Atomic Mail Privacy Policy
Last Updated: 23.09.2026
This Privacy Policy explains what personal data AtomicMail Systems OÜ ("Atomic", "we", "us") collects, why, who else can see it, how long we keep it and what choices you have. It covers Atomic Mail, the encrypted email service; Atomic Chat, the AI assistant; and Atomic VPN, the no-log VPN service — together the "Services" — and it replaces the separate privacy policies jpreviously published for Atomic Mail and for the chat service.
Detail specific to Atomic VPN is set out in the Atomic VPN Privacy Supplement at atomicvpn.io/privacy, which forms part of this Policy. Everything ecosystem-wide is here and applies to the VPN as well. Capitalised terms are defined in the Terms of Service, which this Policy accompanies.
The three Services share an account, a sign-in and a subscription. They do not share your data. Atomic Chat cannot access your mailbox, mailbox content is never sent to an AI provider, and Atomic VPN keeps no record of where you go. Section 2 sets out the boundary in full.
1. Legal framework
The data controller responsible for your personal data in all three Services is AtomicMail Systems OÜ, Harju tn 3 // Vana-Posti tn 2, Tallinn 10146, Estonia. There is no second controller. Privacy contact: support@atomicmail.io.
We are established in Estonia and process personal data under Estonian law and the General Data Protection Regulation. Where the GDPR applies, each purpose below has a legal basis: performance of a contract for your Account, automatic sign-in, the core features of each Service, subscriptions, and the transmission to AI providers that answering you requires; consent for marketing communications and for optional integrations, withdrawable at any time without affecting processing that already happened; legitimate interests for security, anti-spam and abuse prevention, service reliability and diagnostics; and legal obligation for tax, accounting and lawful requests. Residents of California and of other US states with comprehensive privacy laws have the rights described in Section 6.
2. Data we collect and how we use it
2.1 Separation of the Services
Atomic Chat cannot access or manage any message, draft, attachment, contact, alias, folder or setting in Atomic Mail. No interface, API, connector or permission exists through which it could, and none can be enabled by you, by us, or by a third party. Mail content and Chat Content are stored separately; neither is readable from, derived from, or used to personalise the other.
The shared account layer holds exactly this and nothing more: your Atomic Mail address and account identifier, your credentials and session tokens, your subscription status and entitlements, your account-level settings, your VPN device list, and account lifecycle events. No message, conversation, attachment or connection record sits there.
Signing in once signs you in to all three Services. Atomic Mail and Atomic Chat are served from the same domain, so one session covers both; Atomic VPN sits on its own domain with its own sign-in, and moving there passes a short-lived token. Either way, what is established is a single fact — that you hold a given Atomic Account. Each Service then authorises you against its own storage, and nothing carries mailbox, chat or traffic data across. Sharing a domain grants no access, and neither does crossing between domains: the boundary is enforced on our servers, not by the address in your browser.
Atomic VPN also accepts registration with Apple or Google. Such an account exists for the VPN alone, with no mailbox and no Chat access, and Atomic Mail and Atomic Chat cannot be used with an Apple or Google identity at all. If you hold both a VPN-only account and an Atomic Account, they are two separate accounts and we do not link them.
While you are connected, Atomic VPN carries whatever traffic your device sends, possibly including your use of Mail and Chat. The contents are encrypted between your device and the Service, and no connection record is created, so there is nothing to attribute to your Account or join to your mailbox. The separation holds in that direction too — not because we promise not to look, but because the data that looking would require is never written down.
2.2 Your Account and your subscription
Registration collects an optional name, which may be a pseudonym, your chosen email address and your password. You also receive a Seed Phrase, which we never receive, store or transmit, and without which we cannot recover your Account. We use this data to create and secure your Account, to sign you in across the Services, and to contact you about the Services in your Atomic Mail inbox.
A subscription attaches to your Account rather than to one Service, so one purchase unlocks the paid features of all three. We keep your plan, term, status and renewal date, and the transaction, receipt or invoice references from the payment provider. Payment is taken by Stripe, or by Apple or Google for purchases inside an application; they handle payment details under their own policies and full card numbers never reach us. Our billing records show that an Account holds a given plan — never what you did with it.
2.3 Atomic Mail
Your messages are stored in an encrypted User Vault in secure data centres. We cannot read their contents, which limits what we can produce for anyone (Section 5) and means we cannot restore your mailbox if you lose both your password and your Seed Phrase. Outgoing mail shows our IP address rather than yours.
We keep mail logs for 7 days, containing metadata such as the IP addresses of remote email servers and the SMTP sender and recipient addresses of messages sent and received, for troubleshooting and for combating spam and phishing.
AI features inside Atomic Mail may rely on local and third-party technologies and operate under the principles of data minimisation, no profiling and no persistent context; usage limits apply to prevent abuse. Nothing in your Vault is sent to an AI provider in the ordinary operation of the mailbox.
2.4 Atomic Chat
Atomic Chat necessarily works differently from the other Services: a model cannot answer a question it has not been given. Before setting out what that means in practice, here is what it does not mean — and why a profile of you cannot be assembled, by us or by anyone we send data to.
We build no profile of you. We infer no interests, traits or behaviour from your conversations, from your usage patterns, or from anything in Atomic Mail, and we do not use your Content to train, fine-tune or evaluate AI models, ours or our providers'. The only personalisation is the optional profile you fill in yourself: it contains exactly what you typed, and you can edit or delete it at any time. Embeddings derived from your content are used to retrieve material within your own conversations, never to segment or target you.
Nothing that leaves us identifies you. What travels to a provider is the text or file that one feature needs, and nothing else: no name, no Atomic Mail address, no billing details, no account identifier. The call arrives from Atomic, under our own credentials, alongside every other user's, and carries no field saying which person asked. [TBC — confirm with engineering that no per-user identifier is sent to any AI provider, including optional abuse-monitoring fields.]
There is no single context window. Each provider sees only what one feature sends, for one request or one conversation. Nothing from Atomic Mail, nothing from Atomic VPN and nothing from your other conversations is added to it, because the Services do not pool their data (Section 2.1). No combined record of you exists anywhere for someone to draw on — not at a provider, and not here.
Nothing comes back linked to you. We receive no user-level identifiers or analytics from these providers, and we do not join what they return to an identity beyond delivering it to the session that asked for it.
Profiling needs three ingredients: a stable identifier, continuity between requests, and data drawn from more than one context. The architecture withholds all three. That is a stronger guarantee than a promise not to profile, because it does not depend on our good behaviour.
With that established, this is what the Service handles.
You provide your account identifier and locale; your chat and search queries, pasted text, attachments, dictated audio and the text extracted from it, saved prompts and generated media; an optional profile, if you choose to fill one in; feedback and support messages; and the URL, title and content of web pages when you use Chat with Page. We collect automatically your IP address, for session security, anti-abuse and coarse location; device and session data; country-level location; usage and AI cost counters; crash and performance diagnostics; and any UTM parameters present at sign-up. We receive purchase confirmations from Apple, Google and Stripe, and data from a connected external service only where you connect one yourself.
We use this to deliver the Output you asked for, to operate and secure the Service, and to meet the legal obligations in Section 1 — and for nothing beyond that, as set out above.
2.5 Atomic VPN
Atomic VPN records nothing about what you do while connected: no browsing or download history, no traffic contents, no DNS queries, no originating or assigned IP address, no connection logs and no per-user bandwidth records. Routing requires your IP address to pass through our systems while the connection lasts, as it does for any internet connection; we do not write it to a log, attach it to your Account, or keep it afterwards.
What we do keep is a small account layer, kept separate from the network that carries your traffic: the devices signed in under your plan, so that the device limit can be enforced and you can sign a device out, and a fixed list of product-analytics events about the application itself. The VPN supplement lists every field, names the analytics and error-monitoring providers, and sets out the retention periods.
2.6 Our websites
When you visit our Website we process your IP address, browser and operating system, browser language, IP-derived location, the date and time, your referral source and the pages you visit — for troubleshooting and abuse prevention, to display the site correctly, and to measure our marketing. Browser user agents, visited pages, IP addresses and timestamps are kept in our logs for up to 7 days; other data is processed anonymously by a self-hosted analytics tool. The atomicvpn.io website is measured differently, with Google Analytics, as the VPN supplement explains.
If you contact support or subscribe to our newsletter, we process what you send in order to help you or to send it, and you can unsubscribe at any time.
2.7 How long we keep data
Website and mail logs, 7 days. Emails and Chat content, until you delete them or terminate your Account; deleted emails leave the Vault immediately and persist only in encrypted backups for up to 3 days. The optional Chat profile, until you edit or delete it. VPN activity, never recorded. VPN device records, while the device is signed in. Product analytics, up to 12 months; crash diagnostics, up to 90 days; support correspondence, up to 24 months. Sessions and tokens, until expiry or sign-out. Authentication challenges and rate-limit counters, short-lived.
We do not delete accounts for inactivity. Your Account and your data remain for as long as you keep the Account, whether or not you sign in and whether or not you pay.
When you terminate your Account, everything in it is permanently deleted, within 30 days at the latest. Two things survive: encrypted backups for up to three days, to which you have no right of access; and invoicing records, which Estonian accounting law obliges us to keep for seven years — billing details only, never the contents of a mailbox, a conversation or a session. Anonymous aggregate metrics that cannot be traced back to you may also remain. Terminating the shared Account terminates every Service reached with it; where a Service offers its own in-app deletion controls, you can remove its content without terminating the Account.
3. Data that goes to AI providers
Most Atomic Chat features send your Input to a third-party AI provider, because a model must process it in order to answer.
What is sent: the text of your messages and the current thread's history; page content, URLs and titles when you use Chat with Page; attachments, dictated audio and text extracted from them; data retrieved from a connected service at your instruction; your optional profile, as context; and, for media generation, your prompts and references to your media. What is never sent: the contents of your Atomic Mail Vault, your mail metadata, contacts, aliases or settings, your password or Seed Phrase, and your payment card details.
This transmission is part of delivering the Service rather than a separate permission we ask for. Your control is which features you use: a feature you do not use transmits nothing, and Atomic Mail is unaffected either way. We name every recipient in Section 4 so that the choice is an informed one. Where a feature runs on our own self-hosted models, your content does not leave our environment, and we say so in the application.
Do not submit to Atomic Chat content you are not comfortable having processed by the providers named below. Content that sensitive belongs in Atomic Mail, where it is encrypted and no provider sees it.
4. Data processors
Every processor named here is bound by a written data-processing agreement that limits it to our documented instructions, prohibits use of your data for its own purposes including advertising and model training, and requires protection consistent with this Policy. We do not sell personal data and do not share it with data brokers.
4.1 Our own infrastructure
Atomic Mail runs on our own servers in our own data centres, and Atomic VPN on its own network. Neither uses the AI, search, page-fetching, storage or integration providers listed below. Mail Vault content and VPN traffic never leave our environment.
4.2 Third-party processors
Section 2.4 explains why this list does not add up to a picture of you: what reaches a provider carries no identifier, each one sees a single request in isolation, and nothing comes back linked to you. Every processor named here is additionally bound by contract against using your data for its own purposes.
AI processing (Atomic Chat only): OpenAI, for generating responses, creating embeddings and transcribing audio; Anthropic and xAI, for generating responses; Voyage AI, for embeddings used in retrieval; AIMLAPI and the model providers operating under it — which may include Kling, ByteDance, Google, Alibaba, OpenAI and DeepSeek, and for which AIMLAPI is contractually responsible — for image and video generation and advanced reasoning; and Recraft, for image generation. None of these providers receives any Atomic Mail content.
Everything else: Apple, Google and Stripe for payments; [TBC] for transactional email delivery and newsletters; SerpAPI and Brave Search for search; Bright Data for fetching the pages your query refers to; ip-api.com, Google Translate and Google Knowledge Graph for geolocation and enrichment; Amazon Web Services for storing and processing files uploaded to or generated in Atomic Chat; Composio as integration broker, only where you connect an external account yourself; Sentry for error and performance data and self-hosted Prometheus for aggregate metrics; Google Analytics for the atomicvpn.io website; PostHog for Atomic VPN product analytics; Apple and Google as sign-in providers for Atomic VPN only; and accountants, lawyers and public authorities where legally required.
Some of these processors operate outside the European Economic Area, including in the United States. Where personal data is transferred out of the EEA, the United Kingdom or Switzerland, we rely on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses with additional safeguards where needed; ask us for the safeguards covering a specific transfer. If the company is ever merged, acquired or sold, personal data may transfer to the successor, which will remain bound by this Policy or one no less protective, and we will tell you beforehand.
5. Data disclosure
We comply only with requests from Estonian judicial authorities, after our lawyers verify that a request is valid and we are satisfied that compliance is undeniably our legal obligation. We refuse requests from the authorities of any other country and refer them to the Estonian authorities for mutual assistance. We never cooperate with voluntary surveillance programmes, and we disclose nothing to private third parties without a valid Estonian court order.
Our response to any request is bounded by our architecture rather than by our intentions: the Vault is encrypted beyond our reach, our logs are short-lived, and VPN activity is never recorded. No valid order can compel data we do not hold.
Security. We protect your data with TLS in transit with perfect forward secrecy, encrypted Vault storage, salted password hashes, hashed authentication tokens, access controls and rate limiting; access to production systems is restricted to a small number of authorised personnel bound by confidentiality agreements. Card data never reaches our servers. No system is perfectly secure, so use a strong, unique password and keep your Seed Phrase safe and offline — we cannot replace it. If a breach affects your personal data, we will notify the competent supervisory authority within 72 hours where the law requires it, and you directly without undue delay where the breach is likely to present a high risk to you.
6. Your privacy rights
You have the right to access the personal data we hold about you and receive a copy, to correct it, to have it erased, to restrict or object to certain processing, to receive a portable copy, and to withdraw consent at any time without affecting processing that already happened. We will not deny you service or degrade your experience for exercising these rights.
We can export what we hold, but we cannot decrypt your Vault, so exporting your mail happens in the application, where your keys are.
To exercise a right, write to support@atomicmail.io from your account address. We answer within 30 days and will tell you if we need a permitted extension; we verify requests through your account email rather than by asking for identity documents, and an authorised agent may act for you with written proof of authority. You may also lodge a complaint with your local supervisory authority or with the Estonian Data Protection Inspectorate.
Residents of California may request the categories and specific pieces of personal information collected, their sources, the purposes and the categories of recipients, and may request deletion or correction. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding twelve months. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have comparable rights, together with a right to appeal a decision on a request — reply to our response, or write to us with "Appeal" in the subject line.
No advertising and no tracking. Atomic is entirely ad-free in all three Services: we sell no advertising space, and nothing you write, ask or visit is used to target anything at you. Our applications contain no advertising SDKs and use no advertising identifiers, we do not track you across other companies' applications or websites, and we share nothing with data brokers — so no App Tracking Transparency prompt is shown.
One thing deserves naming rather than glossing over. The atomicvpn.io website loads Google's gtag.js in order to run Google Analytics (Section 2.6). It is a measurement tag rather than an advertising SDK, but it comes from an advertising company, and the same library serves advertising purposes elsewhere on the web. On our property the advertising features of Google Analytics are switched off — no Google signals, no remarketing audiences, no advertising reporting — the property is not linked to a Google Ads account, and no advertising identifier is collected. [TBC — confirm these settings in the GA property before publication.] The atomicmail.io website does not load it at all and uses a self-hosted analytics tool instead.
Cookies keep you signed in and serve the website analytics described above; blocking analytics cookies changes nothing about the Services, and we treat a Global Privacy Control signal as an opt-out of analytics.
Children. The Services are not directed to children below the minimum age set by the law of their country, as described in Section 1 of the Terms of Service. We do not knowingly collect personal data from them; if you believe a child has provided us with data, write to us and we will delete it.
7. Modifications to this Privacy Policy
We may update this Policy. Material changes are announced in the applications or by email at least 30 days before they take effect, and where the law requires new consent we will ask for it. The date at the top reflects the latest revision, and earlier versions are available on request.
Any change that would weaken Section 2.1 is material by definition, and a connection between Atomic Mail and Atomic Chat can only ever be opt-in, off by default and preceded by notice. We will not weaken the no-log commitment in the Atomic VPN Privacy Supplement.
Questions, or to view, amend or delete your data: support@atomicmail.io · AtomicMail Systems OÜ, Harju tn 3 // Vana-Posti tn 2, Tallinn 10146, Estonia
