Security & Privacy

What Atronet connects to, and how access works.
This page covers how Atronet handles access, authentication, and data. For the full legal policy, see our Privacy Policy.

What Atronet connects to

You choose what to connect — nothing is linked to your account by default. Atronet can work with:

Authentication

Your Atronet account login is handled by Supabase Auth — Atronet never sees or stores your raw password.

Calendar and email access use each provider's own sign-in. You authenticate directly with Google or Microsoft, on their own page, and grant access from their consent screen — Atronet never asks for or handles your Google or Microsoft password.

Permissions

Atronet requests the minimum access needed for each connection, not broad account access:

ConnectionAccess requested
Google CalendarRead/create/update/delete events on the one calendar you connect, and check free/busy times. Not your email, contacts, files, or any other calendar.
GmailRead incoming messages and send replies as you. Not the broader permission that would let Atronet delete, label, or archive your mail.
Outlook Mail / Calendar, CalendlyThe same minimum-access principle — read what's needed to check availability or hold a reply, nothing broader.

Data handling

Message and email content is sent to Anthropic's Claude API to draft replies. For messages generated from your calendar (post-visit check-ins, win-back texts), only a client's name and the service/event title are sent — never your full event list, other attendees, descriptions, or free/busy schedule.

Full email bodies are not stored after a reply is drafted — only the sender's address, subject line, thread id, and conversation status are kept, for as long as your account is active.

Nothing you connect is sold, used for advertising, or used to train AI models.

OAuth access and refresh tokens for every connection are stored encrypted, never in plain text.

Payments

All billing runs through Stripe. Atronet never sees or stores your card number. You can view invoices, change your payment method, or cancel your subscription anytime from your dashboard's billing portal.

Disconnecting access

You can revoke Atronet's access to a specific connection anytime, directly from that provider's own settings — for example, Google's third-party access page for Gmail or Google Calendar. This takes effect immediately.

Atronet doesn't currently have a single in-app button to disconnect one integration on its own. To remove everything at once, delete your Atronet account from your dashboard's Account & Data panel — this immediately and permanently deletes your business, client, and message data, revokes every connected token, and cancels any active subscription.

Current security & certification status

Atronet is early-stage. We do not currently hold SOC 2, ISO 27001, HIPAA, or GDPR certification, and we won't claim any of these until they're actually true. Access to your dashboard requires a verified, signed-in session — nothing is reachable from a bare link or guessed ID. OAuth tokens are encrypted at rest.

Contact for security questions

Questions about any of this: jacob@atronet.co