atrium — Legal
legal/privacy.md

Legal

Privacy Policy

This policy explains what information atrium collects through the website, the desktop app, the iOS and iPadOS app, and the push relay, how that information is used, and what choices you have.

Last updated: September 29, 2026

Scope

This policy applies to the atrium website at getatrium.dev, the atrium desktop app, the atrium iOS and iPadOS app, the atrium push relay at push.getatrium.dev, and the public feedback tracker linked from the site.

atrium is operated by Skybot, LLC. This policy is written to describe the product as it exists today. If data practices change, this policy will be updated.

What We Collect

We currently collect or process the following categories of information:

  • Website analytics data, including page views, approximate device and browser information, referring URLs, and interaction events collected through PostHog.
  • Technical identifiers used by analytics tooling, such as cookies or similar browser storage, to understand site usage over time.
  • Information you choose to submit publicly through the feedback tracker or GitHub, such as issue text, screenshots, usernames, and any other content you include.
  • App data stored on machines you choose, such as workspace state, pane state, settings, scrollback, and related session metadata needed to make atrium persistent. A remote location stores the data it owns on that box.
  • If you turn on notifications in the iOS app, the push relay processes your phone’s Apple push token, delivery passes, encrypted notifications it cannot read, and the network address, user agent and time of each request, only to deliver notifications. See Push Notifications below.

How atrium Handles App Data

atrium is designed to keep core workspace and session state on machines you control. Local work stays on your Mac. When you add a Linux location, the app connects directly over SSH and that box stores its repositories, terminal sessions, scrollback, tasks, notes, and related configuration. atrium does not proxy that traffic or copy those repositories through an atrium-operated server.

The iOS app connects directly to the machines you pair it with, over your own network or your own tailnet. Conversations, terminals and approvals travel between your phone and your machine; they don’t pass through an atrium server. Current versions of the iOS app encrypt that connection with TLS 1.3 and accept only the paired machine’s own key, so another device on your network can’t read the traffic or pose as your machine. Your phone learns that key from the pairing code or, if it was paired before this encryption existed, the first time it connects after you update. Pairing keys are stored in your phone’s Keychain and on the paired machine.

The first time the iOS app needs its natural voices (Settings → Walk Mode → Voice), it downloads their voice model and pronunciation files once, from third-party model hosts such as Hugging Face and GitHub. As with any download, those hosts see your device’s network address and a standard request, such as the app’s user agent. No conversation content, pairing information or account data is sent. You can delete the downloaded files in Settings → Walk Mode → Voice → Delete voice data.

After you make a telemetry choice, the desktop app can send a small amount of telemetry to PostHog in two tiers. The core tier is limited to update checks and app-lifecycle events — including a periodic active-use heartbeat (version, OS, architecture, locale) that fires only while the atrium window is focused. The optional analytics tier covers feature usage, performance counters, and crash stack traces, and is off by default. Both tiers exclude file contents, command history, pane contents, browser URLs, and agent transcripts; the master switch disables both. Full details and the opt-out controls live in the telemetry documentation.

Push Notifications

Push notifications are optional, and the iOS app offers them only once it is paired with at least one machine. When an agent needs you and you aren’t using atrium on your phone or on your Mac, the Mac the agent runs on can send your phone a notification. Apple delivers notifications to iPhone and iPad apps only through its Apple Push Notification service (APNs), and only for a sender holding atrium’s APNs key, so your Mac hands each notification to a small relay we run, which passes it to Apple. In this section, “phone” also means an iPad running atrium.

Notifications are end-to-end encrypted. When you turn them on, your phone and each paired Mac agree on a key over the encrypted connection they already share; the key itself is never sent over any network. Your Mac encrypts each notification (such as the agent, project and command) before it leaves, and only your phone and that Mac hold the key.

To decide whether you’re using atrium on your Mac, atrium notes when you last clicked, typed, scrolled or moved the mouse in one of its windows there. Input in other apps doesn’t count. That time stays on the Mac and is never sent anywhere.

What the relay receives:

  • your phone’s Apple push token, which tells Apple which phone to wake;
  • the encrypted notification, which the relay can’t read. Every notification is padded to the same size and sent with the same priority and expiry;
  • an opaque tag, so a newer notification about the same session replaces an older one. The relay can tell two notifications are about the same session, but not which session;
  • a key identifier, which is the same for every notification one Mac sends your phone. It reveals nothing about the key, but it lets the relay tell which notifications came from the same Mac;
  • a delivery pass your phone gave the Mac, which proves your phone agreed to receive notifications;
  • the network address and time of each request, and the software details it carries (its user agent), as with any request on the internet.

About every few days your phone asks the relay for a new delivery pass. The relay sends the pass back to your phone through Apple, never in its reply, so only your phone can obtain one. Your phone gives passes only to Macs you still have paired, and each pass expires after 14 days.

The relay forwards each notification to Apple and reports whether Apple accepted it. It doesn’t store push tokens, delivery passes or notification contents. Its rate limits count requests per network address, and per phone using a one-way hash of the push token, for at most ten minutes. It has no user accounts and is not used for analytics or advertising. Apple receives your push token, delivery passes and the encrypted notifications in order to deliver them, under Apple’s own privacy policy.

You can turn notifications off in the atrium app (Settings → Notifications), in iOS Settings → Notifications → atrium, or for one device on your Mac (Settings → Locations → This Mac → Paired devices). Revoking your phone on a Mac stops that Mac’s notifications immediately. Removing a Mac from your phone deletes the key on your phone right away, and on the Mac too if it’s reachable. A Mac that can’t be reached may keep sending for up to 14 days, until its last delivery pass expires; your phone can’t open those notifications, so they may appear as a generic “New activity from your agents” alert. When no paired Mac is left, the app turns push notifications off and deletes its push token, delivery pass and keys.

How We Use Information

  • To operate, secure, and improve the website.
  • To understand aggregate usage of the website and releases pages.
  • To review bug reports, feedback, and feature requests.
  • To maintain the desktop app’s persistence and user experience across the machines you connect.
  • To deliver push notifications you turn on in the iOS app.
  • To comply with legal obligations and protect the service.

Third Parties and Sharing

We may share information with a small set of third parties that help operate atrium:

  • PostHog, which is used for website analytics.
  • GitHub, when you open or participate in public feedback or issue threads.
  • Apple, which delivers push notifications through APNs.
  • Vercel, which hosts the website and the push relay.
  • Third-party model hosts, such as Hugging Face and GitHub, which serve the iOS app’s one-time voice model download.

We may also disclose information if required by law or if needed to protect users, the service, or our rights.

Your Choices

  • You can limit or block cookies and similar website storage through your browser settings, though parts of analytics may still function in aggregate form.
  • You can choose not to use the public feedback tracker if you do not want information posted publicly on GitHub.
  • You can remove atrium’s local desktop data from your Mac by deleting the relevant local app files, including the~/.atrium/ directory.
  • Removing an SSH location from the Mac unregisters it but does not erase that machine. Delete remote atrium data and repositories on the box itself when you want them removed.
  • You can turn push notifications off at any time in the atrium app or in iOS Settings, or for one device from your Mac.

Retention

Website analytics is retained only as long as reasonably needed for product and site operations. Content you submit to GitHub is subject to GitHub’s own retention and visibility model. Local app app data remains on its owning machine until you delete it or the app removes it.

The push relay keeps no copy of push tokens, delivery passes or notifications. Our hosting provider, Vercel, keeps request logs (the time, the requesting IP address, the user agent, the path and the result) for about a day for operations and security, under its own policies. The relay keeps push tokens and notifications out of its own log lines, but a push token may still appear in those hosting logs; if it does, it is deleted with them. A paired Mac keeps your phone’s push token, delivery pass and notification key until you turn notifications off, remove the Mac from your phone, or revoke the phone.

Children

atrium is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes and Contact

We may update this policy as atrium evolves. Material changes will be reflected by updating the date at the top of this page.

For private questions or privacy-related requests, email sup@getatrium.dev.

For public bug reports and product feedback, use the public feedback tracker.

You may also want to review our Terms of Service.