Privacy Policy
This policy explains what data Atrium (atriumreader.com) collects when you use it, why, who it is shared with, and the choices and rights you have. Atrium is a reading application: you save passages and links, and it reads them aloud. We keep the amount of personal data we handle small and we do not sell it.
Atrium is an independent product. For any privacy question or request, contact privacy@atriumreader.com.
Information we collect
Account information
You sign in with Google. We receive and store your Google account email address, name, and profile picture URL. We do not receive your Google password. We also store a text-to-speech voice preference and the date your account was created.
Content you create
We store the content you put into Atrium so we can show it back to you and read it aloud: the passages you write, paste or save (including any original formatting we keep for your reference), the links and files you save, and the shares you send (a copy of the shared item plus the recipient email address you type).
Usage and diagnostics
To keep Atrium working and understand which features are used, we collect a limited set of product-usage events (for example, that a passage was played or a share was sent) and error diagnostics when something goes wrong. See Analytics and error diagnostics below for exactly what these contain.
On your device only
Some preferences stay in your browser and are never sent to us: playback speed, your position in a passage, display font size, and notification prompt state.
How we use your information
- To provide the app: store and display your passages, links and shares.
- To read text aloud and, when you ask, to refine a passage for listening.
- To sign you in and keep you signed in.
- To send you a notification when someone shares content with you, if you opt in.
- To fix bugs, keep the service secure, and understand which features are used.
We do not sell your personal data, and we do not use your saved passages or links to build advertising profiles.
Text to speech and audio
When you play a passage, its text is sent to Google's Vertex AI (Gemini) to generate speech, and, if you use the refine feature, to rewrite the passage for listening. The generated audio is cached so repeat plays are fast. The audio cache is addressed by the content of the text, not by your identity, so identical text produces the same cache entry regardless of who requested it.
Analytics and error diagnostics
Product analytics (PostHog).We record a small, fixed set of usage events tied to a random internal account identifier. Analytics is locked down: it does not scrape the content of your passages, does not record your screen, and respects your browser's "Do Not Track" setting. Your email and name are never sent to analytics.
Error diagnostics (Sentry). When a request fails, we capture an error report so we can fix it. To make a failure debuggable, that report can include the content of the failed request (for example, the passage that failed to save) and your email address. These reports are used only for diagnosing and fixing problems.
Cookies and local storage
We use one essential cookieto keep you signed in. It is required for the app to function; there are no advertising or third-party tracking cookies. We also use your browser's local storage for the on-device preferences listed above.
Who we share data with
We share data with the service providers below so Atrium can operate. They process data on our behalf and only for the purposes shown. Several are based in the United States, so using Atrium involves transferring data internationally.
The last column is deliberate: it says whether each provider can identify you from what it receives. Only our analytics provider (PostHog) receives data that is anonymous from its point of view — a random identifier with none of your name, email or content. The others necessarily handle data that can identify you in order to do their job.
| Provider | Purpose | Data | Can it identify you? |
|---|---|---|---|
| Google (OAuth + Vertex AI) | Sign-in, and text-to-speech / passage refinement (Gemini). | Your Google account email, name and profile picture at sign-in; the text of a passage when you play it aloud or refine it. | Yes at sign-in (it is your Google account). Text-to-speech and refine requests carry only the passage text, under our service account, not linked to your Atrium profile. |
| Supabase | Database and file storage. | Everything you save (passages, links, files, shares, notification subscriptions) and your generated audio. | Yes. It holds your account record and all your content. |
| Vercel | Application hosting. | Requests to the app, plus operational server logs. | Yes. It processes your requests, so logs can include identifiers. |
| Sentry | Error and crash diagnostics. | Error reports, which may include the content of a failed request (for example a passage that failed to save) and your email, so a broken save is debuggable. | Yes. Reports can include your email and request content. |
| PostHog | Product analytics (which features are used). | A small, fixed set of usage events keyed to a random internal account identifier. Never your passages, links, email or name. | No. From PostHog's point of view the data is anonymous: it sees only a random identifier, never your name, email or content. |
We may also disclose information if required by law, or to protect the rights, safety and security of Atrium and its users.
Sharing with other people
When you share a passage or link with someone, we store the recipient email address you enter and a copy of the shared item so we can deliver it. If the recipient does not have an account yet, the pending share waits until they sign in with that email. A share is a one-time copy: editing or deleting the original does not change what the recipient received.
Data retention and deletion
We keep your data while your account exists. Deleting a passage or link removes it from your lists.
You can delete your entire account at any time from Settings, under Account. Deleting your account permanently removes your profile, passages, links, shares, files, notification subscriptions and connected-app tokens. This cannot be undone. Cached generated audio is addressed by content rather than by your identity and is not personal data; it may be retained.
Your rights
Under Brazil's LGPD (Lei Geral de Proteção de Dados), and comparable laws elsewhere, you have the right to access the personal data we hold about you, to correct it, to delete it, to obtain a copy, and to ask about how it is shared. You can exercise most of these directly: update your profile in Settings, and delete your account in Settings under Account. For anything else, email privacy@atriumreader.com and we will respond.
Children
Atrium is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
Security
We use reputable infrastructure providers, encrypt data in transit, and restrict access to your data. No online service can be perfectly secure, but we take reasonable measures to protect your information.
Changes to this policy
We may update this policy as the app evolves. When we do, we will change the effective date at the top, and we will notify you by email in advance of any significant change.
Contact
Questions or requests: privacy@atriumreader.com. Atrium is operated from Brazil.