Legal
Privacy Notice
Atmark (“the service”) processes personal information in accordance with the Personal Information Protection Act of Korea and other applicable laws. This notice explains what we process, why, and how we protect it.
1. What we collect
Atmark processes only the information it needs to run the service.
- Sign-up email
- The organization owner’s email address, used to sign up and log in. We send service mail such as sign-up confirmations and login links to this address.
- Waitlist
- The email address you add to the waitlist and, if you wrote one, your one-line note (“What do you want to do with Atmark?”). We use them to send the confirmation and invitation emails and to decide the order of invitations. We also store the intended use you choose, where you heard about Atmark if you answer, and the referral value attached to the sign-up page address (only values we have set — anything else is recorded as “none”). We use these three to decide the order of invitations and to learn which channels work. When you sign up, we copy these three values (not your email address or note) to your organization’s record.
- Organization name
- The name you enter at sign-up. Shown in the console and used for operator review.
- Invitee email
- When an organization owner invites someone to their organization, we use that person’s email address to send the invite and their login link.
- HMAC of the requesting IP address
- To detect sign-up and login requests that come too often, we store only a keyed hash of the requesting IP address. The IP address itself is not stored in our database.
- Mail your agents send and receive
- The raw messages and attachments are kept in file storage; metadata such as sender, recipients, subject and time is kept in our database. This includes the email addresses and message content of the people your agents correspond with.
- Audit records
- Actions taken in the console (who did what, when, to which item) and the decisions of the sending gate. Secret values such as tokens are never recorded.
- Access logs
- For security and troubleshooting, server access logs record the request time, path, result and the requesting IP address.
This website (atmark.ai) uses a single cookie (atmark_lang), set only when you switch languages, to remember your choice. The console uses only the cookies it needs to keep you logged in and to confirm the browser that made a request. We use no analytics or advertising cookies and no third-party trackers.
2. Why we process it
- Sign-up, identity confirmation, login and account management
- Sending, receiving and storing your agents’ mail, and letting your agents read it
- Applying receive and send policy (allow and block lists), quarantining and recording blocked inbound mail, and controls such as the emergency stop
- Preventing spam, impersonation and abuse, responding to security incidents, and reviewing new organizations
- Service notices and answering your inquiries
3. How long we keep it
We keep personal information until you close your account or the purpose it was collected for has been fulfilled. Where a law requires us to keep it for a set period, we keep it for that period and use it for that purpose only. Retention periods by category:
- Mail bodies
- The raw mail and attachments your agents receive, and the body of mail your agents send, are automatically deleted one year after they are stored. Metadata such as sender, recipients, subject and time, and the sending-gate decision record, are kept separately from the body for as long as needed to run the service.
- Access logs
- Server access logs (request time, path, result, and requesting IP address) are kept for three months and then deleted.
- Invitee email
- If someone is invited but never joins the organization, we erase their email address 30 days after their last invite was revoked or expired.
- Waitlist
- A waiting entry is kept until you sign up or ask us to take you off the list. When you sign up, we delete the waitlist entry. If you were invited but never signed up, we delete it 30 days after the invitation expired.
- Unfinished sign-ups
- If someone requests a sign-up but never uses the confirmation link, we delete the email address and organization name 30 days after the link expired.
- Audit records
- Console actions (who did what, when) and sending-gate decisions never include mail bodies. We keep them until you close your account or we stop running the service.
Two things are kept separately from the periods above.
- Bounce and complaint lists
- Email addresses that bounced permanently or whose recipient marked our mail as spam are kept on a suppression list as the address itself, so that we never send to them again. They stay on this list even after the address is erased elsewhere. Temporary bounces are kept until their set expiry; permanent bounces and spam complaints are kept until removal is requested or we stop running the service.
- Backups
- The database is backed up automatically every day for disaster recovery, and backups are kept for 14 days. Information we have deleted remains in backups for that period and disappears as backups are replaced. Backups are used only to recover from failures.
We run a transparency log so that audit records can be checked against public values for later changes. Every five minutes, audit records such as sending decisions, inbound verdicts, console actions, and policy and identity changes are appended to the log as chained hashes. Every hour we publish a signed checkpoint at id.atmark.ai/log/checkpoint, and once a day we timestamp it externally with OpenTimestamps. What we publish is only signed checkpoints and hashes. Log entries never hold mail content or personal information in plain text; values such as addresses appear only as salted hashes (commitments). Published files are locked against deletion for one year, and rewriting a file keeps the earlier version.
4. Sharing with third parties
Atmark does not provide personal information to third parties, except where a law specifically requires it or an investigative authority requests it through legally prescribed procedures.
Mail your agents send is delivered to the recipients chosen by you and your agents. That is how the service works; it is not Atmark sharing your data.
5. Service providers
We use the following providers to run the service.
- Amazon Web Services, Inc.
- Servers, database and file storage. Data is stored in the AWS Seoul Region (ap-northeast-2).
- Amazon Web Services, Inc. (Amazon SES)
- Sending and receiving email (Seoul Region).
- Anthropic, PBC (Claude)
- When our operator reads and answers mail sent to Atmark’s support and operations addresses (support@atmark.ai, onve@atmark.ai, abuse@atmark.ai, postmaster@atmark.ai) with an AI assistant, Anthropic processes that mail (the sender’s email address and the message). This is a transfer to the United States, made over the network at the time the mail is read and answered.
Our agreements with these providers require them to handle personal information securely. If a provider changes, we will update this notice.
6. Your rights
You can ask at any time to access, correct or delete your personal information, or to stop us processing it. Send your request to the contact below; we will verify your identity and act without delay. Information we are legally required to keep may not be deleted, and we will tell you why.
7. Destruction
When the retention period ends or the purpose has been fulfilled, we destroy the information without delay. Electronic files are deleted in a way that cannot be recovered.
8. How we protect it
- Encryption in transit (HTTPS) and at rest
- Least-privilege access split by function — sending, reading and administration run under separate permissions
- A keyed hash instead of raw IP addresses; single-use, short-lived login and sign-up links
- Audit records of console actions and sending decisions
9. Contact
Questions about how we handle personal information, requests to access, correct or delete it, and complaints are handled here.
Contact: support@atmark.ai
You can also report a privacy violation or seek advice from the Korea Internet & Security Agency’s Privacy Infringement Report Center (118, within Korea) or the Personal Information Dispute Mediation Committee (1833-6972).
10. Changes to this notice
This notice applies from October 1, 2026. If it changes, we will post the update on this page before it takes effect.
This English version is provided for convenience. If it differs from the Korean version, the Korean version prevails.