Privacy Policy — Ama Work
Last updated: 2026-10-02
Ama Work ("the App") is published on Google Play by the developer Sono POS - Restaurant Solutions and operated by ATC GROUP COMPANY LIMITED ("we", "us"). The same app is listed on the Apple App Store as Tax Paper Tool (its name until September 2026) and runs on the web at tax.atcgroup.cc. This policy explains what data the App collects, how it is collected, what it is used for, and who it is shared with. It covers the iOS app, the Android app and the web version.
Data We Collect, and How
- Documents you scan or upload — photos/PDFs of receipts, invoices and tax documents, plus the text extracted from them. Collected when you actively scan, pick a file, or forward an email to your inbox address.
- Account information — the username and password you create to sign in, and which company you belong to.
- Chat messages to the AI assistant — the question you type, and the document it refers to. If you ask about your payslip, the App also uses de-identified text from your own current and previous payslip. Collected only when you send a message in the KI-Chat.
- Internal team messages — messages, announcements and shift handovers you write for your colleagues, and any picture you attach. These stay on our servers and are not sent to an AI service, with one exception: where your employer has switched on translation, a reader who taps translate on an announcement or on a message in a group room — and has agreed to translation for themselves — sends that one text, and nothing else, to the AI provider that translates it. The translation is shown to that reader and not stored. Messages in direct conversations are never translated and never sent.
- Time tracking — clock-in, clock-out and break times and, where your employer has enabled it, a check of your location at the moment you clock in or out, together with a device identifier. Your precise position is read only at that moment, never in the background, for two purposes: to attribute the punch to the right branch, and to confirm that you are at your workplace. It is compared on our server and then discarded — your coordinates are never stored. What is kept is whether you were within range of the branch (yes or no), how accurate the phone's position was, and, only when you were outside, the distance to the branch, rounded (to 10 m below 100 m, to 50 m below 1 km, to 100 m beyond). Where your employer has put a Bluetooth sender (beacon) in the branch, the App also listens for it for a few seconds at that same moment, and stops listening as soon as the punch is sent — it is never switched on in the background. A sender only ever says which branch it stands in; it holds no personal data, and the signal strength is weighed on our server and then discarded like the position. Either the sender or your position is enough. Where your employer requires the check, a clock-in or clock-out that cannot show you are at the branch is not booked straight away: you can try again, scan the QR code shown on the counter screen, or report a problem with a reason — the punch then keeps the time you pressed and waits for a manager to confirm it.
- Task proof photos — where your employer asks for a photo when a task is handed in: the photo you take, the time it was taken, and — where your employer has enabled it — whether it was taken within range of the branch (yes or no) and how accurate the phone's position was. Your position itself is compared on our server and then discarded; it is not stored, and a photo taken with the App is stored without the location and device data a camera writes into the image file.
- Task results, points and bonus — where your employer uses them: whether a task was approved, sent back for rework or needs another photo, who decided (a person or the automatic check) and why; the points booked for your tasks, each with its reason; and any bonus worked out from them with its approval and payment status.
- Push token — if you allow notifications, a device token so we can notify you about a message, an announcement, a shift handover, a task given to you or due soon, a changed rota, the result of a task you handed in, or new points. It carries no record of when you use the app. A notification never shows an amount of points or money on the lock screen.
- Camera and photo access — used only while you are actively scanning a document, attaching a picture, photographing a task you hand in, or scanning the QR code on the counter screen when you clock in or out. The QR code proves that you are standing at the counter; it contains no personal data. We never access the camera in the background.
How We Use It
- To extract text (OCR), classify, name and tag your documents automatically.
- To answer your questions in the KI-Chat, including questions about your own payslip, and to translate documents when you ask.
- To let you search and organise your own document archive.
- To run shift planning, task lists and time records for your employer — including, where your employer requires it, confirming that a clock-in or clock-out happens at the workplace.
- To check the tasks you hand in — by a person, or automatically where your employer has switched that on and you have agreed (see below) — and, where your employer uses points, to keep your points and work out a bonus that a person then decides on.
We do not use your data to train any AI model of ours, we do not sell it, we do not share it with data brokers, and the App contains no advertising or third-party analytics SDKs.
Third-Party AI Processing — and Your Consent
To perform OCR, classification, translation and chat, the following is sent through our backend to third-party AI providers — Google (Gemini) and OpenAI — for processing:
- the image or PDF of a document you scan, and the text read from it;
- your KI-Chat question and the content of the document it refers to; for a payslip question, de-identified text from your own current and previous payslip;
- the text you ask to have translated — including a single announcement or a single message in a group room of the team channel that you tap to translate, where your employer has switched translation on (never a message from a direct conversation);
- a question you put to the assistant in the team chat, together with the company documents you are already entitled to read — standing instructions, your own tasks for today, and current announcements;
- the proof photo you take when you hand in a task, together with that task's example photo, its written description and, if you use the App in a language other than German, the name of that language — only where your employer has switched on automatic checking, and only if you have agreed (see "Automatic Checking of Task Photos").
The App asks for your permission inside the App before any of this is sent, and states what is sent and to whom. If you decline, the App keeps working — scanning to your archive, document management, time tracking, shift planning, tasks and the team channel need no AI. You can grant or withdraw the permission at any time under Mehr → Einstellungen → KI; withdrawing stops any further transfer.
The following is never sent to an AI provider: your password, your bank transactions, tax ID, social-security number, IBAN, address, health data, internal team messages (apart from the single announcement or group-room message a reader taps to translate, described above), time-tracking records, location data, and your points or bonus. This holds for both assistants: each receives your own question and only the context described above, never what a colleague wrote — consent to use AI is given by each person for themselves, and nobody can give it on somebody else's behalf.
For account suggestions (Kontierungs-KI), the model receives selected invoice fields (supplier name, amounts, tax rates and line descriptions), the account catalogue, applicable accounting rules, confirmed examples and saved accounting instructions. It receives no chat or team-channel messages. Suggestions carry a reason and are held back from DATEV until a person confirms the account.
These providers process the data to generate a response, act as processors on our behalf under contractual terms that require a level of protection equivalent to this policy, and do not use it to serve you ads.
Ami Voice Guide
The web version has a guide, Ami, that walks you through setting the App up, step by step. You can type questions to it; questions you type go through our server to the AI providers named above, together with the texts of the setup steps. You can also talk to it. The voice is optional: it is off unless your employer switches it on, and it starts only after you have agreed to it yourself, in the App, where you can also withdraw that agreement at any time.
When you ask Ami in text about company data, it reads only company data you are allowed to see and sends it to the text AI model as KI-Chat does; the voice AI never receives that looked-up data.
For a command in the web Omnibox that needs an AI answer, the text model receives your command, the current page, up to eight recent command messages and, only for a business document you may read, a limited summary of that document; recognised simple commands stay on our server.
Ami keeps your typed sessions for up to the number of days your business chooses (0, 7, 30 or 90; 30 by default) so you can read them again; spoken turns are not stored; memories are saved only when you click “Remember” (or “Add” for a note you write yourself); only you can read or delete your sessions and memories.
Ami speichert Ihre getippten Sitzungen bis zu der vom Betrieb gewählten Zahl von Tagen (0, 7, 30 oder 90; standardmäßig 30), damit Sie sie wieder lesen können; gesprochene Beiträge werden nicht gespeichert; Erinnerungen werden nur gespeichert, wenn Sie auf „Merken“ klicken (oder für eigene Notizen auf „Hinzufügen“); nur Sie können Ihre Sitzungen und Erinnerungen lesen oder löschen.
Ami lưu các phiên bạn gõ tối đa số ngày do cơ sở chọn (0, 7, 30 hoặc 90; mặc định 30) để bạn xem lại; lượt nói không được lưu; ghi nhớ chỉ được lưu khi bạn bấm “Ghi nhớ” (hoặc “Thêm” với ghi chú tự viết); chỉ bạn được đọc hoặc xóa phiên và ghi nhớ của mình.
Ami looks up company data, reads the document you have open, or prepares an action for you only after you have agreed to that yourself, once, in the App — it asks the first time it needs it. You can withdraw that agreement at any time at the bottom of the Ami panel; without it, Ami answers only general questions. The Ami panel on the right side of the web version follows the same rules as the command field; if you talk to it, the voice rules below apply, and the voice AI never receives looked-up data.
- Where your voice goes. While you hold the microphone button (or, if you choose hands-free mode, while it is on), your voice is sent through our server to SpaceXAI LLC (xAI) in the USA, which turns it into text and answers with a spoken reply that comes back the same way.
- How long. xAI keeps the audio for up to 30 days and does not use it to train its models. We keep no recording and no transcript: our server records only how many seconds were spoken in each direction and why a conversation ended, so that the minutes can be counted.
- What the guide is told. Besides what you say, the guide receives only the texts of the setup steps, which of them are done (as numbers), the language of the page and your role — never the names of employees, documents, chat messages or wages.
- On a phone. Since October 2026 the App on your phone has the Ami panel too, with the same rules: only an office account can open it, your voice travels the same way through our server, and nothing is recorded on the phone. Push-to-talk is the default there; hands-free is a switch you turn on yourself. A conversation ends when the App leaves the screen — it never listens in the background.
Exercise Mode (Übungsmodus)
The web version also offers short exercises in which Ami leads you step by step. They run in a practice copy of your company (Übungsbetrieb) that belongs to you alone. It is filled with made-up example data — a demo branch, three invented employees and two shift templates — and never with the data of your real company. Nothing you do there leaves it: no push notifications, no e-mails, no logins, no bank or DATEV connections.
- Spoken instructions. Ami reads out fixed instruction texts that are the same for everybody and contain no personal data. To turn them into speech, only these catalogue texts are sent to SpaceXAI LLC (xAI) in the USA, once; the audio is then stored on our server. Asking questions by voice during an exercise follows the rules of the Voice Guide above.
- Practice data. Everything you practise stays in your per-person practice copy on our server and is deleted after 14 days in which nobody opened it. You can reset it at any time.
- What is kept about you. Only that you finished an exercise, on which day, and — if you choose to say — how sure you felt. How long a run took, how many hints it needed and where it stopped are kept without your name and without a date or time (only the month), to improve the exercises; nobody, your employer included, can see them per person.
Questions About Your Own Payslip
If you ask the assistant about a payslip, it may receive de-identified text from your own current and previous payslip. Before transfer, the server removes tax ID, social-security number, IBAN, address, health data and internal personnel identifiers. It does not read team-chat messages or another employee's payslip. The assistant explains the figures supplied by the payroll program; it does not calculate tax, social-security contributions or net pay, and it does not give tax or legal advice.
This transfer happens only after you consent to the current AI disclosure. If you decline or withdraw consent, you can still open and download your payslips normally.
Automatic Checking of Task Photos (Automatische Prüfung von Aufgabenfotos)
Your employer can give a task an example photo of the expected result and, separately, switch on automatic checking for it. It is off unless your employer switches it on. When you hand in such a task, our server sends your proof photo, the example photo and the task's description to Google (Gemini) and asks whether the result matches. If you use the App in a language other than German, the name of that language is sent too, so that the reason can be written in it.
- Only with your consent. The App asks you first, in the language you use the App in, and says what is sent and to whom. Your answer is also stored on our server, with the date, the version of the text and the language it was shown in, because the server sends the photo. Without your consent — or after you withdraw it under Mehr → Einstellungen — a person checks your photo instead. You have no disadvantage either way.
- What the result can do. The result is a proposal with a reason, written in German and, if you use the App in another language, also in that one. It can approve a task (which can add points), ask for rework, or ask for another photo; whenever it is unsure, it passes the task to a person. It can never deduct points or money: every deduction is decided by a person.
- Your right to a person. When the automatic check sends a task back to you — for rework or for another photo — you can dispute that result in the App or on the web, until you hand the task in again. A person then looks at the task and decides (Art. 22 GDPR). An approval needs no dispute, and whenever the check is unsure, a person decides anyway.
- No recognition of people. The check looks at the result of the work, not at who is in the picture. To notice a photo handed in twice, we compare a digital fingerprint of each photo with earlier ones; there is no face recognition.
- How long. Proof photos are deleted after a period your employer chooses — one year by default — once the task is closed. The decision on the task and its reason are kept.
Points and Bonus (Punkte und Bonus)
Your employer can switch on points for tasks. It is off unless your employer switches it on.
- How points are booked. Points for a task are booked only after the task has been accepted; a person can also book points by hand, always with a reason. Every entry states its reason, a correction is a new entry rather than a change to an old one, and you can see your own entries at any time. Points can be deducted — for example for rework or a task handed in late — but only when a person decides it, never automatically. A deduction for lateness is refused for a day you were on approved leave or had no shift in the published rota.
- Who sees them. You see your own points. Your employer's office and the people authorised to check tasks see the points of the people they are responsible for; a bonus is seen by you and by the people who work it out and approve it. If your employer runs a leaderboard, it shows only the names and ranks of the top places — nobody's number of points — and you can take your name off it in the App.
- Points are not pay. Whether points become a bonus is decided by the business owner or a person they authorise: the rate, the budget, who is eligible, the final amounts and when they are paid. A bonus is marked as not yet approved, approved, or paid. Nothing is ever deducted from your wages because of points.
- What they are not used for. Points are not used to plan shifts, and no decision about your employment is made from them automatically.
- How long. Points and bonus records are not deleted automatically. A bonus that was paid is part of the payroll records your employer must keep for the statutory period.
In Germany, points, a leaderboard, deadline reminders and the automatic photo check may require the agreement of the works council under §87(1) no. 6 and nos. 10–11 BetrVG before they are switched on; that is your employer's decision to take, not something the App decides for them.
Bank Connections (Kontoauszüge)
A business can let the App read one of its bank accounts, so that its statements arrive without anybody uploading them. The account holder signs in to their own bank and confirms it; our servers never receive the bank password, PIN or TAN, and the App never initiates a payment. What our server receives is the list of booked transactions and the balance of the chosen account. Two providers carry this out, and the business chooses which one:
- YAXI GmbH (Germany) — the default. The holder signs in from the App in their own browser; YAXI’s software there sends the bank login end-to-end encrypted to YAXI’s service, which runs in attested, confidential hardware in Germany, and on to the bank. With the holder’s consent our server keeps an encrypted token that lets it read the account again without the holder, until the bank asks for a new confirmation. YAXI logs the masked IP address, the time and the user agent of each request, and keeps a record of each call (which bank, when) for billing and fraud prevention for up to seven years.
- Enable Banking Oy (Finland) — a registered account information service provider. The holder confirms on their bank’s own page; the access lasts at most 180 days.
The business can disconnect the account in the App at any time, and the holder can withdraw the access at their bank. Transactions already imported stay in the business’s books.
Data Storage and Retention
Your documents, extracted text, account data and team messages are stored on our own servers in Europe (not in a third-party consumer cloud product). Tax documents are kept for as long as the statutory retention period your business is subject to requires. Internal team messages are deleted automatically after a period your employer chooses — one year by default, and configurable up to "keep indefinitely" — see Einstellungen → Chat-Aufbewahrung.
Read Marks in the Team Chat
The App can record, per person and per conversation, how far that person has read — a single timestamp per room, overwritten each time, not a log of visits and not a count of anything. It exists so the app can show you which conversations have something new in them.
Your employer controls two separate settings for this, under Einstellungen → Chat:
- Unread counter (on by default): the mark is recorded, and only you can see your own. Switching this off deletes the marks that were stored — it does not merely hide them.
- Read receipts (off by default): the other people in that same conversation are shown how far you have read. Nobody outside the conversation ever sees it.
There is no record of when you opened the App, no "last online", no "is typing", and no count of how many messages anybody writes. Read marks are deleted together with the messages they refer to, under the retention period above. In Germany, switching on read receipts may require the agreement of the works council under §87 BetrVG; that is your employer's decision to take, not something the App decides for them.
Your Rights
You can delete any document from within the App at any time. You may request access to, correction of, or deletion of your personal data, and you may object to processing. Write to the address below: we act within 30 days and confirm when it is done. Deleting your account deletes the data associated with it.
Children
The App is a business tool for company employees and is not directed at children.
Contact
ATC GROUP COMPANY LIMITED, trading on Google Play as Sono POS - Restaurant Solutions (developer of Ama Work)
Email: anhoev@googlemail.com
Support: tax.atcgroup.cc/support · Terms of Service