1. Introduction and scope
Performm is operated by Amove Technologies Inc, a Delaware corporation ("Amove," "we," "our," or "us"). This Privacy Policy describes how Amove collects, uses, discloses, retains, and protects personal data in connection with the following (the "Services"):
- our websites, including https://amove.io and the Performm website (the "Sites");
- Performm, including its web interface, desktop applications and virtual drive extensions for macOS, Windows, and Linux, command line tools, SDKs, APIs, and MCP server;
- the tools delivered through Performm, including Access, AI Search, Edit, Transfer, Sync, Collaborate, Migrate, and Archive;
- Editfly storage;
- beta programs, support, events, and marketing communications that link to this Privacy Policy.
This Privacy Policy does not apply to:
- Customer Content we process on behalf of a Customer, which is governed by the Customer's agreement with Amove, including any data processing addendum;
- Amove software that a Customer, licensee, or partner installs, hosts, or operates in its own environment or under its own brand;
- storage providers, identity providers, AI clients, and other third-party services you connect to the Services.
If this Privacy Policy conflicts with a signed agreement between Amove and a Customer, the signed agreement controls as to that Customer. By using the Services you acknowledge the processing described here. Where the law requires consent, we ask for it separately and do not treat this acknowledgment as consent.
2. Definitions
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable individual, including "personal information" and similar terms under applicable law. Excludes information that is deidentified or aggregated in accordance with law. |
| Customer | The organization or individual that agrees to the Performm User Agreement or another agreement with Amove for the Services. |
| Authorized User | An individual the Customer permits to use the Services, including employees, contractors, freelancers, guests, and share-link recipients. |
| Customer Content | All files, objects, data, file names, paths, metadata, and other content processed through the Services, whether in Editfly storage or Connected Storage, including Input, Output, and derived data such as thumbnails, search embeddings, and transfer logs. |
| Connected Storage | Storage not operated by Amove that you connect to the Services, such as Amazon S3, Azure Blob Storage, Google Cloud Storage, Wasabi, Backblaze B2, Dropbox, Box, other S3-compatible storage, and on-premises storage. |
| Credentials | Access keys, secret keys, OAuth tokens, API tokens, passwords, and other secrets used to access Connected Storage or the Services. |
| AI Features | Features that use AI or machine learning models, including AI Search and access through the MCP server. |
| Input and Output | Input is data submitted to an AI Feature. Output is what an AI Feature returns. |
| Service Data | Account, billing, usage, device, log, and support data relating to the operation of the Services. Excludes Customer Content. |
| Subprocessor | A third party Amove engages to process Customer Content on Amove's behalf. |
3. Our role
| Data | Amove's role |
|---|---|
| Site visitor data, account registration, billing, marketing, sales inquiries, support communications, job applications, and Service Data | Controller under the GDPR and UK GDPR; "business" under US state privacy laws |
| Customer Content, including personal data in files, metadata, Input, and Output | Processor under the GDPR and UK GDPR; "service provider" or "contractor" under US state privacy laws |
When we act as a processor, we process Customer Content only on the Customer's instructions. We do not sell it, share it for advertising, combine it with other personal data for our own purposes, or use it outside our relationship with the Customer. The Customer is responsible for having a lawful basis for Customer Content and for any notices and consents it requires, including from people who appear in footage, images, audio, or documents.
Where Amove hosts the Services for a reseller, OEM, or white-label partner that serves its own customers, Amove acts as a sub-processor to that partner, and the partner's privacy notice governs its customers' data.
If you use the Services as an Authorized User, your organization controls your account and may access your account data, activity logs, and the content you store. Direct requests about Customer Content to your organization. If we receive one, we will forward it to the Customer and will not respond directly unless the Customer authorizes us or the law requires it.
4. Personal data we collect
We collect only the personal data needed for the purposes in Section 7. Where you must provide data, we say so when we collect it. If you do not, we may be unable to provide some or all of the Services.
4.1 Data you provide
| Category | Examples | Required? |
|---|---|---|
| Account and profile | Name, business email, username, password (stored as a salted hash), organization, role, settings, MFA enrollment | Yes, to create an account |
| Billing contacts | Billing name, address, tax ID, purchase orders, invoices | Yes, for paid plans |
| Payment | Card or bank details, collected directly by our payment processor, Stripe. We receive only card brand, last four digits, expiration date, billing postal code, and payment status. | Yes, for paid plans |
| Credentials | Keys and tokens you enter to connect Connected Storage or other services | Yes, to use Connected Storage |
| Support and communications | Messages, call notes, screenshots, log files, and attachments you send us | No |
| Marketing and events | Email address, preferences, event registrations, survey and feedback responses, beta applications | No |
| Sales and partner inquiries | Name, business contact details, company, inquiry details | No |
| Careers | Resume, employment and education history, references, work authorization | Required to be considered |
We do not request sensitive personal data, such as government ID numbers, health data, or demographic characteristics, in account, support, or marketing forms. Please do not include it in support requests.
4.2 Data collected automatically
| Category | Examples |
|---|---|
| Device and client | IP address, device type, operating system, client version, browser type, language, and device identifiers used for license enforcement and security |
| Usage and activity | Sign-ins, features used, settings changes, API and MCP calls, timestamps, and the user who performed each action |
| File operation metadata | File and folder names, paths, sizes, types, and timestamps of operations. We treat this metadata as Customer Content. |
| Performance and diagnostics | Throughput, latency, error codes, and crash reports. Any file paths or content in diagnostics are treated as Customer Content. |
| Approximate location | Country, region, and city inferred from IP address. We do not collect precise geolocation. |
| Cookies and similar technologies | See Section 9. |
4.3 Data from third parties
| Source | Data |
|---|---|
| Your organization | Your name, email, role, and permissions when an administrator invites or provisions you |
| Identity providers (SSO, SAML, SCIM) | Name, email, group memberships, authentication status |
| Connected Storage | Lists of buckets, folders, objects, and object metadata, retrieved with your Credentials. Treated as Customer Content. |
| Resellers, MSPs, system integrators, and partners | Business contact details and order information |
| Stripe | Payment status and fraud signals |
| Public sources and events | Business contact details used for business-to-business outreach |
5. Customer Content, data movement, and storage
How Customer Content moves depends on the feature. For access, streaming, and local transfers, file content moves directly between your device and your storage provider over encrypted TLS connections and is never stored on Amove servers. Cloud-to-cloud migrations and AI requests are routed through Amove infrastructure on Amazon Web Services in US East regions, as described below. File data is encrypted on your device, in transit, and at rest.
| Feature | What happens | Where data is processed |
|---|---|---|
| Access, virtual drive mounts, and streaming | Your device reads and writes directly to your storage provider using your Credentials. Amove's Web API handles authentication and permissions. | File content: your device and your storage provider only |
| File names, paths, and file-tree metadata | Drive (single-object storage): stored locally on your device. Editfly: stored in Amove's cloud database in an AWS US East region, with a cached copy on your device. | Your device, and for Editfly, the Amove database |
| Local cache | Recently used data is cached on your device to improve performance. | Your device, encrypted |
| Local transfers and sync | Run on your device. Data moves directly between your device and storage endpoints. | Your device and storage providers only |
| Cloud-to-cloud migration | Amove's migration service reads data from the source and writes it to the destination, encrypted in transit. No file content is retained after the job completes. The service logs API activity and the names and paths of objects transferred, not file content. | Source provider, Amove migration service in an AWS US East region, destination provider |
| AI Search (when available and enabled) | AI requests are routed through Amove's Web API to the AI model providers in Section 6. Search embeddings are stored in Amove's database in AWS us-east-1. If you choose local processing, a copy is also kept on your device and the AWS copy is still stored. | Your device, Amove Web API, AI model provider, Amove database |
| Thumbnails | Generated and stored locally on your device. | Your device only |
| Editfly storage | Amove provides storage through IDrive, its Subprocessor. File data is stored as encrypted blocks or objects. | IDrive, in the region you select. Amove is the processor of this content. |
| Bring your own storage | You connect your own storage and keep your files there. | Your storage provider |
| Share links | Recipients access shared content from the storage provider. You control expiry, passwords, and permissions where available. | The storage provider and the recipient's device |
| Self-hosted and licensed deployments | The Customer operates the software. | Customer environment. Amove has no access unless the Customer grants support access. |
5.1 Credentials
We encrypt Credentials at rest, restrict access to systems that need them, and use them only to perform operations you initiate or schedule. We never sell Credentials or use them for any other purpose. Use scoped, least-privilege keys, and revoke Credentials with your storage provider when you disconnect storage or close your account.
5.2 Amove access to Customer Content
Amove personnel do not access Customer Content except: (1) as needed to provide the Services you request; (2) to provide support you request, with your authorization, limited to what is necessary, and logged; (3) to investigate or address security incidents, fraud, abuse, or technical issues; or (4) to comply with law, as described in Section 8.
5.3 Content you may not upload
Unless Amove agrees in a signed writing, do not use the Services for: protected health information under HIPAA (Amove does not sign business associate agreements by default); payment card data subject to PCI DSS; data controlled under ITAR or classified under an Export Control Classification Number other than EAR99; classified government information or criminal justice information subject to CJIS; or personal data of children collected for a child-directed service. You are responsible for having the rights, notices, and consents needed for all Customer Content, including releases from people depicted in media.
6. AI Features
Amove does not use Customer Content, Input, Output, or search embeddings to train, fine-tune, or improve any AI or machine learning model, whether Amove's or a third party's, unless the Customer opts in through a signed writing.
6.1 AI Search and AI model providers
AI Features are off by default and run only after a Customer administrator enables them. AI Search is not yet generally available. When enabled, AI requests are routed through Amove's Web API to these AI model providers:
- Anthropic, PBC
- OpenAI
- Google LLC (Gemini API or Vertex AI)
Amove uses these providers only under commercial terms that prohibit training on Customer data. Before AI Search launches, we will update this section with the content sent to each provider, where each processes it, and how long each retains it, and will give Customers at least 30 days' notice.
6.2 No biometric identification
Amove does not offer face recognition. The Services do not create face templates, face embeddings, face geometry scans, voiceprints, or other biometric identifiers, and do not identify, verify, or group individuals by their physical characteristics. Before offering any feature that creates biometric identifiers, we will update this Privacy Policy, publish a biometric data retention and destruction policy, and require Customers to obtain every notice, release, and consent the law requires. Amove will never sell, lease, trade, or otherwise profit from biometric data.
6.3 Output
AI Output can be inaccurate, incomplete, or biased. Review it before relying on it. Do not use AI Features to make decisions with legal or similarly significant effects on individuals, such as decisions about employment, credit, housing, insurance, education, or health care. Amove does not use AI Features to make such decisions about you.
6.4 AI agents and the MCP server
AI agents and AI clients connected through the MCP server act with the permissions granted to them and can read, modify, move, share, and delete Customer Content. We log agent actions. Scope agent tokens to the minimum access required. If you connect a third-party AI client, Customer Content returned to it is processed under that provider's terms, not this Privacy Policy.
6.5 Human review
Amove personnel do not review Input or Output except to provide support you request, to address security or abuse, or to comply with law.
7. How we use personal data and our legal bases
The legal basis column applies to individuals in the European Economic Area, the United Kingdom, and Switzerland.
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide, operate, and maintain the Services | Account, Credentials, Service Data | Performance of a contract |
| Authenticate users and administer accounts | Account, device, identity provider data | Contract; legitimate interests in securing accounts |
| Process payments, invoices, and taxes | Billing, payment | Contract; legal obligation |
| Provide support | Support communications, Service Data | Contract; legitimate interests |
| Secure the Services and prevent fraud and abuse | Device, usage, logs | Legitimate interests; legal obligation |
| Debug and improve the Services | Service Data, aggregated or deidentified where practical | Legitimate interests |
| Send service and security notices | Account | Contract; legal obligation |
| Send marketing communications | Contact details, preferences | Consent where required; otherwise legitimate interests |
| Run events, surveys, and beta programs | Contact details, feedback | Consent or legitimate interests |
| Recruit and evaluate applicants | Careers | Steps before a contract; legitimate interests |
| Comply with law, enforce agreements, and establish or defend legal claims | Relevant data | Legal obligation; legitimate interests |
| Evaluate and complete corporate transactions | Account, billing, Service Data | Legitimate interests |
We do not use Customer Content for marketing, advertising, profiling, or AI training. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. We do not use personal data for a new, incompatible purpose without notice and, where required, consent. Where we deidentify data, we keep it deidentified, do not attempt to reidentify it, and require recipients to do the same.
8. How we disclose personal data
We do not sell personal data. We do not share personal data for cross-context behavioral advertising. We do not use advertising cookies or pixels.
| Recipient | What and why |
|---|---|
| Subprocessors and service providers | Listed in Section 8.4. Each is bound by a written contract limiting its use of personal data to providing services to Amove. |
| Your organization | Customer administrators can access your account data, activity logs, and the content you store. |
| Other users and share-link recipients | Content and profile details you choose to share. |
| Connected Storage and third-party services | Data you direct us to send when you connect a storage endpoint, identity provider, AI client, or integration. |
| Entities under common control with Amove | For the purposes in this Privacy Policy, and bound by it. |
| Resellers, MSPs, system integrators, and partners | Business contact and order information needed to fulfill purchases made through them. |
| Professional advisors | Lawyers, accountants, auditors, and insurers, under duties of confidentiality. |
8.1 Legal process
We disclose personal data to government authorities only when we believe in good faith that a valid subpoena, court order, warrant, or other legal process requires it. For requests concerning Customer Content we will require valid legal process directed to Amove, redirect the requester to the Customer where possible, notify the Customer before disclosure unless legally prohibited, challenge requests we believe are overbroad, and disclose only the minimum required. We may also disclose personal data where we believe in good faith it is necessary to prevent imminent death or serious physical injury, or to protect the rights, property, or safety of Amove, our users, or the public, including by enforcing the Performm User Agreement.
8.2 Corporate transactions
If Amove is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale or license of all or part of its business or technology, personal data may be disclosed to the counterparty and its advisors under confidentiality obligations. Personal data transferred in a completed transaction remains subject to commitments at least as protective as this Privacy Policy, and we will notify affected individuals before their data becomes subject to a different privacy policy. Customer Content belongs to Customers and is not an Amove asset for sale.
8.3 With your consent
We disclose personal data for other purposes only with your consent.
8.4 Subprocessors and service providers
| Provider | Purpose | Location | Status |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting of the Web API, databases, search embeddings, and migration service | United States (US East) | Active |
| IDrive Inc. | Editfly storage | Region selected by the Customer | Active |
| Stripe, Inc. | Payment processing | United States | Active |
| PostHog, Inc. | Product analytics | United States | Active |
| Google LLC (Google Analytics) | Website analytics | United States | Active |
| Anthropic, PBC; OpenAI; Google LLC (Gemini) | AI Search model inference | To be stated before launch | Pending. Not active until AI Search launches and 30 days' notice has been given. |
We will give Customers at least 30 days' notice before a new Subprocessor processes Customer Content. Customers may object on reasonable data protection grounds by writing to contact@amove.io with "Subprocessor Objection" in the subject line within 15 days of notice.
9. Cookies and analytics
| Category | Purpose | Default |
|---|---|---|
| Strictly necessary | Sign-in, security, load balancing, consent records | Always on |
| Functional | Remember preferences such as language and layout | Off until you consent, where consent is required |
| Analytics | Measure Site and product use with Google Analytics (Google signals and ad personalization disabled) and PostHog (US Cloud). We do not use session recording. | Off until you consent, where consent is required |
| Advertising | None. We do not use advertising cookies or pixels. | Not used |
Where the law requires consent for non-essential cookies, we ask for it before setting them. You can change your choices through our cookie settings, where offered, or your browser controls. Google Analytics may collect information about your activity on other websites under Google's own policies; see https://www.google.com/policies/privacy/partners/.
Email tracking. Our marketing emails may record whether and when an email was opened and which links were clicked. We do not track whether or to whom you forward our emails. You can disable tracking by blocking images in your email client or by unsubscribing.
Browser signals. We honor Global Privacy Control (GPC) signals as a request to opt out of any sale, sharing, or targeted advertising for the browser sending the signal. There is no accepted standard for "Do Not Track" signals, and we do not respond to them.
10. Your choices and privacy rights
We extend the rights below to every individual, wherever located, subject only to the exceptions applicable law allows. For Customer Content, submit requests to the Customer (see Section 3).
Choices. Unsubscribe from marketing through the link in any marketing email; you will still receive service and security notices. Disconnect any storage endpoint in Performm and revoke its Credentials with your storage provider. Customer administrators can enable or disable AI Features for their organization.
| Right | US states with comprehensive privacy laws | EEA, UK, Switzerland |
|---|---|---|
| Know and access your personal data | Yes | Yes |
| Correct inaccurate personal data | Yes | Yes |
| Delete personal data | Yes | Yes |
| Receive a portable copy | Yes | Yes |
| Opt out of sale, sharing, targeted advertising, and significant profiling | Yes | Object at any time to direct marketing |
| Restrict or object to processing | Not applicable | Yes |
| Withdraw consent | Yes | Yes, without affecting prior lawful processing |
| Appeal a denied request | Yes | Complain to your data protection authority |
| Freedom from discrimination for exercising rights | Yes | Yes |
How to exercise your rights. Email contact@amove.io with "Privacy Request" in the subject line. We will verify your identity by matching information we already hold and will request no more than needed. We accept requests from an authorized agent with your signed permission and may ask you to confirm the request directly. We respond within 45 days for US requests, extendable once by 45 days, and within 1 month for EEA, UK, and Swiss requests, extendable by 2 months, with notice of any extension. If we deny your request, we will explain why. You may appeal by emailing contact@amove.io with "Appeal" in the subject line within 60 days; we decide appeals within 60 days. If we deny your appeal, you may contact your state attorney general.
California notice at collection. In the past 12 months we collected the categories below. We disclosed each only to the recipients in Section 8, for the purposes in Section 7. We sold or shared none of them.
| CCPA category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, IP address, account ID |
| Customer records (Cal. Civ. Code 1798.80) | Yes | Billing address, payment details via Stripe |
| Commercial information | Yes | Plans purchased, transaction history |
| Internet or network activity | Yes | Site and product usage, logs |
| Geolocation | Approximate only | Location inferred from IP |
| Professional or employment information | Yes | Job title, employer, applicant data |
| Education information | Applicants only | Education history on resumes |
| Audio or visual information | Only if we record a call, and only after telling you | Recorded sales or support calls |
| Inferences | Limited | Product interests from usage |
| Biometric information | No | See Section 6.2 |
| Protected classifications | No, unless an applicant volunteers it | Not requested |
| Sensitive personal information | Yes | Account login credentials, used only to provide and secure the Services |
We use sensitive personal information only for purposes the law permits, so we do not offer a right to limit its use. We do not disclose personal data to third parties for their own direct marketing purposes.
11. Retention and deletion
We keep personal data only as long as needed for the purposes below. A legal hold, an active dispute, or a legal requirement to retain data overrides these periods for the affected data only.
| Data | Retention |
|---|---|
| File content in transit through the migration service | Not retained after the job completes |
| Credentials | Deleted when you disconnect the storage endpoint or your account is closed |
| Customer Content in Editfly storage | Available for export for 30 days after termination, then deleted. Removed from backups on the normal backup cycle. |
| Editfly file-tree metadata and AI Search embeddings | Deleted with the source content, or after termination together with Editfly storage |
| Account and profile | For the life of the account, then deleted after the post-termination export period, unless needed for billing, security, or legal reasons |
| Security, audit, migration, and access logs | Generally up to 12 months |
| Product usage and diagnostics | As long as needed to operate and improve the Services, then aggregated or deleted |
| Support communications | As long as needed to resolve the request and maintain service records |
| Billing, invoices, and tax records | 7 years |
| Marketing contacts | Until you unsubscribe or stop engaging. We keep a suppression record of opt-outs so we can honor them. |
| Job applications | 4 years after the hiring decision |
AI model providers, once active, retain data under their own terms, which we will state in Section 6.1 before AI Search launches. To delete your account, use your account settings or email contact@amove.io. Data on your devices, in local caches, and in Connected Storage is under your control and is not deleted by Amove.
12. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data and Customer Content, including: encryption of file data on the device, in transit using TLS, and at rest; encrypted storage of Credentials; role-based, least-privilege access for Amove personnel; logging and monitoring of access to production systems; confidentiality obligations and training for personnel; security review of Subprocessors before engagement; and a documented incident response process. Our SOC 2 audit is in progress.
No method of transmission or storage is completely secure, and we cannot guarantee the security of any data. You are responsible for securing your devices, Credentials, and account access, and for configuring permissions in Performm and in your Connected Storage.
Breach notification. If we confirm a security breach that leads to unauthorized access to personal data we control, we will notify affected individuals and regulators as the law requires. If a breach affects Customer Content, we will notify the affected Customer without undue delay so it can meet its own obligations.
13. International transfers
Amove is based in the United States. Account data, Service Data, Credentials, Editfly file-tree metadata, and AI Search embeddings are stored on Amazon Web Services in US East regions. Cloud-to-cloud migrations pass through Amove's migration service in an AWS US East region. Editfly storage is located in the IDrive region you select. Other file content stays with your storage provider, in the regions you choose. Amove does not guarantee that Customer Content will remain in any particular country or region unless a signed agreement says so.
When we transfer personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, we use the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, and the Swiss adaptations of those clauses, together with supplementary measures such as encryption. You may request a copy of the relevant safeguards at contact@amove.io.
14. Other terms
Children. The Services are for businesses and professionals and are not directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided personal data to us, email contact@amove.io and we will delete it.
Third-party services. The Services link to and integrate with websites, storage providers, AI clients, and other services we do not own or control. Their own privacy policies govern their practices.
Changes. We will post changes on this page and update the "Last updated" date. For material changes, we will notify account holders by email or in the Services at least 30 days before the change takes effect. We will not apply a material change to personal data collected before the change without your consent where the law requires it.
Contact. Questions, requests, and complaints:
Amove Technologies Inc
Attn: Privacy
177 East Colorado Blvd
Pasadena, CA 91105
contact@amove.io
Privacy lead: Robert Edwards, Product and Security Lead.
