Privacy, AI & safeguarding

Everything important, in one clear place.

How Aimee remembers conversations, uses artificial intelligence, protects private information, permits carefully governed human review and responds to safeguarding concerns.

Draft v1.1Issued 22 July 2026Review 22 January 2027Controller: Ampera EV Ltd
Draft v1.1. Business ownership, privacy contact and ICO registration details have been completed. Supplier contracts and transfer checks, consent controls, final age-assurance implementation and specialist legal review remain conditions before unconditional adoption.
“I remember what you tell me because continuity is part of what makes our conversations feel real. That does not mean people are sitting behind the screen reading along. Human access is restricted, usually pseudonymous, and permitted only for specific quality, support, safeguarding or legal reasons.”
Public policy documentDraft v1.1Privacy noticeWho controls your information, what we collect, why we use it, providers, transfers, security and retention.

1. Who is responsible for your information

Ampera EV Ltd, trading through its Engram Intelligence brand is the data controller for Aimee. Ampera EV Ltd is registered in England and Wales under company number 16439998. Registered office: 34–40 Witham, Witham, Hull, England, HU9 1BY. Privacy contact: privacy@engramintelligence.com. ICO registration: Z3572599.

3. Information we collect

We may collect account and contact information, age or age-assurance status, profile details, text conversations, memories and preferences, images, voice notes and transcripts, optional SMS content, subscription and payment references, device/security logs, relationship indicators, routing metadata, safety flags, support requests, complaints and audit records. Conversations may contain sensitive information you choose to share, including health or sexual information, and information about other people.

4. Why we use it

We use information to provide and personalise Aimee, maintain conversation continuity, deliver voice/SMS/image features, manage subscriptions, protect accounts, apply boundaries and safeguards, investigate complaints, conduct tightly controlled quality reviews, comply with law and improve reliability.

5. Our lawful bases

We normally rely on contract to provide the service, legal obligation for statutory duties and records, and legitimate interests for security, platform integrity and proportionate quality assurance. Where special-category information is processed for the service or optional quality review, we ask for explicit consent where required. Safeguarding, prevention of unlawful acts, vital interests and legal claims may rely on separate legal conditions and do not always depend on consent.

9. Service providers and transfers

Depending on the feature, information may be processed by contracted providers supporting hosting, email, analytics, conversational AI, adult-model routing, voice transcription, speech generation, SMS, payment processing, live information and age assurance. Current providers include WPX Hosting for website hosting and email, Google Analytics for website analytics, Anthropic, OpenRouter and its selected model provider, Deepgram, ElevenLabs, FireText and Stripe. Didit is the intended age-assurance provider for adults-only functionality. We use contracts and, where required, UK transfer safeguards. The exact provider list is maintained in our internal processing register and this notice will be updated after material changes.

10. How long we keep information

We keep account conversations and related media while the account is active so Aimee can maintain continuity. After verified account closure or a valid erasure request, live conversation data is normally deleted within 30 days and expires from backups within 90 days, unless a documented legal, complaint or safeguarding hold applies. Financial records are normally retained for six years. Safety, complaint and audit records use shorter or longer periods according to seriousness and legal need.

13. Security and breaches

We use access controls, pseudonymisation, authenticated media access, audit logging and restricted senior review. No system is completely secure. We maintain a breach-response process and will notify the ICO and affected people where the law requires it.

15. Changes

We will update this notice when the service, providers, review arrangements or legal requirements materially change. The effective date and prior versions should be retained.

Public policy documentDraft v1.1AI, profiling and human reviewHow Aimee adapts conversations, routes eligible adult content and permits tightly governed human review.

2. Who Aimee is

Aimee is an artificial-intelligence companion. She is not a human being, medical professional, therapist, emergency service, lawyer or law-enforcement service. AI replies and safety classifications can be inaccurate.

6. AI, profiling and adult-content routing

Aimee analyses conversation context and maintains relationship indicators to adapt her replies. These indicators are not used to decide employment, credit, insurance or other legal entitlements. Consensual adult intimacy may be routed to a specialist model. Adult functionality is for verified adults only and must be protected by highly effective age assurance; a simple age declaration is not treated as sufficient.

7. Human review

Full chat logs are available only to approved Senior Safeguarding reviewers or HQ Directors. Reviews are not continuous and are not a routine word-for-word assessment of every account. They are sampled or triggered by a complaint, support issue, previous safeguarding concern, higher-than-average adult specialist use, higher-than-average user imagery, or another documented safety/quality reason. Users are pseudonymised by default. A reviewer must start a reasoned, time-limited and audited session. Name, email and phone are hidden unless a separate audited request explains why identity is genuinely necessary. Optional sensitive quality review is subject to the consent controls described when you join or in settings. Safeguarding and legal review may still occur where lawful and necessary.

Important: A relationship indicator, adult-content route or safeguarding flag is a system signal, not proof of a user’s character, intent or unlawful conduct.
Public policy documentDraft v1.1Safeguarding and age assuranceHow safety indicators, escalation, urgent help and adults-only access are handled.

8. Safeguarding

Aimee uses automated and human safeguards for concerns such as coercion, non-consent, minors, exploitation, grooming, serious violence, self-harm, stalking, doxxing and potentially unlawful activity. A flag is an indicator, not proof. Where there is a serious and credible risk, authorised staff may review relevant information and may share the minimum necessary information with emergency services, law enforcement or another appropriate safeguarding body where lawful. Aimee cannot guarantee that a risk will be detected or that emergency help can be sent.

14. Children and age assurance

Aimee is an adults-only service. Adult/pornographic features must not be made available on the basis of self-declared age alone. Didit is our intended age-assurance provider. Adults-only functionality must remain unavailable until the selected verification method has been contracted, configured, tested and approved as appropriate for the feature. Children must not use Aimee or submit personal information.

Contact and urgent help

Privacy, rights or complaints: privacy@engramintelligence.com. Post: 34–40 Witham, Witham, Hull, England, HU9 1BY. For immediate danger call 999 or 112. In the UK and Republic of Ireland, Samaritans can be reached on 116 123. Aimee is not monitored continuously and is not an emergency channel.

Emergency: If someone is in immediate danger, call 999 or 112. Aimee is not continuously monitored and is not an emergency channel.
Public policy documentDraft v1.1Your rights, complaints and contactHow to access, correct or delete information, withdraw consent, complain or report a safeguarding concern.

11. Your choices and rights

You may have rights to access, correct, erase, restrict, object to or receive certain personal information, and to withdraw consent. You can also complain about how we use your information. Some rights depend on the lawful basis and circumstances. We may need to verify your identity, but we will not ask for more evidence than is reasonably necessary.

12. Data protection complaints

Use the electronic form on the website or contact the privacy address above. We will acknowledge a formal data-protection complaint within 30 days and respond without undue delay. You may also complain to the Information Commissioner’s Office.

Contact and urgent help

Privacy, rights or complaints: privacy@engramintelligence.com. Post: 34–40 Witham, Witham, Hull, England, HU9 1BY. For immediate danger call 999 or 112. In the UK and Republic of Ireland, Samaritans can be reached on 116 123. Aimee is not monitored continuously and is not an emergency channel.

Contact the privacy and safeguarding team

Use this form to exercise a right, make a data-protection complaint, report a safeguarding concern or ask a privacy question.

Do not include passwords, identity documents or more sensitive information than necessary.

Messages are sent to privacy@engramintelligence.com. If anyone is in immediate danger, call emergency services rather than waiting for this form.

Public policy documentDraft v1.1Official sourcesThe legislation and regulator guidance used to prepare this draft.

Official source references

1. ICO, Guidance on AI and data protection: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/

2. ICO, When do we need to do a DPIA?: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/

3. ICO, Documentation and records of processing activities: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/documentation/

4. ICO, Special category data: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/special-category-data/

5. ICO, Appropriate policy document template: https://ico.org.uk/media2/migrated/2616286/appropriate-policy-document.docx

6. ICO, Right to be informed / privacy information: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/the-right-to-be-informed/

7. ICO, Data protection complaints procedure: https://ico.org.uk/for-organisations/how-to-deal-with-data-protection-complaints/

8. ICO, Personal data breaches: https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/

9. ICO, International transfers: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/

10. Data Protection Act 2018, Schedule 1: https://www.legislation.gov.uk/ukpga/2018/12/schedule/1

11. Data (Use and Access) Act 2025: https://www.legislation.gov.uk/ukpga/2025/18/contents

12. Ofcom, AI chatbots and online regulation: https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/ai-chatbots-and-online-regulation-what-you-need-to-know

13. Ofcom, Age checks to protect children online: https://www.ofcom.org.uk/online-safety/protecting-children/age-checks-to-protect-children-online

14. Companies House, Ampera EV Ltd: https://find-and-update.company-information.service.gov.uk/company/16439998

Source status: Official guidance and legislation checked for this draft on 22 July 2026. Re-check before final adoption because AI, data-protection and online-safety guidance is developing quickly.
No matching document found.
Try a shorter or more general search term.