AtomikMind logoAtomikMind

Legal

Privacy Policy

Last updated: 2 July 2026

This Privacy Policy explains how AtomikCore Software Technologies and Computer Solutions FZCO ("AtomikMind", "we", "us", "our") collects, uses, and protects personal data when you use AtomikMind (the "Service"), available at https://atomikmind.com.

AtomikMind gives knowledge creators a personalized AI assistant trained on their own content, together with an audience-intelligence dashboard. This policy covers three groups of people: creators (our paying customers), audience members (people who interact with a creator's AI assistant), and website visitors and prospects.

We are a UAE company, but the personal data processed through the Service is stored in the European Union (AWS Europe, Ireland). Where you are located in the EU, EEA, or UK, we handle your personal data in line with the General Data Protection Regulation (GDPR / UK GDPR).


1. Summary

  • We store personal data in the EU (AWS, Ireland region).
  • Creator content and audience conversations are used only to run that creator's assistant and to generate insights for that creator. They are kept isolated per creator.
  • We do not sell personal data, and we do not allow our AI providers to use your content or conversations to train their foundation models.
  • Audience members can use a creator's assistant anonymously — we don't require you to identify yourself.
  • Payments are handled by Paddle as Merchant of Record; we never receive or store your card details.

2. Who we are (Controller)

The data controller for the Service is:

AtomikCore Software Technologies and Computer Solutions FZCO (trading as AtomikMind) Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates Privacy contact: privacy@atomikmind.com

For personal data that a creator uploads or supplies (their content and the conversations held by their assistant), we generally act as a processor on that creator's behalf. In that case, the creator is the controller and our processing is governed by our Data Processing Agreement (see Section 13).


3. Personal data we collect

3.1 Creators (customers)

  • Account data: name, email address, organization or brand name, profile details.
  • Billing data: billing name, country, and transaction records. Card and payment details are collected and processed by Paddle, not by us.
  • Content you provide: the posts, articles, transcripts, documents, and other material you upload or authorize us to ingest so we can train and operate your assistant. This content may itself contain personal data (for example, names mentioned in your posts).
  • Usage data: dashboard activity, feature usage, logs, and diagnostic data.
  • Communications: messages you send us (support, email, onboarding calls).

3.2 Audience members (end users of an assistant)

Chatting with a creator's assistant is anonymous by default — we do not ask you to log in or provide your email.

  • Conversation content: the questions and messages you send to an assistant, and the responses generated.
  • Technical data: IP address, device and browser type, approximate location derived from IP, and timestamps, used for security, abuse prevention, and reliability.
  • If you voluntarily include personal information in a message (for example, your email in a question), that information is processed as part of the conversation.

Conversation content is used to generate the assistant's reply and, in aggregated and de-identified form, to produce the audience-intelligence insights shown to the relevant creator (for example, clusters of common questions and content gaps).

3.3 Website visitors and prospects

  • Analytics and cookie data when you browse our website (see Section 12).
  • Prospect data where we contact creators about the Service using publicly available professional/business contact details (name, professional role, business email, public social profile), on the basis of our legitimate interest in B2B outreach. You can opt out of any further contact at any time.

4. How we use personal data and our legal bases

PurposeData usedLegal basis (GDPR)
Provide and operate the Service (accounts, assistants, dashboard)Account, content, usage, conversation dataPerformance of a contract; legitimate interests
Process payments and manage subscriptions (via Paddle)Billing dataPerformance of a contract; legal obligation
Generate a creator's audience-intelligence insightsAggregated conversation dataLegitimate interests (of the creator); performance of contract
Security, fraud and abuse prevention, reliabilityTechnical and usage dataLegitimate interests; legal obligation
Customer support and service communicationsAccount and communications dataPerformance of a contract; legitimate interests
Product improvement and troubleshootingUsage and diagnostic data (minimized)Legitimate interests
B2B marketing and outreach to prospective creatorsProspect dataLegitimate interests (with opt-out)
Comply with law and enforce our termsAs requiredLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to this processing (see Section 10).


5. How your content and conversations are used with AI

This is central to how AtomikMind works, so we want to be explicit:

  • Per-creator isolation. Each creator's content and the conversations held by their assistant are kept logically segregated. One creator's data is not used to answer another creator's audience, and is not pooled into a shared model.
  • No third-party model training. We use Anthropic (for language models) and Voyage AI (for search reranking) to operate the assistants. These providers process your content and conversations only to return results to us and do not use them to train their own foundation models. We do not train any general-purpose model on your data.
  • Transparency. Assistants are presented as AI. They never impersonate the creator, and answers can cite the source content they draw from.
  • We do not sell personal data or content to anyone.

6. Who we share personal data with (sub-processors)

We share personal data only with service providers who help us run the Service, under contracts that require them to protect it:

  • Paddle — payments, billing, tax, and Merchant of Record services.
  • Amazon Web Services (AWS) — cloud hosting and storage (Europe, Ireland region).
  • Anthropic — large language model inference (Claude Haiku and Claude Sonnet).
  • Voyage AI — search result reranking.

We may also disclose personal data where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice where required).

An up-to-date list of sub-processors is available on request at privacy@atomikmind.com.


7. International data transfers

Personal data is stored in the European Union (AWS, Ireland).

Some processing is performed by providers located outside the EEA. In particular, AI inference (Anthropic) and reranking (Voyage AI) may involve processing in the United States. Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the data processing terms of the relevant provider. You can request a copy of the relevant safeguards at privacy@atomikmind.com.


8. How long we keep personal data

  • Account data: for the life of your account, and up to 90 days after account closure, then deleted or anonymized (except where we must keep records longer for legal or tax reasons).
  • Creator content: while your subscription is active. On account closure or on request, we delete your ingested content within 30 days.
  • Conversation data — security log: each turn (question, response, hashed IP) is stored in a short-term security log retained for 30 days for abuse and reliability investigation, then automatically deleted.
  • Conversation data — audience-intelligence questions: the question text and its vector embedding are stored separately, without IP or visitor identity, and retained for the life of the creator's account so we can produce the ongoing weekly reports and cross-week trend analysis. Deleted on account closure or on request.
  • Billing records: retained as required by applicable law (payment records are primarily held by Paddle as Merchant of Record).

We can adjust these periods on request where the law allows.

8.1 When you close your account

If you decide to leave, we delete your data. Within 30 days of your request or the effective closure of your account, we remove:

  • your ingested content (posts, PDFs, documents, transcripts, and every chunk and embedding derived from it),
  • every conversation your assistant held (both the 30-day security log and the audience-intelligence questions used for reports),
  • every audience-intelligence report generated for you, and
  • your account record.

We keep only the minimum records the law requires us to keep — for example, billing entries needed for tax compliance — and those are held by Paddle as Merchant of Record, not by us. To trigger deletion, contact privacy@atomikmind.com or support@atomikmind.com.


9. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, per-creator data segregation, and hosting with a major cloud provider (AWS) in the EU. No system is perfectly secure, but we work to protect personal data and to respond promptly to any incident, including notifying you and regulators where the law requires.


10. Your rights

Depending on your location, you may have the right to: access your personal data; correct inaccurate data; delete data; restrict or object to processing; withdraw consent; receive your data in a portable format; and lodge a complaint with a supervisory authority.

To exercise any right, contact privacy@atomikmind.com. We will respond within the timeframe required by applicable law (generally one month under the GDPR).

  • If you are in the EEA, you may complain to your local Data Protection Authority.
  • If you are in the UK, you may complain to the Information Commissioner's Office (ICO).
  • If your data is handled by us as a processor on a creator's behalf, we will direct your request to that creator, who is the controller.

11. Children

The Service is intended for creators who are 18 or older and is not directed to children. A creator's assistant is not intended for use by children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact privacy@atomikmind.com and we will delete it.


12. Cookies and similar technologies

The Service currently uses only strictly necessary cookies and similar technologies — for example, to keep your session secure. We do not currently use analytics or advertising cookies. If we add non-essential cookies in the future, we will introduce a consent banner and update this policy before doing so.


13. Creators as controllers; Data Processing Agreement

Where we process personal data on a creator's behalf (their ingested content and the conversations held by their assistant), we do so as a processor under a Data Processing Agreement (DPA) that forms part of our Terms of Service. The DPA sets out our commitments on confidentiality, security, sub-processors, data subject requests, and deletion. Creators can request the DPA at privacy@atomikmind.com.


14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date above and, for material changes, take reasonable steps to notify you.


15. Contact

AtomikCore Software Technologies and Computer Solutions FZCO (AtomikMind) Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates Privacy: privacy@atomikmind.com Support: support@atomikmind.com