Skip to content
Amexa.ai

Legal

Privacy Policy

How Amexa.ai handles information across our website, Business Review, Lumira™ services, and authorized integrations. Last updated August 21, 2026.

Who We Are

Amexa.ai, LLC (“Amexa.ai,” “we,” “us”) provides Lumira™, an AI-assisted business operating and workflow platform. This policy explains how we handle information collected through amexa.ai, the Business Review, customer onboarding, customer workspaces, and authorized integrations.

This policy describes current practices. It is not an independent audit, legal certification, or claim that Amexa.ai holds a compliance certification that has not been formally obtained.

Information We Collect

Information you choose to provide may include your name, business name, business contact information, industry, business goals, existing systems, scheduling preferences, onboarding details, and information included in a Business Review or support request.

We may collect limited technical, authentication, security, audit, and device/browser information needed to operate, protect, troubleshoot, and improve the service.

For a business customer, Amexa.ai may process business and customer information that the customer is authorized to provide or connect. The exact data, provider, purpose, and permitted use depend on the customer's approved scope and configuration.

Production Data and Customer Boundaries

Current Amexa.ai production application data is stored in the Lovable-managed Supabase/PostgreSQL environment used by the application. Access controls are designed around authenticated identity, organization membership, tenant boundaries, role-based access control, row-level security, and stronger authentication requirements such as AAL2/MFA for sensitive Founder or administrative actions where configured.

Customer workspaces are organization-scoped. A user must not gain another customer's records through URL guessing, email-domain matching, prompts, AI requests, frontend manipulation, or another customer's integration. Server-side authorization and database policies remain authoritative.

How We Use Information

We use information to respond to inquiries, conduct Business Reviews, configure and provide approved services, operate integrations, support customers, maintain security and audit records, improve usability, reconcile authorized commerce activity, and comply with legal obligations.

We do not sell personal information and do not provide customer or prospect information to unrelated third parties for their own advertising purposes.

Integration Layer and Provider Access

Lumira™ uses an integration layer to represent approved third-party systems and to separate discovery, authorization, runtime use, revocation, and provider readiness. A provider definition or architecture-ready integration is not the same as a live or production-ready customer connection.

Authorization is intended to be scoped to the applicable tenant, provider, integration, and allowed action. Revoking or disabling an integration is intended to stop future authorized runtime use without granting unrelated access.

Provider credentials, OAuth refresh tokens, API secrets, and similar sensitive values are not intended to be exposed in ordinary frontend code, Lumira™ prompts, or customer-visible records. Secret-reference records are restricted to trusted server-side/service-role access rather than normal authenticated users.

Email and Connected Communications

Lumira™ supports provider-neutral email architecture and may support an approved mailbox provider only after the required authorization and configuration are complete. When a provider uses OAuth, users authenticate with that provider rather than giving Amexa.ai their mailbox password.

Mailbox content and connection data are used only for the authorized features and workspace scope. Connected email content is not made available to Amexa.ai AI team members or external AI providers by default. Any AI use of mailbox content requires an explicitly authorized workflow and applicable privacy/provider controls.

Users may disconnect supported integrations. Provider-side revocation may also be available. Connection metadata, audit records, and legally required records may be retained where necessary to operate or secure the service.

AI Use and Privacy Boundaries

AI-assisted features are subject to workspace permissions, approved scope, and provider/security controls. Sensitive customer information should not be sent to an external AI or provider unless that use has been reviewed and authorized for the workflow.

Amexa.ai does not provide customers, prospects, trials, or guests with a direct bridge to an outside AI review service through Lumira™. AI assistance is provided only through Amexa.ai-controlled product workflows and applicable authorization boundaries.

Communications and Contact Preferences

Where communications are enabled, the customer is responsible for having a lawful basis and any required permission to contact recipients. Qualification, scoring, a Business Review, or the presence of contact information does not itself authorize outreach.

A website inquiry or Business Review request does not create a client agreement or authorize unrelated marketing by itself.

Service Providers

Amexa.ai uses service providers for functions such as hosting, authentication, database infrastructure, security, communications, integrations, payments, and product operations. Providers receive access only as needed for the service and remain subject to their own terms and security obligations.

A third-party provider is not represented as connected, synced, or production-ready unless Amexa.ai has evidence that the relevant account, permissions, configuration, and acceptance requirements are satisfied.

Payments and Financial Information

Where payments are enabled, payment-card and sensitive banking details should be entered directly into the authorized payment or banking provider interface. Amexa.ai does not require customers to place full card numbers, CVVs, full bank-account numbers, routing numbers, payment-provider secret keys, or financial login credentials into Lumira™ prompts or ordinary application logs.

Founder financial dashboards may display authorized provider-derived transaction and payout information while keeping test/sandbox activity separate from live revenue and masking payout destinations where displayed.

Security

Amexa.ai uses layered safeguards appropriate to the current service, including authenticated access, tenant and role boundaries, row-level database controls, AAL2/MFA for sensitive access where configured, encrypted transport, provider authorization controls, secret handling, audit trails, and fail-closed controls for sensitive workflows.

No online system can be guaranteed perfectly secure. Amexa.ai does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or another certification unless and until that status is formally obtained and specifically stated.

Retention, Deletion, and Requests

We retain information only as long as reasonably needed to provide services, maintain security and business records, resolve disputes, satisfy contractual obligations, or comply with law. Customer-specific retention, return, and deletion requirements may also be defined in the applicable customer agreement.

You may contact Amexa.ai to request access to, correction of, or deletion of personal information Amexa.ai controls, subject to identity verification and legal or contractual requirements. If information is controlled by a business customer, that customer may be the appropriate decision-maker for the request.

Cookies, Analytics, and Children

The site may use storage or cookies needed for authentication, security, basic preferences, and operation, along with limited analytics used to understand product or website performance. Amexa.ai does not currently operate cross-site behavioral advertising pixels as part of the public website.

Amexa.ai is a business service and is not directed to children. We do not knowingly solicit personal information from children through the public website.

Policy Changes and Contact

We may update this policy as the website, services, integrations, or legal requirements evolve. The last-updated date identifies the current public version. Material changes affecting an active customer relationship may also be handled under the applicable customer agreement.

Questions, privacy requests, or security reports can be sent to privacy@amexa.ai.