Legal

Privacy Policy

How Atrium handles your information, including the vault items, notes and calendar events we store but cannot read.

Last updated: September 2026

The short version

Your vault items, notes and calendar event details are encrypted on your device before they reach us. We store ciphertext we cannot decrypt, and no employee, administrator or process on our side can read it. What we can see is the account and billing information you give us and the operational metadata needed to run the service, which is listed below and on our security page.

Information we collect

  • Account and billing data: your email address, account name, plan, and payment records.
  • Encrypted content: the ciphertext of your vault items, files, notes, attachments and calendar event details, your wrapped (encrypted) keys, and a one-way value used to check your master password. None of this is readable by us.
  • Schedule rules: the time windows you attach to vault items (for example "weekdays 09:00–17:00"). The server must read these to enforce them; the item's content stays encrypted.
  • Calendar timing: the start and end times of events, repeat rules and reminder times. We need these to send reminders and expand repeating events. Event titles and details stay encrypted, and reminder emails contain only the time.
  • Structural metadata: sizes, timestamps, how folders nest, version counts and sharing relationships, needed to store and sync your data.
  • Audit metadata: an append-only log of events such as unlocks, shares and schedule changes, with the event type, item reference and time. Never content.
  • Usage information: standard log data such as IP addresses and request times.

What we cannot access

Your master password never leaves your device, and we store no key derived from it that could decrypt your data. There is no decrypt path for support staff or platform administrators, and no endpoint on our servers returns your decrypted content to anyone. This also means we cannot recover your data if you lose both your master password and your Recovery Kit.

How we use what we do have

  • To deliver the service: storing and syncing your encrypted data, enforcing schedule windows, relaying shared items, sending calendar reminders, and sending account emails (sign-in codes, billing notices and notifications).
  • To provide accountability: your account's audit log, kept according to your plan.
  • To operate billing and respond to support requests.
  • To monitor platform health and prevent abuse.

Data retention and deletion

Audit-log retention and note version history depend on your plan and are listed on the pricing page. Items and notes you delete stay recoverable in the trash for the period your plan allows. If a trial or subscription ends, your account becomes read-only and your data stays intact; see the terms. When you delete your account, your ciphertext, encrypted files and wrapped keys are purged; billing records are kept as required by law.

Sharing

We do not sell your data. We share it only with the infrastructure providers needed to run the service (hosting, email delivery and payment processing), each bound to process it only on our behalf. Like us, they only ever hold your content as ciphertext.

Contact

Questions about this policy? Contact us.