Your data.
Your rules.
We’re upfront about what we collect, who processes it, and the single toggle that controls whether our team can read it. The details below are pulled straight from our Privacy Policy and Security overview — no marketing gloss.
The six things worth knowing.
Each card maps to a specific commitment in our Privacy Policy. Tap through if you want the legal version.
One toggle controls content review
We show this to you on first run. The “Improve Atmita” setting in Settings is the only switch that determines whether our team can read your chats, prompts, images, and Automation inputs/outputs. Turn it off and we keep only usage metrics (message counts, credit usage). Your content stays stored to run the Service for you.
Your content lives in our Supabase
Chats, agent memories, Automation logs, generated images, and feed items are stored in our Supabase database (US region, hosted on Google Cloud and AWS). Per-row RLS policies scope data to your account, and our team only reaches in under the opt-in toggle above — or for security, abuse-prevention, billing, and support requests you submit.
Frontier AI — never trained on you
We route between Anthropic (Claude) and OpenAI per task, and send video, voice, and video-generation work to Google (Gemini), ElevenLabs, and BytePlus. Anthropic and OpenAI run under enterprise terms that forbid using your content to train shared models. Atmita itself doesn’t train any models on your data — ever.
Tool connections via Composio, revocable anytime
When you connect Gmail, Slack, GitHub, or any of 1,000+ tools, the OAuth flow is handled by Composio — tokens are stored on their infrastructure, not ours. We keep the connection reference and your account label. Disconnect from Settings and the token becomes unusable; pending Automations pause immediately.
Encrypted in transit and at rest
TLS on every public endpoint (Supabase + Google Cloud Run defaults). AES-256 at rest for our primary Supabase database, with keys managed by the cloud provider's KMS. Composio handles encryption of any OAuth tokens it stores on your behalf.
Honest about our compliance stage
Atmita is an early-stage product. We follow security practices appropriate to our stage, but we don’t yet hold SOC 2, HIPAA, or ISO 27001 certifications — and we won’t claim them until we do. If your purchase decision depends on a formal certification, email [email protected] and we’ll discuss timeline and what we can share today.
Every third party we send your data to.
Honest answers to the questions buyers actually ask.
Only if the “Improve Atmita” toggle in Settings is on (the default at signup, which we surface to you on first run). Turn it off and we’re limited to usage metrics — message counts, credit usage. We may still access your data for operational reasons such as security, abuse prevention, billing, and support requests you submit, regardless of the toggle.
No. Atmita does not train any models on your content. Anthropic and OpenAI are contracted under enterprise terms that forbid training on customer inputs. Both providers also offer zero-retention configurations for sensitive inference traffic.
In our Supabase database (US region). Backend services run on Google Cloud (us-central1). Generated media you choose to publish or share may be copied to publicly accessible storage buckets at your direction. EU data residency isn’t available today — email [email protected] if your use case needs it.
OAuth tokens for Gmail, Slack, GitHub, and the rest are stored by Composio on their infrastructure, not ours. We hold the connection reference (which account is linked) but never the token itself. To delete tokens stored at Composio you can email [email protected]. For API-key integrations you save directly in Atmita, those values are stored in our database with row-level security.
For data deletion, email [email protected] with the specifics. Account-level data is removed from our active database; backups are purged according to our Supabase plan’s retention. See the Privacy Policy for the full data-retention picture.
Email [email protected] with details and reproduction steps. We’ll acknowledge as soon as we can, work on a fix, and keep you updated through resolution. No paid bug bounty today, but we’re happy to credit reporters publicly (with permission) once a fix has shipped.
For the full detail, the source documents.
Your tools. Your rules.
One toggle. Every page in plain English.

