Legal

Privacy Policy

This policy explains what information AtomAI processes when founders sign in, add company context, and use the founder workspace.

Effective August 24, 2026

1. Scope

This Privacy Policy applies to AtomAI's website and browser-based founder workspace at atomailab.com. It covers information processed when you create an account, use Google or email sign-in, upload company files, run agent workflows, and save workspace content.

2. Information we process

  • Account information: your email address, account identifier, and basic profile information supplied by you or your sign-in provider, such as your name and profile image.
  • Workspace content: prompts, conversations, session titles, founder-pinned memory, plans, generated artifacts, artifact versions, and feedback you provide.
  • Company context: files you choose to upload, extracted text, filenames, file types, file sizes, and exclusion reasons when likely secrets or unreadable content are detected.
  • Operational information: workflow status, token usage, research and citation counts, timestamps, authentication events, and limited diagnostic or security information needed to operate and protect the service.
  • Public-site analytics: anonymous page paths, referrers, approximate geographic region, device type, operating system, browser, and event timestamps for visits to public pages.

3. Google user data

When you choose Continue with Google, AtomAI uses Google OAuth only to authenticate you and create or connect your AtomAI account. We receive basic identity information made available by Google, such as your Google account identifier, email address, name, and profile image.

AtomAI does not request access to your Gmail, Google Drive, contacts, calendar, or other Google product content. We do not sell Google user data or use it for advertising. We use it only for account authentication, security, support, and operation of your founder workspace.

4. How we use information

  • Authenticate users and administer approved beta access.
  • Provide resumable sessions, selective company-context retrieval, research, analysis, and saved artifacts.
  • Detect likely secrets, enforce usage and security controls, diagnose failures, and prevent abuse.
  • Maintain and improve service reliability and respond to support or privacy requests.

5. How workspace content is handled

Supported files are read and text is extracted in your browser. AtomAI checks extracted text for patterns that resemble secrets before saving or transmitting it. If a likely secret is detected, the file content is excluded; limited file metadata and the exclusion reason may still be recorded so the workspace can explain what happened.

When you approve a company file, its original and extracted text may be stored in private workspace storage. Only context selected for a request is sent through AtomAI's managed backend to its AI and public-web research provider. Generated responses and artifacts may contain information derived from the context you supplied.

6. Service providers and disclosure

AtomAI uses Vercel for website hosting and anonymous public-site analytics, Supabase for authentication, database, and private object storage, and OpenAI for managed model generation and public-web research. These providers process information only as needed to deliver their services to AtomAI. We may also disclose information when required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

Vercel Web Analytics is configured without third-party cookies and AtomAI does not send it account identifiers or custom events. Analytics events are excluded from authenticated workspace routes, including authentication, agent, artifact, and file pages.

AtomAI does not sell personal information or workspace content.

7. Storage, security, and retention

Workspace database records and object storage are protected with account-scoped access rules and private storage policies. Authentication sessions are also stored in your browser so you can remain signed in. No online system is completely secure, so do not upload credentials, private keys, or information you are not authorized to process.

We retain account and workspace information while your account is active or as needed to provide the service, meet security and legal obligations, and resolve disputes. In-product controls let you remove sessions, company files, and artifacts. Residual copies may remain temporarily in backups, logs, or prior artifact versions; contact us to request account-level deletion.

8. Your choices

  • You can sign out, remove workspace files, delete sessions and artifacts, or stop using the service.
  • You can revoke AtomAI's Google access from your Google Account permissions.
  • You may request access, correction, export, or deletion of your personal information by contacting us.

9. International processing and children

AtomAI and its providers may process information in countries other than your own. AtomAI is intended for founders and other business users who are at least 18 years old, and is not directed to children.

10. Changes and contact

We may update this policy as AtomAI changes. We will revise the effective date and provide additional notice when appropriate. For privacy questions or requests, contact sudesh@atomailab.com.