Privacy Policy
This policy explains what Atmos collects, what a scan does and does not send us, how long each category is kept and how to get it deleted.
1. Who is responsible
Atmos Security Consultoria em Ti LTDACNPJ 67.252.845/0001-45
Rua Pais Leme 215, Conj 1713
Pinheiros, São Paulo SP, 05424-150
Brazil
support@atmoslab.dev
For the data we handle to run our own business, such as your account and your billing, we are the controller. For the data your scans upload about your code and your contributors, we act as a processor on your behalf under the Data Processing Addendum, and you are the controller.
Data protection contact: support@atmoslab.dev. This is the communication channel for everything in this policy, including requests about your data, and it reaches the person responsible for personal data at Atmos.
2. What a scan sends us
Scans run on your machine or in your continuous integration. We never clone your repositories. When a scan finishes and upload is enabled, it sends:
- the findings themselves, with their severity, message and rule identifier,
- the identity of the repository being scanned, and the branch and commit the scan ran on,
- file paths relative to the scan root, and line and column numbers,
- the trace behind a finding, meaning the sequence of locations the analysis followed from the entry point to the dangerous call,
- for dependency findings, the package, the resolved version, the advisory identifier and the dependency path,
- one-way hashes of the email addresses of recent committers, covered in its own section below,
- scan metadata such as the CLI version, the operating system family, durations and error counts.
Lines of your source code are not sent. The scanner omits the source text of a finding by default, including inside traces. It is sent only if you pass --snippets yourself on the command line. The editor extension cannot send source text at all: it has no snippet setting and strips the flag if a configuration tries to add it. If you turn it on in the CLI, the source lines around each finding are stored with the finding and are deleted with it.
--no-upload keeps even the findings on your machine. The license check still runs, because a scan cannot run without it, and that check sends only your workspace token and the scan metadata needed to meter it.
Values matched by rules that detect secrets are redacted by the scanner before upload. See what leaves your machine for the same list written for engineers.
3. Committer email hashes
Atmos counts how many developers are active in your repositories, so we can tell you when your team has outgrown the seats you pay for. To do that without collecting an address book, the scanner replaces each recent committer email address with a one-way hash before anything is sent. The addresses themselves never leave your machine.
We treat these hashes as personal data, not anonymous data. Someone who already knows an email address can recognize its hash, so the data is pseudonymous, and every right in this policy applies to it.
Why we are allowed to do it. Our lawful basis is legitimate interest, under GDPR Art. 6(1)(f) and LGPD Art. 7, IX, in metering seats accurately. We never receive the address itself, we never contact anyone from this data, we never use it for marketing, profiling or sale, and the count never blocks a scan.
How long we keep them. A hash is kept only while it is inside the 90 day activity window the seat comparison uses. It is purged when it falls out of that window or when the workspace is deleted, whichever comes first.
If you are a contributor to a repository scanned by Atmos and you want your hash removed, write to support@atmoslab.dev. We will act on that directly, and we will also tell the customer whose workspace holds it, because they are the controller for that data.
4. What else we collect
Account
You sign in with GitHub. We receive your GitHub user identifier, your username, your display name, your avatar URL and the email address on that account. We use it to create your account, to identify you in your workspace, and to send you account email.
Workspace
Workspace names, membership, roles, invitations you send, the projects you connect and your workspace tokens, which are stored as hashes rather than in a form we can read back.
Billing
If you subscribe, our payment processor collects your payment details and your billing address directly. Card numbers never reach our systems. We store the customer and subscription identifiers, the plan, the seat count, the invoice amounts and dates, and the tax identification you give us. Payment events we receive are reduced at the moment they arrive to the fields billing actually needs, so names, email addresses and addresses from those events are not written to our records.
Support
The content of what you send us and the address you sent it from, kept as long as it is useful to the conversation and to the record of what we agreed.
Logs
Application and audit logs record which account or token performed an action, on which resource, at what time, and the IP address it came from. We use them to operate the service, to investigate abuse and to answer your own security questions about your workspace.
This website
atmoslab.dev and docs.atmoslab.dev load no analytics, no telemetry and no third-party scripts today, and set no cookies of their own. If that changes, this policy will describe the change before it takes effect. The application at app.atmoslab.dev sets only the cookies sign-in needs to keep you signed in.
5. Why we are allowed to process it
| Data | Basis |
|---|---|
| Account, workspace, findings, scan metadata | Performance of the contract with you, GDPR Art. 6(1)(b) and LGPD Art. 7, V. Without it there is no service. |
| Billing records and invoices | Performance of the contract, and compliance with a legal obligation for the fiscal records, GDPR Art. 6(1)(c) and LGPD Art. 7, II. |
| Committer email hashes | Legitimate interest in metering seats, GDPR Art. 6(1)(f) and LGPD Art. 7, IX. See the section above for the balancing. |
| Audit logs, including IP addresses | Legitimate interest in security, abuse prevention and operating the service, GDPR Art. 6(1)(f) and LGPD Art. 7, IX. |
| Support messages | Performance of the contract and our legitimate interest in answering you. |
6. Who we share it with
We do not sell personal data and we do not share it for advertising. We use a short list of service providers to run Atmos, each with a written agreement and access to only what its job needs. The categories we use, and the trust review that shares the current named list, are on the subprocessors page.
There is no artificial intelligence or large language model subprocessor. No customer code, no findings and no personal data are sent to a model provider by any part of Atmos, and nothing we hold is used to train a model.
We may also disclose data when the law requires it, and we will tell you first unless we are legally prevented from doing so. If the business is ever sold or merged, data moves with it and this policy continues to apply until it is replaced with notice.
7. Where it is processed
We are established in Brazil and our production systems run in the United States. Transfers out of the European Economic Area and the United Kingdom rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one covers the destination. Transfers out of Brazil follow the international transfer rules in LGPD Chapter V.
8. How long we keep it
| Category | Retention |
|---|---|
| Findings and scan history | Until you delete the workspace or the account. Removal completes within 90 days of the deletion. |
| Source snippets, if you opted in | Stored with the finding and deleted with it. |
| Committer email hashes | The 90 day activity window used for the seat comparison, then purged. |
| Account and workspace records | Until you delete the account. |
| Audit logs, including IP addresses | 12 months, then purged automatically. |
| Invitations that are never accepted | Expire and are purged, and are removed when the workspace is deleted. |
| Billing and fiscal records | 5 years, which is the retention Brazilian fiscal law requires of us. Payment events are reduced to the billing fields at the moment we receive them, so personal details from the payment processor are not part of what is kept. |
| Support messages | While the conversation is useful, and then deleted on request. |
9. Your rights
Whatever law applies to you, you can ask us to:
- confirm whether we hold data about you, and give you a copy of it,
- correct it when it is wrong or incomplete,
- delete it,
- export it in a portable format,
- restrict or object to processing that rests on legitimate interest,
- tell you who we shared it with, and withdraw a consent you gave, without that affecting what happened before you withdrew it.
The dashboard has an export and a delete path you can use yourself. For anything else, write to support@atmoslab.dev. We complete erasure requests within 30 days of confirming who you are, and we will tell you if a request takes longer than that and why. There is no charge for a request that is not clearly excessive.
Deletion removes your workspaces, projects, findings, scan history and tokens. What survives is the fiscal record described above, and only that.
If we get it wrong, you can complain to the Brazilian data protection authority, the ANPD, or to the supervisory authority where you live. We would rather you told us first.
10. How we protect it
Data is encrypted in transit and at rest. Access to production is limited to the people who need it and is logged. Workspace tokens are stored as hashes, are shown to you exactly once, can carry an expiry and can be revoked at any time. Payment card details never reach our systems. Secret values matched during a scan are redacted before upload. No control makes a breach impossible, and if one affects your data we will tell you and the relevant authority as the law requires.
11. Children
Atmos is a tool for professional software development and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, write to us and we will delete it.
12. Changes to this policy
When this policy changes materially we will give notice by email or in the product before the change applies. The date at the top of this page always reflects the version in force.