atonomuse
How it works Gallery Pricing Learn Compare FAQ Contact
Sign in Start free

Privacy Policy

Last updated: October 9, 2026

Data controller

The data controller is CODEGON SRL, a company incorporated in Romania.

  • CUI: 49415663
  • Reg. Com.: J9/41/16.01.2024
  • Registered office: Str. Industriei, Nr. 7, Bl. D6, Sc. 1, Et. 2, Ap. 8, Ianca, Jud. Brăila, Romania
  • Contact: vali@codegon.com

What we collect from the website

This website has no forms and sets no tracking or advertising cookies of its own. We use a self-hosted, cookieless analytics instance (Umami) that records only aggregate, anonymous visit statistics. The only browser storage we use is a single local-storage preference for your light/dark theme choice.

The gallery section shows sample posts hosted on Instagram. These previews load only when you click "Load post from Instagram". When you do, your browser connects to Meta's servers and Meta may set its own cookies and record that visit under Meta's privacy policy. If you do not click, nothing is loaded from Meta on this site.

What we collect when you create an account

When you sign up in the application we store your email address, a hashed password (never the password itself), your name if you provide one, your workspace name and website address, your timezone, and the date you accepted the terms. If you sign in with Facebook instead, we receive your name, email address and Facebook user ID from Facebook Login and store the ID to recognise you next time; we do not receive your Facebook password.

We send transactional email through Amazon Web Services (Simple Email Service): a verification link when you sign up, a password-reset link when you ask for one, and a short notice when a post is ready for review. We do not send marketing email and we do not share your address with advertisers.

The application also stores what it produces for you: your brand profile, generated posts and their review scores, publishing history and the settings you choose. Security logs (sign-in attempts, IP address, browser type) are kept for a limited time to protect accounts.

Data obtained via Meta Platforms (Facebook and Instagram)

When you connect a Facebook Page or Instagram Business/Creator account to Atonomuse, we request access via Facebook Login and the Meta Graph API. We only request permissions strictly necessary to operate the product. Depending on what you enable, we may obtain and store the following on your behalf:

  • Pages and Instagram accounts you administer — identifiers, names, profile pictures, category (from pages_show_list, instagram_basic)
  • Page and Instagram content we publish for you — posts, carousels, reels, captions, publish timestamps (via pages_manage_posts, instagram_content_publish)
  • Engagement data for published content — likes, reach, impressions, saves, follows (via pages_read_engagement, instagram_manage_insights)
  • Comments and basic commenter information on your posts — for moderation, reply generation, and alerting (via instagram_manage_comments)
  • Access tokens — stored in our database with access restricted to the service, transmitted only over encrypted connections, and used solely to perform the above operations on your behalf. They are removed when you disconnect the account or delete your workspace.

We use this data solely to generate, publish, analyze, and moderate content for your account. We do not sell it, rent it, share it with third parties for advertising, or use it for any purpose outside the product features you have enabled. We do not use Meta data to build profiles of end users or for retargeting.

How we use data collected

  • Your email address is used to sign you in, verify your account, reset your password and notify you about activity in your workspace
  • Your website address and the answers you give during setup are used to draft your brand profile and to generate content
  • Meta-derived data is used strictly to operate the publishing, analytics, and moderation features of Atonomuse
  • We do not sell, rent, or share personal data with third parties

Lawful basis: performance of the contract you agree to when you sign up, our legitimate interest in operating and securing the service, and — where you connect a social account — your consent.

Cookies and browser storage

This site stores a single preference in your browser's local storage: your light/dark theme choice. The application stores your sign-in session in your browser so you stay signed in. We do not use tracking or advertising cookies. Instagram previews on the gallery are loaded only on your click, as described above.

Third-party services (sub-processors)

We rely on the following third parties to operate the website and the product. Each is bound by a data-processing agreement and the linked privacy policies:

  • Meta Platforms (Facebook, Instagram) — when you connect an account or sign in with Facebook, data flows through Meta's Graph API. Privacy.
  • Anthropic — Claude models are used to generate and review content. Privacy.
  • OpenAI — image generation for posts. Privacy.
  • Google Cloud (Vertex AI) — may be used for image, video, music and voiceover generation. DPA.
  • ElevenLabs — audio generation for reels (voiceover, music, sound effects). Privacy.
  • Higgsfield and fal.ai — video and image models used for reels on larger plans. Higgsfield privacy · fal.ai privacy.
  • Amazon Web Services — storage of published media (S3, EU Frankfurt region) and transactional email (SES). Privacy.
  • Railway — application hosting, managed PostgreSQL and our self-hosted analytics instance. Privacy.
  • Sentry — error reporting for the application; reports may include your account identifier and the request that failed. Privacy.
  • Stripe — payments and subscriptions. When you pay for a plan, Stripe receives your name, email address, billing address, VAT ID if you give one, and your card details; we never see the card. Stripe is an independent controller for the payment itself. Privacy.
  • Google Fonts — web fonts on this site. Privacy.

Payments. We store the Stripe customer and subscription identifiers, the subscription status and the renewal date of your workspace, so the application knows what your plan includes. Invoices and receipts are issued by Stripe and are kept for ten years as Romanian tax law requires, including after you delete your account.

Transfers outside the EU. Some providers above process data in the United States. Each transfer rests on the European Commission's standard contractual clauses or on an adequacy decision (EU-US Data Privacy Framework) as stated in that provider's agreement.

Model training. Your website content, brand profile, posts and comments are sent to the AI providers only to produce and review your content. We do not use them to train models, and our agreements with the AI providers exclude training on API data.

Data retention

Retention periods by category:

  • Account data and connected-platform data — for as long as your account is active. After you delete your account, or after we close it, deleted within 30 days unless required to retain for legal reasons.
  • Generated content, published posts and engagement metrics — retained while your account is active for reporting; deleted together with the account.
  • Security logs and one-time links (verification, password reset) — the links expire within hours; application logs rotate after 14 days.
  • Invoices and VAT data, where a paid plan has been agreed — retained for 10 years as required by Romanian tax law, redacted of personal identifiers where possible.

Your rights and how to exercise them

Under the GDPR you have the right to access, correct, delete, restrict, or port any personal data we hold about you, and to object to its processing. From your profile in the application you can download a copy of your data and delete your account yourself. For connected Facebook/Instagram data, or if you no longer have access to your account, follow the data deletion instructions. For any other request, email vali@codegon.com. You also have the right to lodge a complaint with a supervisory authority — in Romania, the ANSPDCP (dataprotection.ro).

Contact

For any privacy-related questions or to exercise your rights, reach us at vali@codegon.com.

atonomuse · CODEGON SRL
Learn Compare Sign in Privacy Terms Data deletion Contact Instagram Facebook

CODEGON SRL · CUI RO49415663 · Reg. Com. J9/41/16.01.2024 · Str. Industriei 7, Bl. D6, Sc. 1, Et. 2, Ap. 8, Ianca, Brăila, Romania · vali@codegon.com
Consumers: ANPC · SOL / ODR