Atona/How it works/Privacy
Privacy

How Atona keeps your data private.

Some things never reach AI. Some things never get stored. And anything that does, you can read, export, or delete — anytime.

In this guide: how sensitive content is recognized and held back, how memory ages out, what you control, and what Atona will never do.

What it does

Privacy isn't a feature — it's the foundation. Atona recognizes sensitive information before any AI sees it, ages routine memory out on a schedule, isolates every user's data, and gives you full visibility and control over the rest.

How Atona protects you

01

Sensitive content never reaches AI

Banking, medical, legal, government, and identity information is recognized as it arrives — and held back. It's never sent to any AI model, in the cloud or on your device.

02

Memory ages out on a schedule

Routine notes are pruned after about 90 days. Sensitive content is never stored at all. Standing preferences last until you change them.

03

Your data is yours alone

Every user has their own private, encrypted space. Atona never mixes data between users. You can export or delete everything, anytime.

04

Nothing is used to train AI

Your messages, calendar, contacts, and memory are never used to train an AI model — yours, ours, or anyone else's.

05

You're always in control

Pause Atona anytime. Require approval before any external message. Add anything to a "never touch" list. The off switch is always one tap away.

06

Honest about what's happening

Every action Atona takes shows up in your morning brief and your activity log. Nothing happens silently.

What you control

Sensitive list

Words, contacts, or domains Atona must never read or reply to.

Retention window

How long routine memory lives. Shorter or longer than the default.

Review before sending

Require approval for any outbound message — once, for a topic, or always.

Pause everything

One toggle stops all automation. Atona goes silent until you turn it back on.

Export your data

Download everything Atona knows about you. Yours to keep.

Delete your data

Wipe specific memories, specific contacts, or everything. No questions asked.

What Atona will never do

Common questions

Who at Atona can read my data?

Nobody. Not a support agent. Not a moderator. Not the founder. Atona is automated end-to-end — there is no human pipeline that touches your mail, your calls, or your memory. Your data is encrypted in your own private space, scoped to your account, and the system is built so that the only one who reads it is the assistant working for you.

What if Atona sends something wrong?

You see it the moment it happens — you're CC'd on every email and forwarded every text Atona sends on your behalf. Then you can recall, revise, or apologize from any channel by just asking. The confidence threshold lets you tune how cautious Atona is: set it high and it drafts instead of sending. New contacts always start with a draft for you to review.

Does the recipient know they're talking to an AI?

Yes. Atona identifies itself as your assistant, every time. Voice calls open with an introduction. Emails are signed by your assistant, not by you. This is a hard rule — not a setting you can turn off.

Are voice calls recorded?

Calls Atona places or answers are transcribed and summarized so you have a record of what was said. Transcripts live in your private space, age out on the same schedule as the rest of your memory, and are deletable anytime. When the law requires disclosure, Atona discloses that the call is being recorded.

Can someone impersonate me through Atona?

No. Atona only takes instructions from you — verified through your account and the channels you've connected. It will never act on instructions buried in an inbound email, text, or call telling it to send money, share a password, or contact someone on your behalf. Social engineering against the assistant is rejected by design.

What about people I email — do they need to consent to AI?

Every message Atona sends carries a clear signature identifying your assistant. Recipients can opt out at any time: replying "stop", asking to talk to you directly, or telling Atona to leave them alone all pause it for that contact and escalate to you. Opt-outs are honored permanently.

What if law enforcement asks for my data?

We require valid legal process — a subpoena, court order, or warrant — for any data request. We'll notify you of the request unless we're legally prohibited from doing so. And the most sensitive categories (banking, medical, legal, identity) are never stored in the first place, by design — meaning there's nothing for us to produce.

What counts as sensitive?

Banking, tax, medical, legal, government, and personal identifiers — social security numbers, account numbers, dates of birth, health information, credentials. The full list is intentionally broad.

How is sensitive content actually recognized?

A combination of pattern rules and a dedicated classifier checks every incoming message before any AI processes it. If anything looks sensitive, the message is held back and never sent through an AI model.

Does Atona ever store the original sensitive message?

The message stays in your inbox, untouched. Atona notes that a sensitive message exists so you know about it — but never stores the contents.

Where is my data hosted?

In a private, encrypted space tied to your account. Not shared with other users. Not pooled into any shared dataset.

Can I see what Atona has remembered about me?

Yes. Your memory is fully visible, exportable, and deletable. Nothing is hidden from you.

Is my data used to train AI?

No. Never. Not by us, not by anyone we work with.

What happens if I delete my account?

Everything goes — memory, history, preferences, the dedicated email and phone number, transcripts. Permanently, within 30 days.

Related guides

Ready to try Atona?

Free during private beta.

Get early access