Atomic Labs logo Atomic Labs Book a call

Legal

Privacy Policy

Effective date: September 20, 2026

This policy explains what we collect, why we collect it, and how we handle it. We keep this simple. If you have questions, email atom@atomiclabs.tech.

1. Who we are

Atomic Labs provides managed AI assistant services, custom automation, technical implementation, and related support for businesses and professionals.

2. Scope of this policy

This Privacy Policy applies to the Atomic Labs website, sales and onboarding communications, and the services we provide directly to prospects and clients. It covers information we collect from you, about you, or on your behalf in connection with operating our business and delivering our services.

For information received through Google APIs, the specific commitments in section 9A take precedence over broader statements elsewhere in this policy or our service agreements about use, sharing, service improvement, retention, or third-party responsibility.

3. Information we collect

Depending on how you interact with us, we may collect:

  • Identity and contact details, such as your name, email address, phone number, company name, role, and billing information.
  • Inquiry, sales, and onboarding information you share through forms, calls, email, Discord, scheduling tools, or other communication channels.
  • Client service data, including prompts, messages, files, notes, workflows, project information, uploaded content, documentation, preferences, and business context you provide so we can configure, operate, and improve your assistant.
  • Connected account and integration data, including metadata, tokens, permissions, logs, account identifiers, configuration details, and account-level information needed to connect third-party tools you authorize us to use.
  • Third-party platform data made available through authorized integrations, such as email metadata, CRM records, scheduling data, advertising account data, analytics, messaging content, and performance reporting.
  • Meta or Facebook platform data, where applicable, including business account identifiers, ad account identifiers, campaign, ad set, ad, creative, audience, performance, billing, reporting, and related business data made available through Meta APIs and permissions you authorize.
  • Technical and usage data such as IP address, browser type, device data, approximate location, referring pages, session activity, and site interactions.
  • Payment and transaction data processed through third-party payment providers. We do not store full payment card numbers ourselves.

4. Sources of information

We collect information directly from you, automatically through website and service usage, from third-party services you connect or authorize, from payment and scheduling providers, and from business partners or representatives acting on your behalf.

5. How we use information

We use information to:

  • Respond to inquiries, book calls, prepare proposals, and onboard clients.
  • Provide, configure, secure, maintain, support, and improve our services.
  • Operate AI assistants, workflows, automations, reports, and connected integrations you request or authorize.
  • Access, analyze, synchronize, transform, route, or display data from authorized third-party connections to deliver requested functionality.
  • Use Meta or Facebook advertising data, where authorized, to support ad account connections, campaign management, reporting, optimization, automations, troubleshooting, and related services you request.
  • Communicate with you about onboarding, support, billing, renewals, updates, and service-related issues.
  • Monitor performance, troubleshoot failures, prevent abuse, and keep our systems and client environments secure.
  • Comply with legal, accounting, tax, contractual, and recordkeeping obligations.
  • Analyze website and product usage to improve user experience, service quality, and operations.

6. Legal bases for processing

Where applicable, we process personal information because it is necessary to perform a contract, respond to a request you made, pursue legitimate business interests, comply with legal obligations, protect our rights and security, or because you gave consent.

7. How we share information

We do not sell your personal information. We may share information with:

  • Hosting, infrastructure, analytics, scheduling, communications, payment, storage, monitoring, security, and support providers that help us operate the business.
  • AI model, API, automation, integration, browser, and workflow providers when needed to deliver the services you request.
  • Third-party platforms and services you direct us to connect to, query, update, or use on your behalf.
  • Professional advisers such as accountants, lawyers, insurers, auditors, or consultants where needed.
  • Authorities or other parties when required by law, court order, legal process, or to protect our rights, users, systems, or security.
  • A buyer, investor, or successor if Atomic Labs is involved in a merger, acquisition, restructuring, financing, or asset sale.

8. Client data, service provider role, and confidentiality

When we provide services to clients, we may process data on the client's behalf. In many cases, Atomic Labs acts as a service provider or processor, and the client controls what data is submitted, which accounts are connected, and how the service is used. We treat client business information as confidential and use it only as needed to provide, secure, maintain, and support the services, subject to our agreements and applicable law.

9. Connected accounts and integrations

If you authorize integrations with third-party tools such as email, chat, CRM, scheduling, analytics, advertising, payment, cloud, or other business systems, we may access, retrieve, store, process, transform, transmit, or display data from those systems as needed to provide the service. You are responsible for ensuring you have the authority to connect those accounts and share that data with us.

9A. Google account and Workspace data

Atomic Labs connects Google accounts to provide requested assistant, productivity, administration, and reporting features. Connecting an account does not authorize unrelated access or use. We request only permissions needed for the features you enable, explain the data use when access is requested, and obtain the authorization and consent required for that connection. Some business connections use administrator-approved Google Workspace domain-wide delegation rather than an individual OAuth consent screen.

Data accessed and the purposes it serves

The data we access depends on the connected service, granted permissions, and task you request. Relevant categories include:

  • Account and connection information: account name, email address, account or resource identifiers, permissions, authorization tokens, and connection settings, to identify the correct account and operate the authorized integration.
  • Gmail: message bodies, attachments, headers, labels, and related metadata, to find and summarize email, organize messages, and prepare or send messages when authorized. Mailbox settings are accessed only for requested account-management tasks.
  • Drive and productivity content: file contents, names, identifiers, permissions, and metadata, including documents and spreadsheets, to find, summarize, organize, create, or edit the materials needed for your requested workflow.
  • Calendar, Contacts, and Tasks: event details, attendees, availability, contact records, and task details, to support scheduling, contact management, and task organization.
  • Workspace collaboration and administration: connected Chat messages, meeting information, notes, classroom records, user and group records, domain settings, device information, and audit events, only for the collaboration, reporting, or administrator tasks you authorize.
  • Search and business reporting: Search Console properties, queries, performance and indexing reports, site-verification records, and authorized Analytics or Tag Manager account information, to provide website reporting and related account tasks. Where Google Ads access is enabled, account, campaign, keyword, and performance information supports authorized advertising research, reporting, or campaign workflows.

Not every integration is enabled for every client. API permission alone does not authorize sending a message, editing a file, changing an account, or launching a campaign; those actions remain subject to the workflows you approve.

Processing, storage, and service providers

Relevant Google data may be processed on the device or server running your assistant and by providers supporting the requested feature. We may retain account and connection records, retrieved content or excerpts, task history, logs, generated reports, summaries, and saved assistant context when needed for that feature. This means a copy can remain outside Google after a task ends. Retention and deletion are described below and in our Google deletion instructions.

Where a requested AI feature requires it and you consent, relevant content may be sent to an AI inference provider to generate an answer, summary, draft, or other requested output. Hosting, storage, communications, and integration providers may also process the data needed for that feature. We limit those transfers to the disclosed user-facing purpose and the applicable Google requirements; a provider's general terms do not expand the uses we permit. We remain responsible for compliance by our employees, agents, contractors, and successors.

Limited Use, AI, and human access

Atomic Labs' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its applicable Limited Use requirements. Information received through Google Workspace APIs will also adhere to the Google Workspace API User Data and Developer Policy.

For Google Workspace data and other Google data subject to Limited Use, these restrictions cover raw data and information derived from it, including summaries, aggregated information, and saved context:

  • Use is limited to providing or improving the appropriate user-facing features disclosed to you. We do not sell this data, transfer it to data brokers or information resellers, or use it for creditworthiness or lending decisions.
  • We do not use or transfer this data for serving ads, retargeting, or personalized advertising. Workspace content is not an input to advertising audiences or website advertising tags. Separately authorized Google Ads reporting and campaign work uses the relevant advertising account data, not Workspace content.
  • We do not use or permit providers to use Google Workspace data to create, train, or improve general-purpose or shared AI or machine-learning models. Sending content for an authorized AI response is not permission to train a model. Any user-specific model use would require separate disclosure, the required consent, and compliance with Google's policies.
  • Transfers are limited to providing or improving the disclosed, appropriate user-facing feature with your consent, necessary security purposes, legal compliance, or a merger, acquisition, or asset sale with your explicit prior consent. General financing, investor, adviser, or service-improvement clauses do not authorize additional transfers.
  • Human reading is limited to your documented affirmative agreement to view specific messages, files, or other data; necessary security purposes; legal requirements; or aggregated and anonymized data used for permitted internal operations. General acceptance of our Terms is not consent to read your private messages or files.

Choice and changes in use

You can remove an individual connection through your Google Account's linked-app settings. An administrator must remove or restrict a domain-wide delegated connection through the Workspace Admin console. Revocation stops access under that authorization but does not itself erase copies already retained. See our Data Deletion Instructions to request removal of those copies.

Before accessing an additional type of Google user data or using Google user data for a purpose not previously disclosed, we will explain the change and obtain the authorization and affirmative consent required by Google's policies before the new access or use begins. Continued use of our website or services is not a substitute for that consent.

10. Meta and Facebook platform data

If you authorize a Meta or Facebook connection, we may access and process account, ad account, campaign, ad set, ad, creative, reporting, performance, audience, and related business data made available through Meta APIs and permissions. We use that data only to provide, maintain, secure, analyze, automate, troubleshoot, report on, and improve the services you request. We do not sell Meta platform data.

11. Cookies, analytics, and embedded services

We may use cookies, pixels, local storage, and similar technologies to understand how the website is used, keep the site secure, remember settings, and improve performance. Third-party tools embedded on the site, such as scheduling, video, analytics, and hosting services, may also place cookies or collect usage data under their own policies.

Our public website uses the Google tag for advertising measurement. Website-visit measurements are separate from data accessed through connected Google accounts. We do not send Google Workspace message or file contents to advertising tags. See how Google uses information from sites that use its services for information about Google's processing and available controls.

12. Data retention and deletion

We retain information for as long as reasonably necessary to provide services, operate the business, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and keep appropriate business and accounting records. Retention periods vary based on the type of information and the purpose for which it was collected.

After a service ends, we may delete, return, or de-identify client data, except where retention is reasonably necessary for backups, fraud prevention, security investigations, legal compliance, financial recordkeeping, dispute resolution, or enforcement of our agreements.

For Google data, we retain connection credentials only while needed for authorized access, and retrieved content, saved context, and derived outputs only while needed for the disclosed feature or an applicable, permitted retention requirement. We honor verified deletion requests. Revocation and deletion are distinct: removing a Google connection does not automatically remove saved reports, conversation history, or other retained copies. Deletion includes those copies and relevant derived records within our control, subject to narrow legal or necessary security exceptions. Backup copies, where present, are removed through the applicable backup deletion or rotation process and are not used to continue the disconnected feature. We will explain any remaining backup schedule or specific retention exception when responding to a request. De-identification is not a way to avoid Google's Limited Use restrictions.

If you want us to delete data associated with a connected third-party platform, including Google, Meta, or Facebook data, you can submit a request by contacting atom@atomiclabs.tech or visiting our Data Deletion Instructions page.

13. Security

We use reasonable technical and organizational safeguards designed to protect information, which may include access controls, account permissions, authentication measures, logging, environment separation, managed infrastructure protections, and operational security practices appropriate to the nature of the service. That said, no method of transmission, storage, or security control is perfect, and we cannot guarantee absolute security.

14. International data transfers

If you access our services from outside the United States, your information may be transferred to and processed in the United States or other countries where we or our service providers operate. Those countries may have data protection laws that differ from those in your jurisdiction.

15. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or restrict use of your personal information, or to object to certain processing. You may also have rights related to portability, withdrawal of consent, or appeal of a privacy decision. To make a request, contact atom@atomiclabs.tech. We may need to verify your identity before responding.

16. California privacy notice

If you are a California resident, you may have additional rights under California law regarding access to, deletion of, and correction of personal information, subject to exceptions. We do not sell or share personal information for cross-context behavioral advertising as those terms are commonly used under California privacy law.

17. Children's privacy

Our website and services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

18. Third-party sites and services

Our website or services may link to or rely on third-party sites, applications, and services. Independent sites you visit operate under their own policies. Review those policies before using them. This does not remove our responsibility for data we disclose to our service providers or our obligations under the Google-data commitments in section 9A.

19. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date on this page and provide any notice required by law. New access to or use of Google user data requires the disclosure, authorization, and consent described in section 9A before that access or use begins. Continued use does not supply that consent.

20. Contact

If you have questions about this Privacy Policy or how we handle data, contact atom@atomiclabs.tech.

Atomic Labs logo Atomic Labs

Private AI operators for founders who are done being the bottleneck.

Practice

What you getPricingResults

Company

DemoFAQBook a call

Legal

Privacy PolicyTerms of ServiceData Deletion

design guide · v1.0 · april 2026 · © 2026 Atomic Labs