Privacy Policy
Effective June 11, 2026
Athena (athena.fm) is a private personal execution assistant: you capture notes, voice check-ins, and forwarded emails, and Athena organizes them into promises, follow-ups, reminders, and answers. Privacy is the product's foundation. This policy explains exactly what we collect, why, and the controls you have. The short version: your content belongs to you, it is never sold, never used for advertising, and never shared with other users.
What we collect
Account information. Your email address, name, aliases you add, and timezone.
Content you give Athena. Typed and dictated notes, uploaded or recorded audio and its transcripts, voice check-in conversations and their transcripts, emails you forward to your capture address, and corrections or feedback you submit.
Derived data. To make your content useful, Athena extracts structured items from it (promises, open loops, questions, decisions, people, reminders) and creates mathematical representations (embeddings) for search. Every extracted item links back to your original words as evidence.
Connected services (optional). If you connect Google Calendar, Athena reads upcoming events on demand to show your schedule, ground check-ins, and include meetings in your daily digest. See the Google section below.
Technical data. Product analytics events (for example, that a note was saved — not its contents) and error reports so we can keep Athena reliable. Payment details are handled by Stripe; we never see or store your card number.
How we use your data
Solely to provide Athena to you: organizing your captures, answering your questions over your own history, running your check-ins, sending the reminder, digest, and weekly review emails you can switch off at any time, and processing payments. We do not sell personal data, we do not show ads, and we do not use your content to advertise to you.
Google user data
If you connect Google Calendar, Athena requests read-only access to your calendar events (calendar.events.readonly) and your email address for display. Events are fetched when needed and shown to you; they are not shared with other users or third parties, not used for advertising, and not sold. Your Google OAuth tokens are stored encrypted (AES-256-GCM) and are deleted — and revoked with Google — the moment you disconnect the integration in Settings → Connections. Humans do not read this data except with your explicit consent, for security investigation, or where required by law.
Athena's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers we rely on
Athena runs on a small set of processors, each receiving only what is necessary: Supabase (database, authentication, and storage, encrypted at rest, with row-level security isolating every account), OpenAI (processing your content to transcribe, organize, and answer — under API terms that do not permit training on your data), Mailgun (sending and receiving the emails you opt into), Stripe (subscription billing), PostHog (product analytics), and Sentry (error monitoring). We do not share your data with anyone else except as required by law.
Retention and deletion
Your content is kept until you delete it. Deleting a source in History removes the source and the data extracted from it. Disconnecting an integration deletes its stored tokens. To delete your entire account and all associated data, email us at jamshid@rapiditeration.com and we will complete the deletion within 30 days.
Security
All traffic is encrypted in transit (TLS). Data is encrypted at rest. OAuth tokens carry an additional application-layer encryption. Every database row is scoped to your account with row-level security, and signed, expiring links protect any action taken from email.
Changes and contact
If this policy changes in a way that matters, we will note it here with a new effective date and, for significant changes, tell you by email. Questions or requests: jamshid@rapiditeration.com.
See also the Terms of Service.