Legal

Privacy Policy

1. Who we are

imanna.ai provides Anna, an AI worker that reads your code, builds and ships software, and — at your direction — connects to third-party services on your behalf. We are the data controller for the personal data described here. You can reach us any time at admin@imanna.ai.

2. Information we collect

Information you provide

Information collected automatically

3. How we use your information

We do not sell your personal data, and we do not use the private content of your projects to train third-party foundation models beyond what is necessary to perform your requested task.

4. Google user data — Limited Use disclosure

When you connect a Google account, we request only the scopes needed for the feature you enable, and we use the data solely to provide it:

We do not use Google user data for advertising, do not transfer it to others except to provide or improve the feature (or as required by law), and do not allow humans to read it except with your consent, for security or to comply with law. You can disconnect Google at any time in the app’s settings, which revokes our stored tokens.

5. Meta Platform data

When you connect a Meta (Facebook/Instagram) asset — an ad account, a Page, a WhatsApp number or an Instagram account — we use the access you grant only to provide the feature you enabled (e.g. managing your ad campaigns, or answering messages on your connected channel). We handle Meta data in accordance with the Meta Platform Terms and Developer Policies. Tokens are stored encrypted at rest and are used only to call Meta’s APIs on your behalf. You can disconnect any channel at any time, and you can request deletion of associated data as described in §10.

6. AI model providers

To perform your tasks, Anna sends the necessary content (e.g. your prompt and relevant code) to AI model providers — Anthropic (Claude) and, if you choose, OpenAI or another provider — acting as our sub-processors. In our managed service these providers process your content to return a result and do not use it to train their models. If you bring your own API key, your usage is also governed by that provider’s terms.

7. Sharing & sub-processors

We share data only with service providers that help us run the Service, under contract and only as needed:

We may also disclose information to comply with law, enforce our terms, or protect the rights and safety of users and the public. If we are ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different policy.

8. Cookies & analytics

Our marketing website uses a small number of cookies and measurement tools to understand traffic and campaign performance: Google Analytics 4, Google Ads conversion tracking, and the Meta Pixel (with server-side Conversions API). These may set cookies and share hashed/technical event data with Google and Meta for measurement and attribution. Strictly necessary cookies (such as your login session) are always used. You can control cookies through your browser settings, opt out of Google Analytics via the Google opt-out add-on, and manage ad personalization in your Google and Meta settings.

9. Data retention

We keep your account data for as long as your account is active. Project content, credits and logs are retained as needed to provide the Service and meet legal, security and accounting requirements, then deleted or anonymized. Integration tokens are kept until you disconnect the integration or delete your account.

10. Deleting your data

You are in control of your data and can remove it at any time:

This section also serves as our data deletion instructions for the Meta Platform. To request removal of data obtained via a Meta connection, disconnect the channel in-app or email us as above.

11. Security

We protect your data with encryption in transit (TLS) and encryption at rest for secrets such as passwords (hashed) and integration tokens (AES-256-GCM). Access to production systems is restricted. No system is perfectly secure, but we work to protect your information and will notify you and regulators of a breach where required by law.

12. International transfers

We operate in the United States (AWS, us-east-1). If you access the Service from Brazil, the EEA/UK or elsewhere, your information may be transferred to and processed in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers.

13. Your rights (GDPR / LGPD)

Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Brazilian users have these rights under the LGPD; EEA/UK users under the GDPR. To exercise any right, contact admin@imanna.ai. You may also lodge a complaint with your local data protection authority (in Brazil, the ANPD).

14. Children

The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

15. Changes to this Policy

We may update this Policy from time to time. We will change the “Last updated” date above and, for material changes, provide a more prominent notice. Continued use of the Service after an update means you accept the revised Policy.

16. Contact us

Questions or requests about privacy? Email admin@imanna.ai.