Amika
Graded against 808 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Defines 'Device Data' as information about the user's hardware and network environment (IP address, device IDs, location, browser type, hardware model, ISP/carrier, OS, system config) — operative definition scoping device-level collection.
Introduces the circumstances and categories of third parties with whom personal information may be shared — framing statement that scopes the data-sharing provisions that follow.
Permits sharing personal data with third-party vendors, service providers, contractors, and agents who perform services on the company's behalf and need the data to do so — establishes the legal basis and scope for subprocessor data sharing.
How to read this page: Overall risk rates what Amika's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 49 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 49 citationsLast captured 2026-07-19
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Imposes an obligation to delete or anonymize personal information when there is no ongoing legitimate business need, and where deletion is not immediately possible requires secure storage and isolation from further processing until deletion can occur.
" When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in back..."
Grants users the right to opt out of the sale or sharing of their personal information, and affirmatively discloses that the company has not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months — a user-favorable disclosure prohibiting such commercial sharing.
" Right to opt out of the sale or sharing of your personal information (we have not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months)."
Permits sharing or transferring personal information in connection with mergers, asset sales, financing, or acquisitions — establishes a lawful basis for data transfer in business-transaction contexts.
" Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company."
Grants qualifying residents the right to request, once per year at no charge, information about categories of personal information disclosed to third parties for direct marketing purposes and the identities of those third parties, with a procedure for making such requests via email.
" California Civil Code Section 1798.83 permits California residents to request, once per year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and ..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. This may include information such as your IP address, device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information."
Defines 'Device Data' as information about the user's hardware and network environment (IP address, device IDs, location, browser type, hardware model, ISP/carrier, OS, system config) — operative definition scoping device-level collection.
AI-generated interpretation, not legal advice.
" We may share information in specific situations and with the following categories of third parties."Permalink to this finding →
Introduces the circumstances and categories of third parties with whom personal information may be shared — framing statement that scopes the data-sharing provisions that follow.
AI-generated interpretation, not legal advice.
" Vendors, consultants, and other third-party service providers. We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. The categories of third parties we may share personal information with are as follows:"Permalink to this finding →
Permits sharing personal data with third-party vendors, service providers, contractors, and agents who perform services on the company's behalf and need the data to do so — establishes the legal basis and scope for subprocessor data sharing.
AI-generated interpretation, not legal advice.
" Affiliates. We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us."
Permits sharing personal information with affiliates (parent company, subsidiaries, joint venture partners, and commonly controlled entities) subject to the obligation that those affiliates honor this privacy notice — creates a conditional sharing right with a downstream compliance obligation.
AI-generated interpretation, not legal advice.
" We do not intentionally send prompt text, source code, secret values, raw logs, or full repository URLs to analytics providers."
States that prompt text, source code, secret values, raw logs, and full repository URLs are not intentionally sent to analytics providers — imposes a self-declared restriction on the categories of sensitive content shared with analytics subprocessors, protective of user data.
AI-generated interpretation, not legal advice.
" We use session replay to diagnose usability and reliability issues during onboarding. Session replay is active only on onboarding pages and is not enabled elsewhere in the authenticated app. All text input fields are masked in recordings so that passwords, tokens, and other typed values are never captured."
Discloses that session replay is used only on onboarding pages and not elsewhere in the authenticated app, and that all text input fields are masked so that passwords, tokens, and other typed values are never captured — imposes user-protective restrictions on the scope and content of session-replay data collection.
AI-generated interpretation, not legal advice.
" We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us to keep your personal information for longer than twelve (12) months past the termination of the user's account."
Limits retention of personal information to the period necessary for stated purposes, caps retention at twelve months past account termination unless law requires longer, and subordinates retention to legal requirements such as tax and accounting obligations.
AI-generated interpretation, not legal advice.
" Right to opt out of the sale or sharing of your personal information (we have not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months)."
Grants users the right to opt out of the sale or sharing of their personal information, and affirmatively discloses that the company has not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months — a user-favorable disclosure prohibiting such commercial sharing.
AI-generated interpretation, not legal advice.
" This privacy notice for Amika – Fixpoint, Inc. ("Fixpoint", "we", "us", or "our") describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you visit our website at https://www.amika.dev/ or use the Amika product."
Defines the scope of the privacy notice by identifying the controller entity, the meaning of 'process,' the covered services, and the website URL — establishes the operative framework for all subsequent data-use provisions.
AI-generated interpretation, not legal advice.
" Location Data. We collect location data such as information about your device's location based on your IP address."
Defines 'Location Data' as device-location information derived from IP address — operative definition limiting location collection to IP-based inference rather than precise GPS data.
AI-generated interpretation, not legal advice.
" Opting out of marketing communications. You can unsubscribe from our marketing and promotional communications at any time by clicking the unsubscribe link in the emails we send, or by contacting us using the details provided below."
Grants users the right to opt out of marketing and promotional communications at any time via an unsubscribe link or by contacting the company.
AI-generated interpretation, not legal advice.
" Under the California Consumer Privacy Act (CCPA), you have the following rights:"
Incorporates the rights framework of the named state consumer privacy statute as the basis for the enumerated rights that follow, establishing the legal source for the subsequent provisions.
AI-generated interpretation, not legal advice.
" Right to know whether we collect and use your personal information, and the categories and purposes involved."
Grants users the right to know whether the company collects and uses their personal information and the categories and purposes involved.
AI-generated interpretation, not legal advice.
" Right to request correction of inaccurate personal information."
Grants users the right to request correction of inaccurate personal information held by the company.
AI-generated interpretation, not legal advice.
" Right to non-discrimination for exercising your privacy rights."
Grants users the right to non-discrimination for exercising their enumerated privacy rights.
AI-generated interpretation, not legal advice.
" Right to opt out of the processing of your personal data if it is used for targeted advertising or the sale of personal data"
Grants residents the right to opt out of processing of their personal data when used for targeted advertising or the sale of personal data.
AI-generated interpretation, not legal advice.
" Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please contact us at privacy@amika.dev ."Permalink to this finding →
Grants users a conditional right to request access to, modification of, or deletion of their personal information based on applicable laws of their country, and specifies a procedure for exercising that right via a contact email address.
AI-generated interpretation, not legal advice.
" Personal information you disclose to us. We collect personal information that you voluntarily provide when you register on the Services or otherwise contact us. The personal information we collect may include names, email addresses, usernames, passwords, and contact or authentication data. We do not process sensitive personal information."
Identifies the categories of personal information voluntarily collected (names, email addresses, usernames, passwords, contact/authentication data) and expressly states that sensitive personal information is not processed — describes the controller's data-collection practice and a self-imposed restriction on sensitive data.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Amika's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Amika's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Amika's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Amika requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Amika's published policies yet.
What the policies actually cover
0 topicsNone of Amika's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Verified retention clauses point in different directions: the Privacy Policy, § 7 (How Long Do We Keep Your Information?) describes broad or open-ended retention, while the Privacy Policy, § 10 (What Are Your Privacy Rights?) describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“Right to opt out of the sale or sharing of your personal information (we have not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months).”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. This may include information such as your IP address, device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We may share information in specific situations and with the following categories of third parties.”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Vendors, consultants, and other third-party service providers. We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. The categories of third parties we may share personal information with are as follows:”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Affiliates. We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | conditional | MEDIUM | 1 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 3 |
| Team / Business | subprocessors data sharing | worsens | HIGH | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: third party or vendor sharing on subprocessors data sharing
“Right to opt out of the sale or sharing of your personal information (we have not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months).”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Affiliates. We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.”Open timeline citation
Latest stance: sale or sell on subprocessors data sharing
“Right to opt out of the sale or sharing of your personal information (we have not sold or shared personal information to third parties for a business or commercial purpose in the preceding twelve months).”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. This may include information such as your IP address, device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We may share information in specific situations and with the following categories of third parties.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Vendors, consultants, and other third-party service providers. We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. The categories of third parties we may share personal information with are as follows:”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
50 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Amika's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Amika's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Amika's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.