Last updated: February 2026
Rapid Spark
Ronny Saar
Saarbruecker Strasse 77, 66564 Ottweiler, Germany
Email: info@rapidspark.de
We do not currently have an obligation to appoint a Data Protection Officer (DPO). For any data protection inquiries, please contact us at privacy@amae.app.
Supervisory authority: Landesbeauftragte fuer Datenschutz und Informationsfreiheit des Saarlandes, Fritz-Dobisch-Strasse 12, 66111 Saarbruecken, Germany. You have the right to lodge a complaint with this or any other competent supervisory authority.
We collect and process the following data:
We process your data based on:
You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You can withdraw contact import consent by deleting imported contacts and AI assistant consent by not using the feature.
Your personal data is stored locally on your device using Apple's SwiftData framework and synced via Apple iCloud (CloudKit) to your private iCloud container. The geographic location of your iCloud data is determined by your Apple ID region settings.
Authentication tokens are stored in the iOS Keychain with device-only accessibility protection. All network communication uses TLS 1.2+ encryption with certificate pinning for additional security.
Apple acts as a data processor for iCloud/CloudKit storage. Apple's data processing information is available at apple.com/legal/privacy.
We share data with the following third parties:
We have Data Processing Agreements in place with our sub-processors. A current list of sub-processors is available upon request at privacy@amae.app. We will notify you of significant changes to our sub-processors.
We do not sell your personal data to third parties.
The AI assistant is switched off by default. Before it can be used, the app shows a consent screen that names the recipient (Google) and lists exactly which data will be sent. No data is transmitted to any AI provider before you actively enable the feature, and you can revoke your consent at any time under Settings → AI assistant. The rest of the app remains fully usable if you decline.
Requests are processed by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) using the Gemini AI service (model gemini-2.5-flash). The app never contacts Google directly: every request is routed through our own server in Germany using our API key. Google therefore receives no account identifier, authentication token, device identifier or IP address of yours — the data is pseudonymous from Google's perspective. Transfers are based on the EU-US Data Privacy Framework and Google's data processing terms; Google acts solely as our processor and does not use this data to train its models or for its own purposes such as advertising.
All of the data below originates from entries you typed into the app yourself (or selected during the optional address book import). It is only transmitted when you send a message to the assistant:
If you open the assistant without selecting a person, no contact data at all is transmitted — only your question.
The sole purpose is to generate the answer you requested (message ideas, gift suggestions, conversation topics). We do not use assistant content for advertising, profiling or model training. Our server does not persist the content of your requests; it only counts the number of requests per month in order to enforce the free-tier quota. Conversation history exists only for the duration of the active conversation.
The assistant may propose entries (interactions, reminders, events, topics, gift ideas). This does not constitute automated decision-making with legal effect under Art. 22 GDPR, as you review, modify or delete every entry yourself.
Our backend also contains integrations for spoken answers (text-to-speech by OpenAI, L.L.C., USA) and for speech recognition. Neither is used by the current app version — the app always requests text-only responses, so no data is sent to OpenAI. Should we activate the feature in a future version, we will update this privacy policy and ask for consent again beforehand.
Your data may be transferred to the United States through our use of Apple iCloud, Google, OpenAI, and Resend. These transfers are safeguarded by the EU-US Data Privacy Framework (for Apple Inc., Google LLC, OpenAI L.L.C., and Resend Inc., all certified participants).
Data flow: Your data is first transmitted to our server in Germany (EU). For AI processing, data is forwarded from Germany to Google LLC in the United States. For text-to-speech, AI response text is forwarded to OpenAI L.L.C. in the United States. For password reset emails, your email address and first name are forwarded to Resend Inc. in the United States. Server access logs are retained for a maximum of 90 days for security and troubleshooting purposes.
For users in Japan (APPI): Personal data is first transferred to our server in Germany (covered by the Japan-EU mutual adequacy decision). From Germany, data may be further transferred to Google LLC and OpenAI L.L.C. in the United States for AI processing and voice synthesis (covered by the EU-US Data Privacy Framework). These providers implement encryption in transit and have committed to not using API data for model training.
For users in South Korea (PIPA): Cross-border transfers to Google LLC and OpenAI L.L.C. (United States) for AI processing and voice synthesis, to Resend Inc. (United States) for email delivery, and to Apple Inc. (United States) for iCloud synchronization are conducted with your explicit consent. You may withdraw consent for AI processing at any time by disabling the AI assistant. Data destruction upon account deletion is completed within 5 business days via electronic erasure.
For users in the United Kingdom: International data transfers from the UK to our server in Germany are covered by the UK's adequacy regulations for the EU. Transfers to the United States are safeguarded by the UK Extension to the EU-US Data Privacy Framework.
Under GDPR and applicable local laws, you have the right to:
For users in France: Under the Loi Informatique et Libertes, you have the right to define directives regarding the storage, erasure, and communication of your personal data after your death. To register such directives, contact privacy@amae.app.
For users in France and Spain: You have the right to define directives regarding the management of your personal data after your death (Art. 85 Loi Informatique et Libertes; Art. 96 LOPDGDD).
For users in South Korea (PIPA): You have additional rights including the right to request suspension of processing. Our Chief Privacy Officer for PIPA purposes is Ronny Saar (info@rapidspark.de, +49 6824 302 9780).
To exercise these rights, contact privacy@amae.app or use the in-app features in Settings.
If you are a California resident, you have additional rights under the CCPA/CPRA:
Categories of personal information collected: Identifiers (name, email), personal information (contacts, phone numbers), internet activity (usage data), audio information (voice transcriptions).
We do not use or disclose sensitive personal information for purposes other than providing the services you requested. We do not sell personal information of consumers under 16 years of age.
The AI assistant feature uses automated processing to create entries based on your instructions. This processing does not produce legal or similarly significant effects. You retain full control to review, modify, or delete any AI-created entries.
Residents of other US states with comprehensive privacy legislation (including Virginia, Colorado, Connecticut, Texas, and Oregon) may have additional rights, including the right to access, delete, and correct personal information, and the right to opt out of targeted advertising. We do not engage in targeted advertising or profiling. To exercise your privacy rights, contact privacy@amae.app.
Retention: We retain your data as described in Section 10. To exercise your rights, contact privacy@amae.app or use the in-app data management features.
For users in the United Kingdom, your data is protected under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You have the same rights as described in Section 8. International data transfers from the UK to the EU (our server in Germany) are covered by the UK's adequacy regulations. Transfers to the United States are safeguarded by the UK Extension to the EU-US Data Privacy Framework.
For complaints, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.
For users in Brazil, your data is protected under the Lei Geral de Proteção de Dados (LGPD). You have the right to:
Legal basis for processing: Consent (Art. 7, I LGPD) and contract performance (Art. 7, V LGPD). To exercise your rights, contact privacy@amae.app.
We retain your data as long as your account is active. When you delete your account, all personal data is permanently removed from our servers, your local device, and iCloud within 30 days. Anonymous, aggregated analytics data may be retained.
When you delete your account, deletion propagates to other devices via iCloud sync. Data on devices that are offline at the time of deletion will be removed when those devices next connect.
In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you without undue delay and in accordance with applicable law (Art. 33, 34 GDPR). For users in South Korea: We will notify the Personal Information Protection Commission and affected individuals within 72 hours of becoming aware of the breach, in accordance with PIPA Art. 34.
Amae is not intended for users under 16 years of age (or the applicable minimum age in your jurisdiction). For users in Brazil: Users under 18 years of age must have a parent or legal guardian provide consent for the use of this app, in accordance with LGPD Art. 14. We do not knowingly collect personal data from children. If we become aware that we have collected personal information from a child under 13 (USA) or the applicable minimum age, we will take steps to delete such information promptly.
We may update this policy. We will notify you of significant changes through the app. Where changes require renewed consent for data processing, we will ask for your explicit agreement before continuing to process your data under the updated policy.