Privacy Policy
Last updated July 2026.
This Privacy Policy describes how ACM Platforms (“we,” “us”) collects and uses information when you use AI Agent Avatar Platform (the “Service”).
Information we collect
Account information
When you register or sign in, authentication is handled by AWS Cognito. We store your Cognito subject identifier, email address, tenant membership, and role in our application database so the Service can provision workspaces and enforce access control.
Tenant and agent configuration
We store tenant names, agent definitions (system prompts, avatar selection, allowed embed domains), API key metadata (hashed secrets and prefixes), and knowledge-base configuration including S3 prefixes and Bedrock knowledge-base identifiers.
Conversation and session data
Voice and chat sessions generate message content, token usage metrics, and session state associated with your tenant and agent. We use this to operate the widget during active sessions, measure usage, and provide support. Shared cloud subscription plans (Free, Standard, and Pro) do not include long-term conversation storage or configurable retention.
Billing information
Paid subscriptions are processed by Stripe when enabled. We store Stripe customer and subscription identifiers and plan status in MySQL. Payment card details are collected and processed by Stripe, not stored on our application servers.
Local browser data
The tenant portal may store your theme preference (light/dark) in localStorage. Amplify/Cognito may store session tokens according to AWS Amplify defaults.
Data retention
Shared cloud subscriptions
On shared cloud plans, conversation content is processed only as needed to run the Service and record usage on your dashboard. It is not offered as exportable conversation history or a retention product.
Trial demo data files uploaded for demonstrations are removed automatically after 30 days, as described on the About page.
Self-Hosted and Managed Dedicated Hosting
Professional deployments include conversation retention with automatic clearing. Default schedules are:
- Text chat messages — Up to 24 hours from when each message is stored.
- Voice session messages and live session state — Up to 24 hours from when the session is created or last updated.
- Session metadata — Up to 24 hours.
- Completed voice sessions — A secure archive may be retained after the session ends. Contact us if you need voice archives removed for your workspace.
- Usage summaries — Aggregated dashboard counts may be kept longer than message content and do not include full transcripts.
Removal is automatic after each period below. In most cases, expired records are deleted within about 48 hours of that point.
Retention periods can be adjusted during professional-services onboarding. See Pricing for an overview.
How we use information
- Provide, operate, and improve the Service
- Authenticate users and enforce plan limits and tenant isolation
- Process payments and manage subscriptions
- Deliver voice, avatar, and knowledge-base features through AWS Bedrock and related services
- Respond to support requests and protect against abuse
Service providers
We rely on third-party infrastructure and vendors, including:
- AWS (Cognito, Bedrock, DynamoDB, S3, and cloud hosting)
- Stripe (payments, when enabled)
- MySQL database hosting (tenant control-plane data)
Widget embeds and end users
When you embed our widget on your site, visitors interact with agents you configure. You are responsible for informing your end users and obtaining any consents required for voice capture, logging, and data processing in your jurisdiction.
Contact
Privacy questions: support@acmplatforms.com
See also Terms of Use and About.
