Privacy Policy
What we collect, why we collect it, how long we keep it, and how to get it deleted.
Last updated
Athna, Inc. ("athna", "we") runs the website at athna.ai and the product at app.athna.ai. This policy says what we collect from you, why, how long we keep it, and how to get it deleted. It is written to be read, not skimmed. If anything in it is unclear, email hello@athna.ai and a founder will answer.
The short version
- Right now, the only thing you can give us is an early-access signup: your email and two optional answers.
- When the product opens and you connect accounts (Instagram, TikTok, YouTube, Drive, Dropbox, Frame.io), we access only what the product needs to do the job you asked for, and we say exactly what that is below.
- We don't sell your data. We don't train AI on your content without your opt-in.
- You can disconnect any account, or delete everything, yourself. Data deletion is the step by step.
Who we are
Athna, Inc., a Delaware corporation, is the data controller for everything in this policy. Write to us at hello@athna.ai, or by post to our registered address, which will be published here once incorporation completes.
Part 1 · The website today
What we collect when you sign up for early access
When you put your email in the box on athna.ai, we store one row:
| What | Why | Where it comes from |
|---|---|---|
| Your email address | To send one confirmation email now, and to invite you when the product opens | You type it |
| What you make (short-form, long-form, both, written) | To know who to invite first and what to build first | Optional; you tap it after signing up |
| Who's on your team (just you, you plus an editor, a team) | Same | Optional; you tap it after signing up |
| Where you came from: a source, medium and campaign tag, the page that referred you, and the page you landed on | To know which of our links brought you here, so we know what's working | Read from the link you clicked and kept in a cookie for 30 days (see Cookies) |
| The headline you saw | We test a few headlines on the home page; this records which one you saw | Set by the site |
| Your browser's user-agent string (the browser and device type) | To tell real signups from bots, and to know which browsers to test | Sent by your browser |
| When you signed up | Housekeeping | Set by us |
That's the whole row. No name, no phone number, no location beyond what your browser sends with every request.
What we don't keep
- Your IP address. We use it in the moment to stop one person from submitting the form hundreds of times, then we throw it away. It is not stored with your signup.
- Anything in the hidden field. The form has a field people can't see. If something fills it in, it was a bot, and we discard the submission.
The confirmation email
After you sign up, one email goes out from hello@athna.ai. It is sent by Resend on our behalf. It asks you to reply and tell us what you make; if you do, your reply lands in our inbox and we read it. You won't get a newsletter, a drip sequence or anything else until you've said yes to it.
How long we keep signups
Until one of these happens:
- You ask us to delete it. Reply to the confirmation email, or email hello@athna.ai. Done within 30 days, usually the same day.
- The early-access list closes. When the product opens and the invites have gone out, we delete the rows of anyone who didn't create an account.
Who can see it
The two founders, through an admin page that needs a password. The database is locked so that nothing on the public site can read it. Our hosting and email providers process it on our behalf; the full list, with what each one does, is in the Data Processing Addendum.
Part 2 · The product, once it opens
app.athna.ai is a workspace where you take a post from idea to published. To do that it needs an account, the things you put in it, and, if you choose, access to the accounts you publish to and the places your footage lives. Nothing in this part happens until you create an account; nothing about a connected account happens until you connect it.
Your account
Your email, a display name, how you sign in, and your settings. We keep it for as long as you have an account.
What you put in the workspace
Posts, scripts, notes, tasks, ideas in the Idea Inbox, messages to your team, comments, the docs you attach, and the things you tell athna AI. This is your content. We store it so the workspace works, we back it up so it isn't lost, and we do nothing else with it except what the AI terms say, which is: athna AI reads it to help you, and never trains on it unless you opt in.
The Idea Inbox
You can send ideas in by texting a number, emailing an address, through a Slack connection, from a browser extension, or by sending a reel to athna's Instagram account by direct message. Each one stores what you sent, when, and which channel it came through, and puts it in your Inbox. To match a text or a DM to your account, you enter a one-time code from your settings; we store which sender belongs to which account so we don't ask twice.
Connected accounts
When you connect an account, the service you're connecting shows you a screen that lists what athna is asking for and lets you say no. If you say yes, we receive an access token: a key that lets us act for you within those limits, and nothing more. Here is what we ask for, and why, per service.
Instagram (a professional account, through Meta)
- Publish: publishing the reels, posts and carousels you schedule, at the time you schedule them.
- Read your account and its insights: your username, your profile picture, and the views, reach, likes, comments, saves and shares on your posts, so the calendar shows what happened and athna AI can coach from your own results.
- Messages sent to athna's account: if you use DM-a-reel, you send a reel to @tryathna by direct message. We read the messages sent to our account so we can find the reel, match the sender to your workspace with the one-time code, and put the reel in your Idea Inbox. We do not read your DMs with anyone else, and we never send messages from your account.
Facebook Pages (through the same Meta connection)
- Publish to a Page you manage, and read the Page's insights, for the same reasons as Instagram. Only the Pages you choose.
TikTok
- Publish the clips you schedule. Read your profile and the views, likes, comments and shares on your posts.
YouTube
- Upload and publish the videos and shorts you schedule, with the title, description and thumbnail you set. Read your channel's details and the analytics on your videos.
- athna uses YouTube API Services. By connecting YouTube you also agree to the YouTube Terms of Service; the Google Privacy Policy covers how Google handles your data. You can remove athna's access at any time from your Google security settings. Data we hold from the YouTube API is refreshed or deleted within 30 days.
LinkedIn, X and Threads
- Publish the text posts, threads and carousels you schedule, and read your basic profile and the stats on your posts.
Google Drive, Dropbox and Frame.io (your footage)
- athna links to your footage; it never moves it. We read the folders and files you point us at (names, sizes, thumbnails, and the file itself when a task needs it, say to transcribe it) so a post can show the footage attached to it and an editor can find it. We don't upload, delete or rearrange anything in your storage.
Slack (for the Idea Inbox, as above)
- We read the messages sent to the athna connection in your Slack workspace, nothing else.
athna's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain English: we use your Google data only to give you the features you turned on, we don't sell it, we don't use it for ads, and no human at athna reads it except with your permission, for security, or where the law requires it.
What we do with data from connected accounts
- Publish what you told us to publish, when you told us to.
- Show how your posts did, inside your workspace.
- Let athna AI learn your style from your own posts, so its coaching is about you and not a generic creator. That happens inside your workspace and does not train any model; see the AI terms.
- Nothing else. We don't sell it, we don't share it with other creators, and we don't use it for advertising.
How long we keep it, and how to disconnect
- Access tokens are encrypted at rest and deleted the moment you disconnect the account. Disconnecting is one click in Settings → Accounts. You can also revoke athna from the other side (your Instagram, Google, TikTok or Dropbox settings); the token stops working and we delete it the next time we try to use it.
- Stats and profile details we've copied into your workspace are deleted within 30 days of disconnecting, unless they're attached to a post you keep. Then the numbers stay on that post until you delete the post.
- Footage stays where it is. Disconnecting removes the links.
- Everything goes when you delete your account. Data deletion is the step by step.
Payments
When paid plans open and you pay for one, your card details go to our payment processor and never touch our servers. We keep what we need for billing: your plan, the last four digits of the card, your invoices and your billing address. The processor will be named here before the first charge.
Usage and errors
Once the product is open we record which features are used, on which screens, and what broke, so we know what to fix. That uses PostHog for usage and Sentry for errors. On the website, analytics runs only if you accept it in the cookie banner; see Cookies. In the product, usage recording is part of the service and tied to your account; error reports are scrubbed of content before they're sent.
Everything else
We don't sell your data
Not now, not later. We don't share it with advertisers or data brokers. The only people who see your data are you; the people you add to your brand workspace, within the scopes you give them; the providers who run our infrastructure on our behalf (the list); and, if the law requires it, the authorities who compel it, in which case we tell you unless we're not allowed to.
Team members and editors
If you add a member or an editor to your brand workspace, they see what you scope them to see. Their account data is theirs and is covered by this policy the same way yours is.
Where the data lives
In the United States, on our providers' infrastructure. If you're in the UK, the EU or elsewhere, your data is transferred there under standard contractual clauses with each provider; the DPA has the details.
Your rights
Wherever you live, you can:
- See what we hold about you. Ask, and we'll send you a copy within 30 days.
- Correct it. Most of it you can edit yourself in Settings.
- Delete it. Data deletion.
- Take it with you. Export your workspace from Settings, or ask us for a copy in a machine-readable format.
- Object to a particular use, or ask us to limit it.
- Withdraw a consent you gave (the analytics cookie, the AI opt-in) as easily as you gave it.
- Complain to your data protection authority, if you think we've got it wrong. We'd rather you told us first.
If you're in the EU or UK, our legal bases are: performing our contract with you (running the workspace); your consent (analytics on the website, the AI training opt-in, each connected account); and our legitimate interest in keeping the service secure and knowing what's working (fraud checks, error reports).
If you're in California: the "sale" and "sharing" the CCPA talks about, we do neither, and we don't use your data for cross-context behavioral advertising. We don't treat you differently for exercising your rights.
Age
athna is for people 18 and older. We don't knowingly collect data from anyone younger; if you think we have, email us and we'll delete it.
Security
Encryption in transit and at rest, access tokens encrypted with a separate key, every table locked down, two-factor on every founder account. The whole list is in the Security policy. If we ever have a breach that affects your data, we'll tell you within 72 hours of confirming it.
Changes
When this policy changes in a way that matters, we'll email account holders before it takes effect and update the date at the top. Small fixes, a typo or a clearer sentence, just get a new date.