Privacy Policy
This Privacy Policy explains what information imanna.ai (“imanna”, “Anna”, “we”, “us”) collects when you use our website, web app, desktop app and editor plugins (together, the “Service”), how we use and share it, and the choices you have. By using the Service you agree to this Policy.
1. Who we are
imanna.ai provides Anna, an AI worker that reads your code, builds and ships software, and — at your direction — connects to third-party services on your behalf. We are the data controller for the personal data described here. You can reach us any time at admin@imanna.ai.
2. Information we collect
Information you provide
- Account data — your email address and a securely hashed password (or, if you use “Sign in with Google”, your Google account email and basic profile). We never store your password in plain text.
- Content you give Anna — the code, files, prompts, project data and instructions you submit so Anna can perform the task you asked for.
- Integration connections — when you connect a third-party account (e.g. Google Ads, Google Calendar, Meta/Facebook, WhatsApp/Instagram/Messenger), we store the access and refresh tokens that account grants us, encrypted at rest, plus non-secret identifiers (such as an ad-account or page id) used to route requests.
- Payment data — if you buy credits, payments are processed by Stripe. We receive confirmation and billing metadata; we do not store your full card number.
- Support & communications — messages you send us.
Information collected automatically
- Usage & credit data — token/credit consumption, feature usage and operational logs needed to run and meter the Service.
- Device & connection data — IP address, browser/OS type, and similar technical data.
- Cookies & analytics identifiers — see §8.
3. How we use your information
- To provide, operate and secure the Service and perform the tasks you ask Anna to do.
- To connect to third-party platforms you have authorized and take the specific actions you request there (e.g. create or pause an ad campaign on your own ad account).
- To meter usage, process payments and manage your account and credits.
- To provide support, prevent abuse and fraud, and comply with legal obligations.
- To measure and improve our own website and marketing (see §8).
We do not sell your personal data, and we do not use the private content of your projects to train third-party foundation models beyond what is necessary to perform your requested task.
4. Google user data — Limited Use disclosure
imanna.ai’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, we request only the scopes needed for the feature you enable, and we use the data solely to provide it:
- Google Ads (
adwords) — to read and manage campaigns, budgets and status on the Google Ads account you connect, only when you ask Anna to. Google bills you directly; Anna never holds your funds. - Google Calendar / related (Agenda feature) — to read and create calendar events you ask Anna to manage.
- Google Analytics (read-only) — to report your own site metrics inside Anna.
- Sign in with Google (
openid,email,profile) — to authenticate you into your imanna account.
We do not use Google user data for advertising, do not transfer it to others except to provide or improve the feature (or as required by law), and do not allow humans to read it except with your consent, for security or to comply with law. You can disconnect Google at any time in the app’s settings, which revokes our stored tokens.
5. Meta Platform data
When you connect a Meta (Facebook/Instagram) asset — an ad account, a Page, a WhatsApp number or an Instagram account — we use the access you grant only to provide the feature you enabled (e.g. managing your ad campaigns, or answering messages on your connected channel). We handle Meta data in accordance with the Meta Platform Terms and Developer Policies. Tokens are stored encrypted at rest and are used only to call Meta’s APIs on your behalf. You can disconnect any channel at any time, and you can request deletion of associated data as described in §10.
6. AI model providers
To perform your tasks, Anna sends the necessary content (e.g. your prompt and relevant code) to AI model providers — Anthropic (Claude) and, if you choose, OpenAI or another provider — acting as our sub-processors. In our managed service these providers process your content to return a result and do not use it to train their models. If you bring your own API key, your usage is also governed by that provider’s terms.
7. Sharing & sub-processors
We share data only with service providers that help us run the Service, under contract and only as needed:
- Amazon Web Services — cloud hosting and storage (United States).
- Anthropic / OpenAI — AI model inference.
- Stripe — payment processing.
- Google & Meta — only the platforms you connect, to perform your requested actions and, for analytics, to measure our own site.
We may also disclose information to comply with law, enforce our terms, or protect the rights and safety of users and the public. If we are ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different policy.
8. Cookies & analytics
Our marketing website uses a small number of cookies and measurement tools to understand traffic and campaign performance: Google Analytics 4, Google Ads conversion tracking, and the Meta Pixel (with server-side Conversions API). These may set cookies and share hashed/technical event data with Google and Meta for measurement and attribution. Strictly necessary cookies (such as your login session) are always used. You can control cookies through your browser settings, opt out of Google Analytics via the Google opt-out add-on, and manage ad personalization in your Google and Meta settings.
9. Data retention
We keep your account data for as long as your account is active. Project content, credits and logs are retained as needed to provide the Service and meet legal, security and accounting requirements, then deleted or anonymized. Integration tokens are kept until you disconnect the integration or delete your account.
10. Deleting your data
You are in control of your data and can remove it at any time:
- Disconnect an integration — in the app’s settings, disconnecting Google, Meta or any channel immediately deletes the stored tokens for that connection.
- Delete your account & data — email admin@imanna.ai with the subject “Data deletion request” from your account email. We will delete your account and associated personal data within 30 days, except where we must retain limited records to comply with the law.
This section also serves as our data deletion instructions for the Meta Platform. To request removal of data obtained via a Meta connection, disconnect the channel in-app or email us as above.
11. Security
We protect your data with encryption in transit (TLS) and encryption at rest for secrets such as passwords (hashed) and integration tokens (AES-256-GCM). Access to production systems is restricted. No system is perfectly secure, but we work to protect your information and will notify you and regulators of a breach where required by law.
12. International transfers
We operate in the United States (AWS, us-east-1). If you access the Service from Brazil, the EEA/UK or elsewhere, your information may be transferred to and processed in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers.
13. Your rights (GDPR / LGPD)
Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Brazilian users have these rights under the LGPD; EEA/UK users under the GDPR. To exercise any right, contact admin@imanna.ai. You may also lodge a complaint with your local data protection authority (in Brazil, the ANPD).
14. Children
The Service is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
15. Changes to this Policy
We may update this Policy from time to time. We will change the “Last updated” date above and, for material changes, provide a more prominent notice. Continued use of the Service after an update means you accept the revised Policy.
16. Contact us
Questions or requests about privacy? Email admin@imanna.ai.