AMPX Desktop — optional metrics and GDPR choices

In the desktop app, Settings → Privacy & metrics provides two independent optional categories. On first launch, terms and optional analytics are separate steps. Suggested choices do not enable collection: only the explicit Enable selected analytics action does. Continue without analytics is equally available. Expanded source-service and diagnostic-code collection require renewed consent. Consent is used to improve application reliability and understand platform usage. Licensing and necessary service/security processing are separate and do not depend on these choices.

Each category uses a separate random installation identifier and authentication secret. AmpX stores the identifier, a hash of the secret, consent version, receipt/last-seen timestamps and conversion batch IDs for deduplication. These records are pseudonymous, not anonymous. No content URLs, titles, file names, file contents, account/license identifiers, hardware serial numbers, cookies, error messages or stack traces are included. Network infrastructure necessarily processes connection addresses; those are not stored in the desktop metrics tables.

Metrics go directly to the configured AmpX core (development builds to development, production builds to production) and our application database. They are visible to authorized dashboard administrators. They are not sent to a third-party analytics SDK or sold.

Current retention: 3 calendar months (default 3). The administrator can configure 1–36 months in PHP / Backend settings. Expired metric batches, inactive installation records and legacy aggregates are removed by hourly maintenance. Repeated activity does not extend the lifetime of old conversion batches. No longer-lived conversion aggregate is created after expiration.

Turning an option off immediately stops new collection for that category and requests deletion from our live database. If offline, the app retains the deletion credential and retries on next launch; Settings also provides Retry server deletion. A request already in flight may finish before the deletion request. Unsent conversion events are held only in a bounded in-memory queue and are not replayed from download history; unavailable network/service requests can be lost. Consent and deletion credentials use the operating system's secure storage. Removing the app's secure storage can remove the credential needed to identify these pseudonymous records; the retention window still applies.

For access, portability or other GDPR requests, contact the privacy address listed on this page. Desktop metrics are separate from account exports because they are not linked to your account. The authenticated desktop metrics endpoint supports access and deletion using the installation credential; never send your authentication secret in a support message. Website cookie consent does not enable desktop metrics.

With conversion analytics enabled, fixed diagnostic error codes (such as Spotify audio authorization failures) are included after you accept the updated analytics choice. Raw errors, URLs, media identifiers and credentials are never included.

Coming soon and availability notifications

Opening an interest form does not register a demand signal. Submitting your email registers interest in that specific feature and permits availability notifications about it, not unrelated marketing. We store the normalized email, feature identifier, signup time, website host and a deduplication hash. New registrations do not store submitted content URLs or IP addresses in the waitlist. Historical records may contain previously collected fields. Repeat registrations for the same feature count once. Authorized administrators can review/export these registrations. Each availability email includes a scoped unsubscribe link. Contact the privacy address on this page to withdraw or request deletion.

Optional email updates

Registered AMPX accounts can be selected for account-wide news, offers and calls to action without a separate marketing opt-in. Account → Privacy → Email updates lets you opt out. Saved opt-outs and unsubscribed addresses are excluded from account-wide campaigns, including campaigns targeting explicit marketing subscribers. Feature demand signups permit notifications for that feature only. Essential account and security messages do not depend on marketing consent.

Our database stores your email, recipient name, consent time, subscription scope, queued campaign and delivery status. We recheck account eligibility, preferences and feature subscriptions before sending and include an unsubscribe link. Withdrawal stops pending messages; an email already being sent may still arrive. The mailer adds no open pixels or click tracking and does not collect content/download URLs. Loading an email image can contact the server hosting that image.

Recipient details in processed campaign history are removed after 90 days (default 90; configurable 1–365). Queued recipient details remain until processed or cancelled. Aggregate campaign counts remain without recipient details. Subscriptions remain until withdrawn; minimal email and scope suppression records remain to honor withdrawal. Mail is processed by AMPX and its configured mail delivery provider. Account data export includes email preferences and retained delivery history; account erasure removes these records. Contact the privacy address for feature-only subscriptions or other rights requests.

Política de Privacidad

AM4A trata únicamente la información necesaria para prestar, proteger y mejorar el servicio solicitado. Este aviso explica el tratamiento y cómo ejercer tus derechos.

Datos que tratamos

Puede incluir la dirección IP y metadatos de la solicitud, identificadores de sesión y seguridad, URL o archivos enviados, opciones de conversión, datos temporales de tareas, registros de estado y errores e información enviada a soporte.

Finalidades, bases legales y destinatarios

Tratamos datos para prestar el servicio, protegerlo y evitar abusos, cumplir obligaciones legales y—con tu consentimiento—medir análisis opcionales. Los proveedores de alojamiento, almacenamiento, procesos, supervisión y análisis acceden solo cuando es necesario. No vendemos datos personales.

Configuración de cookies y privacidad

AM4A — Usamos almacenamiento necesario para operar y proteger el servicio. Cuando está disponible, el análisis opcional solo se carga con tu permiso. Puedes cambiar tu elección en cualquier momento. Detalles sobre cookies y privacidad

Conservación y transferencias

Los archivos temporales y datos de tareas se conservan solo por necesidades operativas, de seguridad y diagnóstico, y después se eliminan o anonimizan. Los proveedores pueden tratar datos fuera de tu país con las garantías aplicables.

Tus derechos

Según tu ubicación, puedes solicitar acceso, rectificación, supresión, limitación, oposición o portabilidad, retirar el consentimiento y reclamar ante la autoridad de protección de datos competente.

Contacto

Para solicitudes de privacidad escribe a ytam4a@gmail.com. Indica el servicio y la información necesaria; no envíes contraseñas ni datos sensibles innecesarios.

Última actualización: 2026-09-20

Site status Checking...