DOC · PRIV-2026.09/GDPR · CCPA · Plain English

Privacy Policy.

What we collect, why we collect it, who we share it with, and how long we keep it. We've kept it specific so you can verify what we say. The short version is at the top of section one.

EffectiveSep 03, 2026
Last updatedSep 03, 2026
Reading time≈ 8 minutes

01 The short version

Five things to know before you read the rest.

  • We collect what we need to run the Service — your account, your prompts and generations, and basic usage. We don't sell it.
  • We do not use your prompts or generated code to train AI models — ours or anyone else's.
  • You can export your data and delete your account at any time from your account settings.
  • A short list of subprocessors (AI, payments, email, hosting) is in section seven.
  • If you're in the EU, UK, or California, you have specific rights — see section eight.

02 Who we are

This policy applies to athmane.com and the Service.

RDTM Labs FZE LLC (“Athmane”, “we”), registered at Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, is the data controller for your account and your use of the Service. This policy describes how we handle personal data when you visit our site, sign up for an account, or use the Service to build apps. It does not cover apps you build with Athmane and host yourself — those are your apps, and you're responsible for the people who use them.

The fastest way to reach us about anything in this policy: [email protected].

03 What we collect

Specifically — not “things like your data.” Here's the table.

Category
What it includes
Retention
Account
Email address and an optional display name. That's it to sign up.
Life of account
Content
The prompts you send to the AI and the code or output generated for you.
Until deleted
Abuse & copyright reports
If you report an app or file a copyright notice: your email, your IP address, and — on a § 512 notice or counter-notice — the name you sign it with, plus what you wrote. We need it to act on the report, to tell the two sides apart, and because a § 512 notice is a sworn statement that has to stay attributable.
Kept as a record, with no fixed window
Usage
Number of generations, credits consumed, model used, IP address, and user agent — for security and abuse detection.
Kept while the account exists
Published-app traffic
For an app published on Athmane: how many pages our servers sent, which of the app's own pages were asked for, the site that linked to the page (as a host name only — never the page or query on that site), and the country the request was made from (as a two-letter code supplied by the network edge — never the address). No visitor identifier, no IP address, no cookie, and nothing a visitor typed.
30 days
People you invite, and addresses we must not write to
The email address you give us to invite someone to your workspace, until they accept or the invite expires. And, separately, an address our mail bounced from or whose owner marked it as spam — we keep that one so we stop writing to it.
Invite: until accepted or expired. Suppressed address: until it is removed by hand
Billing
Stripe customer ID and subscription details. We never see your card number — Stripe holds that.
7 years (legal)
Integrations
OAuth tokens for GitHub or Figma — encrypted at rest, only the data you authorize.
Until disconnected
Device
A sign-in token held in your browser's local storage, plus browser and OS for compatibility.
Until sign-out

04 Why we collect it

In plain language.

  • To provide the Service — you need an account to use it.
  • To bill you — Stripe needs an email and a subscription record.
  • To prevent abuse — we throttle suspicious patterns.
  • To improve the Service — using anonymized, aggregated usage only.
  • To comply with the law — we respond to lawful requests.

We don't profile you for advertising and we don't use personal data for automated decisions with legal effects.

05 AI & model training

The most common question. The answer is no.

We do not use your prompts or generated code to train AI models — neither our own nor any third-party provider's. Prompts are sent to model providers under enterprise terms that exclude training and apply short retention windows.

We may use anonymized, aggregated usage data — for example, the number of generations per day — to improve the product. That data can't be linked back to you or to any individual person. It is separate from the per-app traffic counts described in §03, which are tied to an app and therefore to its owner, and are never tied to a visitor.

In practice
If you write the prompt “Build a booking page for Dr. Adams”, the words “Dr. Adams” never enter any training set. Period.

06 Cookies & tracking

Essential cookies only. No third-party tracking.

Your sign-in credential is a token kept in your browser's local storage, not a cookie, and sent with each request. We set three cookies: theme, which remembers light or dark for a year; __rt, a four-hour token that lets your browser load your own app previews; and athmane_site_session, set only if you unlock a published app its owner has put behind an access gate, which remembers for a week that you unlocked it. All of them are required for the Service to work, so no consent banner is needed for them — the full list is in our Cookie Notice.

We don't use Google Analytics, Meta Pixel, or any other third-party advertising tracker. If we add analytics that identifies you, or that stores or reads anything on your device, we'll show a banner first and let you opt out.

Counts our own servers keep of what they sent — see §03 — are not that. They set nothing on your device, read nothing from it, and record no identifier for the person who asked.

07 Subprocessors

The providers we rely on, and what each one is for. Where each processes your data, and under what safeguard, is on /subprocessors.

Mi
MiniMaxAI model provider — your prompts and relevant project files, for generation only.
API
E2
E2BRuns your generated code in an isolated microVM to produce the live preview — your project files, and whatever your code writes or fetches while it runs.
Sandbox
St
StripePayment processing. We receive a customer token, not your card number.
Payments
Cf
CloudflareCDN, DNS, and DDoS/WAF protection. Processes your IP address and request metadata.
Network
Re
ResendOur own transactional email — magic links and billing receipts. We do not run a mail server.
Email
He
HetznerHosting and encrypted at-rest storage of your account and generations.
Hosting
Gh
GitHubOptional integration. Activated only if you connect your account.
Optional
Fi
FigmaOptional integration. Activated only if you connect your account.
Optional
Nc
Name.comRegistrar of record if you buy a domain here. Receives the registrant contact ICANN requires.
Domains
Go
GoogleWeb fonts, served from Google's CDN. Your browser fetches them on every console page, so Google sees your IP and User-Agent.
Fonts
Cd
esm.sh / unpkg / Tailwind CDNPublic CDNs your PUBLISHED app loads code from, in each visitor's browser — their IPs, not yours, and never routed through us.
Published apps

An email provider you connect for an app you build is not our subprocessor. We are not an email provider: if your app sends mail, it goes through your own Resend / Mailjet / SendGrid / Postmark / Mailgun / Brevo account, under your contract with them. We store that credential encrypted and relay only what your app asks us to.

We do not sell your data, and we do not use your prompts to train AI models. If we add a subprocessor that materially changes the privacy picture, we'll let you know in advance.

08 Your rights

Under GDPR, the UK GDPR, and CCPA. Most are one click from your account.

01 Access

Get a copy of the personal data we hold about you. Use Export Data in your account settings.

02 Rectification

Correct anything that's wrong — name, email, account details — directly in your account settings.

03 Erasure

Delete your account and generations from your account settings → Delete Account.

04 Portability

Export Data returns a JSON of your account and generation history.

05 Restriction

Ask us to pause processing while we look into a question. Email [email protected].

06 Objection

Object to processing based on legitimate interest, or opt out of marketing email.

07 Complain to a regulator

Lodge a complaint with your local data-protection supervisory authority — in the EU, the one where you live, where you work, or where the issue arose. You can do this without contacting us first.

To exercise any of these, write to [email protected]. We respond within 30 days, free of charge.

09 Security

What we do to protect your data — and what we ask of you.

  • All data encrypted in transit (TLS 1.2+).
  • Sensitive fields encrypted at rest (AES-256).
  • No one on our team can read your prompts without leaving an audit log entry.
  • If a breach affects your personal data we'll tell you without undue delay, and report a qualifying breach to the competent supervisory authority within 72 hours of becoming aware of it, as GDPR art. 33 requires.

On your side: keep your email account secure with a strong password — anyone with access to your inbox can request a sign-in link.

10 Retention & deletion

How long things stick around, after you delete.

  • Auth data — your sessions end immediately, and the account record itself is deleted 30 days after you ask, along with the sign-up IP. The 30 days exist so an account deleted by mistake, or by someone who got into it, can still be recovered; nothing new is collected in that time and you can ask us to finish it sooner.
  • Generation history — deleted within 30 days of account deletion.
  • Billing records — kept for 7 years (legal requirement).
  • Published-app traffic counts — kept for 30 days, then dropped. Dropped immediately if the app is unpublished or deleted.
  • Anonymized usage logs — kept indefinitely; can't be linked back to you.
  • Apps, projects and their data — deleted immediately when you delete them. There is no trash and no grace period, and we can't restore them for you; export first if you want a copy.
  • Our infrastructure backups — encrypted, kept three days, and not restorable per-customer. Anything you delete is gone from them within three days. They exist so we can recover from an outage, not as a copy of your account.

11 Children

The Service isn't for kids.

The Service is not intended for children under 16. If we discover an account belongs to someone under 16, we'll delete it.

12 Changes to this policy

We'll tell you before anything material changes.

We'll email you at least 30 days before any material change takes effect. Material changes include adding new subprocessors or changing data-retention windows. Minor edits (typos, clarifications) are made in place with a new “Last updated” date.

13 Contact

Real humans. Quiet inbox.

Privacy questions, data requests, or anything else this page should answer but doesn't: [email protected].

Privacy Policy — Athmane