Privacy Policy
Last updated: 15 September 2026
In short
- Amana is a place to keep your family's important documents: passports, policies, certificates, records. You decide what to save, who else can see it, and you can take it all back at any time.
- We do not sell your data. We do not show you adverts. We do not share anything with anyone for marketing.
- We do not read your documents. But we should be honest that we technically could today, and section 8 explains exactly why, and what we are doing about it.
- You can delete everything, at any time, and we will actually delete it.
- If you share your vault with a Helper, a family member or friend you trust, only you decide who, and you can stop it instantly.
The rest of this policy is the detail. If you only read one section, read section 8.
1. Who we are
Amana is provided by Tessera42 Ltd, a company registered in England and Wales, company number 17405769, registered office Suite RA01, 195-197 Wood Street, London, E17 3NU, United Kingdom.
We are the data controller for the information described in this policy. That means we decide how and why it is used, and we are responsible for it.
We are registered with the UK Information Commissioner's Office (ICO), registration reference ZC234594.
Privacy questions and rights requests: privacy@myamana.app
Everything else: support@myamana.app
We are a very small company. There is no legal requirement for us to appoint a Data Protection Officer, and we have not appointed one. Privacy questions go to the address above.
2. Who this applies to
This policy applies to everyone who uses Amana, wherever you live. It also applies to anyone who opens a link to a document that an Amana user has shared with them, even without an account. Section 9.7 is written for you.
Amana is currently in closed beta with testers in several countries. Rather than vary your protection depending on where you happen to be, we apply one standard to everybody, based on UK and EU data protection law. This is the strictest of the standards our current testers are subject to, and the most defensible. If your local law gives you rights beyond the ones described here, those rights still apply, and you can contact us to use them.
You must be 18 or over to hold an Amana account. Amana is not designed for children and we do not knowingly collect information about anyone under 18. If you believe a child has created an account, tell us and we will remove it.
3. What we collect
We collect three kinds of information. Nothing else.
3.1 Your account
What / Why we need it
- Your first name
- So the app can address you, and so a Helper you invite knows who invited them
- Your email address
- To sign you in, to send you the emails described in section 7, and to be able to reach you
- Your password
- Stored only as a one-way cryptographic hash. We never store the password itself and cannot recover it or see it.
- A paper recovery code we generate for you at signup
- We store a digest of it, not the code itself
Amana does not currently process any payments. There is no paid plan, no payment processor connected, and no card details collected today. If a paid plan launches in future, this section will be updated before that happens, naming the processor and exactly what it holds.
3.2 What you put in your vault
This is the part that matters most to you, so here it is in full.
What / Notes
- The files you upload
- Photos, scans and PDFs. Whatever you choose to save.
- The title you give each document
- Any notes you write
- The category you file it under
- Family, Finance, Property, Insurance, Legal, Contacts or Medical
- Details you type in about the document, such as an issue or expiry date, who issued it, and a note about where the paper original is kept
- We can read these, and we need to, so we can remind you before something expires. See section 8.2.
- Details you type in that are locked on your device first, such as a reference number, policy number, sort code or date of birth
- These are sealed on your phone or in your browser before they reach us, and our servers cannot open them. Which of them you are asked for depends on the category. See section 8.1.
Amana does not read your documents. Every detail above is one you type in yourself. We do not scan, transcribe or pull anything out of the file you upload: there is no character recognition and no AI reading your files. Section 8.4 describes what is decided and not built here, and we will update it before any of that ships, not after.
We do not store the original filename of the file on your device. It is replaced with an opaque internal reference the moment you upload, so a filename that might reveal something sensitive never reaches our systems in the first place.
3.3 Helper relationships
If you invite a Helper, someone you trust to have read-only access to your vault, we store who they are, what they can see, and when that access was granted or changed.
3.4 Technical and security information
What / Why
- Your IP address and browser or device type, each time you sign in
- To keep the account secure and to spot someone signing in who should not be
- An activity log of actions taken in your vault
- So you can see what happened in your own vault, especially if you have given a Helper access
- Basic error logs
- So we can fix things when they break
Our activity log records what happened, when, and who did it. It does not record the contents of your documents. A Helper's own account activity outside your vault, such as resetting their own password, is not included, because this log exists for your oversight of your vault, not surveillance of the person helping you.
3.5 Waitlist
If you join the coming-soon waitlist before you have an Amana account, we collect only the information in the table below.
What / Why
- Your email address
- So we can confirm you asked to join, and so we can email you when a beta invite is ready
- Your language preference
- So waitlist emails arrive in a language you can read
The lawful basis is consent. You tick a box on the waitlist form before we store anything. We send a confirmation email; your address stays unconfirmed until you open that link.
Unconfirmed waitlist records are deleted after 30 days. Confirmed records stay until you unsubscribe, or until we no longer need them to run the beta waitlist.
Every waitlist email includes an unsubscribe link. You can also open the unsubscribe link from the confirmation or invite email at any time. After you unsubscribe we will not send you further waitlist or beta-invite mail.
We do not sell waitlist addresses, and we do not use them for advertising.
4. What we do not collect
We think this list is as important as the one above.
- No tracking cookies beyond the two described in section 5, no advertising pixels, no session recording, and nothing that follows you to other websites. Our web pages load no third-party code at all. We do use one analytics tool, PostHog, to count a small number of things about how the app is used, described in section 5. It never sees your documents, your name or your email address, and you can switch it off at any time.
- No location data.
- No contacts, photo library, calendar or other data from your phone, beyond the specific file you choose to upload.
- No payment or card details. See section 3.1.
- No data bought from, or shared with, data brokers, advertisers or marketing companies. Ever. This is a commitment, not a current-policy statement that might change quietly. If it ever changed, we would tell you and give you the chance to leave first.
5. Cookies and similar technology
Amana puts two small pieces of information on your phone or computer. Both are needed for the app to work at all, which is why there is no cookie banner.
What / Why / How long it stays
- A sign-in cookie
- Keeps you signed in, so you are not typing your password on every screen
- Until you sign out, or 90 days after you last used Amana
- A security cookie
- Stops another website making requests to Amana while pretending to be you
- Until you close the app or browser
Neither contains your documents, your name or your email address. The sign-in cookie is a reference number that means nothing to anyone except our server.
If you use the iPhone app and turn on Face ID or Touch ID to unlock Amana, the app remembers that choice on your phone. That setting never leaves your device, and it is off unless you switch it on. It unlocks your existing session on that device; it does not replace or act as your Amana account login.
That is the complete list of what Amana itself puts on your device. Nothing for advertising, and nothing that follows you to other websites.
Usage insights, and how to turn them off.
We would like to know whether Amana actually works: how many people finish signing up, how long it takes to save a first document, whether a Helper can find something when it matters. To measure that we use PostHog, an analytics service whose European servers are in Germany.
What PostHog receives is a random reference number that identifies your account to us and to nobody else, the name of the thing that happened (for example "saved a first item"), and a small number of measurements such as how many seconds something took, or the 0 to 10 score if you answer our feedback question. It never receives your name, your email address, your documents, or anything you type, including the comment box on our feedback questions, which comes to us by email instead. It does not receive your IP address or your location.
This is on unless you turn it off, and you can turn it off at any time in Settings, under "Privacy and consent". It stops immediately, we do not ask why, and nothing else in the app changes. We rely on our legitimate interest in knowing whether the product works, and we have weighed that against your privacy: the data is small, it is not linked to your name or your email, it is never used to advertise to you and never used to make any decision about you.
No analytics code runs in these pages, and PostHog puts nothing on your phone or computer. That is why there is still no cookie banner: the two cookies above remain the only things Amana stores on your device.
(An earlier version of this policy said we used no analytics tool, and promised to update this section before introducing one. We started using PostHog on 4 September 2026 and did not update this section at the time. That was our mistake, and this paragraph is the correction rather than a quiet rewrite.)
6. Sensitive documents
Amana has a Medical category. People use products like this for hospital letters, prescriptions, insurance claims, passports and immigration papers. Some of that is what the law calls "special category data": information about your health, your ethnic origin, your religion, or similar. The law gives it extra protection, and rightly so.
Two things follow from that.
First, we ask for your explicit consent, separately from anything else, before you can store this kind of document with us. That consent is the legal basis on which we hold it (UK GDPR Article 9(2)(a)). It is a real choice, it is not bundled with anything else, and you can withdraw it at any time in Settings. If you withdraw it, every document in your Medical category is deleted immediately, including anything in your Trash. This cannot be undone, and we tell you this before you consent, not after.
Second, you choose document by document whether something goes in your Medical category. Nothing is filed there automatically.
A note about other people's documents. Many people use Amana to keep documents belonging to a parent, a partner or a child: someone else's medical letter, someone else's passport. That is a normal and expected use of the product. If you are doing this purely for your own family and household, data protection law generally treats it as a personal or household activity and does not put legal duties on you. Please think about it anyway: save what you genuinely need, tell the person if you reasonably can, and delete it when it is no longer needed. If you are doing this in a professional capacity, for example as a carer, an adviser, or an attorney acting under a power of attorney, you may have your own legal responsibilities and should take your own advice.
7. Why we are allowed to use your information
Data protection law requires a specific legal reason, a lawful basis, for everything we do with your information. Here is ours, in full.
What we do / Why / Legal basis
- Create and run your account
- You asked us to
- Contract, Article 6(1)(b)
- Store your documents, titles, notes, categories and reminders
- That is the service
- Contract, Article 6(1)(b)
- Store sensitive documents within that
- Same, plus the extra permission the law requires
- Contract, Article 6(1)(b), and explicit consent, Article 9(2)(a)
- Run the Helper feature, and let you revoke access at any time
- You asked us to share with a specific person
- Contract, Article 6(1)(b)
- Send you account and security emails
- Necessary to operate the account
- Contract, Article 6(1)(b)
- Record IP address, device type and sign-in records
- To keep your account secure and detect misuse
- Legitimate interests, Article 6(1)(f)
- Keep an activity log of your vault
- You are entitled to see who did what in your own vault, and we need it to investigate problems
- Contract, Article 6(1)(b), and legitimate interests, Article 6(1)(f)
- Respond to you when you contact us
- Contract or legitimate interests, depending on what you're contacting us about
- Ask for and act on your beta feedback
- To make the product work better
- Legitimate interests, Article 6(1)(f)
- Count a small number of things about how the app is used, unless you switch usage insights off
- To find out whether the product actually works
- Legitimate interests, Article 6(1)(f)
- Meet our legal obligations
- Where the law requires it of us
- Legal obligation, Article 6(1)(c)
- Send you a push alert for a small number of security events, on devices where you've allowed it
- In your own interest, as a second channel alongside email
- Legitimate interests, Article 6(1)(f)
- Record each time a document shared by link is opened
- So there is a reliable record of when a shared document was opened
- Legitimate interests, Article 6(1)(f)
- Count that a shared file was opened, and how long it took
- To find out whether sharing works
- Legitimate interests, Article 6(1)(f)
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it is proportionate. In each case the purpose is security, integrity or basic product improvement, none of it involves profiling you, and none of it is used to make automated decisions about you. You can object to any of it: see section 12.
We do not use your information for advertising, and we do not sell it. This will never change.
8. What our encryption does and does not do
Everything travelling between your device and us goes over an encrypted connection (TLS), on every page.
Beyond that, your vault holds three different kinds of information, and each one is protected differently. Here is each of them, what is true in the app today, and where the limits are.
8.1 The details you fill in on a page
This is how Amana works today.
Some of the details you type onto a document page are locked on your own device before they reach us:
- Holder name
- Reference number
- Policy number
- Account number, the last digits
- Sort code
- Date of birth
- Property address
- Contact name
- Phone number
Which of these you see depends on the category you filed the document under. They are locked using the cryptography built into your phone or your browser (AES-256-GCM), and they arrive at our servers as a single block of ciphertext. We store that block and hand it back to your device when you open the page. Our servers cannot open it. If a device tries to save one of those details as ordinary readable text instead, our server refuses it.
Where the key is. Your device creates a random key for your vault and never sends it to us. What we hold are two locked copies of that key: one your password opens, and one your paper recovery code opens. Both are locked the same way as your details, and we cannot open either.
The limit, said plainly. When you sign in, your password travels to us so we can check it, and your password is also what opens your key on your device. We keep your password only as a one-way scramble that cannot be turned back into the password itself, and we store neither the password nor your key. So the accurate statement is that we do not hold your key and Amana is not built to collect it. It is not that anyone running the service would find it impossible to change that. We would rather you hold us to a promise you can understand than trust a claim you cannot check.
In a web browser your key is held inside that browser tab while you are signed in, and it is gone when the tab closes. Open the same page on a device that does not have your key and these details show as dots.
Helpers do not see these details. A Helper opening your vault, and anyone you send a share link to, does not get your key, so these fields do not appear for them at all.
8.2 The information around your documents
This is how Amana works today.
The title of each page, your notes, the document type, the issuer or provider, the category and the name on your account are encrypted inside our database, and Amana holds those keys. Dates such as an expiry date or an issue date, and your note about where the paper original is kept, are stored as ordinary fields in that same database, which is encrypted at rest and is not reachable from the public internet.
We can read all of this, and we need to. It is what lets us remind you before your passport expires, sort your vault by category, and let a Helper find the right paperwork.
8.3 The document files themselves
This is how Amana works today. It is the part where Amana still holds the ability to open your data.
Your files are stored in Cloudflare's storage, encrypted at rest by Cloudflare, and are not publicly reachable. Amana has the technical ability to open them. Locking a policy number does not lock a photograph of the policy that shows the same number, and a Helper or someone holding a share link can open the file.
We do not read your documents. We would only ever access the contents of your vault if you asked us to in order to fix a problem, or if we were required to by law. If that ever happens for any reason other than your own request, we will tell you.
8.4 What is decided but not yet built
Two further protections are decided and not built. They are not running today, and we are not claiming them.
- Locking your document files with a key kept offline, away from the running service, so the service itself could not open them. Decided. No such key exists in the system today.
- Reading your document on your device, removing the identifiers we can recognise before any text leaves it, and keeping only a masked copy so you can search inside your documents. Decided. Today Amana does not read the text of your documents at all: there is no text extraction, no character recognition, and no AI reading your files.
We will rewrite this section on the day each of those goes live, and not before. That has been our rule from the start and it has not changed.
No method of storing or transmitting information is completely without risk, and we will always tell you plainly what is and is not protected, rather than imply more than is true.
9. How we share your information
We do not sell your information, ever. We share it only in these situations.
9.1 With your Helpers
Inviting someone as a Helper gives them read-only access to your full vault, every category, not selected items or documents. Item and category-level sharing is a planned feature, not yet built. You can revoke a Helper's access instantly, at any time, from within the app. Revoking access is immediate and unilateral; it does not require the Helper's agreement.
9.2 With service providers who help us run Amana
We work with a small number of providers under contract, each restricted to using your information only to provide their specific service to us.
Provider / What they do / Where
- Supabase
- Database hosting
- Frankfurt, Germany (EU)
- Cloudflare (R2)
- File storage, with a jurisdictional restriction locking data to the EU
- EU
- Cloudflare
- Also sits on the network path as our content delivery and TLS termination layer for all traffic, wherever the nearest edge happens to be
- Global edge network, observed for Amana traffic in London
- Render
- Application hosting
- Frankfurt, Germany (EU)
- Resend
- Transactional email (account and security emails only)
- EU processing region
- PostHog
- Usage insights, unless you have switched them off. Counts of things that happened, tied to a random reference number, never to your name or email
- EU servers in Germany
Data processing agreements with Supabase, Cloudflare, Render, Resend and PostHog are in place. For Supabase, Cloudflare, Render and Resend these form part of the standard terms we accept when using the service; with PostHog we have a separate signed agreement. We do not currently have any payment processor, so there is nothing to disclose there yet; see section 3.1.
9.3 With Apple
If you join our closed beta through TestFlight, Apple receives your email address to send you the invitation, and collects its own installation and crash information from the TestFlight app. Apple acts as an independent controller for this, under its own privacy policy and terms, which you agree to separately when you join TestFlight. This is outside our control and outside the data processing agreements described above.
9.4 If required by law
We may disclose information if legally required to, such as in response to a valid court order, or where necessary to protect someone's life or safety. We will tell you if that ever happens, unless we are legally prohibited from doing so.
9.5 If Amana is acquired or merged
If this happens, your information may transfer as part of that transaction. We will tell you before this affects you.
9.6 With Apple, for security notifications
If you've turned on notifications, we register your device with Apple's push notification service (APNs) so we can alert you about a small number of security events, for example a password change or someone starting to help you recover your account. Apple delivers the alert; the alert itself carries no content by design, only a device token and the timing, except that it may name a Helper by their first name. This is separate from the account and crash information Apple collects if you join our TestFlight beta, described in 9.3. You can turn push alerts off at any time in Settings, or by disabling notifications for Amana in your phone's settings.
9.7 Sharing a document by link, and if someone sent you one
You can send one document to someone who does not have Amana by creating a link. The link works for anyone who has it until it runs out, which is one month at most, or until you cancel it under "What You've Shared". Treat it like a key: if it is forwarded, whoever receives it can open that document too. We cannot tell who opened it, only that it was opened.
If someone sent you a link. You do not need an account, and this section is the part of this policy that applies to you. Tessera42 Ltd, named in section 1, is responsible for the information described here.
Each time the link is opened, we record the time, the type of browser or device you used, and a network address. At the moment that address belongs to Cloudflare, the network provider that passes your request on to us, not to you. We keep this record for 24 months, or less if the person who shared the link deletes their account, and it cannot be changed in the meantime. It exists so there is a reliable record of when a shared document was opened, and we rely on our legitimate interest in keeping one (Article 6(1)(f)).
The document is delivered to your browser from Cloudflare's storage, which receives your IP address in order to send it to you. We also count that the file was opened and how long it took to load, using PostHog (see section 5). That count is tied to the link, not to you, and PostHog does not receive your IP address. The usage insights setting of the person who shared the link does not currently switch this count off.
We do not learn your name or email address from you opening the link, and we never use any of this to contact you, follow you elsewhere or advertise to you. If you are signed in to your own Amana account when you open it, the visit is recorded against your account like your other activity.
You have the rights in section 12, including the right to object. Email us at the address in section 18. Because we hold nothing that identifies you, we may need you to tell us which link it was and roughly when you opened it.
10. Where your information is stored
Your data is stored and processed within the European Economic Area: Frankfurt, Germany for our database and application hosting, and the EU for file storage. We do not currently transfer your information outside the UK or the EEA on a routine basis.
One honest exception. Cloudflare, our content delivery and security layer, terminates encrypted connections at whichever of its edge locations is nearest to you, which for our testers has been observed to be London. Traffic is decrypted briefly at that edge before being re-encrypted and forwarded to our Frankfurt servers. This is normal for how content delivery networks work, and London is within the UK, so this does not take your data outside the UK or EEA. We are disclosing it because it is a genuine step in the path your data takes, and we would rather tell you than let "EU residency" imply a single unbroken pipe that does not quite exist.
All four of our providers are headquartered in the United States, though your data itself rests in Europe as described above. Their support and engineering staff may occasionally need access from outside Europe to fix a problem. Where that counts in law as an international transfer, we protect it using the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as appropriate, with each provider.
If you are using Amana from outside the UK or EEA, for example from the UAE, Algeria, Venezuela or Chile, your information still travels to and is stored in Europe as described above, and this policy still applies to you in full.
11. How long we keep your information
What / How long
- Your account and everything in your vault
- Until you delete your account
- A deleted account
- 30 days, then permanently erased. This gives you a window to change your mind.
- A document you put in the Trash
- 30 days on paid plans, 7 days on the Free plan, then permanently erased. You can permanently delete it yourself at any time before that.
- Medical category documents, if you withdraw consent
- Deleted immediately, including anything in Trash. This overrides the row above.
- An unaccepted Helper invitation
- 7 days, then it expires
- Your sign-in records
- Until you sign out or delete your account
- Activity log entries
- 24 months, then permanently deleted. This covers your own activity, your Helper's activity in your vault, and each time a link you shared was opened. If your account is permanently erased, the network address and device type are removed from these entries at that point.
- A link you shared
- Stops working when it runs out or you cancel it. The record that it existed is kept until the document is permanently deleted.
Everything above is genuinely deleted on a nightly automated run. It is not a flag in a database that hides your data from you while we keep it.
12. Your rights
You have the following rights over your information, from UK and EU data protection law, extended to every Amana user wherever you live.
- See it. Ask for a copy of everything we hold about you.
- Correct it. Have anything inaccurate fixed.
- Delete it. Have it erased. You can do this yourself at any time in Settings, without asking us or giving a reason.
- Take it elsewhere. Get your data in a portable format so you can move it to another service.
- Restrict it. Ask us to stop using it while a dispute or a correction is sorted out.
- Object. Object to anything we do on the basis of legitimate interests.
- Withdraw consent. Withdraw your consent to storing sensitive documents at any time, in Settings. Withdrawing it does not make anything we did beforehand unlawful.
To use any of these, email privacy@myamana.app. We will respond within one month. It is free, unless a request is genuinely excessive or repetitive, in which case we may charge a reasonable fee or decline it and explain why.
If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to a regulator without coming to us at all. In the UK that is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk, 0303 123 1113. If you live elsewhere in the EEA you may complain to your own national supervisory authority. If you live outside the UK and EEA you may complain to your local regulator where one exists, and you may still complain to the ICO because we are established in the UK.
Separately, and more immediately: revoking a Helper's access is something you can do yourself, instantly, inside the app, without waiting on us at all.
13. Helpers: sharing your vault in full
Because inviting a Helper means someone else sees your information, here is exactly how it works.
Nothing is shared unless you invite them. There is no default sharing, no automatic sharing, and no way for anyone to request access to your vault without you starting it.
What a Helper can see: the documents in your vault, their titles, notes and categories. That is read-only. A Helper cannot edit, delete or add anything, and cannot invite anyone else.
What you can see: every action your Helper takes in your vault appears in your activity log. You will know what they looked at and when.
What your Helper knows about you: their invitation carries your first name, so they know who invited them.
What you know about your Helper: their email address, and the dates the invitation was sent, accepted or ended.
You can end it instantly. Revoking a Helper's access takes effect immediately, needs no reason, and does not require their agreement. Both of you get an email confirming it.
If you are the Helper, the vault owner sees your activity in their vault. You have your own Amana account and your own vault, entirely separate from theirs, and they cannot see anything in yours.
14. Automated decisions and AI
Amana does not currently use AI to make decisions about your documents, sort them, or act on them without your review. We do not profile you, and no algorithm decides anything about your account. If this changes in future updates, any such feature will always require your review before anything is filed, extracted or shared automatically. Nothing happens silently, and we will update this section before any such feature ships, not after.
15. Keeping your information safe
- Everything travels over an encrypted connection (TLS), enforced for every page.
- Passwords are stored as one-way hashes and must meet a minimum length.
- Sensitive details such as reference numbers, policy numbers, sort codes, dates of birth and addresses are locked on your own device, and our servers cannot open them. See section 8.
- Document titles, notes, types, issuers and categories are encrypted in the database using keys Amana holds, as described in section 8.
- Files are stored separately from the database, in Cloudflare's storage, and are not publicly reachable.
- Access to the production system is tightly restricted.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If there is a data breach that puts your rights or freedoms at risk, we will tell you directly and without undue delay, and we will report it to the ICO within 72 hours as the law requires.
You can help: use a long, unique password that you do not use anywhere else, and consider a password manager. Amana is not a password manager and will never ask you to store passwords in it.
16. This is a beta
Amana is currently in closed testing. Two things to be aware of.
It may break. Beta software has bugs. Features may change or disappear. Please keep your own copy of anything you cannot afford to lose, and do not treat Amana as your only copy of an important document during the beta.
Your data will not be deleted at the end of the beta. If Amana launches properly, your account and documents carry over. If we ever had to shut the service down, we would give you at least 30 days' notice and a way to download everything first. We would not delete your documents without warning you.
This policy itself is a beta document. It has been written by us to be accurate and complete under UK and EU GDPR, and will be reviewed by a qualified adviser before Amana leaves beta. If we identify anything in it that needs correcting in the meantime, we will fix it and update the date at the top.
17. Changes to this policy
If we change this policy in a way that materially affects you, we will email you before it takes effect and give you time to read it. Minor corrections, such as fixing a typo or clarifying wording, we will just make, and the "last updated" date above will change.
We will never quietly reduce your protections. If we ever wanted to use your data for something genuinely new, we would ask you first.
18. Contact
Privacy questions and rights requests: privacy@myamana.app
Everything else: support@myamana.app
Post: Tessera42 Ltd, Suite RA01, 195-197 Wood Street, London, E17 3NU, United Kingdom
Regulator: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. ico.org.uk. 0303 123 1113.