Skip to content
inAmber

Privacy Policy

Last updated 27 July 2026

1. Who we are

inAmber is a trading name of Capitalizt Ltd (company number 16890768), registered at 128 City Road, London EC1V 2NX, United Kingdom. We are the data controller responsible for your personal data.

For anything to do with privacy, write to hello@inamber.ai.

2. What we collect

The least we can. Your name, your email address, and your account credentials. The messages you write, and any recordings, photographs or documents you add, are encrypted and stored encrypted. Section 4 explains exactly what that does and does not mean, including the one thing most services in this field are not straight about.

We also collect basic usage information, such as which pages are visited, so we can make the service better. Payment details are handled by our payment provider and we never store your full card details.

3. What we use it for

To run the service, to take payment, to tell recipients and guardians when something needs them, to let you know about changes, and to meet our legal obligations.

We do not sell, rent or share your personal data with anyone for marketing. Ever.

4. Encryption, said plainly

Every message is encrypted. Each message has its own key, and that key is itself encrypted with a master key that is held in our production environment and never stored in our database. If our database were ever copied, the contents would be unreadable.

The part other services are not straight about

inAmber is not zero knowledge, and this is not end to end encryption in the strict sense. We hold the master key, so we are technically able to decrypt your messages.

That is a deliberate decision, not a shortcut. The alternative is that a key lives only on your device, and when you die, so does every message you wrote. A service that cannot deliver a letter to your daughter twenty years from now is not a legacy service.

What we commit to instead: we do not read your messages, we do not analyse what is in them for advertising or for training models, access is restricted and logged, and a message is only ever decrypted when the person you named opens it, or when you open it yourself.

5. Where it is kept, and for how long

Your data is stored on servers within the European Economic Area. Messages are kept for the period your plan sets out, up to a maximum of twenty five years, and the exact term is fixed at the moment you buy. If we change our plans later, your terms do not change with them.

If we deliver a message and the person it was written for never comes to read it, we keep trying to reach them. We email when it arrives and again after a week, a month, three months, six months and ten months, and at six months we also ask the guardian to confirm or correct the address. We write once more before the end.

We delete a message only after the person it was for has not signed in at all for twelve months. Signing in is enough. A message you have chosen not to open yet is not at risk, however long you leave it: some messages are written to be kept unopened until the day you need them, and those are safe for as long as you keep coming back.

Account data is kept for as long as your account is open.

6. Children

Some of what people write here is for a child. A message left for a daughter to open on her eighteenth birthday, or for a grandchild who is nine now.

A person under eighteen may hold a free account in order to read what was left for them. They cannot open anything until an adult they have named confirms by email that they are happy for them to. We use eighteen everywhere, which is stricter than the law requires in the United Kingdom, because one conservative rule is right across every country we operate in.

For a young person we hold a declared date of birth and one adult’s name and email address. Nothing else. We do not profile children, we do not market to them, and a request to delete a child’s data is actioned straight away rather than at the end of any retention period.

7. Your rights

Under the General Data Protection Regulation and the UK Data Protection Act 2018 you may ask to see your data, correct it, delete it, restrict what we do with it, take it elsewhere, or object to us processing it. Write to hello@inamber.ai and we will act within thirty days.

There is more detail on your data rights.

8. Cookies

Essential ones only, for signing in and for security. No advertising, no tracking. See the cookie policy.

9. Changes to this policy

We may update this from time to time. If a change matters, we will email you about it rather than quietly changing the date at the top.