Privacy policy.
This Privacy Policy explains how Amplis handles information when organisations and their authorised users use Amplis OS, the Amplis web app, the Amplis mobile app distributed under package identifier com.amplis.app, and related services. These are business tools for operational and workplace use.
An organisation controls its workspace, decides who may use it and determines much of the information entered into Amplis. Users should follow their organisation's policies when handling personal, confidential, safety or operational information.
1. Information we process
Account, profile and organisation data
We process information used to identify and authorise people within an Amplis workspace, such as names, email addresses, profile details, organisation membership, roles, permissions, authentication records and session information.
Operational, work and safety records
Amplis OS processes records created through customer workflows, including project and asset information, work records, HSE and inspection records, checklists, testing results, responses, notes, assignments, timestamps, approvals and audit history. Customer-configured HSE workflows may include injury, illness, medical treatment or other health-related information when a user or organisation chooses to record it. These records may identify the people who created, changed, reviewed or approved them.
Location data
When a user grants device permission and uses a feature that needs location, the mobile app may collect approximate or precise foreground location. Location may be shown on a map or attached to work records, responses, photos or other evidence. Amplis does not use location data for advertising.
Photos, audio, documents and files
Users may capture or attach photos and camera images, select videos, upload documents or other files, and optionally send raw audio for transcription. We also process related details such as filenames, file types, timestamps, upload status and links to the relevant workspace record.
AI and chat content
When AI or chat features are used, we process prompts, messages, instructions, selected workspace context, attachments, generated outputs and feedback needed to provide the requested workflow. The information sent depends on the feature and the content the user or organisation chooses to provide.
Device, sync, notification, analytics and support data
We may process device and browser type, operating system and app version, network and request information, on-device sync state, notification tokens, product-interaction events such as feature use or workflow actions, request timing and latency, security events, diagnostic and error details, and support communications. Product and diagnostic telemetry may be linked to account, organisation, thread or request identifiers. This information is used to operate offline sync, understand feature and service performance, deliver notifications, protect accounts and investigate faults or support requests.
2. How information is collected
We receive information directly from users and organisations when they create or administer accounts, configure a workspace, enter records, upload content, use AI or transcription features, contact support or otherwise use the service.
The mobile app receives location from the device only when the user grants permission and uses a foreground feature that requests it. It receives photos, camera images, audio and files when the user captures or selects them.
We also receive limited information from devices, browsers, connected customer systems and service providers where needed for authentication, synchronisation, notifications, security, support and customer-configured integrations.
3. How we use information
- create and administer accounts, organisations, roles and access controls
- provide customer-configured operational, work, HSE, inspection and testing workflows
- capture and present location, photo, document and other evidence where a user chooses to provide it
- sync authorised workspace data between devices and Amplis services, including for offline work
- provide AI, chat and optional transcription features requested by a user or organisation
- deliver service notifications and respond to support requests
- understand product usage and service performance, maintain security, prevent misuse, diagnose faults and keep appropriate audit records
Amplis does not sell personal information. Amplis OS and the Amplis mobile app do not include third-party advertising networks and we do not use customer workspace information to serve advertising. Product and diagnostic telemetry is not used for third-party advertising or cross-app tracking.
4. Who receives information
Information may be available to authorised users and administrators of the relevant organisation. We may disclose information to service providers that process it for us, to customer-selected systems, when required by law, or where reasonably necessary to protect the service, users or others.
- Amplis-operated application services and APIs, including Neon-backed database services used by Amplis OS.
- Clerk for account authentication, session management and related identity services.
- PowerSync and local SQLite storage for offline access and synchronisation between a device and authorised workspace data.
- Cloudflare R2 for customer-uploaded objects such as photos, documents and other files.
- Microsoft Graph and customer Microsoft 365 or SharePoint environments when an organisation enables those integrations.
- Expo and Google notification delivery services where notifications are enabled for the mobile app.
- Map tile and mapping providers, such as Esri or OpenFreeMap, when a map is displayed.
- AI and transcription providers selected by Amplis or the customer for the feature being used. Providers and models may vary by feature, configuration and availability.
- PostHog for linked product-interaction analytics, service-performance measurements, and diagnostic or error telemetry. AI or chat traces may include prompt and output text as well as associated user, organisation, thread, feature, timing and error metadata. The default configuration automatically masks selected credential, contact and local-path patterns, but this filtering does not remove all content.
The providers used for a particular workspace or feature depend on the organisation's configuration and the services available at the time. A customer's Microsoft 365 or SharePoint environment is controlled separately by that customer.
5. On-device storage and permissions
The mobile app uses local SQLite storage to support offline work and synchronisation. Local cached copies may remain on a device until the app's data is cleared or the app is removed, subject to how the device operating system manages storage. Users should protect their device and follow their organisation's device-management requirements.
Location, camera, photo library and notification access depend on the relevant device permission and feature. A user can change device permissions through the operating system, although disabling a permission may prevent the related feature from working.
If a user separately saves or backs up an image to Camera Roll or another personal device service, that copy is controlled through the device and the user's account rather than the Amplis workspace.
6. AI and transcription
AI and transcription features may send the user's prompt, selected workspace information, attachments or raw audio to an AI or transcription provider chosen by Amplis or the customer. Different features may use different providers or models. Users should provide only the information needed for the task and follow their organisation's rules for sensitive information.
AI-generated and transcribed content may be incomplete or inaccurate and should be reviewed before it is relied on for operational, safety or other important decisions.
7. Retention
We retain information according to the needs and instructions of the relevant workspace or organisation and as reasonably required for service operation, security, legal obligations, disputes and audit purposes. Retention can therefore vary between organisations and record types.
Uploaded photos, documents, files, transcriptions and other evidence may be retained as part of an operational or audit record even after the immediate task is complete. Raw audio and other content sent to a provider is also subject to the applicable feature configuration and provider arrangements.
Local cached copies may remain until app data is cleared. Copies saved to Camera Roll, device backups, or a customer-controlled SharePoint or Microsoft 365 environment have separate retention and deletion controls. Removing information from Amplis does not automatically remove those separately controlled copies.
8. Access, correction and deletion requests
To delete an Amplis OS or Amplis mobile account, use our account deletion request form. The form starts the request directly; you do not need to call or send a separate email. We acknowledge requests within three business days and normally complete them within 30 calendar days after successful identity verification.
We may need to verify the request and consult the organisation that controls the relevant workspace. Account, profile, session, notification and other personal service data that is no longer required will be deleted or de-identified. Operational, HSE, inspection, audit, legal, contractual, security or dispute records may need to be retained or de-identified. If that applies, we will explain what remains, why, and the applicable retention handling in the completion response.
To ask about personal information or request access or correction, contact enquiries@amplis.com.au.
9. Security
We take reasonable steps designed to protect information and limit access to authorised people and services. No system or transmission method is completely secure. Users and organisations are responsible for protecting their credentials, devices and connected customer systems. Please report a suspected security issue to enquiries@amplis.com.au.
10. Children
Amplis OS and the Amplis mobile app are business tools for workplace and operational use. They are not directed to children and are not intended for consumer use by minors.
11. Changes to this policy
We may update this Privacy Policy to reflect changes to the service, providers or our practices. We will publish the revised policy at this address and update the effective date above.
12. Contact
For privacy, security or general questions about Amplis OS and the Amplis mobile app, contact enquiries@amplis.com.au.