Home / Legal / Privacy Policy
LegalPrivacy Policy
What ATNOS collects, why, who it is shared with, how long it is kept, and the rights you hold over it.
Sections
Who we are
ATNOS Technologies Inc., 1 Market Street, Suite 3600, San Francisco, CA 94105. Data questions go to privacy@atnos.ai.
Account information
What you give us to create and run a workspace.
Usage data
How the workspace itself is used, and what we keep from that.
OAuth permissions and connected credentials
The section specific to a platform that acts inside your own accounts.
Third-party integrations
Google, Meta, commerce and CRM, AI model providers.
Cookies and analytics
Covered in full by the Cookie Policy.
Lawful basis
Why each category of processing is permitted.
Data retention
Full schedule below.
Your rights
Access, rectification, erasure, restriction, portability, withdraw consent, complaint.
International transfers
Standard Contractual Clauses and the UK Addendum.
Security
Summarised here, detailed on the security page.
Children
The service is not directed to children.
Changes and contact
How we notify you of material changes.
Google user data and Limited Use
ATNOS's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access. Only the scopes required by the features you enable: advertising data from Google Ads, traffic and conversion data from Google Analytics, search performance from Search Console, and listing data from Business Profile. The full per-service breakdown, including what is read and what is written back, is on Connected access.
Why we access it. To plan, prepare and report on the marketing work inside your own accounts. Nothing that changes publicly visible material is executed without your approval.
What we never do with it. We do not transfer it to third parties except as needed to provide the features you enabled, to comply with applicable law, or as part of a merger or acquisition. We do not use it for advertising. We do not use it to train generalised models. No human reads it except with your explicit permission, for security purposes, or where the law requires it.
How long we keep it. Access and refresh tokens are destroyed immediately on disconnection or deletion. Everything else follows the retention schedule below.
Retention schedule
| Category | Period |
|---|---|
| OAuth access and refresh tokens | Destroyed immediately on disconnection or deletion |
| Account and workspace records | Life of the account plus 30 days |
| Campaign, analytics and CRM data | 25 months, then aggregated irreversibly |
| Application and security logs | 12 months |
| Audit logs | 12 months (longer under an enterprise agreement) |
| Consent records | 24 months from the consent event |
| Invoices and financial records | 7 years, as required by tax law |
| Encrypted backups | 35-day rolling window |