Data Privacy and Security

You upload sensitive interview transcripts, persona definitions, and research questions. Here's what's done with your data, what isn't, and what control you have.

The short version

  • Your data is isolated to your account — other users can't see it
  • Your data is not used to train AI models
  • Your data is not sold or shared with third parties
  • You can export your data anytime
  • You can delete your data anytime, and deletion is permanent

The platform makes money from subscriptions, not from your data. That's the structural reason these promises hold.

What "isolated" means in practice

Each account has its own data space. No mechanism for one user to view another user's content. Even if you're on the same Team plan, members don't see each other's private projects unless the creator shares them.

If your competitor also uses the platform, they cannot see your research, personas, or reports. Same way two people using the same email provider can't see each other's inboxes.

What's not done with your data

Not used to train models. When you upload a transcript and AI analyzes it, that analysis is for your session only. The content does not become training data for any model. This is true even if you're on the free plan.

Not shared with third parties for advertising. Your data isn't sold to advertisers, data brokers, or anyone else. The business model is subscription fees, not data monetization.

Not visible to other users. No mechanism for content from your account to leak into another user's session, persona picker, or report.

What does happen with anonymized usage data

The platform collects anonymized usage statistics — that you used a feature, not what you did with it. Things like "user ran an interview on Tuesday" or "report generation took 40 seconds." This is used to improve product performance. The data cannot be reverse-identified back to you or your content.

Who at the company can see your data

By default, no one. atypica employees do not have access to your content as part of normal operations. There are two narrow exceptions:

  • You explicitly grant access (e.g., you contact support and ask them to look at a specific report to debug an issue)
  • Required by law (e.g., a valid court order; the platform would notify you if legally permitted)

In both cases, access is logged and limited to specific people. The platform does not give employees general "look at user data" permissions.

How data is protected in transit and at rest

  • In transit: Encrypted between your device and the platform's servers. Standard banking-level encryption.
  • At rest: Encrypted on disk using industry-standard encryption. Even in the unlikely event of a server breach, the stored data is not readable without the encryption keys.
  • Backups: Encrypted backups in geographically separate locations for disaster recovery. Same encryption as primary storage.

What you can do with your data

  • Export anytime: Download your reports, persona definitions, and transcripts in standard formats (Markdown, PDF, Word, JSON). Export doesn't affect anything in your account — it's a copy operation.
  • Delete anytime: Delete a single project, a single persona, or your entire account. Deletion is permanent. After you delete, the platform removes the data from active systems and from backups within 30 days (backups cycle on a regular schedule).
  • Account deletion is irreversible: Once you delete your account, the same email cannot be re-registered for some time. Use the export feature first if you might want the data later.

Team plan data handling

When you're on a Team plan, your data handling depends on what you choose to share:

  • Private projects and personas stay private to you, even from team admins
  • Shared personas and projects are visible to other team members per the permissions you set
  • When you leave a team, you lose access to team-shared content, but your private work stays in your personal account
  • When admins remove you, same as above — your private work stays with you, shared work stays with the team

Compliance

The platform is designed to meet common regulatory frameworks (the specifics depend on your jurisdiction — GDPR, CCPA, etc.). What this means practically:

  • You have the right to export your data (implemented)
  • You have the right to delete your data (implemented)
  • Data breach notification procedures exist (you'd be informed if your data was affected)
  • Standard contractual clauses are available for enterprise customers who need them

For specific compliance documentation (SOC 2 reports, DPA, etc.), enterprise plans can request these from the support team.

What happens if the company shuts down

The platform commits to advance notice and data export tools if the service is ever discontinued. The intent is: you'd have time to export everything before the service ends. (No company plans for shutdown, but it's worth knowing the commitment exists.)

Common questions

Is my data used to improve the AI? No. Training is excluded by policy.

Can I use the platform for HIPAA-protected health data? Probably not — the platform is not designed as a HIPAA-covered service. Don't upload data that's covered by specialized regulations unless you've confirmed compliance with the support team.

What if I accidentally share something I shouldn't have? You can revoke sharing immediately. If it was shared externally (via exported PDF, for example), you can't recall it — but you can delete the source from the platform.

Can I get a copy of all my data? Yes, via export. Multiple formats supported. If the export doesn't cover something you need, contact support.

Does the platform read my content? No humans at the company read your content unless you grant explicit access (e.g., asking support to help debug a specific issue).

Related

  • Editing exported reports
  • Sharing within a team

Last updated: 8/8/2026