Privacy Policy
Last updated: 12 August 2026.
Atrium is operated by WAVIISoft, LLC. This policy describes what the service holds about you, what it does not hold, where your information goes when you connect another tool, and what you can ask us to do about any of it.
It describes the product as it works today. Where a section says Atrium does not do something, that is a description of how the software is built, not only a promise about how it is operated.
What Atrium holds
Your account. An email address, a display name, a time zone, and the role your account carries. Accounts are created by invitation; there is no open sign-up.
Your passkeys. Atrium stores no passwords, because it does not use any. Signing in uses a passkey, which means your device keeps the private key and Atrium keeps only the corresponding public key, a credential identifier, and a counter. Nothing Atrium stores can be replayed to sign in as you anywhere.
What you write. Jots, topics, topic names and descriptions, relationships between them, and anything else you enter. This is your content and it stays yours.
What your connected tools return. If you connect a source, Atrium stores the items it reads from that source so it can assemble them around your work — see Connected services.
Sessions. A session cookie identifies your signed-in browser. It is stored in the database only as a hash, so the database does not carry anything that could be used as your session.
Operational records. Logs and durable events describing what the system did, so a fault can be diagnosed after it happens.
What Atrium does not hold
Atrium does not store payment details, and it does not run advertising, tracking pixels, or third-party analytics. There is no profile of you sold, shared, or built for anyone else's purposes.
The application itself sends nothing from your browser to a third party. Its content security policy confines every request the page makes to Atrium's own origin, so a script added by accident or by a dependency cannot quietly send anything anywhere. The one exception is deliberate and visible: the public landing page embeds a sign-up form hosted elsewhere, which is a document you choose to open rather than a request Atrium makes about you.
Who can reach your data
Your data reaches you alone. Atrium is single-owner: there are no shared workspaces, no team members to invite, and no view in the product that shows one person another person's content.
Administrators of your deployment can manage accounts, integrations, model providers, and settings, and can read operational records. They do not have a screen that shows them your jots, your topics, or the items your connections have pulled in.
Measurement, and why it carries no content
Atrium measures how the product is used — counts of things done, how long something took, which capability was called. These records carry identifiers, fixed categories, and numbers. They never carry what you wrote: not a jot's text, not a topic's name, not an email subject, not a file name.
Operational logs follow the same rule. An identifier can appear in one; your content cannot.
Product measurement goes further and carries no identifier either. Figures rolled across people are only kept once enough distinct people are behind them, on the reasoning that a sum over enough people is genuinely about none of them.
Connected services
Connecting a source is optional, and each one is connected by you, through that provider's own consent screen. Atrium supports GitHub, Microsoft 365, and Google.
When you connect a source, Atrium reads the items you have granted it access to — which may include messages, calendar events, files, issues, and pull requests — and stores them so they can be gathered around the work they belong to. Access tokens are stored encrypted.
Atrium does not post, send, or write anything on your behalf. For Google and Microsoft it asks only for read permissions, so it could not if it tried. The GitHub connection is the exception worth naming plainly: GitHub's permission model has no read-only option covering private repositories, so the access you grant there is broader than what Atrium uses.
You can disconnect a source at any time from Settings. Disconnecting revokes Atrium's access and stops any further reading. Items already gathered from that source stay in your account, where you can delete them, until you ask for the account itself to be deleted.
Artificial intelligence
Atrium uses models to name topics, decide which topic an item belongs to, summarise a topic, and compute embeddings used for matching. Doing that means sending the relevant text to whichever model provider your deployment has configured — which may be a hosted provider such as OpenAI or Anthropic, or a model running on your own infrastructure.
Which provider is used, and therefore where that text goes, is a configuration choice made by whoever operates your deployment. If no provider is configured, these features degrade rather than send anything anywhere.
Model output is never treated as fact. Anything a model proposes — a topic name, a filing decision — is a suggestion until a person accepts it.
Forms, and the identifier they carry
The waitlist and the feedback form are hosted by a third-party form provider, not by Atrium. What you type into either goes to that provider: Atrium stores nothing about someone on the waitlist, and keeps no copy of feedback you send. Which provider hosts them can change, so the form's own address is the honest place to look for who is receiving what you submit.
When you open the feedback form while signed in, the link can pass your Atrium account identifier to the form, so a report can be matched to the account that sent it. That identifier is an opaque value with no meaning outside Atrium — it is not your name, your email address, or anything that describes you. Opening the form while signed out passes nothing.
That provider's handling of what you submit is governed by their terms, not this policy.
Your device
Atrium installs as an application and keeps working through a lost connection. To do that it stores a snapshot of what you were looking at in your browser's own storage, on your device. Signing out clears it.
How long things are kept
Your content is kept until you delete it or your account is closed. Operational logs and durable records of what the system did are kept for a year by default and then aged out automatically.
Your choices
You can edit or delete your content at any time, disconnect any source from Settings, remove a passkey, and ask for your account and its data to be deleted. To make a request about your information, or to ask a question about this policy, use the contact address in the footer of this page.
Changes to this policy
If this policy changes in a way that affects what is collected or where it goes, the date at the top changes with it. Checking that date is the reliable way to tell whether anything has moved since you last read it.