Last updated: September 11, 2026 — added Business Email deliverability & anti-spam (SPF/DKIM/DMARC/PTR) section
When you use Amemis, we collect the following types of information:
We use your information to provide and improve the Amemis platform:
We do not sell your personal data. We share data only with trusted third-party processors necessary to operate the service:
Each processor is contractually obligated to protect your data and use it only for the agreed services.
We implement industry-standard security measures to protect your data, including encryption at rest (AES-256) and in transit (TLS 1.3), regular security audits, and strict access controls for our engineering team. Environment variables and secrets entered in the dashboard are encrypted and never logged in plaintext.
Your repository is your responsibility. Amemis reads configuration from your repository to build and run your app. If you commit a .env containing secrets to a public repository, those secrets are publicly readable and we cannot protect them — you must rotate anything exposed and make the repository private. See Your .env and Repository Visibility below for the required checks before deploying.
You have the right to:
To exercise any of these rights, contact us at privacy@amemis.com.
If you have questions about this privacy policy, please reach out to privacy@amemis.com or write to our data protection team at Amemis, Inc.
Amemis supports custom domains for your deployed applications, similar to platforms like Vercel and Netlify. You can connect any domain you own (purchased from Namecheap, GoDaddy, Cloudflare, Google Domains, or any other registrar) to your deployed service.
Once verified, your app will be accessible at https://yourdomain.com with automatic HTTPS.
To point your domain to Amemis, add the following DNS records at your registrar:
@ or leave blank → Value/Points to: 204.168.174.49www → Value/Points to: 204.168.174.49www → Value/Target: your-app-name.amemis.comDNS propagation typically takes 5 minutes to 24 hours depending on your registrar and TTL settings.
namecheap.com.@ and Value to 204.168.174.49. Set TTL to Automatic or 5 min. Click the checkmark to save.www and Value to 204.168.174.49. Save.Namecheap note: If you see an existing CNAME record for www, you must delete it before adding the A record.
godaddy.com.@. Points to: 204.168.174.49. TTL: 1 Hour or Quick. Click Save.www. Points to: 204.168.174.49. Save.GoDaddy note: GoDaddy may have default forwarding records. Delete any existing forwarding for @ and www before adding A records.
dash.cloudflare.com.@. IPv4 address: 204.168.174.49. Proxy status: DNS only (gray cloud). TTL: Auto. Click Save.www. IPv4 address: 204.168.174.49. Proxy: DNS only. Save.Cloudflare note: You must set the proxy status to DNS only (gray cloud) for the A record. If the orange cloud is active, the domain verification may fail because Cloudflare will proxy the traffic before Amemis can verify ownership.
squarespace.com).@. Type: A. TTL: 3600. Data: 204.168.174.49. Save.www. Type: A. TTL: 3600. Data: 204.168.174.49. Save.For any other domain registrar (Hover, Porkbun, Dynadot, Name.com, AWS Route 53, etc.), the steps are the same:
@ pointing to 204.168.174.49.www pointing to 204.168.174.49.www, delete it first.Amemis automatically provisions a free SSL/TLS certificate for your custom domain via Let's Encrypt once domain ownership is verified. No manual certificate installation is required. The certificate renews automatically before expiry.
If SSL status shows as pending, wait a few minutes and refresh. If it shows failed, verify that your DNS A records are correct and that no proxy (like Cloudflare orange cloud) is blocking verification.
dig yourdomain.com or an online DNS checker to confirm the A record resolves to 204.168.174.49.204.168.174.49 (not a CNAME or another IP). If using Cloudflare, ensure the proxy is disabled (gray cloud).@ and www are configured. Check that you have not exceeded your plan's custom domain limit.Fixed Sep 11, 2026 — DKIM for all business mailboxes. Our mail server now signs every outbound message with DKIM (mail._domainkey) for amemis.com and every connected business-email domain, and the records are kept in sync automatically. Independent checks (verifier.port25.com) report SPF="pass" and DKIM="pass" for each mailbox.
Email providers like Gmail, Outlook and Yahoo authenticate your messages using four DNS records about your sending domain. If one is missing, wrong, or mismatched, your mail is still delivered but is much more likely to be filed into the recipient's Spam folder:
mail.amemis.com). Gmail heavily penalizes a missing or mismatched PTR.For every domain using Amemis business email, these are configured on the mail server and in DNS:
mail.amemis.com (priority 10) — routes incoming mail to your mailbox.v=spf1 mx a ip4:204.168.174.49 ~all — authorizes our mail server (204.168.174.49).mail._domainkey.<yourdomain> — the signing key, auto-published and re-published whenever keys are rotated._dmarc.<yourdomain> with p=none while your sending reputation warms up (we recommend p=quarantine after ~3 weeks of clean delivery).The exact host names and values you need for any domain that points at Amemis business email (Namecheap: Domain List → Manage → Advanced DNS → Add New Record):
Type Host Priority Value MX @ 10 mail.amemis.com. TXT @ v=spf1 mx a ip4:204.168.174.49 ~all TXT mail._domainkey v=DKIM1; k=rsa; p=… (shown on the Business Email page) TXT _dmarc v=DMARC1; p=none; rua=mailto:postmaster@<yourdomain>.com
PTR / Reverse DNS (required for inbox delivery to Gmail & Outlook): open your server provider's panel (Hetzner: Network → Reverse DNS) and set the reverse record of 204.168.174.49 to mail.amemis.com.
check-auth@verifier.port25.com. You'll get an automatic reply showing SPF=pass, DKIM=pass and DMARC results for your mailbox.dig +short TXT _dmarc.yourdomain.com — every record must return a result.hello@yourdomain.com) so the recipient adds one address to their address book / safelist.none to quarantine for stronger reputation.Amemis builds and runs the branch you select when you create a service, and auto-deploy rebuilds and redeploys your app on every subsequent push to that same branch. The branch is therefore the single setting that determines what code is actually running.
dev instead of main, a stale feature branch, or a fork — will build and serve that branch's code, and every later push to it will keep replacing your live app.Specifically:
.env and Repository VisibilityThe single most important thing to check before your first deploy is whether your repository is private and what your .env contains. Amemis reads your .env from the repository to configure your app, so a .env that contains real secrets is a real risk when the repository is public.
.env is publicly readable. That includes API keys, database passwords, tokens, private service URLs and payment credentials. Anyone can clone the repository and read them, and search engines and archive services may retain copies even after you delete the file. Treat any secret that has been in a public repository as compromised and rotate it.What you must do before deploying:
.env and set those values in Dashboard → your app → Settings → Environment Variables instead. Dashboard values are injected at runtime and are never written into your repository..env.example with the required keys and no values, so the shape of the file is documented without exposing anything.“Sync from .env” makes your repository’s .env the source of truth. With it enabled (the default), the values in your repo’s .env overwrite your dashboard environment variables on every push and redeploy. That makes a stale or wrong .env on your branch a live problem, not just a cosmetic one, so check the .env on the branch you are deploying before you deploy it. Amemis imports .env, .env.local and .env.production, and ignores .env.example.
Where Amemis stores your environment variables. Values you enter in the dashboard are stored in our database and injected into your app when the container starts. They are not committed to your repository and are not written into your app’s source tree on disk. Nevertheless, treat them as secrets: they are visible to anyone with access to your Amemis account, so do not share account access and use per-environment values rather than one shared production credential across environments.
.env ProblemFixed Aug 29, 2026 — self-healing deploys (all 20 apps). If you pushed to GitHub and the Amemis dashboard showed Git clone failed: ... Entry '.env' not uptodate. Cannot merge. that bug is now auto-healed. Every log and event now shows YYYY-MM-DD HH:MM:SS so you can verify the deploy time in Monitoring → Logs / Events.
What happened: Many apps (e.g. VerboCalls on branch VerboCalls-app) commit their .env to git. Amemis rewrites PORT=3027 (platform-assigned) via routes/env-import.js:102 syncEnvFilePort so the app listens on the correct port. That left a dirty working tree: git status reported clean (due to skip-worktree) while git reset --hard origin/<branch> failed — blocking every webhook-triggered redeploy until manual intervention.
How Amemis now fixes it:
routes/deploy.js:336 cloneRepository now clears all skip-worktree / assume-unchanged flags (git ls-files -v), reset --hard HEAD, clean -fd, removes .env .env.local .env.*, checkout -f, then reset --hard origin/<branch>.--depth 1 — guaranteed to succeed on next push.server.js:511 calls reconcileAllWebhooks() — all autoDeploy:true services are re-registered on GitHub/GitLab/Bitbucket, so a deleted webhook self-heals within 15 s.building → failed loop.What you should do (best practice — prevents future surprises):
.env with secrets. Add it to .gitignore:
echo ".env" >> .gitignore echo ".env.local" >> .gitignore echo ".env.*.local" >> .gitignore git rm --cached .env # stop tracking without deleting local file git commit -m "chore: stop tracking .env" git push origin VerboCalls-app
spawn env and via mergeEnvFileVars (user vars take priority over any .env in the repo)..env.example or .env.template (without secrets) so teammates know required keys. Amemis only auto-imports .env, .env.local, .env.production and skips .env.example..env, the platform will still handle it — just expect a short rm -f .env + reset on each deploy (visible as [ENV] Set PORT=… in logs).Below is a quick checklist for any app hosted on Amemis. All checks can be done from Deploy Apps → your app → Monitoring (Logs / Events / Metrics) which now shows YYYY-MM-DD HH:MM:SS for every entry.
npm install / Docker build errorSymptom: Event Git clone failed → Build failed, logs show npm ERR or Dockerfile: …
BUILD — read the first [ERROR] line with timestamp.package.json engines: Amemis runs node:20-alpine. Pin "engines": {"node":"20"} if needed.package-lock.json drift locally: rm -rf node_modules package-lock.json && npm install && git push.Dockerfile has EXPOSE 3000 or whatever httpPort is set to — platform maps 204.168.174.49:PORT → container:EXPOSE and also injects PORT env.502 Proxy error / Health check failedSymptom: Blue-green log [BLUE-GREEN] New version failed its health check — rolled back, previous version kept online.
process.env.PORT (not hard-coded 3000). Amemis injects PORT=3027 etc. and also rewrites .env PORT. Check server.js: const PORT = process.env.PORT || 3000./health → /. Set a custom path in Settings → Health Check Path if needed; ensure it returns 2xx within 90 s.cpuLimit / memoryLimitMb in Settings if hit.APP / ERROR with timestamps to see crash stack.git pushON (badge shows Auto-deploy ON).branch matches push branch (e.g. VerboCalls-app vs master) — mismatched branch is ignored with event Push to "master" ignored — watching VerboCalls-app.Settings → Repository (case-sensitive full_name). A push to a fork will be ignored.Auto-deploy skipped — subscription required. Renew in Subscription.https://amemis.com/api/services/webhook/<id>/<secret> (visible in Monitoring → Settings → Webhook). Use Copy to re-add manually on GitHub Settings → Webhooks if deleted.Invalid signature or Not found: webhook secret rotated — toggle Auto-deploy off/on.routes/git.js:113 ensureFreshToken.Git push webhook received (branch) from github should appear within seconds of push. If not, verify GitHub webhook Deliveries shows 200 (Amemis GitHub App) and that the branch is not behind by >50 commits (shallow clone depth 50 — force-push may need fresh clone).stopped or asleepasleep is normal for Starter on idle (15 min). First request auto-wakes (Auto-waking service … in logs) or click Start in Deploy Apps. Set Always Awake (Premium) to disable.stopped: click Start or Redeploy in Deploy Apps or Monitoring → Settings → Actions.Running: true/false with internalPort — if port shows — the app never bound to PORT..env file. Missing var? Check Monitoring → Settings → Environment Variables — add via + Add Variable → Save & Restart. Each save is logged with timestamp in Events.DATABASE_URL / MONGODB_URI provisioned via database dropdown injects a container and auto-sets the connection string — ensure app reads the same key (see routes/deploy.js: databaseEnvKey).[ENV] Imported X variable(s) from .env file(s) (skipped platform keys: PORT,…) with date/time.[YYYY-MM-DD HH:MM:SS] [LEVEL] [scope] message (from utils/telemetry.js). Use search + level filter (APP / ERROR / SYSTEM) — click Copy to share.date: 2026-08-29 time: 13:19:22 dateTime: 2026-08-29 13:19:22 (from routes/events.js + models/deploy.js). Title + timestamp + data JSON if present.GET /api/platform/logs?limit=200 and /api/platform/events also carry the same fields.entry '.env' not uptodate, the Aug 29 fix already handles it — just push again. If it persists, click Redeploy to force a fresh clone.Starter plans include one custom domain per service. Premium plans include unlimited custom domains. Each custom domain must be a registered domain that you own.
Paying yearly gives you 12 months of access for the price of 11 — that is, one month free. The full year is added to your subscription end date on the day the payment succeeds, and the plan renews yearly at the same rate unless you change or cancel it.
Specifically:
Every plan is per service and has an end date. When that date passes and the subscription is not renewed, the app is disconnected. This applies to monthly and yearly plans identically — the only difference between them is how long the period lasts, not what happens at the end of it. Your code, repository link and settings are kept, so reconnecting is a payment rather than a rebuild.
Check the end date and the auto-renew switch for each app under Dashboard → your app → Settings, and turn auto-renew on for anything you need to stay online.
We do perform maintenance on Amemis from time to time, and occasionally the platform is briefly unavailable while we do it. Maintenance is how we ship new versions, apply security patches, upgrade the host, rebuild images, prune disk, and repair infrastructure — so it is a normal part of using the platform rather than an outage.
By accessing or using the Amemis platform, you agree to be bound by these Terms of Service. If you do not agree, do not use the service. These terms apply to all users, visitors, and anyone who accesses or uses the platform.
You are responsible for maintaining the security of your account credentials. You must provide accurate, current, and complete account information. You may not use the platform for any illegal or unauthorized purpose. You must notify us immediately of any unauthorized use of your account.
You agree not to misuse the Amemis platform or interfere with its operation. Prohibited activities include, but are not limited to: deploying malicious software, launching denial-of-service attacks, scraping or data mining without permission, hosting illegal content, and any activity that violates applicable law. We reserve the right to suspend any account that violates these terms.
Paid plans are billed monthly or annually as selected. All fees are non-refundable. An annual payment buys 12 months of access for the price of 11 — one month free — and the free month is a discount on the annual price rather than extra service time, so an annual subscription never extends beyond 12 months. If you cancel your subscription, you will not receive a refund for any payments already made, including for partial billing periods and including the unused remainder of a yearly plan, and no pro-rated refund or credit is issued when you upgrade, downgrade, or move between monthly and yearly billing. See Cancelling Does Not Produce a Refund above. Auto-renewal payments are charged automatically at the start of each billing cycle until you cancel. We may change pricing with 30 days notice. If your payment fails, we may suspend access until the balance is paid. You are responsible for all taxes associated with your use of the service.
Deployments are non-refundable. A deployment, redeployment or auto-deploy cannot be cancelled or reversed once started, and no refund or credit is issued for a deployment — including one that fails, builds the wrong branch, or replaces a working app with broken code. Check your branch and configuration before you deploy. See Check Your Branch Before Deploying and Deployments Are Non-Refundable above.
We strive to maintain 99.9% uptime for the platform. Our Service Level Agreement (SLA) provides credits if we fail to meet this commitment. Details are available on our SLA page. Announced and scheduled maintenance windows do not count against this commitment and no SLA credit is issued for them; emergency maintenance that we are unable to avoid does count, in line with the SLA. See Planned Maintenance above for how we deploy updates, how far ahead we announce them, and what happens if a window overruns. Amemis makes no guarantees about the availability of third-party services integrated with the platform.
You retain all rights to the code, content, and data you deploy on Amemis. The Amemis platform, including its proprietary software, brand, and design, is owned by Amemis, Inc. These terms do not grant you any license to our intellectual property beyond using the service as intended.
You may terminate your account at any time through the dashboard. We may terminate or suspend your account for violation of these terms, extended inactivity, or at our discretion with 30 days notice. Upon termination, you will not receive any refund for payments already made. Your services will be deactivated at the end of your current billing period. We will delete your data within 90 days unless required by law to retain it.
Expiry of a plan subscription is a termination of that service. Each service is billed separately and carries its own end date. If a monthly or yearly plan reaches its end date without being renewed — whether because auto-renew was off, the renewal payment failed, or no default card was on file — the app is stopped 24 hours after that date and stops serving traffic, and it cannot be started again until a plan is active again. Where auto-renew is on and collection succeeds, the end date is extended and the app is not stopped; a renewal that succeeds within 2 days after the end date also restores an app that has already been stopped. The unused remainder of the period is not refunded, credited, or carried over, and a yearly plan's one-month-free discount does not apply a second time on renewal. See When Your Subscription Expires above.
Amemis, Inc. shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the platform. Our total liability is limited to the amount you paid us in the 12 months preceding the claim. Some jurisdictions do not allow certain limitations, so this may not apply to you.
For questions about these terms, contact us at legal@amemis.com or write to Amemis, Inc., Attn: Legal Department.