Skip to content
AtomicReps

Legal

Privacy Policy

Last updated: September 23, 2026

Atomic Reps is operated by Atomic Reps AB, a Swedish limited liability company (aktiebolag) with its registered office at Arvid Tydéns Allé 28, 171 69 Solna, Sweden (org. no. 559593-4398). All references in this Privacy Policy to "Atomic Reps", "we", "us", or "our" mean Atomic Reps AB, which is the party responsible for the processing described here. Under the EU General Data Protection Regulation (GDPR), Atomic Reps AB acts in two distinct roles depending on the data:

The two GDPR roles we act in, and the data each one covers.
Our roleData it covers
ControllerAccount data, billing data, marketing email, security logs, and product analytics.
ProcessorWorkspace member practice data, processed on behalf of your organization under the Data Processing Agreement at /dpa, which applies on every plan, Free included.

This Privacy Policy explains what data we collect, how we use it, the lawful basis for processing, your rights under applicable privacy law (including the GDPR), and how to contact us. For privacy inquiries, contact us at privacy@atomicreps.com.

Data we collect

We collect and process the following categories of data:

  • Account data - Name, email address, and profile information provided through Clerk authentication. During onboarding you may also declare an optional experience band (years in the industry, in coarse buckets). It is used only in the anonymous aggregate research described in "How We Use Data", it is never shown to your workspace or your manager, and skipping it changes nothing.
  • Organization data - Organization name, membership records, and role assignments within your team.
  • Game data - Responses, scores, timing information, participation records from practice sessions, and the name other players see: the first name on your account, or a three-word name we generate. Nobody types a name into a game.
  • Daily practice data - Answers to daily questions, streaks, progress tracking, and team-level aggregate statistics. Each answer also records which surface it arrived on (the web, the iPhone app, a Slack direct message, or a coding agent), whether the question was fresh or one coming back and at what level, the confidence you tapped and the prompt setting in force, and how long you took. Time taken is kept for research on the schedule only: no rule reads it, and nothing infers your mood, effort or confidence from it.
  • Slack integration data - Workspace ID, bot tokens, user ID mapping, email addresses, and display names when you connect Atomic Reps to your Slack workspace.
  • Technical logs - IP address and request metadata, processed for security and abuse prevention.
  • Preferences - Theme, audio, and motion settings stored locally in your browser via localStorage, or in the iPhone app's own storage on your device.
  • iPhone app data - The same account and practice data as the web, sent to the same backend. On the phone itself we keep the practice record of a visitor without an account, your reminder settings and the day's tally the home-screen widget shows, all in the app's storage on your device. Details under "The iPhone app" below.

Slack integration data

When you connect Atomic Reps to a Slack workspace, we collect and process the following Slack-specific data:

  • Slack user ID and display name - Used to link your answers to your own practice record and to address you in Slack messages. Public leaderboards display a nickname you choose or an anonymous handle, not your Slack identity.
  • Email address - Used to link your Slack identity to your Atomic Reps account and to verify the email-match claim gate for free-tier installers (no end-member email is stored in the aggregate path).
  • Workspace (team) ID - Used to route messages to the correct workspace.
  • Answer history - Your responses to daily reps and sprint sessions delivered via Slack.

Slack-specific data is retained while the Slack integration is active for your workspace. When a workspace admin uninstalls Atomic Reps from Slack, all attributed Slack-specific data (user mappings, post history, sprint sessions, question feedback, insight delivery records, practice preferences, and in-Slack companion progress such as apprentice pets, their skills, and reward balances) is permanently deleted within 15 days (a 14-day retention window plus a daily deletion sweep). Anonymous aggregate statistics that contain no identifiers are retained under the 90-day rolling window described in "Your rights" below. An individual's erasure request follows the one-month erasure process described in "Your rights".

To request deletion, contact us at privacy@atomicreps.com.

Lawful basis for processing (GDPR Art 6)

We process personal data under the following GDPR Article 6 lawful bases:

  • Performance of contract (Art 6(1)(b)) - Account, authentication, billing, transactional email, and core game/practice functionality.
  • Legitimate interest (Art 6(1)(f)) - Service security, fraud and abuse prevention, request logging, storage of integration credentials, generation of team-level aggregate statistics that contain no per-member breakdowns, and anonymous counting of page visits (described under Cookies & local storage). You may object to legitimate-interest processing under Art 21; see "Your rights" below.
  • Consent (Art 6(1)(a)) - Optional product analytics and session replay (PostHog) in the browser, optional product analytics in the iPhone app, and marketing email. Withdrawable at any time via the Cookie settings control in the site footer, the analytics switch in the app's Me tab, or the unsubscribe link. Declining still leaves the anonymous page counting described under Cookies & local storage, which places nothing on your device.
  • Legal obligation (Art 6(1)(c)) - Accounting and tax records as required under Swedish Bokföringslagen (1999:1078) and equivalent foreign law.

Who can see your practice data

Your individual answer history, accuracy, and streaks are visible only to you. On the workplace plans (a free Slack install or Team), workspace administrators cannot access individual answer history, accuracy, streaks, or inferred skill ratings, and other members never can. A Pro or free account on its own has no workspace and no administrator: its settings belong to that one person. Atomic Campus is a separate product where the institution buys an instructor view of observed course facts under Schedule E of the DPA; it never reads workplace practice data. If we introduce a workplace plan that permits administrator access to individual practice data, we will identify that functionality clearly before it is activated and update this policy and the applicable contractual terms first. The administrative hub contains configuration and goals only (Slack setup, channel routing, close scheduling, skill expectations, and billing); it contains no dashboards, activity views, or per-member statistics of any kind. Nothing derived from a person reaches your shared Slack channel: the daily question and the weekly recap carry question content and nothing else, with no scores, no accuracy figures, and no count of how many people answered. One team figure exists elsewhere: the Slack leaderboard. It is shown only to the member who asked for it, and withheld until at least 3 distinct people have answered. Skill expectations a manager assigns are goals the manager wrote; managers do not see the answers, accuracy, or measured levels behind them.

We retain your practice data both for your own visibility (your record, streaks, and certificates) and to improve the platform, for example tuning question difficulty and detecting broken questions. We never train third-party AI models on your data; see "AI and your data" on the Security page.

Public leaderboards display a nickname you choose or an anonymous handle (for example, Player-1234), not your workspace identity; setting or removing a nickname is your own reversible action. Scores in a live game session are visible to the players in that session. See our Terms of Service for the corresponding contractual description.

How we use data

  • Provide the Service: games, daily practice sessions, and leaderboards.
  • Authenticate users through Clerk.
  • Choose the level of your next question from your own answer history (adaptive level). This uses only your answers, produces no legal or similarly significant effect, and is visible only to you.
  • Bring back a question you missed, on a widening gap (the spaced re-ask). The first return is usually the same question, and it may come back one level easier, once. Which question returns and when is arithmetic written by people, over your own answers and the calendar; no answer reaches a model. Returns are capped per day, a question you did not answer is never counted as a miss, and how long you took is never read as a signal. The schedule ranks nobody against anyone. The confidence prompt that asks whether you were sure is yours to set: every question, or off. On the workplace plans the schedule is visible to you alone; on Atomic Campus the school holds its class record separately, under Schedule E of the DPA. Processed under Art 6(1)(b), performance of contract. The gap itself, in days, is published on the ladder, dated and versioned, so this policy describes the shape and never a number that could go stale here.
  • Deliver Slack integrations including Question of the Day and collection of your answers.
  • Generate the k-anonymous team figures shown in ephemeral Slack replies. The leaderboard is the only one left: only the member who asked for it sees it, and nothing person-derived is posted to the shared channel. The count that used to appear after you answered has been removed.
  • Maintain de-identified question-level statistics (containing no user or organization identifiers) to calibrate question difficulty across the platform. We may publish these anonymous aggregates as research findings (for example, which topics working engineers most often answer incorrectly). A published finding is never attributed to a person, a team, or a company, every published figure states the number of answers behind it, and nothing is published below a minimum sample across multiple organizations.

We never use your data to train, fine-tune, or improve AI or machine-learning models, and we never sell or share it. We do not send customer data to third-party AI providers. Beyond providing the Service, we use personal data only for the limited purposes set out in "Lawful basis for processing" above: security and abuse prevention, optional analytics and marketing email (which you can decline or withdraw), and legally required record-keeping.

Third-party services (subprocessors)

We rely on the following third-party services to operate Atomic Reps. Each service processes data under its own privacy policy and a written data processing contract with Atomic Reps AB as required by GDPR Art 28(3):

  • Clerk (clerk.com) - Authentication and user management. United States. Certified under EU-US Data Privacy Framework.
  • Convex (convex.dev) - Database and serverless backend. EU West (Ireland). Convex Inc. is a US company; EU SCCs cover vendor support access from the United States.
  • Slack (slack.com) - Workspace integration for daily practice delivery. United States. Certified under EU-US Data Privacy Framework (through Salesforce, Inc.).
  • Cloudflare (cloudflare.com) - Frontend hosting, deployment, and CDN. United States and global edge network including EU points of presence. Operates under EU SCCs.
  • PostHog (posthog.com) - Optional product analytics and session replay, enabled only after explicit consent: the cookie banner on the web, the analytics switch in the iPhone app. Once consent is given on the web, a signed-in user's name, email address, and organization name are sent to PostHog as profile properties; the iPhone app sends none of those, only the events described under "The iPhone app". Session replay runs only on our public marketing pages (never inside the app, in games, or on checkout and claim pages) and masks all text you type. Analytics requests are proxied through our own domain and carry none of your session cookies. EU-region instance (eu.posthog.com); where a non-EU instance is configured, EU SCCs apply (Module 2 where we act as controller; Module 3 where we act as processor on your organization's behalf). Separately from browser analytics, and for every visitor rather than only consenting ones, we send PostHog an anonymous page-visit event from our own servers. It carries a one-way daily fingerprint instead of any identifier, and it deliberately creates no PostHog person profile, so these events are never joined to an account. The mechanism, and why the fingerprint cannot be traced back or matched across days, is described under Cookies & local storage below. Separately again, our Slack integration sends server-side product usage events to PostHog: when the apprentice and practice features are used, we record the event keyed to a pseudonymous internal user identifier, never your name or email address. These events carry no message content and are not used for advertising profiling. The legal basis is legitimate interest (GDPR Art 6(1)(f)); you can object at any time by emailing privacy@atomicreps.com.
  • Polar (polar.sh) - Payment processing and subscription management as Merchant of Record. Processes billing information including email address and subscription status. United States. For the payment and tax transaction itself, Polar acts as Merchant of Record in its own capacity (an independent controller, not our processor); we list Polar here for the billing-contact and subscription-management data it processes on our behalf, safeguarded under the EU Standard Contractual Clauses Polar has entered into. Polar uses Stripe (certified under the EU-US Data Privacy Framework) as a subprocessor for payment card handling.
  • Resend (resend.com) - Transactional and marketing email delivery. United States; transfers safeguarded under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement. Processes email addresses and email content for account notifications including data export, deletion confirmation, onboarding drip sequences, and billing communications.
  • RevenueCat (revenuecat.com) - Holds the status of plans bought in the iPhone app: your account identifier, the vendor identifier iOS assigns to the app on your device, and Apple's purchase records (product, dates, renewal state). It never receives your name, email address or payment card. United States. RevenueCat's published Data Processing Addendum is part of our agreement with RevenueCat, and its paragraph 11 incorporates the EU Standard Contractual Clauses, Modules 2 and 3, with the UK addendum and the Swiss adaptation. Apple itself is not a subprocessor; "The iPhone app" below says what Apple holds on its own account.

We provide 30 days' advance notice before adding a new subprocessor. To subscribe to subprocessor change notifications, email privacy@atomicreps.com.

Data storage & retention

We separate your own practice record from your workspace's view of it. Your record is permanent; the workspace's link to it expires on a tiered schedule:

  • Your practice record - permanent: Every answer you give (which question, which answer, when) belongs to your own practice record on every plan, free or paid. It is visible only to you, it does not expire, and you can export, reset, or delete it from your account page. The windows below end the workspace's link to your answers, never the answers themselves, and this holds against the retention windows, a subscription ending, and being removed from a workspace. The one exception: if a workspace administrator deletes the whole workspace, the answers you gave inside it are deleted with it, since that is a complete erasure of the workspace and everything recorded in it.
  • Free tier - 90 days: Anonymous aggregate statistics (response counts, accuracy rates, domain-level metrics) on a 90-day rolling window. The aggregate rows contain no personal identifiers, and no admin-facing view of them exists: we keep them to tune question difficulty, not to report on a workspace. The workspace's link to the underlying participation records (Slack user ID, per-question correctness) is removed after 90 days; those records are never shown to admins at any point, and each member keeps their own answers as described above.
  • Pro plan (individual): Pro is a personal subscription held by one named individual rather than by a workspace. Your practice history is your permanent record as described above; no workspace administrator sees it.
  • Team plan - 365 days: The workspace's attribution layer (which member answered, for streaks and participation) runs on a 365-day rolling window, in addition to the 90-day aggregate layer. Individual answer history is visible only to the individual member (plus workspace leaderboards that show a chosen nickname or an anonymous handle, never a Slack identity). When the window rolls past an answer, the workspace's link to it is removed and the member keeps it in their own record.
  • Your own progress summary: A small summary of your own record: current and longest streak, lifetime answered and correct counts, and per-skill accuracy scores. It is yours to read. No administrator or manager surface reads it on any workplace plan, and the only place any of its numbers appear to another person is the pseudonymous leaderboard described above. It has no time window; it is kept for as long as you remain a member so your progress does not reset when the windows above roll. It is deleted when your account is erased, when an admin removes you from the workspace, and when a Team subscription ends. Your own practice record is not affected by any of those events.
  • End of subscription: Cancellation takes effect at the end of the paid billing period; the workspace's attributed layer remains available and exportable until then. On Team, when the subscription ends, that layer is removed immediately and cannot be restored, even on resubscribe: the practice targeting set up for each member is deleted, and every member's answers are permanently unlinked from the workspace. Each member keeps their own practice record. Anonymous team aggregates continue under the 90-day rolling window, and the workspace continues on the free tier until an administrator deletes it (see Your rights below). On Pro, your account returns to the free plan and your practice record is unaffected.
  • Slack integration data: Retained while the integration is active. Attributed Slack data is deleted within 15 days of uninstall (14-day retention window plus a daily deletion sweep); individual erasure requests follow the one-month erasure process.
  • Account and profile data: Your name, email address, and sign-in identifiers are held by Clerk, our authentication provider, for as long as your account exists. When your account is deleted, an erasure workflow removes your personal records across the Service, anonymizes attributed game history, and (where we hold a contact email for you) sends a confirmation email.
  • Aggregated, anonymized statistics: Statistics that contain no personal identifiers (for example, per-question accuracy rates and difficulty calibration across all users) are retained indefinitely to improve question quality and the Service (GDPR Art 89(1) statistical purposes; anonymized data is not personal data under Recital 26). Attributed records are folded into these statistics when they are written; removing a workspace link or deleting a record never reverses its contribution to an anonymous statistic, and no anonymous statistic can be traced back to you.
  • Email suppression list: When you unsubscribe from marketing or product email, we retain your email address on a suppression list so that we do not contact you again. This retention is necessary to honor your opt-out (legitimate interest, GDPR Art 6(1)(f)). The address is removed entirely when your account is deleted.
  • Webhook event logs: Records of the payment, authentication, email and Slack webhooks we receive, retained on a rolling 30-day window for security and for debugging a delivery that failed. A sweep deletes anything older.
  • IP addresses: Used transiently for rate limiting and abuse prevention. No IP address is stored on your account record or on your workspace record. The one counter we key on an address, the throttle on Slack install attempts, is deleted within two hours of the attempt. Beyond that, IPs appear only where any web service sees them: short-lived operational logs at our hosting and backend providers. We do not build a profile from them and we do not use them to identify individuals.
  • Workspace audit log: When someone changes a workspace (settings, roles, teams, the Slack connection, the subscription) we record who did it, what changed, and when. We do not record the IP address or the browser the action came from. Entries are readable by workspace administrators, cover administrative actions rather than practice answers, and are kept for 365 days from the event, after which a weekly job purges them automatically, on the legitimate-interest basis of security and accountability (GDPR Art 6(1)(f)). Unlike every other category above, audit entries are not removed by an individual erasure request: a trail an administrator could erase from their own account is not an audit trail, and Art 17(3)(e) preserves the record where it is needed to establish, exercise or defend a legal claim. The identifiers that survive are the acting administrator's user ID and, where the action concerned another person, that person's user ID, Slack user ID, or the email address an invitation was sent to. Deleting the workspace deletes the whole log with it.
  • Billing and tax records: Retained for 7 years as required by Swedish Bokföringslagen (1999:1078) and equivalent foreign law.
  • Application data is stored in a Convex cloud database hosted in the EU (Ireland).
  • UI preferences (theme, audio, motion) are stored in your browser's localStorage or in the iPhone app's storage on your device, and never leave it.

Security incidents (breach notification)

If a personal data breach affects your data, we notify the affected workspace administrator(s) without undue delay after becoming aware of it. Where Atomic Reps AB is the controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, as required under GDPR Art 33(1), and, where the breach is likely to result in a high risk to individuals, we notify the affected individuals directly under GDPR Art 34. Our breach obligations as a processor are set out in the DPA.

International data transfers

Your data may be processed outside the European Economic Area (EEA), the United Kingdom, or Switzerland by our subprocessors. We rely on the following transfer mechanisms:

  • EU-US Data Privacy Framework - Clerk, Slack (through Salesforce, Inc.), and Stripe (Polar's payment-card processor) are certified under the EU-US Data Privacy Framework (adequacy decision adopted by the European Commission on 10 July 2023), including the UK Extension to the Framework for transfers from the United Kingdom; transfers from Switzerland rely on the Swiss adaptation of the SCCs described in our DPA. If the Framework ceases to provide a valid transfer mechanism, we rely on the EU Standard Contractual Clauses (Decision 2021/914) with appropriate supplementary measures for those transfers.
  • Standard Contractual Clauses (SCCs) - Convex and Cloudflare operate under the EU SCCs approved by the European Commission: Module 2 (controller-to-processor) where we act as controller, and Module 3 (processor-to-processor) where we act as processor on behalf of your organization. Resend (United States) safeguards its transfers under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement. RevenueCat (United States) safeguards its transfers under the EU Standard Contractual Clauses incorporated in its published Data Processing Addendum (paragraph 11). Polar, as Merchant of Record, processes the payment transaction in its own independent capacity; where Polar processes billing or platform data on our behalf it does so as our processor under a separate controller-to-processor agreement that incorporates the EU SCCs. PostHog relies on EU-region hosting so no restricted transfer occurs; where a non-EU instance is configured, the EU SCCs apply (Module 2 where we act as controller; Module 3 where we act as processor on your organization's behalf). For transfers from the United Kingdom, the UK Addendum to the SCCs applies; for transfers from Switzerland, the Swiss adaptation of the SCCs described in our DPA applies.
  • Region selection - Where a subprocessor offers EU-region hosting, we configure that region. Our PostHog project is hosted in the EU (eu.posthog.com).

A complete register of our subprocessors, their hosting locations, and applicable Data Processing Agreements is available on request by contacting privacy@atomicreps.com.

Cookies & local storage

  • Clerk session cookies - Strictly necessary for authentication. These do not require consent under GDPR/ePrivacy.
  • Consent cookie (atomicreps-cookie-consent) - Records your analytics choice (accepted or declined) for 365 days so the banner does not return on every visit. Strictly functional; holds no identifier.
  • localStorage - Used for theme, audio and animation preferences, and for the local practice record of a visitor without an account. This data stays in your browser and is not transmitted to our servers.
  • Optional analytics cookie/local storage - If you accept analytics cookies, PostHog may set identifiers to measure page visits and product usage events, and to record session replays on our public marketing pages with all text input masked. Not loaded until consent is granted.
  • Returning visitor cookie (ar_vid) - Set only if you accept analytics cookies. It holds a random value that means nothing anywhere except here, and it lets us tell a returning visit from a first one. That is the only way to see whether people come back. Our server sets it rather than a script, because Safari deletes script-set cookies after seven days, which made every returning visitor look like a stranger. Scripts on the page cannot read it, and your browser never sends it to another site. It expires after 13 months. Decline and we never set it. Withdraw later and our server deletes it on your next visit, because nothing else can.

We do not use advertising cookies. Browser analytics and session replay are optional and only enabled if you explicitly accept them in the cookie banner. The server-side product usage events from the Slack integration, described under Subprocessors above, involve no cookies and no browser.

Anonymous page counting. Separately from the optional analytics above, we count page visits on our own servers without placing anything on your device. There is no cookie and no browser storage for this, so there is nothing for you to accept or decline. When a page is served we combine your IP address, your browser's user-agent string and a random value that we generate fresh each day, and we turn the three into a one-way fingerprint. We record only that fingerprint, the page address with any private query values stripped, the site that referred you, your country and whether you are on a phone, tablet or desktop.

The same counting covers a short, fixed list of things you do on our public pages: moving from one page to another without a full reload, answering a sample question, opening the pricing page, clicking an install or an upgrade button. Your browser sends these in small batches. We never tell it the fingerprint we file them under, so it cannot recognize you either.

We never include anything you type into a box. Each record may carry only a short label from a list we wrote in advance, a plain number, or a yes/no. Your browser drops anything else before sending, and we drop it again on arrival. An email address or a name cannot fit through that filter even by mistake.

The random daily value is deleted when the day ends and is never recoverable. That is what makes this anonymous rather than merely obscured: once it is gone, the fingerprints from that day cannot be recreated from anyone's IP address, and a fingerprint from one day cannot be matched to the same visitor on any other day. Your IP address is used for the calculation and immediately discarded. We never store it, never log it and never send it to PostHog. This is measurement of aggregate audience, not tracking of a person, and we rely on our legitimate interest in knowing how the site is used (GDPR Art. 6(1)(f)). You can object at any time by writing to privacy@atomicreps.com.

Tracking: We do not sell or share personal information and do not track you across other sites, so there is nothing to opt out of. Our optional analytics cookies are governed by the consent banner, and you can change or withdraw your choice at any time via the Cookie settings control in the site footer.

The iPhone app

The iPhone app is the same Service on a phone. It signs you in through Clerk, talks to the same backend in Ireland, and writes to the same practice record. It collects your name and email address from the sign-in provider you choose (with Sign in with Apple that may be a private relay address), your account identifier, your answers, and how you use the app. The only permission it asks for is the one it needs to show a reminder. It does not ask to track you. There is no advertising SDK in it and no App Tracking Transparency prompt.

On the phone itself. Before you sign in, your practice record lives only in the app's storage on your device, and the home-screen widget reads the day's tally from the same place. When you sign in the app offers to move that record onto your account. If you decline, it stays on the phone. Reminders are local notifications the app schedules on the device. We hold no push token and nothing about a reminder reaches our servers. When you rate an explanation or report a question, the app sends a random identifier it created on your device, which our backend uses only to limit how many ratings and reports one device can send, and does not store. Deleting the app deletes that storage. iOS keeps keychain entries across an uninstall, so sign out first if you want the sign-in token gone too.

Purchases. A plan bought in the iPhone app is an App Store purchase. Apple takes the payment, holds your card details, issues the receipt and handles refunds, under Apple's own privacy policy. We never see the card. RevenueCat, listed under subprocessors above, receives your account identifier, the vendor identifier iOS assigns to the app on your device, and Apple's purchase records, and tells our backend which plan you hold. We keep that plan and its dates on your account. The licence for the app is Apple's standard end user licence agreement.

Apple, in its own right. Apple distributes the app through the App Store and TestFlight and acts as an independent controller under its own privacy policy, not as our processor. Apple records that you downloaded and installed the app. If you have turned on sharing with app developers in your iPhone's analytics settings, Apple also passes us crash logs and aggregate usage figures from the app. They carry no name, email address or account identifier. No crash reporting is switched on inside the app, so a crash report reaches us only through Apple and only on that setting.

Analytics. The app sends product usage events to PostHog only after you switch analytics on, in the one-time ask under your first verdict or in the Me tab. The switch is off until you touch it, and the ask never returns whatever you answer. Each event names the screen or action and what it was about: the question, course, level, path or game mode, whether your answer was right, how hard the question was, and your plan. It also carries the app version, the iOS version, your device model and language, and a random identifier the app generates when you switch it on. It never carries your name, your email address or the text of an answer you picked. If you switch it off, the app stops sending. If you later switch it back on, it generates a new identifier.

Your rights in the app. The Me tab deletes your account through the same erasure workflow as the web and links to this page. Export and every other right work as described under "Your rights".

Your rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Access your personal data we hold (Art 15).
  • Export (data portability) in a machine-readable format (Art 20). This one is self-serve: from your account page, download your practice record as a single JSON file. It covers every answer you have given, your course progress, certificates, streaks and your apprentice, across every workspace you belong to. We build it and email you a link that works for 24 hours, and you can request one export a day. For any personal data the file does not carry, email the address below and we will assemble it for you.
  • Correct inaccurate or incomplete data (Art 16).
  • Delete your personal data (Art 17). We retain anonymized aggregate statistics on a 90-day rolling basis. Because these rows contain no personal identifiers, they fall outside the scope of the GDPR (Recital 26); to the extent any residual identifiability exists, they are retained for statistical purposes and exempt from erasure under GDPR Art 17(3)(d) read with the safeguards of Art 89(1). Your identified answer history is deleted without undue delay and within one month of a verified erasure request, subject to any extension permitted by GDPR Art 12(3) - independent of the 90-day aggregate retention window. One further carve-out, stated plainly because it is the kind of thing a policy usually buries: entries in a workspace's administrative audit log are not erased with your account, though every entry is still purged 365 days after it was recorded. See "Workspace audit log" under Data storage & retention for what those entries hold and why.
  • Object (Art 21) to processing of your personal data, including processing under legitimate-interest grounds.
  • Restriction of processing (Art 18).
  • Withdraw consent at any time, where processing is based on consent (Art 7(3)).
  • Lodge a complaint with your national supervisory authority. In Sweden: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy.se. In the United Kingdom: the Information Commissioner's Office (ICO, ico.org.uk). You may also contact your local supervisory authority.

Provision of data: Provision of account data is contractually necessary; without it we cannot provide the Service. Provision of optional analytics consent is voluntary.

How to exercise them. Access, export and erasure of your own data are self-serve from your account page on the web, and erasure also from the Me tab in the iPhone app: download your practice record, reset parts of it, or delete the account. Workspace administrators can delete a workspace and its data from billing settings. For anything those controls do not cover, including personal data outside the export file, a workspace-wide export, an erasure request made on someone else's behalf, correction, restriction, or an objection, email privacy@atomicreps.com. We verify your identity using the email tied to your account before actioning a request.

United States (state privacy laws)

Residents of US states with comprehensive privacy laws may have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of its sale or sharing. We do not sell or share personal information and have not done so in the preceding twelve months, do not use it for targeted or cross-context behavioral advertising, and do not profile individuals for decisions that produce legal or similarly significant effects. We do not retaliate against anyone for exercising these rights.

To exercise a right, email privacy@atomicreps.com. We verify your identity using the email tied to your account and respond within the period required by applicable law.

Most people use Atomic Reps as employees of a customer organization. In that case the customer organization is responsible for the data and Atomic Reps AB acts as its service provider under the DPA; we will direct end-user requests to the customer organization and assist as needed.

Outside the EU, the UK and the United States

We sell worldwide, and every right listed under "Your rights" is available to you on the same terms wherever you live, through the same address and the same one-month clock. Your data is held in Ireland by our backend provider and reaches the subprocessors listed above in the United States; the section on international transfers names the safeguards. Brazil and Japan require specific statements.

Brazil (LGPD). Atomic Reps AB is the controller. Beyond the rights above, Lei 13.709/2018 Art 18 lets you ask us to confirm that we process your data, to anonymise, block or delete data processed in breach of the law, to tell you which public and private bodies we have shared it with, and to be told that you may refuse consent and what follows if you do; that last answer is under "Provision of data" above. Our channel for these requests is privacy@atomicreps.com. You may complain to the Autoridade Nacional de Proteção de Dados (ANPD, gov.br/anpd). Your data leaves Brazil for Sweden, Ireland and the United States, the countries named in this policy.

Japan (APPI). The business operator is Atomic Reps AB, at the address at the top of this page. The purposes of use are those under "How we use data". Your personal data is transferred to Sweden and Ireland, member states of the European Union, which the Personal Information Protection Commission has designated as having a protection system equivalent to Japan's, and to the subprocessors named above in the United States, which has no such designation and no single federal privacy law. Each United States recipient is bound to us by a written data processing contract carrying the safeguards described under international transfers, and we review those arrangements at least once a year. You may ask for disclosure, correction, suspension of use or deletion of your retained personal data at the address above.

Australia and South Africa. The rights above apply as written. A complaint about our handling of your data may also go to the Office of the Australian Information Commissioner (oaic.gov.au) or to South Africa's Information Regulator (inforegulator.org.za).

Data Processing Agreement (GDPR Art 28)

Where Atomic Reps AB acts as data processor for your organization (e.g., when you upload custom questions or process member responses), a Data Processing Agreement under GDPR Art 28 is published at /dpa. Our standard DPA incorporates the EU Standard Contractual Clauses (Decision 2021/914): Module 2 (controller-to-processor) governs the transfer between your organization and us, and Module 3 (processor-to-processor) governs onward transfers from us to non-EEA subprocessors.

The DPA applies on every plan, Free included: your organization accepts it by subscribing to a plan, installing the Slack app, or creating a workspace. Counter-signed copies for procurement records are available on request from legal@atomicreps.com.

Age requirement

Atomic Reps is a tool for business users and is not directed to children. You must be at least 13, or the minimum age required where you live, to use it. We do not knowingly collect personal data from children; if you believe a child has provided us with personal data, contact us and we will delete it promptly.

Business transfers (change of control)

If Atomic Reps AB is involved in a merger, acquisition, or sale of all or substantially all of its assets, your personal data remains subject to this Privacy Policy, and any successor may process it only for the purposes described here. We will notify you before your personal data becomes subject to a different privacy policy, and you may exercise your deletion rights before any transfer takes effect.

Changes to this policy

We may update this Privacy Policy. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will provide at least 30 days' notice via email or in-product notification.

Governing law

This Privacy Policy is governed by the laws of Sweden, excluding its conflict-of-law rules. Any disputes shall be resolved by the courts of Stockholm, Sweden, except that nothing in this section limits any non-waivable statutory right under your local law.

For US residents: Any rights under applicable US state privacy law that cannot be waived by contract are not waived by this clause.

For EU and EEA consumers: Mandatory consumer protections in your country of residence apply notwithstanding this clause. An EU or EEA consumer may escalate an eligible dispute to Allmänna reklamationsnämnden (ARN, arn.se).

Contact

For privacy-related inquiries, contact us at privacy@atomicreps.com. For legal inquiries (including DPA requests), contact legal@atomicreps.com.

Security contact: to report a vulnerability, write to security@atomicreps.com. The same address is published at /.well-known/security.txt under RFC 9116. We confirm receipt before we fix.

See also: Terms of Service · Data Processing Agreement · Security