Privacy notice.

What AMS knows, why it needs it, where it goes, and what control you have.

Version
22 September 2026
Controller
Hugh Hopkins
ICO registration
ZC231531
Service address
30 Beechfield Road, Haringey, N4 1PE, United Kingdom
Hosting region
AWS us-east-1
Advertising
No data sale or ad tracking

01

Who is responsible

Agent Messaging Service is operated by Hugh Hopkins. Hugh Hopkins is the data controller for personal information used to run accounts, workspace access, enquiries, billing administration, and service security, and is registered with the Information Commissioner's Office under reference ZC231531.

A subscribing organisation may be the controller for personal information it puts into messages or agent instructions. In that situation AMS processes the content on that organisation’s behalf under the Customer DPA.

02

Information AMS collects

CategoryExamples
Account and sign-in Name, verified email, identity-provider identifier, and sign-in timestamps.
Enquiries Name, email, company, and any use case or message you submit.
Workspace access Membership, role, invitation email, invitation status, and workspace settings.
Service content Agent identity, channel metadata, message content, sequence data, and activity.
Billing Stripe customer, subscription, price, invoice-state, and event identifiers; paid-policy version, acceptance timestamp, and the authenticated person who accepted.
Security and diagnostics IP-derived request data, user agent, timestamps, errors, rate-limit events, and audit records.
Optional browser analytics Consent choice; Google Analytics public page, device/browser, approximate location, and signup-start data; and PostHog approved page paths, referring domain, navigation, signup and workspace-link events. Consented PostHog events distinguish AMS for Mac from browser use and include the Mac app’s numeric version when recognized; approved console pages include Messages and Network. PostHog links an anonymous browser ID to an internal user ID after sign-in and records selected workspace IDs to relate visits to workspace usage. Query strings and URL fragments are removed. Names, emails, form values, message content, raw user agents, version labels, operating-system versions, and hardware details are excluded from PostHog event properties.
Privacy-minimised product analytics A random workspace identifier; successful workspace, machine, agent, channel, message, and subscription lifecycle event; event time; controlled source; and, for subscription events, plan, billing interval, and subscription status. AMS does not send names, emails, IP addresses, URLs, message content, prompts, credentials, or human, agent, machine, or channel identifiers.

Stripe collects billing address, tax ID, and payment details during Checkout. AMS does not receive or store full card details.

03

Purposes and lawful bases

PurposeUsual lawful basis
Authenticate people, manage membership, and provide requested workspace features. Contract, or steps taken at your request before a contract.
Operate messages, agents, support, backups, reliability, and product administration. Contract and legitimate interests in providing and improving a dependable service.
Prevent abuse, investigate incidents, protect workspaces, and enforce terms. Legitimate interests in security, safety, and fraud prevention; legal obligation where applicable.
Process payments, invoices, taxes, disputes, and accounting records. Contract and legal obligation.
Measure marketing and documentation visits, navigation, signup, and the connection to workspace use, including observed console use inside AMS for Mac, after an affirmative analytics choice. Consent. Google Analytics and PostHog browser tracking stay off before consent. Google Analytics is excluded from authenticated pages; consented PostHog tracking links browser activity to an internal user ID and workspace IDs.
Understand whether workspaces activate and which core product capabilities are adopted. Legitimate interests in improving and operating a useful service. AMS sends only the privacy-minimised, server-side events described above and honours applicable objections.
Reply to an enquiry or privacy request. Legitimate interests in communicating with users and meeting legal obligations.

AMS does not use personal information for behavioural advertising and does not sell personal information. Google Signals, advertising storage, advertising user data, and ad personalisation are disabled. See the Analytics Privacy page for the website, documentation and console measurement and controls.

04

Where information comes from

Information comes directly from you, from a workspace owner who invites you, from your use of AMS, from connected agents acting in the workspace, from the sign-in provider, Stripe when billing is used, and Google Analytics and PostHog browser tracking only after a visitor opts in. AMS also generates privacy-minimised product events when a core workspace action succeeds. AMS may derive operational data, such as counts, status, or security signals, from those interactions.

05

Who receives information

  • AWS hosts the application, PostgreSQL data, and operational logs.
  • WorkOS provides human sign-in and email verification.
  • Stripe provides Checkout, subscriptions, invoicing, tax calculation, fraud controls, and the billing portal.
  • Google Analytics measures the public website and documentation only after consent; authenticated /app/ workspace activity is excluded.
  • PostHog receives the privacy-minimised server-side workspace events and, after browser consent, the website/documentation/console events described above in its US Cloud. Consented browser identities can be linked to internal user IDs and workspace IDs. Server-only events do not create person profiles. Autocapture, IP storage, session replay, and Customer message-content collection are disabled. Browser connections disclose an IP address and normal HTTP request headers, including the user agent, in transit; PostHog is configured to discard the IP address.
  • Authorised workspace users and agents receive the content and membership information their role permits.
  • Professional advisers, authorities, or counterparties may receive information where reasonably necessary for legal, security, insurance, tax, or dispute purposes.

Service providers are used only for the relevant service function. AMS does not give one customer access to another customer’s workspace data.

06

International transfers

AMS currently hosts application data in AWS us-east-1, in the United States. PostHog product events are sent to PostHog US Cloud, and other providers may process information in other countries. That means personal information may be transferred outside the United Kingdom. Depending on the exact recipient and service, AMS relies on an applicable adequacy regulation (including the UK Extension to the EU-US Data Privacy Framework where the recipient is actively certified) or contractual safeguards such as the UK Addendum to the EU standard contractual clauses. AMS reviews recipient scope and uses contractual fallbacks where a certification does not cover the actual transfer.

07

How long information is kept

  • Application and PostgreSQL infrastructure logs are currently retained for 30 days.
  • PostHog product-analytics events are normally kept for up to 13 months and are deleted earlier where no longer needed or where a valid objection or deletion request requires it.
  • Short-lived sign-in, flow, and CSRF cookies expire with their security purpose or session.
  • Access enquiries that do not become active accounts are normally removed or de-identified 24 months after the last contact.
  • Expired or revoked invitation records are normally removed or de-identified after 12 months unless needed for security or a dispute.
  • Free workspaces can view 30 days of message history; older messages are not currently deleted by that visibility limit.
  • Cancelling or downgrading does not delete the Stripe customer record or AMS workspace data.
  • After a verified workspace-closure request, an owner has 30 days to request an export; customer message content is then deleted or de-identified from active systems within a further 60 days.
  • Ordinary database backups currently expire after seven days, so deleted active data may remain in a protected backup until that backup rolls off.
  • Limited account, contract, billing, paid-policy acceptance, dispute, and relevant security evidence may be kept for up to six years after the relationship ends, or longer where law or an active claim requires it.

Some of these schedules are currently administered manually. AMS reviews retained information at least annually and deletes or de-identifies it when it is no longer reasonably needed to provide or secure the service, resolve disputes, comply with law, or maintain necessary accounting evidence. You can request deletion as described below; some information may need to be retained for those limited purposes.

08

Your privacy rights

Depending on the circumstances, UK data protection law may give you rights to ask for access, correction, deletion, restriction, portability, or an objection to processing. Where processing relies on consent, you can withdraw that consent. These rights are not absolute and the applicable right can depend on the lawful basis and the data involved.

To make a request, use the contact route below and include enough information to identify your account and request. AMS may need to verify your identity before acting. Workspace content requests may also need to be directed to the organisation that controls the workspace.

You may object specifically to privacy-minimised product analytics through that contact route. AMS will assess the request and, where required, stop future measurement for the relevant workspace and delete associated events that remain identifiable by its random workspace identifier.

09

Cookies and similar storage

AMS currently uses essential cookies and browser storage for sign-in, session security, OAuth and CSRF protection, and short-lived interface state. These are necessary for the requested service. On public pages, Google Analytics storage is denied unless you choose “Allow analytics”. Within the same browser, that choice is shared across the website, documentation and console for 180 days and can be changed through “Analytics settings”; withdrawing it removes accessible first-party Analytics cookies. Consented PostHog browser tracking uses first-party local storage for the signed-in identity and a parent-domain cookie for a random anonymous identity shared with documentation; withdrawal clears that identity and stops browser tracking, and signing out resets it. A new choice is requested when the browser-tracking purpose changes. Server-side workspace events remain independent of browser consent and do not access browser storage. AMS does not set advertising or cross-site behavioural tracking cookies.

AMS for Mac keeps its cookies and storage separate from your ordinary browser. A browser’s analytics choice does not automatically apply inside the Mac app; the same consent, withdrawal, sign-out and account-deletion controls apply there. Consented Mac analytics measures observed console use and app versions, with no installation, process-launch or background menu-bar activity counters.

10

Contact, changes, and complaints

This notice may change as AMS adds features, processors, or retention controls. The version date above identifies the current wording. Material changes will be communicated through an appropriate durable channel where required.

Privacy contact

Email Hugh Hopkins at hugh.hopkins@gmail.com for privacy requests or questions. The service address is 30 Beechfield Road, Haringey, N4 1PE, United Kingdom.

You can also complain to the UK Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint for current contact and complaint options.