01 The short version
Five things to know before you read the rest.
- We collect what we need to run the Service — your account, your prompts and generations, and basic usage. We don't sell it.
- We do not use your prompts or generated code to train AI models — ours or anyone else's.
- You can export your data and delete your account at any time from your account settings.
- A short list of subprocessors (AI, payments, email, hosting) is in section seven.
- If you're in the EU, UK, or California, you have specific rights — see section eight.
02 Who we are
This policy applies to athmane.com and the Service.
RDTM Labs FZE LLC (“Athmane”, “we”), registered at Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, is the data controller for your account and your use of the Service. This policy describes how we handle personal data when you visit our site, sign up for an account, or use the Service to build apps. It does not cover apps you build with Athmane and host yourself — those are your apps, and you're responsible for the people who use them.
The fastest way to reach us about anything in this policy: [email protected].
03 What we collect
Specifically — not “things like your data.” Here's the table.
04 Why we collect it
In plain language.
- To provide the Service — you need an account to use it.
- To bill you — Stripe needs an email and a subscription record.
- To prevent abuse — we throttle suspicious patterns.
- To improve the Service — using anonymized, aggregated usage only.
- To comply with the law — we respond to lawful requests.
We don't profile you for advertising and we don't use personal data for automated decisions with legal effects.
05 AI & model training
The most common question. The answer is no.
We do not use your prompts or generated code to train AI models — neither our own nor any third-party provider's. Prompts are sent to model providers under enterprise terms that exclude training and apply short retention windows.
We may use anonymized, aggregated usage data — for example, the number of generations per day — to improve the product. That data can't be linked back to you or to any individual person. It is separate from the per-app traffic counts described in §03, which are tied to an app and therefore to its owner, and are never tied to a visitor.
08 Your rights
Under GDPR, the UK GDPR, and CCPA. Most are one click from your account.
01 Access
Get a copy of the personal data we hold about you. Use Export Data in your account settings.
02 Rectification
Correct anything that's wrong — name, email, account details — directly in your account settings.
03 Erasure
Delete your account and generations from your account settings → Delete Account.
04 Portability
Export Data returns a JSON of your account and generation history.
05 Restriction
Ask us to pause processing while we look into a question. Email [email protected].
06 Objection
Object to processing based on legitimate interest, or opt out of marketing email.
07 Complain to a regulator
Lodge a complaint with your local data-protection supervisory authority — in the EU, the one where you live, where you work, or where the issue arose. You can do this without contacting us first.
To exercise any of these, write to [email protected]. We respond within 30 days, free of charge.
09 Security
What we do to protect your data — and what we ask of you.
- All data encrypted in transit (TLS 1.2+).
- Sensitive fields encrypted at rest (AES-256).
- No one on our team can read your prompts without leaving an audit log entry.
- If a breach affects your personal data we'll tell you without undue delay, and report a qualifying breach to the competent supervisory authority within 72 hours of becoming aware of it, as GDPR art. 33 requires.
On your side: keep your email account secure with a strong password — anyone with access to your inbox can request a sign-in link.
10 Retention & deletion
How long things stick around, after you delete.
- Auth data — your sessions end immediately, and the account record itself is deleted 30 days after you ask, along with the sign-up IP. The 30 days exist so an account deleted by mistake, or by someone who got into it, can still be recovered; nothing new is collected in that time and you can ask us to finish it sooner.
- Generation history — deleted within 30 days of account deletion.
- Billing records — kept for 7 years (legal requirement).
- Published-app traffic counts — kept for 30 days, then dropped. Dropped immediately if the app is unpublished or deleted.
- Anonymized usage logs — kept indefinitely; can't be linked back to you.
- Apps, projects and their data — deleted immediately when you delete them. There is no trash and no grace period, and we can't restore them for you; export first if you want a copy.
- Our infrastructure backups — encrypted, kept three days, and not restorable per-customer. Anything you delete is gone from them within three days. They exist so we can recover from an outage, not as a copy of your account.
11 Children
The Service isn't for kids.
The Service is not intended for children under 16. If we discover an account belongs to someone under 16, we'll delete it.
12 Changes to this policy
We'll tell you before anything material changes.
We'll email you at least 30 days before any material change takes effect. Material changes include adding new subprocessors or changing data-retention windows. Minor edits (typos, clarifications) are made in place with a new “Last updated” date.
13 Contact
Real humans. Quiet inbox.
Privacy questions, data requests, or anything else this page should answer but doesn't: [email protected].