Legal

Privacy Policy

How Atrium handles your information, including the vault items, notes, calendar events, lists, contacts and budgets we store but cannot read.

Last updated: September 2026

The short version

Your vault items, notes, calendar event details, lists, contacts and budgets are encrypted on your device before they reach us. We store ciphertext we cannot decrypt, and no employee, administrator or process on our side can read it. What we can see is the account and billing information you give us and the operational metadata needed to run the service, which is listed below and on our security page.

Information we collect

  • Account and billing data: your email address, account name, plan, and payment records.
  • Encrypted content: the ciphertext of your vault items, files, notes, attachments, calendar event details, lists, contacts and budgets, your wrapped (encrypted) keys, and a one-way value used to check your master password. None of this is readable by us.
  • Schedule rules: the time windows you attach to vault items (for example "weekdays 09:00–17:00"). The server must read these to enforce them; the item's content stays encrypted.
  • Calendar timing: the start and end times of events, repeat rules and reminder times. We need these to send reminders and expand repeating events. Event titles and details stay encrypted, and reminder emails contain only the time.
  • Structural metadata: sizes, timestamps, how folders nest, version counts and sharing relationships, needed to store and sync your data.
  • Audit metadata: an append-only log of events such as unlocks, shares and schedule changes, with the event type, item reference and time. Never content.
  • Usage information: standard log data such as IP addresses and request times.

What we cannot access

Your master password never leaves your device, and we store no key derived from it that could decrypt your data. There is no decrypt path for support staff or platform administrators, and no endpoint on our servers returns your decrypted content to anyone. If you belong to a Family, Business or Enterprise team, a sealed copy of your account key is kept for the team's owner and released to them only if they remove you or close the account; that release is enforced by our servers, not by encryption alone, and you accept it when you join (see the security page). On a Family account, the owner also holds a sealed recovery copy of the key of each account they set up for a child, so they can help the child back in; that recovery takes 24 hours, the child is emailed when it starts, and the child then chooses a new master password and Recovery Kit. Apart from these two cases there is no organization-level recovery. This also means we cannot recover your data if you lose both your master password and your Recovery Kit.

Support access

Our support team can view your account's settings and records read-only (for example your plan, members, billing history and audit log), never the content you encrypt. They can make changes to your account or sign in as the account owner only when the owner has turned support access on for them. Every grant and every support session is recorded in your audit log and emailed to you, and support tools have no way to decrypt your data.

How we use what we do have

  • To deliver the service: storing and syncing your encrypted data, enforcing schedule windows, relaying shared items, sending calendar reminders, and sending account emails (sign-in codes, billing notices and notifications).
  • To provide accountability: your account's audit log, kept according to your plan.
  • To operate billing and respond to support requests.
  • To monitor platform health and prevent abuse.

Polls, invitations, registries and forms

These features exist to collect answers from people who don't have an account, so some of their data is not end-to-end encrypted: to show a public page and send emails, our servers can read what you publish and the names and email addresses of the people you invite. That data is stored encrypted on our servers, and our systems can read it to run the page and the emails. Fields that a page marks as sealed (for example dietary needs on an invitation, or answers to a private-mode form) are encrypted in the guest's browser so that only you can open them. Each app shows a "What we can see" sheet with the details.

For the people you invite or who answer your pages, we act on your behalf as a service provider. We keep delivery records (sent, bounced, complained) for 90 days and consent records for 3 years after the last message. Unsubscribes are kept as a one-way fingerprint of the address, never the address itself, so we can keep honouring them. Guests can unsubscribe from any message, and can ask the host to delete their answers. Open and click counting is off unless the host turns it on for a message, and the unsubscribe page says when it was on.

Data retention and deletion

Audit-log retention and note version history depend on your plan and are listed on the pricing page. Items and notes you delete stay recoverable in the trash for the period your plan allows. If a payment can't be collected within 24 hours or a cancelled plan runs out, the account is suspended and permanently deleted 30 days later unless it is renewed; a trial that ends without a subscription is deleted 1 day after it ends. See the terms. When a team member is removed, their account is deleted and what they stored in the team is handed to the team's owner; when the owner deletes the account, every member's account is deleted with it. When you delete your account, your ciphertext, encrypted files and wrapped keys are purged; billing records are kept as required by law.

Sharing

We do not sell your data. We share it only with the infrastructure providers needed to run the service (hosting, email delivery and payment processing), each bound to process it only on our behalf. For your end-to-end encrypted apps, they only ever hold ciphertext. Some data is not end-to-end encrypted and is processed in the clear:

  • Our email provider receives the messages we send and the addresses we send them to: account emails (sign-in codes, billing notices, notifications and reminder times), and the invitations, poll, form and booking messages you send to your guests, with whatever content you put in them.
  • PayPal processes your payment details (card or PayPal account, billing name, address and country) and the amounts you pay. We receive payment records from PayPal, never your full card number.
  • Our hosting provider stores the guest-facing data described above under "Polls, invitations, registries and forms", which our systems can read to run those pages.

Contact

Questions about this policy? Contact us.