Skip to content
AtomicReps

Legal

Privacy Policy

Last updated: August 28, 2026

Atomic Reps is operated by Atomic Reps AB, a Swedish limited liability company (aktiebolag) with its registered office at Arvid Tydéns Allé 28, 171 69 Solna, Sweden (org. no. 559593-4398). All references in this Privacy Policy to "Atomic Reps", "we", "us", or "our" mean Atomic Reps AB, which is the party responsible for the processing described here. Under the EU General Data Protection Regulation (GDPR), Atomic Reps AB acts in two distinct roles depending on the data:

The two GDPR roles we act in, and the data each one covers.
Our roleData it covers
ControllerAccount data, billing data, marketing email, security logs, and product analytics.
ProcessorWorkspace member practice data, processed on behalf of your organization under the Data Processing Agreement at /dpa, which applies on every plan, Free included.

This Privacy Policy explains what data we collect, how we use it, the lawful basis for processing, your rights under applicable privacy law (including the GDPR), and how to contact us. For privacy inquiries, contact us at privacy@atomicreps.com.

Data we collect

We collect and process the following categories of data:

  • Account data - Name, email address, and profile information provided through Clerk authentication. During onboarding you may also declare an optional experience band (years in the industry, in coarse buckets). It is used only in the anonymous aggregate research described in "How We Use Data", it is never shown to your workspace or your manager, and skipping it changes nothing.
  • Organization data - Organization name, membership records, and role assignments within your team.
  • Game data - Responses, scores, timing information, participation records from practice sessions, and any leaderboard nickname you choose.
  • Daily practice data - Answers to daily questions, streaks, progress tracking, and team-level aggregate statistics.
  • Slack integration data - Workspace ID, bot tokens, user ID mapping, email addresses, and display names when you connect Atomic Reps to your Slack workspace.
  • Technical logs - IP address and request metadata, processed for security and abuse prevention.
  • Preferences - Theme, audio, and motion settings stored locally in your browser via localStorage.

Slack integration data

When you connect Atomic Reps to a Slack workspace, we collect and process the following Slack-specific data:

  • Slack user ID and display name - Used to link your answers to your own practice record and to address you in Slack messages. Public leaderboards display a nickname you choose or an anonymous handle, not your Slack identity.
  • Email address - Used to link your Slack identity to your Atomic Reps account and to verify the email-match claim gate for free-tier installers (no end-member email is stored in the aggregate path).
  • Workspace (team) ID - Used to route messages to the correct workspace.
  • Answer history - Your responses to daily reps and sprint sessions delivered via Slack.

Slack-specific data is retained while the Slack integration is active for your workspace. When a workspace admin uninstalls Atomic Reps from Slack, all attributed Slack-specific data (user mappings, post history, sprint sessions, question feedback, insight delivery records, practice preferences, and in-Slack companion progress such as apprentice pets, their skills, and reward balances) is permanently deleted within 15 days (a 14-day retention window plus a daily deletion sweep). Anonymous aggregate statistics that contain no identifiers are retained under the 90-day rolling window described in "Your rights" below. An individual's erasure request follows the one-month erasure process described in "Your rights".

To request deletion, contact us at privacy@atomicreps.com.

Lawful basis for processing (GDPR Art 6)

We process personal data under the following GDPR Article 6 lawful bases:

  • Performance of contract (Art 6(1)(b)) - Account, authentication, billing, transactional email, and core game/practice functionality.
  • Legitimate interest (Art 6(1)(f)) - Service security, fraud and abuse prevention, request logging, storage of integration credentials, generation of team-level aggregate statistics that contain no per-member breakdowns, and anonymous counting of page visits (described under Cookies & local storage). You may object to legitimate-interest processing under Art 21; see "Your rights" below.
  • Consent (Art 6(1)(a)) - Optional in-browser product analytics and session replay (PostHog), and marketing email. Withdrawable at any time via the Cookie settings control in the site footer or the unsubscribe link. Declining still leaves the anonymous page counting described under Cookies & local storage, which places nothing on your device.
  • Legal obligation (Art 6(1)(c)) - Accounting and tax records as required under Swedish Bokföringslagen (1999:1078) and equivalent foreign law.

Who can see your practice data

Your individual answer history, accuracy, and streaks are visible only to you. On all current self-serve plans, workspace administrators cannot access individual answer history, accuracy, streaks, or inferred skill ratings, and other members never can. If we introduce a plan that permits administrator access to individual practice data, we will identify that functionality clearly before it is activated and update this policy and the applicable contractual terms first. The administrative hub contains configuration and goals only (Slack setup, channel routing, close scheduling, skill expectations, and billing); it contains no dashboards, activity views, or per-member statistics of any kind. Nothing derived from a person reaches your shared Slack channel: the daily question and the weekly recap carry question content and nothing else, with no scores, no accuracy figures, and no count of how many people answered. One team figure exists elsewhere: the Slack leaderboard. It is shown only to the member who asked for it, and withheld until at least 3 distinct people have answered. Skill expectations a manager assigns are goals the manager wrote; managers do not see the answers, accuracy, or measured levels behind them.

We retain your practice data both for your own visibility (your record, streaks, and certificates) and to improve the platform, for example tuning question difficulty and detecting broken questions. We never train third-party AI models on your data; see "AI and your data" on the Security page.

Public leaderboards display a nickname you choose or an anonymous handle (for example, Player-1234), not your workspace identity; setting or removing a nickname is your own reversible action. Scores in a live game session are visible to the players in that session. See our Terms of Service for the corresponding contractual description.

How we use data

  • Provide the Service: games, daily practice sessions, and leaderboards.
  • Authenticate users through Clerk.
  • Choose the level of your next question from your own answer history (adaptive level). This uses only your answers, produces no legal or similarly significant effect, and is visible only to you.
  • Deliver Slack integrations including Question of the Day and collection of your answers.
  • Generate the k-anonymous team figures shown in ephemeral Slack replies. The leaderboard is the only one left: only the member who asked for it sees it, and nothing person-derived is posted to the shared channel. The count that used to appear after you answered has been removed.
  • Maintain de-identified question-level statistics (containing no user or organization identifiers) to calibrate question difficulty across the platform. We may publish these anonymous aggregates as research findings (for example, which topics working engineers most often answer incorrectly). A published finding is never attributed to a person, a team, or a company, every published figure states the number of answers behind it, and nothing is published below a minimum sample across multiple organizations.

We never use your data to train, fine-tune, or improve AI or machine-learning models, and we never sell or share it. We do not send customer data to third-party AI providers. Beyond providing the Service, we use personal data only for the limited purposes set out in "Lawful basis for processing" above: security and abuse prevention, optional analytics and marketing email (which you can decline or withdraw), and legally required record-keeping.

Third-party services (subprocessors)

We rely on the following third-party services to operate Atomic Reps. Each service processes data under its own privacy policy and a written data processing contract with Atomic Reps AB as required by GDPR Art 28(3):

  • Clerk (clerk.com) - Authentication and user management. United States. Certified under EU-US Data Privacy Framework.
  • Convex (convex.dev) - Database and serverless backend. United States. Operates under EU SCCs.
  • Slack (slack.com) - Workspace integration for daily practice delivery. United States. Certified under EU-US Data Privacy Framework (through Salesforce, Inc.).
  • Cloudflare (cloudflare.com) - Frontend hosting, deployment, and CDN. United States and global edge network including EU points of presence. Operates under EU SCCs.
  • PostHog (posthog.com) - Optional product analytics and session replay, enabled only after explicit cookie-banner consent. Once consent is given, a signed-in user's name, email address, and organization name are sent to PostHog as profile properties. Session replay runs only on our public marketing pages (never inside the app, in games, or on checkout and claim pages) and masks all text you type. Analytics requests are proxied through our own domain and carry none of your session cookies. EU-region instance (eu.posthog.com); where a non-EU instance is configured, EU SCCs apply (Module 2 where we act as controller; Module 3 where we act as processor on your organization's behalf). Separately from browser analytics, and for every visitor rather than only consenting ones, we send PostHog an anonymous page-visit event from our own servers. It carries a one-way daily fingerprint instead of any identifier, and it deliberately creates no PostHog person profile, so these events are never joined to an account. The mechanism, and why the fingerprint cannot be traced back or matched across days, is described under Cookies & local storage below. Separately again, our Slack integration sends server-side product usage events to PostHog: when the apprentice and practice features are used, we record the event keyed to a pseudonymous internal user identifier, never your name or email address. These events carry no message content and are not used for advertising profiling. The legal basis is legitimate interest (GDPR Art 6(1)(f)); you can object at any time by emailing privacy@atomicreps.com.
  • Polar (polar.sh) - Payment processing and subscription management as Merchant of Record. Processes billing information including email address and subscription status. United States. For the payment and tax transaction itself, Polar acts as Merchant of Record in its own capacity (an independent controller, not our processor); we list Polar here for the billing-contact and subscription-management data it processes on our behalf, safeguarded under the EU Standard Contractual Clauses Polar has entered into. Polar uses Stripe (certified under the EU-US Data Privacy Framework) as a subprocessor for payment card handling.
  • Resend (resend.com) - Transactional and marketing email delivery. United States; transfers safeguarded under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement. Processes email addresses and email content for account notifications including data export, deletion confirmation, onboarding drip sequences, and billing communications.

We provide 30 days' advance notice before adding a new subprocessor. To subscribe to subprocessor change notifications, email privacy@atomicreps.com.

Data storage & retention

We separate your own practice record from your workspace's view of it. Your record is permanent; the workspace's link to it expires on a tiered schedule:

  • Your practice record - permanent: Every answer you give (which question, which answer, when) belongs to your own practice record on every plan, free or paid. It is visible only to you, it does not expire, and you can export, reset, or delete it from your account page. The windows below end the workspace's link to your answers, never the answers themselves, and this holds against the retention windows, a subscription ending, and being removed from a workspace. The one exception: if a workspace administrator deletes the whole workspace, the answers you gave inside it are deleted with it, since that is a complete erasure of the workspace and everything recorded in it.
  • Free tier - 90 days: Anonymous aggregate statistics (response counts, accuracy rates, domain-level metrics) on a 90-day rolling window. The aggregate rows contain no personal identifiers, and no admin-facing view of them exists: we keep them to tune question difficulty, not to report on a workspace. The workspace's link to the underlying participation records (Slack user ID, per-question correctness) is removed after 90 days; those records are never shown to admins at any point, and each member keeps their own answers as described above.
  • Pro plan (individual): Pro is a personal subscription held by one named individual rather than by a workspace. Your practice history is your permanent record as described above; no workspace administrator sees it.
  • Team plan - 365 days: The workspace's attribution layer (which member answered, for streaks and participation) runs on a 365-day rolling window, in addition to the 90-day aggregate layer. Individual answer history is visible only to the individual member (plus workspace leaderboards that show a chosen nickname or an anonymous handle, never a Slack identity). When the window rolls past an answer, the workspace's link to it is removed and the member keeps it in their own record.
  • Your own progress summary: A small summary of your own record: current and longest streak, lifetime answered and correct counts, and per-skill accuracy scores. It is yours to read. No administrator or manager surface reads it on any current self-serve plan, and the only place any of its numbers appear to another person is the pseudonymous leaderboard described above. It has no time window; it is kept for as long as you remain a member so your progress does not reset when the windows above roll. It is deleted when your account is erased, when an admin removes you from the workspace, and when a Team subscription ends. Your own practice record is not affected by any of those events.
  • End of subscription: Cancellation takes effect at the end of the paid billing period; the workspace's attributed layer remains available and exportable until then. On Team, when the subscription ends, that layer is removed immediately and cannot be restored, even on resubscribe: the practice targeting set up for each member is deleted, and every member's answers are permanently unlinked from the workspace. Each member keeps their own practice record. Anonymous team aggregates continue under the 90-day rolling window, and the workspace continues on the free tier until an administrator deletes it (see Your rights below). On Pro, your account returns to the free plan and your practice record is unaffected.
  • Slack integration data: Retained while the integration is active. Attributed Slack data is deleted within 15 days of uninstall (14-day retention window plus a daily deletion sweep); individual erasure requests follow the one-month erasure process.
  • Account and profile data: Your name, email address, and sign-in identifiers are held by Clerk, our authentication provider, for as long as your account exists. When your account is deleted, an erasure workflow removes your personal records across the Service, anonymizes attributed game history, and (where we hold a contact email for you) sends a confirmation email.
  • Aggregated, anonymized statistics: Statistics that contain no personal identifiers (for example, per-question accuracy rates and difficulty calibration across all users) are retained indefinitely to improve question quality and the Service (GDPR Art 89(1) statistical purposes; anonymized data is not personal data under Recital 26). Attributed records are folded into these statistics when they are written; removing a workspace link or deleting a record never reverses its contribution to an anonymous statistic, and no anonymous statistic can be traced back to you.
  • Email suppression list: When you unsubscribe from marketing or product email, we retain your email address on a suppression list so that we do not contact you again. This retention is necessary to honor your opt-out (legitimate interest, GDPR Art 6(1)(f)). The address is removed entirely when your account is deleted.
  • Webhook event logs: Records of the payment, authentication, email and Slack webhooks we receive, retained on a rolling 30-day window for security and for debugging a delivery that failed. A sweep deletes anything older.
  • IP addresses: Used transiently for rate limiting and abuse prevention. No IP address is stored on your account record or on your workspace record. The one counter we key on an address, the throttle on Slack install attempts, is deleted within two hours of the attempt. Beyond that, IPs appear only where any web service sees them: short-lived operational logs at our hosting and backend providers. We do not build a profile from them and we do not use them to identify individuals.
  • Workspace audit log: When someone changes a workspace (settings, roles, teams, the Slack connection, the subscription) we record who did it, what changed, and when. We do not record the IP address or the browser the action came from. Entries are readable by workspace administrators, cover administrative actions rather than practice answers, and are kept for 365 days from the event, after which a weekly job purges them automatically, on the legitimate-interest basis of security and accountability (GDPR Art 6(1)(f)). Unlike every other category above, audit entries are not removed by an individual erasure request: a trail an administrator could erase from their own account is not an audit trail, and Art 17(3)(e) preserves the record where it is needed to establish, exercise or defend a legal claim. The identifiers that survive are the acting administrator's user ID and, where the action concerned another person, that person's user ID, Slack user ID, or the email address an invitation was sent to. Deleting the workspace deletes the whole log with it.
  • Billing and tax records: Retained for 7 years as required by Swedish Bokföringslagen (1999:1078) and equivalent foreign law.
  • Application data is stored in a Convex cloud database hosted in the United States.
  • UI preferences (theme, audio, motion) are stored in your browser's localStorage and never leave your device.

Security incidents (breach notification)

If a personal data breach affects your data, we notify the affected workspace administrator(s) without undue delay after becoming aware of it. Where Atomic Reps AB is the controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, as required under GDPR Art 33(1), and, where the breach is likely to result in a high risk to individuals, we notify the affected individuals directly under GDPR Art 34. Our breach obligations as a processor are set out in the DPA.

International data transfers

Your data may be processed outside the European Economic Area (EEA), the United Kingdom, or Switzerland by our subprocessors. We rely on the following transfer mechanisms:

  • EU-US Data Privacy Framework - Clerk, Slack (through Salesforce, Inc.), and Stripe (Polar's payment-card processor) are certified under the EU-US Data Privacy Framework (adequacy decision adopted by the European Commission on 10 July 2023), including the UK Extension to the Framework for transfers from the United Kingdom; transfers from Switzerland rely on the Swiss adaptation of the SCCs described in our DPA. If the Framework ceases to provide a valid transfer mechanism, we rely on the EU Standard Contractual Clauses (Decision 2021/914) with appropriate supplementary measures for those transfers.
  • Standard Contractual Clauses (SCCs) - Convex and Cloudflare operate under the EU SCCs approved by the European Commission: Module 2 (controller-to-processor) where we act as controller, and Module 3 (processor-to-processor) where we act as processor on behalf of your organization. Resend (United States) safeguards its transfers under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement. Polar, as Merchant of Record, processes the payment transaction in its own independent capacity; where Polar processes billing or platform data on our behalf it does so as our processor under a separate controller-to-processor agreement that incorporates the EU SCCs. PostHog relies on EU-region hosting so no restricted transfer occurs; where a non-EU instance is configured, the EU SCCs apply (Module 2 where we act as controller; Module 3 where we act as processor on your organization's behalf). For transfers from the United Kingdom, the UK Addendum to the SCCs applies; for transfers from Switzerland, the Swiss adaptation of the SCCs described in our DPA applies.
  • Region selection - Where a subprocessor offers EU-region hosting, we configure that region. Our PostHog project is hosted in the EU (eu.posthog.com).

A complete register of our subprocessors, their hosting locations, and applicable Data Processing Agreements is available on request by contacting privacy@atomicreps.com.

Cookies & local storage

  • Clerk session cookies - Strictly necessary for authentication. These do not require consent under GDPR/ePrivacy.
  • Masthead marker (local storage, ar_wm) - Remembers for 45 minutes that the logo animation has played, so it does not replay on every page. Stored only in your browser, never sent to us, and it holds no identifier: the value is a timestamp.
  • Consent cookie (atomicreps-cookie-consent) - Records your analytics choice (accepted or declined) for 365 days so the banner does not return on every visit. Strictly functional; holds no identifier.
  • localStorage - Used for theme, audio and animation preferences, and for the local practice record of a visitor without an account. This data stays in your browser and is not transmitted to our servers.
  • Optional analytics cookie/local storage - If you accept analytics cookies, PostHog may set identifiers to measure page visits and product usage events, and to record session replays on our public marketing pages with all text input masked. Not loaded until consent is granted.
  • Returning visitor cookie (ar_vid) - Set only if you accept analytics cookies. It holds a random value that means nothing anywhere except here, and it lets us tell a returning visit from a first one. That is the only way to see whether people come back. Our server sets it rather than a script, because Safari deletes script-set cookies after seven days, which made every returning visitor look like a stranger. Scripts on the page cannot read it, and your browser never sends it to another site. It expires after 13 months. Decline and we never set it. Withdraw later and our server deletes it on your next visit, because nothing else can.

We do not use advertising cookies. Browser analytics and session replay are optional and only enabled if you explicitly accept them in the cookie banner. The server-side product usage events from the Slack integration, described under Subprocessors above, involve no cookies and no browser.

Anonymous page counting. Separately from the optional analytics above, we count page visits on our own servers without placing anything on your device. There is no cookie and no browser storage for this, so there is nothing for you to accept or decline. When a page is served we combine your IP address, your browser's user-agent string and a random value that we generate fresh each day, and we turn the three into a one-way fingerprint. We record only that fingerprint, the page address with any private query values stripped, the site that referred you, your country and whether you are on a phone, tablet or desktop.

The same counting covers a short, fixed list of things you do on our public pages: moving from one page to another without a full reload, answering a sample question, opening the pricing page, clicking an install or an upgrade button. Your browser sends these in small batches. We never tell it the fingerprint we file them under, so it cannot recognize you either.

We never include anything you type into a box. Each record may carry only a short label from a list we wrote in advance, a plain number, or a yes/no. Your browser drops anything else before sending, and we drop it again on arrival. An email address or a name cannot fit through that filter even by mistake.

The random daily value is deleted when the day ends and is never recoverable. That is what makes this anonymous rather than merely obscured: once it is gone, the fingerprints from that day cannot be recreated from anyone's IP address, and a fingerprint from one day cannot be matched to the same visitor on any other day. Your IP address is used for the calculation and immediately discarded. We never store it, never log it and never send it to PostHog. This is measurement of aggregate audience, not tracking of a person, and we rely on our legitimate interest in knowing how the site is used (GDPR Art. 6(1)(f)). You can object at any time by writing to privacy@atomicreps.com.

Tracking: We do not sell or share personal information and do not track you across other sites, so there is nothing to opt out of. Our optional analytics cookies are governed by the consent banner, and you can change or withdraw your choice at any time via the Cookie settings control in the site footer.

Your rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Access your personal data we hold (Art 15).
  • Export (data portability) in a machine-readable format (Art 20). This one is self-serve: from your account page, download your practice record as a single JSON file. It covers every answer you have given, your course progress, certificates, streaks and your apprentice, across every workspace you belong to. We build it and email you a link that works for 24 hours, and you can request one export a day. For any personal data the file does not carry, email the address below and we will assemble it for you.
  • Correct inaccurate or incomplete data (Art 16).
  • Delete your personal data (Art 17). We retain anonymized aggregate statistics on a 90-day rolling basis. Because these rows contain no personal identifiers, they fall outside the scope of the GDPR (Recital 26); to the extent any residual identifiability exists, they are retained for statistical purposes and exempt from erasure under GDPR Art 17(3)(d) read with the safeguards of Art 89(1). Your identified answer history is deleted without undue delay and within one month of a verified erasure request, subject to any extension permitted by GDPR Art 12(3) - independent of the 90-day aggregate retention window. One further carve-out, stated plainly because it is the kind of thing a policy usually buries: entries in a workspace's administrative audit log are not erased with your account, though every entry is still purged 365 days after it was recorded. See "Workspace audit log" under Data storage & retention for what those entries hold and why.
  • Object (Art 21) to processing of your personal data, including processing under legitimate-interest grounds.
  • Restriction of processing (Art 18).
  • Withdraw consent at any time, where processing is based on consent (Art 7(3)).
  • Lodge a complaint with your national supervisory authority. In Sweden: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy.se. You may also contact your local supervisory authority.

Provision of data: Provision of account data is contractually necessary; without it we cannot provide the Service. Provision of optional analytics consent is voluntary.

How to exercise them. Access, export and erasure of your own data are self-serve from your account page: download your practice record, reset parts of it, or delete the account. Workspace administrators can delete a workspace and its data from billing settings. For anything those controls do not cover, including personal data outside the export file, a workspace-wide export, an erasure request made on someone else's behalf, correction, restriction, or an objection, email privacy@atomicreps.com. We verify your identity using the email tied to your account before actioning a request.

United States

Residents of US states with comprehensive privacy laws may have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of its sale or sharing. We do not sell or share personal information, do not use it for targeted or cross-context behavioral advertising, and do not profile individuals for decisions that produce legal or similarly significant effects. We do not retaliate against anyone for exercising these rights.

To exercise a right, email privacy@atomicreps.com. We verify your identity using the email tied to your account and respond within the period required by applicable law.

Most people use Atomic Reps as employees of a customer organization. In that case the customer organization is responsible for the data and Atomic Reps AB acts as its service provider under the DPA; we will direct end-user requests to the customer organization and assist as needed.

Data Processing Agreement (GDPR Art 28)

Where Atomic Reps AB acts as data processor for your organization (e.g., when you upload custom questions or process member responses), a Data Processing Agreement under GDPR Art 28 is published at /dpa. Our standard DPA incorporates the EU Standard Contractual Clauses (Decision 2021/914): Module 2 (controller-to-processor) governs the transfer between your organization and us, and Module 3 (processor-to-processor) governs onward transfers from us to non-EEA subprocessors.

The DPA applies on every plan, Free included: your organization accepts it by subscribing to a plan, installing the Slack app, or creating a workspace. Counter-signed copies for procurement records are available on request from legal@atomicreps.com.

Age requirement

Atomic Reps is a tool for business users and is not directed to children. You must be at least 13, or the minimum age required where you live, to use it. We do not knowingly collect personal data from children; if you believe a child has provided us with personal data, contact us and we will delete it promptly.

Business transfers (change of control)

If Atomic Reps AB is involved in a merger, acquisition, or sale of all or substantially all of its assets, your personal data remains subject to this Privacy Policy, and any successor may process it only for the purposes described here. We will notify you before your personal data becomes subject to a different privacy policy, and you may exercise your deletion rights before any transfer takes effect.

Changes to this policy

We may update this Privacy Policy. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will provide at least 30 days' notice via email or in-product notification.

Governing law

This Privacy Policy is governed by the laws of Sweden, excluding its conflict-of-law rules. Any disputes shall be resolved by the courts of Stockholm, Sweden, except that nothing in this section limits any non-waivable statutory right under your local law.

For US residents: Any rights under applicable US state privacy law that cannot be waived by contract are not waived by this clause.

For EU and EEA consumers: Mandatory consumer protections in your country of residence apply notwithstanding this clause. An EU or EEA consumer may escalate an eligible dispute to Allmänna reklamationsnämnden (ARN, arn.se).

Contact

For privacy-related inquiries, contact us at privacy@atomicreps.com. For legal inquiries (including DPA requests), contact legal@atomicreps.com.

Security contact: to report a vulnerability, write to security@atomicreps.com. The same address is published at /.well-known/security.txt under RFC 9116. We confirm receipt before we fix.

See also: Terms of Service · Data Processing Agreement · Security