Privacy Policy
Plain language: what Amistio collects, why, where it lives, and how to delete it - including exactly how data from apps you connect is used.
Overview
Amistio is an agent platform operated by Lamplit Labs. You use it to build AI agents, connect them to apps you already use, and share a page where others can run them. This policy explains, in plain language, what data we collect, why we collect it, where it is stored, who can see it, and how you can delete it.
The short version: we collect only what the product needs to work, we store it encrypted in the European Union, we never sell it, we never use it for advertising, and data from apps you connect is used for exactly one thing - carrying out the actions your agents perform at your direction.
Information We Collect
Account information. When you sign up we receive your name, email address, and sign-in identifiers through Clerk, our sign-in provider.
Workspace content. The agents you build - their configuration, forms, branding, and knowledge you add - plus the runs they execute: inputs submitted, outputs produced, and files uploaded to a run.
Connected-app credentials. When you connect an app, we receive the access token that app issues and, where the app provides it, your basic profile on that app. The next section describes exactly how this is handled.
Contact information. If you email us, we receive what you choose to send, such as your name, work email, organization, and message.
Technical information. Browser, device, network, request, security, and error data needed to operate and protect the service.
Analytics. On the public website only, and only with your consent, Google Analytics and Microsoft Clarity may process usage data. Analytics never loads before you agree, and advertising storage stays disabled.
Data From Apps You Connect
You can connect third-party apps to your agents - for example Google (including Google Sheets), Microsoft, Facebook, Instagram, and Threads (Meta), LinkedIn, X, GitHub, Slack, Discord, Telegram, Notion, and Airtable. Connecting is always your explicit choice, made through that provider's own consent screen, and limited to the permissions shown there.
What we receive: the access token the provider issues and, where provided, basic profile details such as your display name. We request only the permissions the integration needs to do its job.
How we use it: solely to perform the actions your agents carry out at your direction - such as sending a message, creating an issue, publishing a post, or reading a sheet your agent works with. We do not read, collect, scrape, or sync your third-party account data in the background, and no human at Lamplit Labs looks at it except with your permission to resolve a support issue you raise.
What we never do with it: we never sell it, never share it with data brokers or advertisers, never use it to build profiles, never use it for advertising or credit purposes, and never use it to develop or train AI or machine-learning models.
How it is protected: access tokens are encrypted at rest with AES-256-GCM under a key unique to your account, which you can rotate yourself at any time. The plaintext token is never stored, logged, or shown - the interface displays only a masked hint.
How to revoke: disconnect the app inside Amistio, which deletes the stored token immediately, or revoke Amistio's access from the provider's own security settings - either is enough. You can also request deletion of any related data by emailing us.
Google User Data
Amistio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: Google user data (for example the contents of a spreadsheet an agent reads or writes) is used only to provide the agent action you asked for, is never used for advertising, is never sold, is never used to train AI or machine-learning models, and is transferred only as necessary to perform that action, to comply with law, or with your explicit consent. You can revoke access at any time at myaccount.google.com/permissions or by disconnecting Google inside Amistio.
AI Processing
When an agent runs, the inputs it needs - the prompt, the form values submitted, and any connected-app data the specific task requires - are processed by AI model endpoints hosted on Microsoft Azure in the European Union. Your content is not used to train those models.
Voice conversations on shared run pages stream audio directly between your browser and the Azure-hosted realtime endpoint over a short-lived session; the audio does not pass through or get recorded by our servers.
AI output can be inaccurate or incomplete. Review it before relying on it, and use approval steps for consequential actions.
Who We Share Data With
We use a small number of service providers to run Amistio, each limited to its role: Microsoft Azure hosts the platform and stores data in the Germany West Central region; Clerk provides sign-in; Google Analytics and Microsoft Clarity process public-website usage only after you consent. When your agent performs an action on a connected app, the data needed for that action goes to that provider - that is the feature working as you configured it.
Beyond that, we disclose information only when required by law, to protect rights and security, or as part of a corporate transaction with equivalent protections. We do not sell personal information and we do not share it for advertising.
Cookies And Analytics
Essential storage supports sign-in, security, and basic functionality. Analytics cookies do not exist until you grant consent, and you can change your choice at any time.
We do not use advertising cookies, cross-site tracking, or sell data derived from cookies.
Retention And Deletion
We keep data only as long as it serves the purpose it was collected for. Disconnecting an app deletes its stored token immediately. Deleting an agent deletes its definition; its run history follows your workspace controls. Contact and support threads are kept only as long as reasonably needed.
You can request a copy of your data, or deletion of your account and everything in it, by emailing us. We act on verified requests promptly; residual copies in encrypted backups are purged on the backup rotation schedule shortly after.
Security
Data is encrypted in transit with TLS and encrypted at rest. Connected-app credentials get an additional layer: AES-256-GCM under a per-account key you can rotate yourself. We follow least-privilege access internally and never display or log plaintext credentials.
No system is perfectly secure, so never send passwords, API keys, or other secrets through contact forms or email.
Your Rights
Where the GDPR or similar laws apply, you can ask us for access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing, and you can withdraw consent at any time without affecting prior processing. You also have the right to complain to your data-protection authority.
We honor these rights for everyone, not only where the law compels it. We do not sell or share personal information as those terms are defined in US state privacy laws, and we will never treat you differently for exercising a privacy right. To exercise any right, email hello@lamplitlabs.com.
Where Data Lives, And Children
Platform data is stored on Microsoft Azure in Germany (Germany West Central) and stays in the European Union at rest. Limited processing by the providers named above may occur in the countries where they operate, subject to appropriate legal safeguards such as standard contractual clauses.
Amistio is a work tool and is not directed to children under 16. We do not knowingly collect children's data; if you believe a child has provided personal information, contact hello@lamplitlabs.com and we will delete it.
Changes To This Policy
If we change this policy, we will update the date on this page, and for material changes we will give clearer notice. We will never quietly weaken the commitments in the connected-apps section.
Contact
Lamplit Labs is the data controller for the processing described here. For privacy questions or requests, contact hello@lamplitlabs.com. Do not include passwords, access tokens, or other credentials in your message.