Atona reads, drafts, and replies on your behalf. That only works if your data stays yours: encrypted always, never sold, and never used to train AI models.
Atona drafts, you decide. Nothing goes out under your name until you approve it, and you can switch any automation off at any time.
Every reply Atona drafts, sends, or holds back is there for you to review — along with why it made that call.
Encrypted in transit and at rest. Never sold, never shared for advertising, and never used to train AI models.
Email that looks financial, medical, or legal is recognized and held back before AI ever sees it.
Everything you send to Atona is encrypted on its way to us, and everything Atona stores is encrypted where it sits.
The connections to your email and calendar are protected separately, so they are only ever usable inside your own account.
Atona is built so that one account's data can never appear in another's. That rule is enforced everywhere and tested continuously — it is the single thing we are strictest about.
Today, all data is stored in the United States. We do not sell your data, and we do not share it for advertising.
Atona uses AI to understand your email and draft replies. Your data is never used to train AI models — ours or anyone else's. The providers who process it on our behalf are contractually barred from keeping it or using it for anything else.
Some email never reaches AI at all. Anything that looks financial, medical, or legal is recognized and held back before it can be sent for processing. That check runs first, every time.
Access is limited to what is needed to run and support Atona. Personal details are stripped from our operational records automatically, so routine monitoring never exposes your email, your contacts, or your messages.
You can turn on two-factor authentication at any time, and changing your password signs you out everywhere.
You can delete your account from the app at any time. Deletion is real: your account and the data attached to it are removed — not deactivated and quietly kept.
Atona's handling of Google user data has been independently assessed under CASA — the Cloud Application Security Assessment, a framework published by the App Defense Alliance. It is the route by which applications that request access to sensitive Google user data demonstrate that they handle it responsibly.
A successful assessment produces a Letter of Validation: a scoped, dated document covering a named application, not an open-ended endorsement of the company that builds it. The framework and its current requirements are published at appdefensealliance.dev/casa.
A CASA assessment is deliberately bounded, and being specific about the boundary is part of taking it seriously. CASA is administered by the App Defense Alliance — it is an independent assessment, not a Google certification, endorsement, or partnership.
A point-in-time assessment says that a defined set of requirements was met on a defined date. It does not say nothing will ever go wrong. If you find a security issue, we would rather hear about it — see below.
Report a suspected vulnerability or a compromised account to [email protected]. For how data is collected, retained, and deleted, see the privacy policy.