Skip to main content
AtmitaAtmita

Privacy Policy

Last updated October 4, 2026

Introduction

Atmita ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.

Information We Collect

Account Information: When you sign in with a third-party authentication provider (Google or Apple), we receive your name, email address, and profile information from that provider. If you sign in with an email address, we collect that email address and send one-time sign-in codes to it.

User Content: We store the content you create within the Service, including prompts, chat messages, automation configurations, agent settings, agent memories, generated images and media, and feed items.

Chat History: Your conversations with the AI assistant are stored in our database to provide continuity across sessions.

Automation Data: When automations run, we store execution logs including inputs, outputs, tool calls, results, token usage, and credit usage.

Device and Analytics Information: We may collect browser and device information, IP address, user agent, referrer, landing page source, landing page version, and event metadata for security, debugging, abuse prevention, and product analytics. Some marketing-page analytics use an anonymous visitor identifier stored in your browser.

Integration Data: When you connect third-party accounts (such as Gmail, GitHub, or Google Calendar), we store references to those connections, account labels, and related settings. OAuth tokens for connected third-party accounts are stored by Composio, our integration provider. For API-key or token-based integrations, the authentication values you provide may be sent to and stored by Composio. If you save API keys or credentials directly in Atmita, we store those values and related labels so the Service can use them at your direction.

Payment and Subscription Data: If you subscribe to a paid plan on the web, MyFatoorah processes payment-card entry and card vaulting. If you purchase through our iOS app, Apple processes the payment through its In-App Purchase system, and we store transaction and subscription identifiers Apple provides so we can grant and manage your purchase. We store subscription records, plan and billing status, amount and currency, invoice and payment identifiers, saved-card tokens used for renewals, cancellation and retry state, and payment event metadata.

Push Notification Data: If you enable push notifications, we store your push subscription endpoint, browser push keys, user agent, and active status so notifications can be delivered.

Agent Email Data: Each account is assigned an agent email address on our email domain. We store email sent to and from that address, including sender and recipient addresses, subject lines, message bodies, headers, and supported attachments (see "Agent Email" below).

Usage Metrics: We collect usage statistics, such as the number of messages sent, chats created, automations run, images generated, and credits consumed.

Your Privacy Controls

Atmita provides an "Improve Atmita" setting (found in Settings) that controls how our team accesses your data:

  • When enabled: Our team may review your content - including chat messages, images, prompts, and automation inputs and outputs - to diagnose issues, improve the Service, and develop new features.
  • When disabled: We do not review your content for product-improvement purposes in ordinary admin workflows. We continue to collect and view usage metrics such as message counts, automation counts, credit usage, and similar operational data, and we may view high-level signals generated automatically from your activity, such as connected services, topics, errors, outcomes, and short automated summaries of the kinds of tasks or features you asked for. Your chats, images, inputs, and outputs remain stored to provide the Service to you.

Regardless of this setting, your data is always stored as described in "Information We Collect" in order to provide the Service. The "Improve Atmita" setting controls whether our team reviews that content for improvement purposes.

Aggregate and account-level usage metrics are always collected under both settings to maintain the Service, enforce usage limits, process billing, and understand overall usage patterns. The setting does not prevent automated processing by the Service or limited access where needed for security, abuse prevention, legal compliance, billing, or support requests you submit.

How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Manage your account and usage limits
  • Process subscriptions, renewals, cancellations, and payment issues
  • Send you important updates about the Service
  • Deliver push notifications if you enable them
  • Run AI features, integrations, stored credentials, and automations at your direction
  • Improve the Service (if you have enabled "Improve Atmita," we may review your content for this purpose; otherwise we rely on usage metrics and automatically generated signals as described in "Your Privacy Controls")
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We always collect usage metrics to maintain and improve the Service. We do not use your data for advertising. We do not send marketing emails. We may send transactional emails about your account, subscription, payment status, price changes, security, or important Service changes.

AI and Data Processing

Our Service uses AI to process your requests, automate tasks, generate images, cover images, and videos, transcribe voice messages and audio, generate spoken audio, watch and summarize videos, and perform web searches. When you use AI features, your prompts, messages, files, audio, video, images, tool results, and other relevant context may be sent to third-party AI providers to generate responses. These providers currently include Anthropic (Claude), OpenAI, Google (Gemini), ElevenLabs, and BytePlus, though we may change, add, or remove providers at any time.

When you use image or video generation features, your prompts, any reference images or videos you provide, and relevant context are sent to AI providers to create images or videos. Generated images and videos may be stored in our database and storage buckets, and media you choose to publish or share may be copied to publicly accessible storage. When you use voice input, or ask your agent to transcribe an audio or video file, that audio or video file is sent to an AI provider for transcription. When you ask your agent to watch or summarize a video, the video link or video file you provide is sent to an AI provider for analysis. When you use AI web search, your search queries are sent to external search services through these providers.

Your content is processed to provide the Service to you. We do not use your content to train our own AI models. Third-party AI providers may have their own data handling policies, which we encourage you to review.

Third-Party Integrations

The Service allows you to connect third-party accounts (such as Gmail, GitHub, Google Calendar, Slack, and others) through Composio, an integration platform. When you connect a third-party account:

  • You are redirected to the third-party service to authorize access via OAuth. Composio handles the OAuth flow and stores the resulting access tokens and credentials on its infrastructure - we do not store those OAuth tokens.
  • Your user identifier is shared with Composio to manage your connections and execute actions on your behalf.
  • When the Service performs actions on a connected account (such as sending an email or creating a calendar event), the action parameters are sent to Composio, which executes them using your stored credentials.
  • For integrations that use API keys, bearer tokens, or similar credentials instead of OAuth, the authentication values you provide may be sent to and stored by Composio.
  • If you store API keys, usernames, passwords, or other credentials directly in Atmita, we store them in our database and may retrieve them for AI tools and automations you request.
  • Data your agent retrieves from a connected account at your direction or through your automations - such as emails, calendar events, messages, or files - may be processed by the Service and included in AI prompts, which means it may be shared with third-party AI providers as described in "AI and Data Processing".

You can disconnect third-party accounts and remove saved credentials from Settings where supported. Disconnecting removes the connection reference from our database. For deletion of credentials stored by Composio, you may contact them at [email protected].

Your use of connected third-party services is also subject to those services' own terms and privacy policies. Composio's privacy policy is available at composio.dev/privacy.

Agent Memory and Logs

When you use AI agents and automations, the Service stores execution logs and agent memories. This includes:

  • Records of automation runs and their results
  • Agent memory logs that help the AI maintain context across sessions
  • These logs may be included in future AI prompts to improve the relevance of your automations

You can view and manage your agent logs within the app.

Matching and Shared Conversations

Matching helps your agent find people with relevant needs, offers, or shared interests. Discovery is on by default for every account, including accounts with Improve Atmita disabled: the Service tells you in the app once your card and posts are published, and you can turn discovery off at any time in People. Your agent uses your Library and activity to create and maintain a Matching profile card and posts, and searches other users' cards and posts through a shared discovery automation. For existing accounts with Improve Atmita enabled, we may also use the Library to create an initial card and posts.

Matching is anonymous by default: your name is stored on your card but hidden from other users and their agents during discovery. Posts are designed to omit names, contact details, company names, and other identifying details. Other agents can read the published card and posts and show them to their users in suggestions. Descriptions of your work, location, or needs may still allow someone to infer who you are; anonymity is not a guarantee that you cannot be identified.

The Service checks claims against your Library, connected accounts, and public sources and displays verification levels. These levels describe the available evidence and are not guarantees of identity, accuracy, or suitability. The underlying private evidence is not published with your posts.

You or your agent may send a connection request. Sending reveals the sender's card name and published profile to the recipient; accepting reveals the recipient's card name to the other members. The request and resulting conversation may be in an existing group. Messages, the matched posts, and the shared explanation become available to the conversation's members and its group agent. A group agent's access to Library information and connected accounts follows the conversation's permissions. Inactive recipients may receive a transactional email containing the sender's profile and request message.

You can turn Matching discovery on or off and change Anonymous in People, review your card and posts, ask your agent to correct them, and delete posts. Turning Matching off removes your card and posts from discovery and declines pending requests; it does not undo information already shared in suggestions or conversations. Improve Atmita and Matching are separate controls. Matching activity and verification use credits under the Service's normal usage rules.

Agent Email

Each account is assigned an agent email address on our email domain (for example, [email protected]). The first part of the address may be derived from the name we receive from your authentication provider. This address lets your AI agent receive email and, at your direction, send email. When you use agent email:

  • Email sent to your agent address - including sender and recipient addresses, subject lines, message bodies, headers, and attachments - is processed and stored in our database. Supported attachment types may be saved to your files in the app.
  • Content from email received at your agent address may be included in AI prompts to run your email-triggered automations, which means it may be shared with third-party AI providers as described in "AI and Data Processing".
  • When your agent sends email, the outbound message content, recipients, and any attachments you direct it to include are stored so conversations can be threaded and reviewed in the app.
  • Email routing and delivery are handled by third-party email infrastructure providers (currently Cloudflare), which process email content in transit.

Anyone who knows your agent address can send email to it, and email received there may contain personal data about the sender or others. If you would like your agent address suspended or its stored messages deleted, contact us at [email protected].

Personal WhatsApp

You can optionally link your personal WhatsApp account to your agent as a companion device. Linking is your choice and can be undone at any time. When you link WhatsApp:

  • The linked session runs on our own servers, and we store your WhatsApp chats, contacts, and the last 90 days of messages in our database so your agent can read and search them; older messages are deleted automatically. Attachments are fetched from WhatsApp only when your agent opens them, and the keys for the linked session are stored encrypted. We also keep a short per-message log entry (sender, chat, and a truncated text preview) used to trigger your automations and prevent duplicate processing.
  • Content of WhatsApp messages you receive may be included in AI prompts to run your WhatsApp-triggered automations, and chats your agent reads at your direction may be included in AI prompts, which means it may be shared with third-party AI providers as described in "AI and Data Processing".
  • Messages your agent sends appear in your WhatsApp as you, and are sent only at your direction or through automations you configured.
  • Linking an unofficial companion client is not endorsed by WhatsApp; while normal conversational use is designed to look like WhatsApp Web, WhatsApp could restrict accounts that use it, and you accept that risk by linking.

Unlinking, in Atmita or from your phone's Linked devices list, ends the session and deletes the chats, contacts, and messages we stored for it. To have your WhatsApp log entries deleted too, contact us at [email protected].

Numbers linked before October 2026 were linked through Unipile, which hosted that data in the European Union as a data processor (unipile.com/privacy-policy). Those links are moving to our own servers: once you relink, or a week after we ask you to, the Unipile link is deleted along with the data Unipile held for it.

Push Notifications

With your permission, we may send push notifications to your device about automation results and other Service updates. This requires:

  • Your explicit consent via the browser notification prompt
  • Storage of your push subscription endpoint, browser push keys, user agent, and active status in our database

You can disable push notifications at any time through your browser or device settings.

Data Storage and Security

Your data is stored and processed using third-party infrastructure providers, currently including Supabase for database, authentication, and storage, and Google Cloud for backend services. We use encryption for data in transit (TLS/SSL). We implement access controls and authentication safeguards to protect your data.

While we take reasonable measures to protect your information, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

Data Sharing

We do not sell your personal information. We may share your information with:

  • AI Providers: Third-party AI providers (currently including Anthropic, OpenAI, Google, ElevenLabs, and BytePlus) receive your prompts, audio, video, and other content as necessary to provide AI features
  • Integration Provider: Composio receives your user identifier, authentication values where applicable, and action parameters when you use connected third-party accounts, and stores credentials for those accounts (see "Third-Party Integrations")
  • Messaging Infrastructure: Unipile, only for personal WhatsApp numbers linked before October 2026 and until they move to our own servers (see "Personal WhatsApp")
  • Payment Providers: MyFatoorah processes web payments and card vaulting, and receives information necessary to complete and renew transactions; Apple processes purchases made through the iOS app, and we exchange transaction and subscription information with Apple to validate and manage those purchases
  • Email Provider: Transactional email providers, currently Resend, help us send account, billing, and Service emails
  • Email Infrastructure: Third-party email infrastructure providers (currently Cloudflare) route email to your agent address and deliver email your agent sends, and process email content in transit (see "Agent Email")
  • Analytics and Network Providers: Service analytics, IP lookup, and geolocation providers may receive technical data such as IP address, user agent, referrer, and event metadata
  • Code Execution Provider: When your agent runs code or processes files in a sandbox, a third-party sandbox provider (currently E2B) may receive the code, the files, images, and repository contents used in that work, and may hold sandbox files and state for a period of time after use
  • Infrastructure Providers: Third-party infrastructure providers (currently including Supabase and Google Cloud) host and process your data
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Data Retention

We retain your data for as long as your account is active. Chat history, automation logs, generated images, payment records, integration records, saved credentials, agent email messages, and agent memories may be stored indefinitely while your account exists, as they are needed to provide ongoing Service functionality, billing, security, and audit history. If you would like specific data deleted, contact us at [email protected].

You can delete your account from the app's Settings. Account deletion is designed to remove your stored content and account records - including chats, automations and their run logs, files, generated images, agent memories, agent email messages, saved credentials, connection records, push subscriptions, and settings - along with your sign-in record. Even after deletion, we may retain certain records where we consider them necessary for legal, accounting, tax, security, or audit purposes - including payment and transaction records and security audit logs - and residual copies of your data may persist in backups or archived systems for a period of time.

Your Rights

Subject to legal and technical constraints, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Request a copy of the personal data we hold about you, where technically feasible

Note that we may be unable to delete data we are legally required to retain or data embedded in backups and archived systems.

To exercise these rights, contact us at [email protected]. We will respond to your request within a reasonable timeframe.

Local Storage

We use your browser's local storage and IndexedDB to maintain your session, save preferences (such as theme and layout settings), store local app state, remember landing-page attribution, keep anonymous analytics identifiers, and cache data locally for faster loading. This may include cached chat messages, feed images, UI state, notification preferences, and authentication state. We do not use your data for advertising.

Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it.

International Data Transfers

Your information may be transferred to and processed in countries other than your own, as our infrastructure providers operate globally. By using the Service, you consent to the transfer of your information to these locations.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated date. Continued use after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at [email protected].

Questions about this privacy policy? Email [email protected] and we'll get back to you.