Veridion (incl. Registry Lookup) | company lookup and global trade-registry tools | per call: the company name or registry number you asked about | see vendor |
| Signa | trademark search | per call: the mark text you asked about | see vendor |
| Stripe | subscription billing | your email, name, billing address, card details, subscription state; and, attached to a checkout, the advertising identifiers described in §10 plus a marker recording whether you consented, so a purchase can be attributed to the ad that led to it — the identifiers are omitted entirely when you did not consent. Nothing from inside the service — no prompts, no images, no usage | United States |
| Resend | delivering our emails | your email address and the message content | United States |
| Honeycomb | diagnostics | timings, errors, vendor names, your account identifier. No prompt content, no images, no keys, no email, no name | EU (Frankfurt) |
| Meta | advertising measurement on our website getamplifiers.com — the marketing pages and /upgrade, the paywall page your assistant links you to from inside the product. Never inside Amplifiers itself | the website pages you visit, clicks and conversions, your IP, device/browser info, the cookie it sets — and, sent from our servers rather than your browser, a one-way hash of your email address: the one you typed into a marketing form, or the one on your Amplifiers account when the event came from the paywall page. In the EEA, the UK and Switzerland nothing is sent unless you accepted (§10). Nothing from inside Amplifiers | United States |
Each of these is bound by a data-processing agreement or their published processor terms. We update this list when it changes; additions are recorded in the changelog.
Vendor notes worth reading
- Google — traffic on Google's paid tier is excluded from training. If you supply your own paid Google API key, the call runs on your key and your contract with Google.
- OpenAI — API traffic is not used to train OpenAI's models by default. We have not taken the zero-retention contractual option.
- Storage location. Our database and file storage are hosted in the EU, in Frankfurt, Germany — so the bulk of what Amplifiers stores never leaves the EU, and neither does the server that runs the code. Supabase is a US-incorporated company, so its personnel may access data from outside the EU for support and operations; that access is covered by its data-processing terms and the safeguards in §6.
§6. Where your data lives, and transfers out of the EU
We are an EU controller. Some of our infrastructure is not.
- In the EU: the server running Amplifiers (Romania), our database and file storage (Frankfurt), and all diagnostics (Frankfurt). That covers everything Amplifiers stores about you.
- Outside the EU: payments (Stripe), email delivery (Resend), the image models (Google, OpenAI), marketing-site hosting (Vercel), advertising measurement (Meta), and most tool vendors — all in the United States. These receive data in the course of a specific action you take, as set out in §5; they are not where your account lives.
Several of our EU-hosted vendors are US-incorporated companies. Data residency and corporate nationality are different things: your data sits on EU servers, while the vendor's staff may access it from elsewhere for support and operations. The safeguards below cover that access as well as outright transfers.
Transfer mechanism. Transfers to the United States rely on the European Commission's 2021 Standard Contractual Clauses, incorporated through each vendor's published data-processing terms. For UK data we rely on the UK International Data Transfer Addendum or the UK Addendum to the EU SCCs, as each vendor provides.
We have not produced a standalone Transfer Impact Assessment. If you need one for a procurement review, email support@aiblewmymind.com and we'll do the work. You may also request a copy of the safeguards in place under Art. 46 GDPR.
§7. How long we keep things
This table describes what we actually do today. Where we have no cleanup, it says so.
| Data | Retention |
|---|---|
| Search log (§2.2) | 90 days, then deleted automatically. Also deleted immediately on account erasure |
| Review Room sessions and the work shared in them | 30 days from creation |
| Library share links (§2.6) | the link stops working after 10 minutes or 50 openings; the spent link is deleted shortly afterwards |
| Sign-in tokens | expire after 30 days; revoked tokens are deleted shortly after expiry |
| Saved prompts, image sessions, quotas, entitlements, credits, usage records, background requests, email preferences and send records | kept while your account exists. All deleted when you erase your account. None of these has a time-based expiry — a usage record from your first day is still there on your thousandth |
| Generated images, reference images and Review Room files | kept while your account exists; deleted when you erase your account — the file itself, not just the record pointing at it. No time-based expiry — an image you made a year ago is still there until you delete it or your account |
| The record of which files are yours | for as long as we hold the file; it goes when the file goes |
| Marketing-site quiz answers and captured emails | no time-based expiry today. Deleted when you erase your account, matched on your email address (§8.2) |
| Sign-in security log, including IP addresses | kept indefinitely. We have no retention job on it today |
| Diagnostics | 60 days, enforced by the vendor's retention on our plan |
| API keys you gave us | until you delete the key, or you erase your account |
| Email suppression records (unsubscribes, bounces, complaints) | kept indefinitely and deliberately retained after account erasure, keyed to your email address, so that we never mail someone who told us to stop |
| Subscription and payment records | held by Stripe under Stripe's retention; on our side, your payment records and any marketing-funnel purchase are deliberately retained after account erasure and kept for as long as Romanian tax and accounting law requires |
| Advertising events we sent to Meta | held by Meta under Meta's own retention, not ours (§10) |
The attr_gclid advertising cookie we set (§10) | 90 days on your device, then it expires by itself. Ours, not Meta's |
| The record of your cookie choice (§10) | the cookie on your device lasts 180 days, after which we ask you again. Our own record of the answer is kept 24 months and then deleted automatically by a scheduled job |
The honest note about what has no expiry
Two things above have no time limit, and we would rather explain than bury it:
- Requests you left running in the background are deleted when you erase your account, but while your account exists nothing prunes them — a research question you asked a year ago is still stored.
- The sign-in security log keeps sign-in events, with IP addresses, with no expiry. It is the record we investigate account compromise and token theft from, and it is only useful as far back as it goes.
And two things outlive your account on purpose, both financial: your payment records, and the record of any purchase you made through our marketing funnel. We keep them because tax law requires it and because they are our evidence if a payment is disputed later. Note the asymmetry, which is deliberate rather than an oversight: we delete our own record of what you spent your credits on, and keep the record that you paid us.
If you want any of this removed sooner rather than waiting on us, email support@aiblewmymind.com and we will do it by hand. We will not ask you why.
§8. Your controls
8.1 Manage your library
Sign in at getamplifiers.com and your library lists everything we hold for you — the images you have generated, the reference images you have uploaded, and the files our tools have produced for you — newest first. For any one of them you can open it, delete it, or mint a ten-minute share link (§2.6). Your saved prompts are listed, editable and deletable in the same place.
Delete removes the file itself, not just its entry in the list. Any share link you had minted for that item stops working immediately.
You don't need to contact us and you don't need to delete your whole account to remove one thing.
8.2 Erase your data (30-day grace period)
From your account page, choose to erase your account. Here's exactly what happens:
- We email the address on your account a confirmation link. Nothing happens until you click it — the email is the safety gate, so someone with access to a logged-in screen can't erase your account without also having your inbox.
- The link shows you a checklist of what will be removed and what it will cost you — including that any remaining credits are forfeited and non-refundable, and that your subscription will be cancelled. You tick through it.
- We schedule the erasure for 30 days out. During those 30 days your account keeps working normally, and you can cancel the erasure yourself from your account page. Change your mind and everything stands down.
- At the end of the 30 days we cancel your Stripe subscription and delete everything we hold for you. Your files go first — every generated image, every reference image you uploaded, every file our tools produced for you, and any Review Room files you own. Then the rest: your usage records, quotas, saved prompts, image sessions, credits, entitlements, background requests, email preferences and send records, search log, Review Room sessions and their comments, and your subscription record. We also delete the marketing-site data held against your email address: your quiz answers, the email you gave us there, and the record tying your sign-up to a campaign.
- If any file cannot be deleted, we stop and start over rather than press on — so an erasure either completes or is retried, never half-finished. We also wait for any upload still in progress instead of leaving it behind. This runs for roughly three days before we flag it for a human, and we never report an erasure as done when it isn't.
- What survives, and why: your email suppression record, if you ever unsubscribed or bounced — keyed to your address so a future sign-up doesn't get mailed against your wishes; and your payment records and any purchase you made through our marketing funnel, kept because tax law requires it and because they are our evidence in a payment dispute (§7). Nothing else.
Erasing your Amplifiers data is separate from deleting your central AI Blew My Mind account. The former removes what Amplifiers holds. To close your sign-in identity across everything, use account deletion at auth.aiblewmymind.com.
8.3 Sign out everywhere
If you think your account has been compromised, reset your password at auth.aiblewmymind.com and tick sign out everywhere. That revokes every active session for every connected app at once — every AI assistant you'd linked has to sign in again. Do this first if anything looks wrong; then email support@aiblewmymind.com.
Note that revocation can take up to a minute to reach every part of the service.
8.4 API keys
Any AI-vendor key you gave us can be deleted from your account settings at any time. Deleting it removes it completely — nothing of the key is kept. While a key is stored, we hold it encrypted, together with its last four characters so you can tell which key it is; deletion removes both.
8.5 Your rights under law
You have the right to access your data, correct it, erase it, restrict or object to how we use it, take it with you in a portable format, and withdraw consent where consent is the basis. You can also complain to a regulator (§A.6, §B.3, §C.4).
Your cookie choice is the one consent you can change entirely on your own, without emailing anyone: Cookie settings, on our website, reopens that choice and takes effect immediately (§10).
Most of it is self-service — see 8.1 to 8.4. For anything else, email support@aiblewmymind.com from the address on your account; that's how we verify it's you. If we can't match the address, we'll ask for something else that proves it, and we'll ask for as little as possible.
We reply within 30 days. If a request is genuinely complex we may take up to 60, and we'll tell you inside the first 30 if that happens. California residents: see §C.4 for the 45-day window.
Portability, plainly: we do not have a one-click export yet. Ask and we'll assemble your data as JSON by hand.
Authorized agents. Someone can act for you if they send us signed authorization from you and we can reasonably verify your identity.
§9. Security
- In transit. Everything between your assistant and us is encrypted (TLS). Same for our calls to every vendor.
- At rest. Databases and file storage are encrypted by our infrastructure providers.
- Authentication on every request. We hold no server-side session. Every request re-verifies your token. When our sign-in service has a transient failure we return "try again" rather than treating a good token as invalid — a design choice so an outage doesn't quietly log everyone out.
- Isolation between users. The database itself checks your identity before returning anything, independently of our application code — so a bug in the application cannot show one person another person's data.
- API keys you provide are encrypted, decrypted only in memory for the single outbound call that needs them, never logged, and never returned to anyone.
- Secrets in logs. We strip credentials, tokens and other secrets from every log line before anything leaves our servers, and we do not send prompt content or images to our diagnostics vendor. This is best-effort by nature: something unusual could in principle slip through, so we re-audit it whenever we change how diagnostics work.
- Separate credentials for separate blast radii. Different parts of the system hold different, narrowly-scoped credentials, so a compromise in one place doesn't hand over the others.
- Development practice. Code review on every change, automated vulnerability scanning on dependencies, and a mandatory security checklist for every change that touches user data.
Breach notification. If a breach happens that is likely to risk your rights and freedoms, we will notify the Romanian supervisory authority within 72 hours of becoming aware, as Art. 33 GDPR requires, and we will tell you directly and without undue delay if the risk to you is high (Art. 34).
No system is perfect. Report a security issue to support@aiblewmymind.com and we will take it seriously.
§10. Cookies, and our website
Inside Amplifiers we set no analytics or advertising cookies at all. The connector, the panels in your assistant, and the Review Room carry none.
On getamplifiers.com we do — and in the EEA, the UK and Switzerland we ask you first.
What we set
| What | Set by | Purpose | How long |
|---|---|---|---|
| Strictly necessary | us | keeping you signed in, keeping the site working, preventing abuse | varies by cookie |
aibmm_consent — strictly necessary | us | records the cookie choice you made: a random identifier for that choice, which categories you allowed, when you chose, and which version of this policy you were shown. It is what stops us asking again on every page | 180 days, then we ask again |
aibmm_region — strictly necessary | us | records only whether your request came from a country where we must ask before setting advertising cookies. Its value is literally in or out | until you close your browser; re-set on each request |
_fbp, _fbc — advertising | Meta | Meta's browser identifier, and the identifier of the Meta ad click that brought you | set and controlled by Meta's own script |
attr_gclid — advertising | us | the identifier of the Google Ads click that brought you, so we can report back that a click led to a sign-up | 90 days |
In the EEA, the UK and Switzerland the advertising rows are set only after you accept. Before that, none of them is written or read, Meta's script is never loaded, and no advertising identifier is attached to a checkout. Outside those countries we load advertising measurement by default — see the last section here.
Asking, and changing your mind
On your first visit from the EEA, the UK or Switzerland we ask before anything advertising-related is loaded, set or read, and nothing of the kind runs until you have answered. Consent is per category. Nothing in the advertising category is on by default, and we never treat silence, scrolling or simply carrying on using the site as agreement — an affirmative choice is the only thing that turns it on. There is one real choice today, advertising and measurement; strictly necessary is disclosed rather than offered, because the site does not work without it.
Changing your mind. Cookie settings reopens that choice on any page, and withdrawing takes effect immediately: we delete the advertising cookies we can reach — on both the exact hostname and the parent domain, because they are not always set at the same level — and reload the page so that Meta's script is no longer running on it. Art. 7(3) GDPR gives you the right to withdraw consent, and using it here is self-service and immediate: no email, no form, no waiting on us. The one page it is not offered on is /upgrade, the paywall your assistant sends you to — nothing advertising-related runs there unless you had already accepted elsewhere, and it links to this policy.
We keep a record of your answer. It holds a random identifier for the choice, the categories you allowed, the time, the policy version you were shown, and the two-letter country your request came from. It carries no IP address, no user agent, no email and no link to your account, and we keep it for 24 months. Consent law requires us to be able to show that we asked and what you said, so this record is written whether you accept or reject — it is the one thing here that is deliberately not conditional on your answer.
If a Meta ad brought you and you accept later in the visit, we keep the click identifier from the address bar in the page's memory in the meantime, and hand it to Meta's script only if you accept. Being precise about what that is and is not: holding it in memory is neither storing something on your device nor reading something already stored there, so the cookie-consent rule is not engaged by it — but it is an online identifier and is personal data, so it is processed under this policy like everything else here. If you reject, or you leave without answering, it is discarded and never reaches Meta.
What Meta receives
The Meta Pixel receives the website pages you visit, button clicks and form submissions, purchase events (which plan, the price), basic device and browser information, the cookie identifier Meta sets, and the IP address your browser sends Meta directly.
We also send Meta the same conversion events from our own servers, not only from your browser. Meta calls this the Conversions API, and it exists because browser trackers are so widely blocked. That server-to-server copy carries the event and, for a purchase, its value; the Meta cookie identifiers your browser had; your IP address and user agent; and a one-way cryptographic hash of your email address, so Meta can match the event to an account it already holds without us handing over your address in readable form.
There are two places that email can come from, and the previous version of this policy admitted only one: the address you typed into the quiz or a capture form on the marketing site — and the address on your Amplifiers account, when the event came from /upgrade, the paywall page your assistant links you to from inside the product. That page is not the marketing site, you did not type your address into it, and we should have said so.
Being blunt about the consequence: blocking the Pixel in your browser does not stop this leg. In the EEA, the UK and Switzerland your consent decision does: a rejection — or no answer at all — suppresses the server-to-server leg as well as the browser one, and the advertising identifiers are left off the checkout record we send Stripe entirely.
Both legs receive nothing from inside Amplifiers — no prompts, no images, no library, no usage.
Outside the EEA, the UK and Switzerland
We do not ask first there, and we load advertising measurement by default. These routes work anywhere:
- Block it in your browser. Any tracker blocker, or blocking third-party cookies, stops the Pixel — but only the browser half. The server-to-server half above keeps running; use the email route below to stop that one.
- Don't give us your email on the marketing site. That removes one of the two sources of the hashed-email match; signing in to Amplifiers gives us the other. You can still sign up for Amplifiers normally.
- Turn off ad personalisation at Meta, in your Facebook or Instagram ad settings — that governs what Meta does with what it collects, on their side, across every site.
- Email
support@aiblewmymind.comand we will pass a deletion request to Meta through their consumer-rights process and record your objection. - Global Privacy Control: we do not yet detect the
Sec-GPCbrowser signal ourselves. Meta's own handling of it is governed by Meta's policies.
Declining works everywhere, even where we don't ask first. Outside the EEA, the UK and Switzerland we still load advertising measurement by default, and we do not ask you first. But Cookie settings is available to everyone, and if you use it to decline, that decision is honoured exactly the same way it would be inside those countries: we delete the advertising cookies we can reach, and the decision is remembered on later visits, not just for the page you're on. Two limits are worth stating plainly, because they are real: the record is a cookie that lasts 180 days, and it is tied to the version of this notice you declined under. If it expires, or you clear your cookies, or we materially change what we ask for under §12, the record stops applying — and because we do not ask first outside the EEA, the UK and Switzerland, nothing will prompt you again: advertising measurement resumes by default until you open Cookie settings and decline again. Inside those countries we would simply ask you once more. If you want something that does not expire, use the browser-blocking or email routes above. What's genuinely different outside the gated countries is that we don't ask first, and doing nothing is not a rejection — if you never open Cookie settings, we load advertising measurement by default. Use the routes above for ways to limit what we and Meta do with what we collect by default before you use it.
We do not run Google Analytics, and no Google advertising tag runs on the site. We do set attr_gclid, the cookie in the table above, and it travels with a checkout into our billing records — so it is a Google advertising identifier, and we would rather name it than let a flat "we don't run Google Ads tracking" quietly cover it. Switching on a Google tag or a Google conversion feed would be a new advertising vendor and therefore a material change under §12, as would adding any other advertising or analytics vendor; you'll hear about it first.
§11. Children
Amplifiers is not for anyone under 16. Romania sets the digital age of consent at 16, and we do not knowingly collect data from children under that age. If you think we have, email support@aiblewmymind.com and we will delete it.
§12. Changes to this policy
The "Last updated" date at the top is current, and every version is listed in the changelog below.
For routine edits — clarifications, corrections, rewording — the changelog and the "Last updated" date are the record, and it's worth checking back from time to time.
Material changes are different: we will tell you. We publish them in the changelog at least 14 days before they take effect, and we notify you — in the product, by email, or both — rather than leaving you to notice. Material means:
- a new category of personal data collected;
- a new purpose for existing data;
- a new vendor that handles your content;
- a retention period getting longer (shortening one is good news and doesn't need notice);
- a change to who the controller is or how to reach us.
Continuing to use Amplifiers after a change takes effect means you accept it. If you don't, erase your account (§8.2) — no notice period, no penalty.
§13. Contact
- Everything privacy-related, including rights requests:
support@aiblewmymind.com - Security issues:
support@aiblewmymind.com - Postal: INNOVALISTA S.R.L., Aleea Narciselor 2, Bl. C28, Sc. G, Ap. 14, Râmnicu Vâlcea, Vâlcea County, Romania
We are established in Romania, inside the EU, so no Art. 27 GDPR EU representative is required — you can reach the controller directly at the address above.
Addendum A — European Economic Area (GDPR)
If anything here conflicts with the main body, this addendum wins for people in the EEA.
A.1 Controller
INNOVALISTA S.R.L., Trade Register no. J38/730/2020, VAT RO43097137, registered at Aleea Narciselor 2, Bl. C28, Sc. G, Ap. 14, Râmnicu Vâlcea, Vâlcea County, Romania. Contact: support@aiblewmymind.com.
A.2 EU representative
Not required. The controller is established in Romania, an EU member state, so Art. 27 GDPR does not apply.
A.3 Data Protection Officer
We have not appointed one. Our processing does not meet the Art. 37 thresholds: we do not carry out large-scale systematic monitoring, and we do not process special categories at scale. If that changes, we will appoint one and announce it in the changelog.
A.4 Legal bases
Set out per purpose in §4. In summary we rely on Art. 6(1)(a) consent (stored API keys; advertising measurement on our website, asked for through the consent gate described in §10; the marketing-site quiz), 6(1)(b) contract (running the service, the record of which files are yours, billing, service emails), 6(1)(c) legal obligation (accounting records, including those retained after erasure; the record of the cookie choice you made — which is why it is written when you reject as well as when you accept, and why it is not itself consent-based; and lawful requests), and 6(1)(f) legitimate interests (security, abuse prevention, diagnostics, search-quality logging, email suppression, defending disputed payments).
For each legitimate-interests use we have weighed our interest against your rights and concluded the processing is proportionate: it is limited to what the purpose needs, it is bounded by retention where the data is at all sensitive, and none of it is used to build a profile of you or to advertise to you.
A.5 Special categories, and automated decision-making
We do not knowingly process special-category data (Art. 9). If you put such information into a prompt, it is forwarded to the AI vendor for that call under their terms; note that for image generation the prompt text is stored in your session history so you can iterate on it (§2.4) — you can delete the session (§8.1).
We make no decisions about you based solely on automated processing that produce legal or similarly significant effects (Art. 22).
A.6 Your rights, and complaining
Art. 15 access · Art. 16 rectification · Art. 17 erasure · Art. 18 restriction · Art. 20 portability · Art. 21 objection to legitimate-interests processing · Art. 22 automated decisions · Art. 7(3) withdrawal of consent. Exercise any of them per §8.
You may complain to the supervisory authority in your member state. Ours is Romania's:
Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania dataprotection.ro
The full list of EEA authorities is at edpb.europa.eu.
A.7 Transfers
Covered in §6. Transfers to the US rest on the 2021 Standard Contractual Clauses via each vendor's published terms. Note that the core of the service does not leave the EU at all: the server running Amplifiers, the database and file storage holding everything we keep about you, and all diagnostics are hosted inside it. What goes to the United States is confined to specific actions you take — paying, receiving an email, generating an image, running a tool — and to our website, including the paywall page your assistant links you to.
Addendum B — United Kingdom (UK GDPR)
B.1 Controller and representative
INNOVALISTA S.R.L., at the address in A.1.
UK representative (Art. 27 UK GDPR): we have not appointed one. We rely on the exemption in Art. 27(2): our processing of UK residents' data is occasional, does not include special categories or criminal-conviction data on any scale, and is unlikely to result in a risk to the rights and freedoms of individuals given its nature, context and purposes. You can reach the controller directly at support@aiblewmymind.com. We will appoint a representative if our UK processing grows past that threshold.
B.2 Your rights
The same as A.6, under UK GDPR. Exercise them per §8.
B.3 Supervisory authority
The Information Commissioner's Office — ico.org.uk/make-a-complaint.
B.4 PECR
Consent for non-essential cookies on our website is required by PECR as well as UK GDPR, and we ask for it. UK visitors get the consent gate described in §10: no advertising cookie is set or read before an affirmative choice, consent is never inferred from silence or continued use, nothing in the advertising category is on by default, and the choice can be withdrawn at any time from Cookie settings. Strictly necessary cookies are set without consent, as PECR reg. 6(4) permits. §10 has the full detail, including what our server-to-server conversion feed sends Meta and how your choice governs it.
B.5 Transfers from the UK
We rely on the UK International Data Transfer Addendum, or the UK Addendum to the EU SCCs, as each vendor provides. The data that crosses the border is described in §6.
Addendum C — California (CCPA / CPRA)
Applicability. We are a small company and we do not believe we currently meet the CCPA's thresholds for a covered "business". We are providing these disclosures anyway, and we honour these rights for California residents regardless. If anything here conflicts with the main body, this addendum wins for Californians.
C.1 Notice at collection
| CCPA category | In Amplifiers | Purpose |
|---|---|---|
| A. Identifiers | your account identifier and email; on our website, the cookie identifier Meta sets, the Google Ads click identifier we store (attr_gclid), the identifier we generate for your cookie choice (consent_id), the IP your browser sends Meta, and a one-way hash of your email sent to Meta from our servers — from a marketing form, or from your account when the event came from the paywall page; in our sign-in security log, the IP of your sign-in requests | account and service delivery; security; ad measurement; evidencing your cookie consent |
| B. Cal. Civ. Code §1798.80(e) | email, payment information (held by Stripe), purchase details | billing |
| F. Internet or network activity | your usage records, the requests you left running, your search phrases, and the record of which files are yours; marketing-site pageviews, quiz answers, clicks and conversions | billing, abuse prevention, search quality, ad measurement |
| G. Geolocation | the two-letter country derived from your IP when you make a cookie choice, stored on that record, plus the same in-scope/out-of-scope determination in a cookie so we know whether to ask you. Nothing finer, and not your IP itself. Meta may infer coarse location from IP under its own policies | deciding whether consent is required, and evidencing the choice |
| H. Sensory data | reference and generated images, where you upload or generate images of people | image generation |
| K. Inferences | none drawn by us. Meta may draw its own from marketing-site events | ad audience modelling, by Meta |
| Sensitive Personal Information | API keys you give us — account credentials under §1798.140(ae)(1)(A) | making calls on your behalf |
C.2 Sale and sharing
We do not sell your personal information.
We do share personal information for cross-context behavioral advertising on our website — the marketing pages and /upgrade, the paywall page your assistant links you to — through the Meta Pixel and the matching server-to-server conversion feed we send Meta, including the one-way hashed email described in §10. What that covers is set out in full in §10. What it never covers: anything from inside Amplifiers — no prompts, no images, no library, no usage, no account content.
Why it isn't a sale: money flows the other way. We pay Meta to show our ads; the Pixel is how we find out whether that money did anything. Meta uses it for our campaigns under its own policies, not to identify you to other advertisers. CCPA still classifies it as "sharing", so the opt-outs stand.
To opt out, use any of the routes in §10, or email support@aiblewmymind.com with the subject "Do Not Sell or Share My Personal Information". We will record your objection and pass a deletion request to Meta through their consumer-rights process. Opting out changes nothing about your access to the service.
About the consent gate. We now ask for consent before any advertising cookie in the EEA, the UK and Switzerland (§10). That gate is not a California opt-out and we are not going to present it as one: it doesn't ask California residents anything, and it isn't the "Do Not Sell or Share" mechanism CCPA contemplates. But the underlying control works the same way wherever you use it: Cookie settings is available to you too, and if you use it to decline, that decision is honoured exactly as it would be in the EEA — we clear the advertising cookies we can reach, and the sharing described above durably stops on that browser going forward, not just for the page you're on. The routes in this section, including the email route below, remain what we'd point you to for a request that doesn't depend on you finding and using that link yourself.
Being straight: we have not built an automated opt-out preference signal for California — we do not detect Sec-GPC, and we do not publish a "Do Not Sell or Share" toggle that is honoured here. §10 explains what works today. That is a gap we intend to close.
C.3 Limiting Sensitive Personal Information
The only sensitive personal information we hold is an API key you chose to give us. We use it for exactly one thing — the outbound call you triggered — and for nothing else, so there is no secondary use to limit. Delete the key (§8.4) and that use ends.
C.4 Your rights
Know what we collected, from where, why, and who we disclosed it to in the past 12 months · delete it, subject to the exceptions in §1798.105(d) · correct inaccuracies · opt out of sharing (C.2) · limit sensitive PI (C.3) · non-discrimination — we will never treat you worse for exercising any of this.
Email support@aiblewmymind.com. We respond within 45 days, extendable once by another 45 with notice inside the first 45.
C.5 Authorized agents
Send us signed written authorization from the consumer, plus enough to reasonably verify their identity.
C.6 Metrics disclosure
Not applicable — that requirement applies to businesses handling the personal information of 10 million or more California residents a year. We are nowhere near it.
C.7 Shine the Light (§1798.83)
We do not share personal information with third parties for those third parties' own direct marketing.
Changelog
- v1.2 — 2026-08-24. We ask before advertising cookies now — and we name one we had not disclosed.
- New: §10 describes the consent gate we now apply in the EEA, the UK and Switzerland. Nothing advertising-related is loaded, set or read there until you choose; consent is per category and nothing in the advertising category is on by default; silence and continued use are never treated as agreement; and Cookie settings changes or withdraws the choice at any time, on any page, taking effect immediately. v1.1's admissions that we did not ask (§10) and had built no consent capture (§B.4) are retired because they stopped being true.
- New, and a correction we owe you: §10 and §C.1 now disclose
attr_gclid, a first-party advertising cookie recording the Google Ads click that brought you. It lasts 90 days, it has been live on the site, and no previous version of this policy named it. §10's closing paragraph no longer lets "we do not run Google Ads tracking" stand on its own over a Google advertising identifier we set. - Corrected, and it is the same kind of scoping error as last time: §5, §10 and §C.2 said the Meta disclosure covered "the marketing site". It never only covered the marketing site —
/upgrade, the paywall page your assistant links you to, sends Meta a hashed copy of your Amplifiers account email. v1.1 said the hashed email only came from an address you typed into a marketing form. That was incomplete. - New: §3, §4, §7, §A.4 and §C.1 disclose the record we keep of your cookie choice — a random identifier for the choice, the categories, the time, the policy version and the two-letter country your request came from. No IP, no user agent, no email, no account link. Kept 24 months. Its legal basis is Art. 6(1)(c), legal obligation, and deliberately not consent: a record of you saying "no" cannot be conditional on you saying "yes", which is why it is written on rejection as well as acceptance.
- Corrected: §7 said marketing-site advertising data was "held by Meta under Meta's own retention, not ours". Two pieces of it are ours — the
attr_gclidcookie (90 days) and the record of your cookie choice (24 months) — and §7 now lists both. - Corrected: §C.1's geolocation row said we collect none. We derive a two-letter country from your IP to decide whether you must be asked, and store it on the record of your answer. Not the IP, and nothing finer.
- Unchanged, and still true: we do not detect the
Sec-GPCsignal (§10, §C.2), and the consent gate is not a California opt-out — §C.2 now says so explicitly rather than letting it imply a right it does not deliver there. We would rather leave those admissions standing than quietly drop them while taking credit for the gate. - Why this one carries no 14-day notice. §12 gives 14 days' notice for material changes, and the relevant trigger is a new category of personal data collected. The identifier on your consent record is personal data — a pseudonymous identifier is still personal data, and we are not going to claim otherwise — but it is a device identifier, and device identifiers are a category this policy already discloses (Meta's cookie identifier,
_fbp/_fbc, and nowattr_gclid). It is generated to meet a legal obligation rather than for a new purpose, and it replaces no existing disclosure. Everything else in this version either reduces what we collect without asking, or names something that was already happening and should have been disclosed sooner. Neither is a change we should make you wait 14 days for.
- v1.1 — 2026-08-19. Your library, and being straighter about Meta.
- New: §2.6 describes library sharing — a link that dies after ten minutes or 50 openings, served through our own domain, with no permanent-public-link option. §8.1 rewritten for the library as it actually is, including naming the one gap (uploaded reference images are not yet listed individually).
- New: §3 now discloses that we keep a record of which files are yours, and the marketing-site quiz answers and captured emails, which the previous version did not describe at all.
- Corrected, and the reason for the "straighter" above: §10, §5 and §C.1/§C.2 now disclose that we send Meta conversion events from our servers as well as from your browser, including a one-way hash of your email address if you gave us one on the marketing site. v1.0 described only the browser Pixel. Blocking the Pixel never stopped this leg, and we should have said so.
- Changed: §8.2 — account erasure now works from the record of your files rather than reconstructing web addresses, so it reaches files the old method could miss; it waits on an upload still in flight rather than stranding it; and it now also deletes your marketing-site quiz answers and captured email.
- Changed, and it is a retention disclosure: §7 and §8.2 now state that payment records and marketing-funnel purchase records outlive account erasure, for tax and payment-dispute reasons. v1.0 said email suppression was the only thing that survived. That was wrong.
- Removed: the v1.0 carve-out saying we leave an image in place if someone else's session referenced it. Your files are erased regardless.
- Corrected, and it matters: v1.0 said our database and file storage were in the United States. They are in the EU (Frankfurt), and always have been. §5, §6 and §A.7 now say so — everything Amplifiers stores about you stays in the EU, and only specific actions you take reach vendors outside it.
- Removed: PhotoRoom from the vendor list in §5, §6 and §A.7. The image-processing tool that used them has been withdrawn, so no image of yours goes to them any more.
- Rewritten throughout to describe what we hold and why, by category, without the internal specifics — vendor model names, storage layout, file limits — that told you nothing about your privacy.
- v1.0 — 2026-08-05. First publication.