Legal
Policies andproduct guidance.
Last updated: . These Terms of Service and this Privacy Policy apply to Super Amplify. The Terms form an agreement between you and Super Amplify LLC ("Super Amplify," the "Company," "we," "us"). When you explicitly accept, we record the version, date and time, and session details described below. The Privacy Policy explains processing; acknowledging it is not blanket consent to monitoring, marketing, or model training.
Terms of Service
1. Acceptance, eligibility, and recorded assent
By creating an account, clicking to accept, or accessing or using Super Amplify in any way, you agree to be bound by these terms. If you do not agree, you must not access or use the platform. If you use the platform on behalf of an organization, you represent that you have authority to bind that organization, and "you" includes that organization.
When you accept these terms, we record your acceptance — including the terms version, timestamp, IP address, and device information — and this record constitutes evidence of your agreement. You are responsible for ensuring your use complies with applicable laws and your organization's internal policies. You must be at least 18 years old (or the age of majority in your jurisdiction) to use the platform.
2. Accounts and security
You are responsible for the confidentiality of your account credentials and for all activity on your account. Notify us promptly if you suspect unauthorized access. You may not share, sell, or transfer your account, or create an account using false information or on behalf of someone who has been blocked or banned.
3. Plans, features, and suptokens
Super Amplify offers multiple plans. Features, model access, usage limits, and support levels vary by plan. The Company may add, modify, limit, or discontinue any plan, feature, model, or usage allowance at any time at its sole discretion.
- Free: Includes 1,000 suptokens per month to get started.
- Pro: Paid plan with expanded usage limits, additional models, and advanced workflow capabilities.
- MyAgent Elite: Paid plan with expanded MyAgent capabilities, voice usage, and priority feature access.
- Enterprise: Custom plan for teams that need advanced controls, integration support, and tailored rollout terms.
Suptokens are usage units that meter platform activity. Suptokens have no cash value, are not property, are non-transferable, and may be adjusted, expired, or revoked by the Company in connection with plan changes or enforcement actions.
3A. Public demonstrations, evaluations, and estimates
Public dashboards and guided tours identified as examples use fictional data and simulated states. They do not connect to your employer, inspect your computer, or pause or quarantine a real application. A tool name in an example catalog does not establish a working integration, endorsement, or vendor partnership. Actual availability, capture, control reach, support, and deployment requirements depend on the ordered service and validated configuration. A demo request is a request for follow-up, not a confirmed appointment, purchase, service-level commitment, or promise of a particular outcome.
Token counts, usage totals, risk indicators, and cost estimates may be incomplete, delayed, or based on provider reports and assumptions. Estimates are not invoices or guarantees of savings, budget compliance, or a maximum charge. Applicable order forms, plan terms, and provider billing govern actual charges. Preview and evaluation features may change and must be assessed before production reliance.
4. Third-party and custom AI model providers; informed assumption of risk
Super Amplify provides access to large language models, generative AI systems, and related tools developed, hosted, or operated by multiple unaffiliated providers ("Model Providers"). Model Providers may be based in the United States or other countries and may offer proprietary, open-source, self-hosted, customer-supplied, custom, fine-tuned, experimental, or otherwise constructed models. A Model Provider includes the developer, host, inference or API operator, and any upstream vendor involved in processing a request.
When you use an AI feature, your prompts, files, instructions, relevant workspace context, metadata, and generated outputs may be transmitted to and processed by one or more Model Providers. A provider may be selected directly by you or your organization, or automatically through routing, fallback, tool, agent, availability, or performance features. Model Providers maintain their own terms, acceptable-use rules, privacy practices, data-retention periods, safety and abuse-monitoring procedures, security controls, training or service-improvement settings, data-residency options, and legal-compliance processes. Those policies and practices differ by provider, model, account configuration, region, and feature and may change without the Company's control.
The Company uses reasonable safeguards designed to protect customer and company data, but no safeguard, model, provider, transmission, or storage system is risk-free. Risks include unauthorized access or disclosure, security incidents, provider retention or human review, processing in a foreign jurisdiction, government or legal demands, use for safety monitoring or model improvement where the applicable provider terms or settings permit it, loss of confidentiality or intellectual-property protection, and inaccurate, biased, harmful, or non-unique output. The Company does not control Model Providers and cannot guarantee their continued availability, security, legal compliance, data location, deletion, confidentiality, or adherence to any particular policy.
By selecting or using any model or AI feature, you acknowledge these risks, knowingly authorize the processing needed to provide the selected feature, and accept the risks associated with the applicable Model Providers. You are responsible for reviewing the provider and configuration before submitting sensitive data; complying with your organization's policies and all applicable laws; obtaining all required rights, notices, consents, and approvals; and avoiding submission of regulated, export-controlled, privileged, highly confidential, or other sensitive information unless your organization has expressly approved that provider and configuration for the data. You must comply with any Model Provider policies that apply to your use. To the maximum extent permitted by law, the Company is not responsible for acts, omissions, policy changes, outages, security incidents, data practices, or outputs of unaffiliated Model Providers.
5. Acceptable use and prohibited conduct
You may not use the platform for unlawful, abusive, fraudulent, infringing, or harmful activity. Without limiting the foregoing, you must not:
- Threaten, harass, stalk, defame, intimidate, or attempt to harm the Company, its personnel, its users, or any third party, whether on or off the platform;
- Violate any law, regulation, or third-party right, including privacy, intellectual property, and safety laws;
- Probe, scan, breach, or test the vulnerability of the platform, circumvent authentication or security measures, or access data or accounts you are not authorized to access;
- Interfere with or disrupt the platform, including overloading, flooding, spamming, or introducing malicious code;
- Scrape, harvest, or extract data from the platform, or use the platform or its outputs to build, train, or improve a competing product or service;
- Misrepresent your identity or affiliation, evade an enforcement action (including creating new accounts after suspension or ban), or assist others in doing any of the above;
- Use the platform to generate, store, or distribute content that is illegal, exploitative, or intended to deceive, defraud, or harm others.
6. Right to refuse, block, suspend, or ban
The Company reserves the right, exercisable at its sole and absolute discretion, to refuse service to anyone and to block, restrict, suspend, or permanently ban any user, account, organization, IP address, or device — with or without prior notice and, to the maximum extent permitted by applicable law, with or without stated reason. This includes, without limitation, users the Company reasonably believes pose a risk of harm to the Company, its personnel, its users, its systems, or the public; users who threaten, harass, or abuse anyone; and users engaged in fraud, security abuse, unlawful conduct, or violations of these terms.
The Company has a zero-tolerance policy for threats, harassment, and conduct intended to harm the Company or any person. Such conduct will result in immediate termination of access and may be reported to law enforcement.
Determinations regarding violations of these terms, enforcement actions, account standing, and eligibility for service are made unilaterally by the Company and are final. Where required by applicable law, the Company will provide any legally mandated notice or review; otherwise, no refund, credit, or compensation is owed for access, plans, features, or suptokens lost due to an enforcement action taken for cause.
7. Monitoring, investigation, and enforcement
The Company may monitor use of the platform for security, abuse prevention, and compliance purposes; investigate suspected violations; preserve and disclose information as required by law or as reasonably necessary to protect the Company, its users, or the public; and cooperate with law enforcement. The Company may take any enforcement action it deems appropriate, including content removal, feature restriction, suspension, or permanent ban.
7A. Enterprise governance, connectors, and customer responsibilities
If your organization enables governance services, its authorized administrators determine the permitted users, devices, tools, providers, data sources, capture settings, access permissions, and policies. You may install a connector, configure a webhook, enroll a computer, or direct an agent only where you have authority over the affected systems and data. Your organization is responsible for a lawful and proportionate deployment, clear worker and other affected-person notices, required consultation and consents, an appropriate legal basis, and compliance with employment, communications, recording, privacy, and other applicable laws. Accepting these Terms does not supply those notices or permissions or authorize covert or indiscriminate monitoring.
Your organization must limit collection and administrator access to the approved purpose, review sensitive-data risks, maintain its own credentials, device and network controls, and validate integration coverage before relying on the service. You are responsible for your instructions, policy settings, webhook destinations, connected third-party accounts, and authorized users. Do not use a public demo or enquiry form to submit credentials, production secrets, privileged material, or sensitive employee or customer records.
Governance controls act only at supported and configured control points. Pause, quarantine, disable, revocation, and budget settings may affect subsequent governed actions and may not stop an action already running, an offline device, an uninstrumented path, or an independent application. Telemetry may be missing, delayed, redacted, or application-reported; prompts and source context are available only where supported and enabled. Risk flags and policy decisions require review and do not establish misconduct, complete capture, successful external enforcement, security certification, or legal compliance. The service does not replace your endpoint security, backups, incident response, professional advice, or human oversight. You must not use a risk flag as the sole basis for an employment or other consequential decision about a person.
Agents and workflows that you or your organization authorize may access systems, create or change content, consume paid resources, or trigger external actions within their permissions. Set appropriate approval gates and spending limits, test in an appropriate environment, and independently verify consequential results. Instructions to suspend or revoke access do not erase retained history or reverse completed external actions. Separately signed enterprise agreements and data-processing terms govern the services and processing they cover, including any expressly agreed commitments.
8. Billing and subscriptions
Paid plans are billed on the schedule presented at checkout. You can manage, upgrade, or cancel subscriptions from your account. Unless otherwise stated in a written enterprise agreement or required by applicable law, payments are non-refundable once a billing cycle begins, including where access is terminated for cause under Section 6.
9. Intellectual property and feedback
The platform, including its software, models, designs, and branding, is owned by the Company and its licensors. No rights are granted to you except the limited, revocable, non-exclusive, non-transferable right to use the platform in accordance with these terms. If you provide feedback or suggestions, you grant the Company a perpetual, irrevocable, royalty-free license to use them without restriction or obligation.
As between you and the Company, you or your licensors retain your rights in submitted customer content and telemetry. You grant only the rights needed to host, copy, transmit, process, and display that information to deliver the features you authorize and to secure and support the service, subject to the Privacy Policy, applicable law, and any signed data-processing agreement. This provision does not grant ownership of your customer content or an unrestricted right to use it for model training. You are responsible for having the rights necessary for the information and instructions you provide.
10. Disclaimer of warranties
YOUR ACCESS TO AND USE OF THE PLATFORM, MODEL PROVIDERS, AND OUTPUTS IS AT YOUR SOLE RISK. THE PLATFORM AND ALL THIRD-PARTY MODELS, SERVICES, AND OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, CONFIDENTIALITY, SECURITY, DATA LOCATION, DELETION, OR UNINTERRUPTED AVAILABILITY. AI-GENERATED OUTPUTS MAY BE INACCURATE, INCOMPLETE, BIASED, HARMFUL, OR NON-UNIQUE; YOU ARE RESPONSIBLE FOR HUMAN REVIEW BEFORE RELYING ON OR DISTRIBUTING THEM, AND YOU ASSUME ALL RISK ARISING FROM YOUR USE OF THE PLATFORM, MODEL PROVIDERS, AND OUTPUTS.
11. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, CONFIDENTIALITY, INTELLECTUAL PROPERTY, BUSINESS OPPORTUNITY, OR GOODWILL, ARISING FROM OR RELATED TO THE PLATFORM, A MODEL PROVIDER, AI PROCESSING OR OUTPUT, A SECURITY INCIDENT, OR THESE TERMS. THE COMPANY'S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED THE GREATER OF THE AMOUNTS YOU PAID TO THE COMPANY IN THE TWELVE (12) MONTHS BEFORE THE CLAIM AROSE OR ONE HUNDRED U.S. DOLLARS (US$100). SOME JURISDICTIONS DO NOT ALLOW CERTAIN LIMITATIONS; IN THOSE JURISDICTIONS, LIABILITY IS LIMITED TO THE MAXIMUM EXTENT PERMITTED BY LAW.
These warranty and liability provisions also apply, to the extent permitted by law, to demonstrations, governance reports, connectors, policy controls, agents, and customer-configured integrations. Nothing in these Terms excludes liability that cannot lawfully be excluded, waives mandatory privacy or consumer rights, excuses the Company from its own legal obligations, or overrides an expressly conflicting provision in a separately signed enterprise or data-processing agreement.
12. Indemnification
You will defend, indemnify, and hold harmless the Company and its affiliates, officers, directors, employees, agents, licensors, and service providers from and against any claims, damages, liabilities, regulatory actions, costs, and expenses (including reasonable attorneys' fees) arising from your content, your selection or use of a Model Provider, your failure to obtain required rights or approvals, your violation of a Model Provider policy, your use or distribution of AI output, your use of the platform, your violation of these terms, or your violation of any law or third-party right.
For organizational customers, this obligation includes third-party claims caused by unlawful monitoring, unauthorized connector deployment, improper disclosure to a customer-selected destination, or instructions and policy settings that violate others' rights, to the extent attributable to that customer. It does not require indemnification for the Company's own unlawful conduct or amounts that applicable law prohibits shifting. The Company will give reasonably prompt notice of a covered claim, provide reasonable cooperation at your expense, and allow an appropriate defense; no settlement may admit fault or impose an obligation on the Company without its written consent.
13. Changes to plans, providers, and terms
The Company may add, replace, reroute, suspend, or discontinue plans, features, Model Providers, models, and these terms at any time. Updated terms will be posted with a revised date. For this material update, signed-in users must review and accept the current version through the existing acceptance flow before continuing where that flow applies. We provide additional notice or obtain separate consent when required by law. A terms update does not by itself authorize materially different use of previously collected personal information or override a separately signed agreement.
14. Governing law and dispute resolution
These terms are governed by the laws of the State of Delaware, USA, without regard to conflict-of-law principles, except where the mandatory consumer-protection law of your place of residence applies. To the maximum extent permitted by applicable law, any dispute arising out of or relating to these terms or the platform will be resolved by binding individual arbitration, and you and the Company each waive the right to a jury trial and the right to participate in a class, collective, or representative action. Nothing in this section prevents the Company from seeking injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property, systems, personnel, or users, and nothing in these terms limits any non-waivable statutory rights you hold under applicable law.
15. No waiver; reservation of rights
No use of the platform, course of dealing, delay, or failure by the Company to exercise or enforce any right or provision of these terms operates as a waiver of that or any other right or provision. Any waiver by the Company must be express, in writing, and signed by an authorized representative, and applies only to the specific instance for which it is given. All rights and remedies of the Company under these terms, at law, and in equity are cumulative and are expressly reserved.
16. Severability and survival
If any provision of these terms is held unenforceable, it will be enforced to the maximum extent permissible and the remaining provisions will remain in full force and effect. Sections concerning intellectual property, disclaimers, limitation of liability, indemnification, no waiver, dispute resolution, and any accrued payment obligations survive termination of your access or these terms.
17. Assignment, order of precedence, and entire agreement
The Company may assign these terms in connection with a merger, acquisition, reorganization, or sale of assets. You may not assign these terms or your account without the Company's prior written consent. If you have a separately signed enterprise or data-processing agreement with the Company, that agreement controls only to the extent it expressly conflicts with these terms. These terms, together with any applicable enterprise agreement and the policies referenced on this page, constitute the entire agreement between you and the Company regarding the platform.
Privacy Policy
This Privacy Policy explains what information Super Amplify LLC collects, how we use and disclose it, and your choices and rights. It applies to our platform, public websites, demonstrations, and related services. Processing depends on the features you use, the integrations your organization enables, and the applicable instructions and settings.
We act as a controller where we determine the purposes and means of processing, including our account administration, billing, public enquiries, and service security. Where we process organization workspace content or governance records solely on a customer's documented instructions, that customer ordinarily acts as controller and we act as its processor or service provider, subject to the applicable agreement. Roles depend on the actual processing; this policy does not remove either party's legal obligations. Your organization's notice explains its purposes and policies for information it controls. Acknowledging this notice does not authorize unrestricted monitoring or waive privacy rights; separate choices, notices, and consent apply where required.
1. Information we collect
- Account data: Name, email, password hashes or third-party sign-in identifiers, authentication factors (including MFA enrollment), role, and company membership.
- Usage data: Feature usage, suptoken activity, product interactions, log data, IP address, and device/browser diagnostics.
- Content data: Prompts, uploaded files, connected data sources, generated outputs, and workspace data you or your organization choose to store in the platform.
- Voice, avatar, and likeness data: If you use avatar or voice features, the images, video, and audio you provide — including consent recordings — to create and operate your avatar and voice profile.
- Billing data: Subscription status, invoices, and payment events. Card details are collected and processed by our payment providers; we do not store full card numbers.
- Agreement and security records: When you accept our terms, we record the terms version, timestamp, IP address, and browser/device details as evidence of your acceptance. We also keep security logs of significant account events (such as sign-ins, account creation, and enforcement actions).
- Enquiries and public demonstrations: Contact details, company, enquiry, and other information you submit; the form source, submission time, verification information, and permitted campaign labels described in Section 2A.
- Public MyAgent conversations: Messages, responses, contact details you provide, and audio and transcription information when you activate voice. With your permission for a lead handoff, contact details and the public conversation transcript are included in the enquiry emailed to our team and the copy sent to you.
- Connected-tool governance: Where a customer enables a supported integration, company, user, installation and application identifiers; event times; workspace or resource references; reported tool, model, token and cost activity; action outcomes; policy decisions; risk indicators; and coverage status. Prompts, responses, tool inputs and outputs, and context references depend on the supported source and authorized capture settings. Enabling governance does not mean every application, interaction, or content field is captured.
- Website and device activity: Cookies or similar identifiers, browser and network information, page and interaction activity, referral information, and measurement or conversion signals. Sources include your browser or device, your organization, and the connected tools and providers used for the feature.
2. How we use information
- Deliver, secure, maintain, and improve Super Amplify services.
- Operate plan entitlements, usage limits, suptoken metering, and billing.
- Personalize your workspace, including agent context, personas, and role-based dashboards you configure.
- Provide customer support and send service communications.
- Meet legal, tax, accounting, compliance, and security obligations.
- Maintain records of terms acceptance, and detect, investigate, and act on abuse, threats, fraud, security incidents, and violations of our terms — including blocking or banning accounts, IP addresses, or devices, and preserving related evidence.
- Produce aggregated or de-identified analytics that do not identify you, which we may use and share for any lawful purpose.
We do not sell your personal information.
We use enquiries to respond, arrange requested demonstrations, prepare relevant follow-up, maintain the relationship record, and prevent misuse. Campaign and website measurement help us understand interest and marketing effectiveness. For configured governance services, we process records to provide visibility, usage and cost reporting, policy evaluation, risk review, audit evidence, and supported controls or workflows.
Where a lawful basis is required, it depends on our role and purpose: performance of a contract with you or requested pre-contract steps; legitimate interests such as responding to business enquiries and operating and protecting the service, subject to applicable balancing and objection rights; legal obligations; or consent where required. Organizational customers determine and document the basis for processing they instruct, including monitoring and any additional requirements for sensitive information. These are not interchangeable blanket permissions. References to service improvement do not grant permission for unrelated training or advertising using confidential customer content; any such use requires the applicable disclosures, lawful basis, permissions, and contractual authority. Section 3 addresses provider-specific practices.
2A. Demo requests, campaigns, and public MyAgent
The demo form collects the contact details and enquiry you submit, its source and submission time, and permitted campaign information from the page open when you submit. Campaign attribution accepts only bounded source, medium, campaign, and content labels and an approved public landing-page path. That attribution field excludes the full URL, arbitrary query parameters, fragments, referrer, advertising click identifiers, and contact fields; invalid labels are omitted. Do not put personal or confidential information in campaign links. These limits apply to the demo-attribution field, separately from website operational records and tracking described below.
Requests undergo abuse screening and, for the demo form, human verification. We and the verification provider may process network, browser, and verification information for this purpose. Our enquiry service emails your request and campaign labels to the Company's contact team; a confirmation copy is sent to the supplied address without the campaign labels. That copy may fail even when our team receives the enquiry. The form's confirmed-submission measurement event includes a source, an event identifier containing a timestamp, and conversion labels; it excludes submitted contact fields, enquiry text, and campaign labels.
Public MyAgent is a separate conversational experience. It asks permission before a contact handoff and explains that contact information and the full public conversation transcript will be emailed to the Company and the supplied address. Its handoff does not currently collect the demo form's campaign labels. Optional microphone audio and transcription are processed by the relevant voice and AI services to support the conversation, separately from avatar or cloned-voice enrollment. Avoid confidential, regulated, proprietary, or sensitive personal information in public forms and conversations.
An enquiry permits us to handle that request and relevant follow-up; it does not by itself provide consent to unrelated marketing where required. You may stop marketing follow-up using an unsubscribe option in a message or the contact details below. Necessary account, security, legal, and requested-service communications may continue. A handoff or microphone permission does not authorize unrelated recording, monitoring, or training.
2B. Cookies, website measurement, and advertising
We use cookies, browser storage, tags, and similar technologies for sessions, preferences, verification, service operation and security, website measurement, conversion reporting, advertising, and referral attribution. Providers may receive browser, network, page, referral, and activity or conversion information. Our first-party activity service also records page, interaction, and request activity using a visitor identifier; it sanitizes query values from stored page and referral paths. These operational records are separate from optional marketing tags and from connected-tool content capture.
Cookie Preferences in the site footer let you change analytics, marketing, and preference choices for the current browser. Browser controls offer additional choices. Google analytics and advertising storage begin denied until a valid choice is applied; denied settings can still produce consent and cookieless measurement signals. Session, verification, security, and operational functions may operate independently of optional choices. Changing a choice does not recall previously transmitted information or remove every vendor record; contact us for applicable privacy or advertising requests. Cookie choices and Terms acceptance do not waive statutory opt-out rights.
Our PromoteKit referral script and Aggle marketing pixel start only with a current marketing opt-in. A Global Privacy Control signal exposed by your browser overrides that stored opt-in for these scripts and our Google advertising-consent settings. Withdrawing marketing permission prevents new loads by these controls; previously executed third-party code and information already sent may require additional browser or recipient controls.
3. AI processing, Model Providers, and data risks
Super Amplify offers models from multiple Model Providers, including U.S.-based and foreign providers and providers of proprietary, open-source, self-hosted, customer-supplied, custom, fine-tuned, experimental, or otherwise constructed models. Depending on the model, feature, configuration, and route, prompts, files, relevant workspace context, instructions, metadata, and outputs may be transmitted to and processed by one or more Model Providers and supporting infrastructure vendors. A provider may be selected by you or your organization or automatically through routing, fallback, agent, tool, availability, or performance features.
Model Providers have different and independently maintained terms and practices concerning privacy, retention, human review, abuse and safety monitoring, model training or service improvement, security, data residency, subprocessors, government requests, and deletion. Practices may differ by product tier, API, feature, region, and account setting and may change. Depending on the arrangement, a provider may process data as our service provider or subprocessor, through an account controlled by you or your organization, or in another role permitted by law. Applicable provider agreements, settings, and policies govern that provider's processing; the Company does not control and cannot guarantee an unaffiliated provider's practices.
We use reasonable safeguards designed to reduce risk, but use of any AI model involves residual privacy, confidentiality, intellectual-property, cybersecurity, cross-border-transfer, and output risks. Do not submit regulated, privileged, export-controlled, highly confidential, or other sensitive information unless you and your organization have determined that the selected provider, region, retention setting, and contractual safeguards are appropriate and lawful. You are responsible for having the rights, notices, consents, and lawful basis required for data you submit. You may contact us for current information about providers used for your service configuration.
AI-generated outputs are produced automatically and may be inaccurate. You are responsible for reviewing outputs before relying on or distributing them, and for ensuring you have the necessary rights to any content you upload for processing.
4. Voice, avatar, and likeness
Avatar and voice features are optional. When you enroll, we record your consent and use your provided images, video, and audio solely to create and operate your avatar and synthetic voice within the platform. You must only upload a voice or likeness that is your own or that you have documented rights and consent to use. You may disable these features and request deletion of your enrollment data at any time through support or the privacy contacts below.
5. Workspace visibility and organization data
Workspace content and activity may be visible to your organization's authorized administrators and teammates according to configured access controls. Where governance is enabled, this may include supported telemetry, policy and risk records, and content categories permitted by its capture settings. Your organization controls its purposes, member access, integrations, workspace policies, and retention instructions, subject to its agreement with us and applicable law.
Before monitoring or content capture, the organization must provide required worker and other affected-person notices, identify a lawful basis, limit collection and access to what is necessary and proportionate, and obtain consent or complete assessments, consultation, and other safeguards where required. Employment or Terms acceptance is not blanket consent; employee consent may be inappropriate without a freely exercisable choice. Customers should provide a contact for questions, corrections, and challenges to decisions based on these records. This allocation does not excuse our own obligations.
Collection and control depend on integration support, configuration, permissions, connectivity, and what the source exposes. Metadata and content capture are distinct; fields may be absent, redacted, truncated, estimated, or incomplete. Context references do not establish everything a model used. Risk indicators are aids to review, not conclusive findings about a person or a guarantee of compliance. Customers must provide human review and other required safeguards before consequential decisions. Direct requests about organization-controlled purposes or records to that organization; you may also contact us, and we will handle our duties and assist or route requests as appropriate.
6. Support access
Authorized Company personnel may access accounts and workspace data where reasonably necessary to provide requested support, investigate abuse or security incidents, or comply with law. Administrative access of this kind is authenticated, logged, and limited to the purpose at hand.
7. Sharing and disclosure
- Providers and processing partners: Hosting, storage, AI inference, voice and transcription, payment, email, human verification, abuse prevention, analytics, advertising, and referral attribution providers, where used for the relevant feature. Their roles as service providers, subprocessors, or independent recipients depend on the applicable arrangement, agreements, and settings.
- Your organization: As described in Section 5, for company workspaces.
- Customer-selected destinations: Information within the configured scope may be sent to an authorized export, webhook, connector, workflow, or other supported destination. Its use and retention depend on the customer's instructions and recipient arrangement; customers must authorize destinations and provide required disclosures and safeguards.
- Legal and safety: Where required by law, subpoena, or legal process, or where reasonably necessary to protect the rights, property, safety, or security of the Company, our users, or the public, including sharing with law enforcement in connection with threats, fraud, or abuse.
- Business transfers: In connection with a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy or successor terms.
- Aggregated or de-identified data: Which does not identify you.
8. Data retention and deletion
We retain personal data for as long as needed to provide the service, operate your account, and meet the purposes above. We retain billing records, terms-acceptance records, security logs, and enforcement records for as long as necessary to satisfy legal, accounting, audit, dispute-resolution, and abuse-prevention purposes — including after account closure. You can request deletion of eligible personal data through the GDPR request form or support; some data may be retained where we have a legal obligation or legitimate interest (such as fraud and abuse prevention) to keep it.
Retention depends on the data category, purpose, customer instructions and agreement, operational need, applicable law, and justified investigations or disputes. Enquiries and emails may remain in business communication systems for relationship handling and required recordkeeping. Account closure, a policy switch, revocation, or expiration of a content-viewing window is not necessarily immediate erasure of records, exports, recipient copies, or backups. Access windows and deletion are separate controls; a displayed access period is not a guaranteed physical-deletion schedule. Retention exceptions remain limited by applicable law.
9. Security safeguards
We use technical and organizational controls designed to protect data, including encryption in transit, access controls and per-user isolation of stored content and generated outputs, multi-factor authentication options, security logging, and monitoring for abuse and misuse. No system is completely secure; you are responsible for safeguarding your credentials, and we encourage enabling MFA. If we become aware of a breach affecting your personal data, we will notify you and regulators as required by applicable law.
Governance protections depend on the enabled feature and configuration. Redaction and risk detection do not identify every sensitive value or prevent every disclosure, and do not replace appropriate collection and access decisions. A dashboard, demonstration, or policy setting does not imply certification, complete coverage, or absolute security.
10. International transfers
We, Model Providers, and other service providers may process data in the United States and other countries, including countries whose privacy laws or government-access rules differ from those where you live or work. The provider and processing location can vary by selected model, automatic route, feature, availability, and account configuration. Where required for transfers for which the Company is responsible, we use recognized transfer mechanisms or other appropriate safeguards, such as standard contractual clauses. No transfer mechanism eliminates all legal, governmental-access, or security risk.
11. Your rights
Depending on your jurisdiction (including under GDPR and U.S. state privacy laws), you may have the right to access, correct, delete, or receive a copy of your personal data, restrict or object to certain processing, and withdraw consent where processing is based on consent. We will not discriminate against you for exercising these rights. We may need to verify your identity before acting on a request, and we may deny requests where an exception applies (for example, data we must keep for legal or security reasons).
Where applicable, rights may also include opting out of sale, sharing, targeted advertising, or certain profiling; limiting certain sensitive-information uses; appealing a request decision; using an authorized agent; and complaining to a privacy regulator. The process depends on the applicable law and our role. Withdrawal of consent does not affect prior lawful processing. A policy acknowledgment, contract, or organization rule does not waive mandatory privacy or consumer rights.
Submit privacy requests through the GDPR request form, email [email protected] with the subject "Privacy request," or use . These routes also accept marketing opt-out requests. We will route your message to the appropriate team; no new account is required to email a request.
12. Children
Super Amplify is not directed to children and may not be used by anyone under 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy and will post the revised date here. We provide additional notice of material changes and obtain separate consent where applicable law requires it. We may ask you to acknowledge the updated notice; acknowledgment, continued use, or acceptance of updated Terms does not substitute for required consent or by itself authorize a materially different use of previously collected information. Applicable agreements and nonwaivable rights continue to apply.
14. Contact
- General support: Reach us through . Submissions are screened for spam and abuse before reaching our team.
- Privacy requests: Use the GDPR request form or email [email protected] to exercise applicable rights or ask about this policy.
Getting started
Turn your files, prompts, and workflows into useful output with this six-step path.
- Create your account and start on Free. Sign in and begin with the Free plan. You can explore the platform with 1,000 monthly suptokens before upgrading.
- Set up your workspace. Create or open a workspace, organize your threads, and set context for the tasks you want Super Amplify to help with.
- Upload files and connect knowledge. Add documents and data sources, then use them as context so answers and outputs are grounded in your material.
- Run prompts, assistants, and workflows. Use chat, assistants, and multi-step workflows to draft content, analyze data, and automate repeatable work.
- Track usage and plan limits. Monitor suptoken usage in your account so you always know remaining capacity and when an upgrade may be useful.
- Scale when you are ready. Move to Pro, MyAgent Elite, or Enterprise as your team needs more capacity, features, or governance controls.
Your first week
- Day 1: Review pricing and plan fit, then start on Free.
- Day 2: Upload 2-3 real documents and test contextual Q&A.
- Day 3: Build one assistant for a recurring workflow.
- Day 4: Create one multi-step workflow to automate a repeat task.
- Day 5: Review usage and decide whether to stay on Free or upgrade.
Resources
Go deeper with documentation, examples, and live training.