Privacy Policy
Effective 4 October 2026
Your archive is not our advertising inventory.
AtArchive is operated by At Archive, a United States business based in New York, New York. AtArchive is built to preserve and make sense of records you choose to entrust to it. We do not sell customer archive content or use it to build advertising profiles.
An archive may contain years of sensitive correspondence, files, calendars, contacts, and derived history. Our privacy and security design therefore emphasizes least privilege, user and tenant isolation, protected credentials, data minimization, bounded operational access, and deletion and retention behavior that matches the promise we make.
1. Who we are and how to contact us
At Archive operates the AtArchive service from New York, New York, United States. This Privacy Policy is written primarily for a U.S.-based service and U.S. privacy requirements, while the service may be offered globally where lawful and operationally supported.
Privacy questions and requests may be sent to info@atarchive.com.
2. What this Policy covers
This Policy describes how AtArchive processes personal data when you visit the public site, join early access, connect supported providers, preserve records, search an archive, use insights or model-assisted features, purchase a service, or contact us for support.
3. Data AtArchive may process
- Account and transaction data. Account/profile information, service settings, purchase and entitlement records, payment-related transaction records, and support communications.
- Provider authorization data. Provider account identifiers, authorization grants, access/refresh tokens, scopes, and connection state needed to access a source you choose to connect.
- Archive content. Supported email, attachments, files, calendar records, source metadata, and other material you choose to preserve.
- Derived archive data. Search indexes, embeddings where used, People/Organization projections, classifications, measured insights, generated summaries, reports, histories, and other intelligence produced from your archive.
- Operational data. Import-job state, usage/metering records, service health, security events, bounded diagnostics, and technical logs.
- Early-access data. If you join early access, we store the normalized email address you submit, the signup time, and the applicable consent version in private AtArchive-managed Azure storage.
- Public-site acquisition context. The current public site uses a first-party cookie named
aa_acq_v1to remember first-touch and last-touch acquisition context for up to 90 days. It may contain the page/route you visited, bounded campaign parameters, the referring host, and page/scenario metadata. It does not contain archive message bodies, attachments, provider tokens, or private archive contents.
4. Why we process data
AtArchive processes data to provide the archive and features you choose; authenticate and maintain provider connections; preserve, index, search, analyze, and export records; operate background jobs; protect the service; investigate failures and abuse; provide support; meter and bill for services; communicate about early access or launch where you requested those communications; improve product reliability and usability; and comply with legal obligations.
We do not repurpose customer archive content for targeted advertising or data-broker enrichment.
5. Ownership and authorization
AtArchive does not take ownership of your archive content. You are responsible for having the rights, permissions, consents, and lawful authority required to connect and preserve the material you submit. Technical access to an account is not itself proof that you have the legal right to retain all material in that account.
See the Terms of Service for the full user-authority representation and the limited license you grant AtArchive to operate the service.
6. Sale, advertising, and cross-customer use
AtArchive does not sell customer archive content. We do not use archive content to build advertising profiles or to target advertisements across customers.
The current public site does not require third-party advertising trackers to operate. It does use the first-party acquisition-context cookie described above. That cookie is host-scoped by default, uses SameSite=Lax, and is not intended to become a shared authentication cookie across AtArchive subdomains.
7. Model-assisted features
Preservation and deterministic archive functions are separate from model-assisted features. When you use a feature that requires model processing, AtArchive may send the bounded source material needed for that feature to the configured model-service boundary.
AtArchive does not use one customer's archive to train a general-purpose or cross-customer AtArchive model.
External model services have their own processing, retention, and training terms. AtArchive does not make a universal “never used for model training” claim until the applicable provider, contract, and configuration support that promise. Product information for a model-assisted feature should identify the relevant provider boundary, source scope, retention/training terms, persistence, and deletion behavior.
8. Service providers and subprocessors
AtArchive relies on service providers to operate parts of the service. Depending on the feature, these may include Microsoft Azure infrastructure, Google or Microsoft source-provider APIs, payment services, and model/AI services.
We limit provider access to what is reasonably necessary for the service being delivered. Provider contracts, configuration, region, retention, and transfer behavior may vary by service and feature.
9. Security
AtArchive treats archive content as sensitive data. Current security principles include least-privilege provider access, user/tenant isolation, protected credential handling, HTTPS transport, bounded operational access, sensitive-log minimization, and evidence-backed public security claims.
No online service can promise perfect security. We avoid absolute claims such as “no backups,” “immediate physical deletion everywhere,” or “always region-local” unless the deployed system can actually prove them. See Trust & Security for the current public explanation.
10. Retention, deletion, and provider disconnection
Disconnecting a provider, deleting an archive, deleting generated intelligence, deleting an export, and deleting an AtArchive account are different operations and may affect different data.
Deletion can involve primary records, attachments/files, calendar data, derived People/Organization records, search indexes or embeddings, generated intelligence, queues, operational logs, backups, soft-delete/versioning, and exports. Some residual copies may remain for a limited period where necessary for backup recovery, security, fraud prevention, legal obligations, or provider/platform operation.
For early-access email, you may request removal by contacting info@atarchive.com. Launch emails will include an unsubscribe path when outbound launch communications begin.
11. U.S. privacy rights
Depending on the U.S. state in which you live and the law that applies, you may have rights to request access to personal data, correction, deletion, or a portable copy, and in some cases to appeal a privacy-request decision or opt out of certain uses.
AtArchive does not sell customer archive content or use archive content for targeted advertising. To make a privacy request, contact info@atarchive.com. We may take reasonable steps to verify your identity and authority before acting on a request, and we will respond as required by applicable U.S. law.
12. International users and processing
At Archive is a U.S. business and this Policy is centered on U.S. law. AtArchive and its providers may process data in the United States and other locations where our providers operate. We do not promise that all processing remains in one region unless the applicable product and provider configuration expressly says so.
If you use AtArchive from outside the United States, mandatory local privacy or consumer rights may still apply. This Policy is not intended to waive rights that applicable law does not permit you to waive.
13. Children
AtArchive is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The private archive product may apply additional age or contractual-capacity requirements when customer accounts open.
14. Changes to this Policy
We may update this Policy as the service, provider relationships, data flows, or legal requirements change. The effective date above will change when the Policy materially changes.
15. Contact
At Archive · New York, New York, United States · info@atarchive.com