Fixpoint, Inc. Privacy Policy

Last Updated: June 18, 2026

This privacy notice for Amika – Fixpoint, Inc. ("Fixpoint", "we", "us", or "our") describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you visit our website at https://www.amika.dev/ or use the Amika product.

Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. If you have questions or concerns, please contact us at privacy@amika.dev.

1. What Information Do We Collect?

Personal information you disclose to us. We collect personal information that you voluntarily provide when you register on the Services or otherwise contact us. The personal information we collect may include names, email addresses, usernames, passwords, and contact or authentication data. We do not process sensitive personal information.

Information automatically collected. We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services. This information is primarily needed to maintain the security and operation of our Services and for our internal analytics and reporting purposes.

The information we collect includes:

2. How Do We Process Your Information?

We process your personal information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

3. When and With Whom Do We Share Your Personal Information?

We may share information in specific situations and with the following categories of third parties.

Vendors, consultants, and other third-party service providers. We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. The categories of third parties we may share personal information with are as follows:

We also may need to share your personal information in the following situations:

4. Analytics and Tracking Technologies

We use PostHog to understand website traffic and product usage.

Marketing website. PostHog starts in a privacy-conscious mode that only creates person profiles for identified users. You can reject analytics from the cookie banner, which opts the browser out of PostHog capture on the marketing website. If you decline, no analytics data is collected from your visit. You can change your preference at any time using the cookie banner.

Authenticated app. We use product analytics to understand onboarding, repository setup, sandbox creation, agent usage, and similar product workflows. These events are linked to your account and organization so we can operate, debug, secure, and improve the service.

We do not intentionally send prompt text, source code, secret values, raw logs, or full repository URLs to analytics providers.

Cookies and local storage. We use cookies and local storage for authentication, OAuth flows, saved preferences, and analytics consent. Some authentication cookies are necessary for the service to work. On the marketing website, we also use PostHog analytics cookies and local storage. You can opt out using the consent banner, or set your browser to remove or reject cookies (though this may affect certain features of the Services). Most web browsers are set to accept cookies by default; you can usually change this in your browser settings.

5. Session Replay

We use session replay to diagnose usability and reliability issues during onboarding. Session replay is active only on onboarding pages and is not enabled elsewhere in the authenticated app. All text input fields are masked in recordings so that passwords, tokens, and other typed values are never captured.

6. Is Your Information Transferred Internationally?

Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information, in the United States and other countries.

If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, these countries may not necessarily have data protection laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this privacy notice and applicable law.

7. How Long Do We Keep Your Information?

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us to keep your personal information for longer than twelve (12) months past the termination of the user's account.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), we will securely store your personal information and isolate it from any further processing until deletion is possible.

8. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. We cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. You should only access the Services within a secure environment.

9. Do We Collect Information from Minors?

We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at privacy@amika.dev.

10. What Are Your Privacy Rights?

Withdrawing your consent. If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the contact details in the "How Can You Contact Us?" section below. Please note that this will not affect the lawfulness of the processing before its withdrawal.

Opting out of marketing communications. You can unsubscribe from our marketing and promotional communications at any time by clicking the unsubscribe link in the emails we send, or by contacting us using the details provided below.

Account information. If you would like to review or change the information in your account or terminate your account, you can contact us using the contact information provided. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms, and/or comply with applicable legal requirements.

If you have questions or comments about your privacy rights, you may email us at privacy@amika.dev.

11. Controls for Do-Not-Track Features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.

12. Do United States Residents Have Specific Privacy Rights?

If you are a resident of California, Connecticut, Colorado, Utah, or Virginia, you are granted specific rights regarding access to your personal information.

California Residents

Under the California Consumer Privacy Act (CCPA), you have the following rights:

California Civil Code Section 1798.83 permits California residents to request, once per year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. To make such a request, please contact us at privacy@amika.dev.

If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us at privacy@amika.dev with the email address associated with your account and a statement that you reside in California.

Colorado, Connecticut, Utah, and Virginia Residents

Residents of Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Virginia (VCDPA) may have the following rights, subject to certain exceptions permitted by law:

To submit a request to exercise these rights, please email privacy@amika.dev. If we decline to take action regarding your request and you wish to appeal our decision, please email us at privacy@amika.dev. We will respond to appeals within the timeframes required by applicable law (generally 45–60 days).

Verification process. Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We may ask you to provide information so that we can match it with information you have previously provided us.

13. Do We Make Updates to This Notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. The updated version will be indicated by an updated "Last Updated" date and will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.

14. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may email us at privacy@amika.dev or contact us by post at:

Fixpoint, Inc.
169 Madison Ave STE 11506
New York, NY 10016
United States

15. How Can You Review, Update, or Delete the Data We Collect from You?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please contact us at privacy@amika.dev.