Loading

Privacy Policy

Last updated: August 28, 2026

This policy explains what data Atomo (atomo.dev) collects, why, and what your rights are. The short version: we collect what's needed to run your workspace, we use two strictly necessary cookies and no tracking, and we never sell your data.

1. Who's responsible

Atomo is operated by atomo.dev, based in Austria, which is the data controller for the personal data described in this policy. For any privacy question or data request, contact us at hello@atomo.dev.

2. What we collect

  • Account data: your email address, display name, and a securely hashed password (argon2id — we never store the password itself).
  • Your content: the spaces, sections, entries, comments, captures and uploaded files you (or your connected agents) put into your workspace.
  • Agent keys and attribution: named keys you create for AI tools, stored hashed, and the record of which account or agent made each change.
  • Technical data: server logs (IP address, timestamps, requested routes) kept briefly for security and debugging.

3. Cookies

Atomo sets two first-party cookies, both strictly necessary to run the service: an HttpOnly session cookie that keeps you signed in, and a CSRF security cookie that protects your sign-in and edits against cross-site abuse (set when you first submit a form). Neither tracks you. There are no analytics cookies, no advertising cookies, and no third-party trackers on this site — which is why you don't see a cookie banner.

Fonts and every other page asset are served from our own domain; simply browsing this site sends no request to any third-party service.

4. Statistics without cookies

On our public pages (the landing page, blog, docs and these legal pages — never inside your workspace) we count visits ourselves, first-party and without cookies: nothing is stored or read on your device, and there is no fingerprinting. Our server counts a page view, which button was clicked, how far the landing animation was watched, the referring site, and a coarse screen-size class (phone/tablet/desktop).

To tell visitors apart within a single day we compute a hash of your IP address and browser identifier together with a random salt. The salt is destroyed and replaced every 24 hours, which makes recognising the same visitor across days technically impossible; your raw IP address and browser identifier are never stored for statistics. Raw counting data is deleted within 30 days, after which only aggregate totals (numbers per day) remain. If your browser sends a Global Privacy Control or Do Not Track signal, we count the page view without any visitor hash at all.

We do this under our legitimate interest in understanding whether our public pages work (Art. 6(1)(f) GDPR). Because nothing is stored on your device and no profile of you is ever built, no consent banner is required — and none is shown.

5. How we use your data

  • To provide the service: storing and displaying your workspace to you and the agents you authorise.
  • To secure your account: session management, rate limiting, and abuse prevention.
  • To send transactional email — verification, password reset and similar — through our own mail service (Sendmails, hosted on our EU server — no third-party email provider). We don't send marketing email without your consent.
  • For optional AI features (such as writing suggestions): the relevant text excerpt is sent to an AI provider solely to generate the result; we don't use your content to train models.

6. What we don't do

  • We don't sell your data or share it with advertisers.
  • We don't read your workspace content except as needed to operate the service, investigate abuse, or when you explicitly ask us to help.
  • We don't profile you or track you across other sites.

7. Sharing and processors

Your data is shared only with the infrastructure providers needed to run Atomo — hosting, email delivery, and (for the optional features above) an AI provider — each bound by data-processing agreements. Agents you connect via your own keys act under your control and are your choice.

If you subscribe to a paid plan, checkout and payment are handled by Polar (Polar Software Inc., USA) as merchant of record: Polar receives the details needed to process the purchase — your name, email, billing country and payment method — and tells us that your subscription is active. We never see or store your full payment details. Transfers outside the EU are covered by EU standard contractual clauses.

8. Retention and deletion

We keep your data for as long as your account is active. When you delete content it is removed from the live system; when your account is closed, your account data and content are deleted, with residual copies in backups expiring on their regular schedule. Server logs are kept only briefly.

9. Your rights

Under the GDPR and similar laws you can request access to, correction of, export of, or deletion of your personal data, and you can object to or restrict certain processing. Write to us and we'll act on it promptly. You also have the right to complain to your local data-protection authority.

10. Security

Passwords are hashed with argon2id, sessions are server-side with HttpOnly cookies, connections are encrypted in transit, and every AI tool gets its own revocable key rather than your password. No system is perfectly secure, but we treat security as a feature, not an afterthought.

If a breach affects your personal data, we'll notify the competent authority and — where it puts you at high risk — you as well, without undue delay, as the GDPR requires.

11. Changes to this policy

If this policy changes materially, we'll notify you before the change takes effect. The date at the top always reflects the latest revision.

12. Contact

Privacy questions and data requests: hello@atomo.dev.

Atomo — the workspace your AI agents live in · MCP docs