← Connect

Privacy Policy

Effective date: July 22, 2026 · Connect is a product of Atoms & Bits, Inc., a Delaware corporation ("we", "us").

What we collect

When you create a Connect account we collect the contact details you provide — such as your email address, phone number, and name — and the content you choose to store in Connect: your plans, files, lists, notes, and the workspaces you share with others. Depending on the features you turn on, Connect also holds: calendar availability and events (if you connect a Google account), email you or people you allow send to your workspace's address, and information Connect gathers from the public sources you choose to follow. We do not sell your personal information, we do not run advertising, and we do not use your content to profile you.

How we use it

We use your information only to operate Connect: to verify your account, turn your own plans and rules into useful actions, deliver the notifications you asked for, keep your data backed up, and provide support. Connect acts on your data only within the scope and permissions you set.

Text messaging (SMS)

If you provide your phone number, we send SMS messages for account verification (one-time passcodes) and for service notifications generated by your own plans. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and get help by replying HELP or emailing support@iykyk.ai.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers and SMS opt-in consent are not sold, rented, or shared with any third party.

Email to your workspace

Each workspace has its own inbound email address. Email that you, or senders you have explicitly allowed, send to that address becomes content in your workspace (for example, a conversation or a captured note). Email from senders you have not allowed is discarded without storing its contents. If you set up per-source newsletter addresses to follow a creator, messages to those addresses are stored as source material for your own digests and are never replied to.

Following and public sources

When you choose to follow a creator, place, or publication, Connect periodically fetches the public feeds and pages you point it at and stores derived observations (such as a new post or event), along with where and when it came from. These observations are a cache: they are retained for about 90 days and then expire. Connect honors robots.txt and fetches only public content. Connect never asks for or holds your login credentials to any third-party platform; any collection that requires being signed in runs only on a device you control and enroll yourself.

Google services

We use Google in two ways. First, we relay account login codes and digest emails through Google Workspace. Second, if you connect your Google Calendar, we request the calendar.readonly and calendar.events scopes so Connect can read your free/busy availability to suggest times and create the calendar events you approve. Access tokens are stored encrypted and are used only for those purposes.

Connect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the calendar features you asked for, and we do not use it to train generalized AI models. You can disconnect Google at any time from Connect's settings or by revoking access in your Google account.

AI features

Some Connect features can use an AI model to interpret your requests or draft content. Where AI is used, the model provider processes only the content needed to produce the output you asked for, and we pass model usage through at cost. Model provider keys are set per workspace or per node, never per person: on the hosted service the node's key is ours, and an administrator of a workspace may save that workspace's own provider key in settings, after which its AI usage is billed to that account with the provider instead of to us. A saved key is encrypted, never shown back, and removing it deletes it. If you run Connect on your own node you set the node's key yourself. AI providers are contractually bound not to use your content to train their models, and we never sell your content or use it for advertising. Connect always shows what an AI action did, and higher-risk actions require your approval.

Sharing

We share data only with the service providers required to run Connect — cloud hosting and email/backup storage (Amazon Web Services), email and calendar (Google), SMS delivery (Twilio), and, where you enable AI features, your chosen model provider — and only to the extent needed to provide the service. Content you explicitly share through Connect (for example, a guest link to a folder) is visible to the people you share it with, under the scope you set, and can be turned off at any time by the person who shared it.

Retention and deletion

We keep your account content while your account is active. Followed-source observations expire after about 90 days as described above. You can request deletion of your account and its data at any time by emailing privacy@iykyk.ai, and we will remove your workspaces, content, and associated login records.

Security

Data is encrypted in transit, stored on infrastructure with restricted access, and backed up regularly. Sensitive third-party tokens are stored encrypted, and the secrets that let someone act as you — login codes, session tokens, and every share link — are stored only as one-way hashes, so they cannot be read back out of the database. To report a vulnerability, or to ask us what we do and do not defend against, write to security@iykyk.ai.

Changes and contact

We will post any changes to this policy on this page. Questions: privacy@iykyk.ai.