Nuncioan Attomik product

Privacy Policy

Last updated: August 22, 2026

Nuncio is a customer-support assistant operated by Attomik (“we”, “us”). This policy explains what data Nuncio accesses when you connect your Google or Microsoft account, what we do with it, who else sees it, and the choices you have. By connecting your account you agree to this policy.

Information we access

When you sign in and grant access, Nuncio uses the Gmail API or Microsoft Graph API to, on your behalf:

  • Read incoming messages in the connected inbox, so we can draft replies.
  • Send replies you approve, or that your automation rules approve.
  • Modify labels / move to Archive to file conversations we’ve handled.

On first connection, Nuncio also reads a limited window of your already-sent mail — messages you sent before Nuncio existed — to learn how your team actually writes to customers, so its drafts sound like you rather than a generic assistant. This is a one-time historical read, separate from the ongoing inbox sync above, and it is covered by the same scopes; we do not request anything broader to do it.

We request only the scopes needed for these features: for Google, gmail.modify and gmail.send; for Microsoft, Mail.ReadWrite and Mail.Send. We also store your account email address and OAuth tokens (encrypted) so the service can run.

If you connect Shopify, we use Shopify’s Admin API, read-only, to look up order status (shipping, tracking, items) for a customer who is asking — this sends the customer’s email address or order number to your own Shopify store to answer the question, nothing more.

How we use your information

Incoming support emails, and the historical sent-mail sample described above, are processed to generate suggested replies using Anthropic’s Claude API. The messages, the drafts we generate, any business knowledge you add, and — if connected — order data from Shopify are stored in our database (hosted on Supabase) solely to operate the service for you. We do not sell your email content.

AI processing and model training

Nuncio is an AI product, so we want to be exact about what that means for your mail.

  • Message content — including the historical sent-mail sample used to learn your voice — is sent to Anthropic’s Claude API for the single purpose of producing the classification, draft reply, and resolution shown to you in Nuncio. It is not sent anywhere else for AI processing.
  • We do not use your email content — or any other data obtained through Google or Microsoft APIs — to develop, improve, or train generalized artificial intelligence or machine learning models, including foundational models. Anthropic does not train its models on data submitted through its API.
  • Features that learn from your history — suggested knowledge entries, brand voice, and inbox signals — operate only on your own account’s data, to serve features you use inside Nuncio. Nothing derived from your mailbox is shared with, or used to benefit, any other customer.
  • No human at Attomik reads your email content except with your consent, where necessary for security or to comply with law, or where the data has been aggregated and anonymized.

Google API Services User Data Policy

Nuncio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data obtained through Gmail scopes — including the one-time read of your historical sent mail described above — is used only to provide and improve Nuncio’s support features; it is not transferred to others except as needed to provide the service, to comply with law, or with your consent; it is not used for advertising; and no humans read it except with your consent, for security, to comply with law, or where the data has been aggregated and anonymized.

Service providers

We rely on a small set of subprocessors to run Nuncio:

  • Google / Microsoft — the connected mailbox: reading, sending, labels.
  • Anthropic — generating draft replies and classifications.
  • Shopify (if you connect a store) — order status lookups.
  • Resend — delivering your weekly summary email and account notifications. These contain counts and categories, never customer message content.
  • Stripe — processing your subscription payment. Stripe sees your billing details directly; we store only your subscription status and renewal date.
  • Supabase — database and authentication.
  • Vercel — application hosting.

Data retention & deletion

We retain your data for as long as your account is active. There is currently no automatic expiry — we do not delete data on a schedule, only on request or when you disconnect. You can stop future access at any time by revoking Nuncio’s access in your Google Account permissions, or, for Microsoft, from your Microsoft 365 account’s connected-apps settings (your IT administrator can do this for an organization-managed account). Revoking access stops all future reading and sending immediately but does not, by itself, delete what is already stored.

To request deletion of your data, email us at hello@attomik.co. This is a manual process, not an automated self-service tool — we verify the request, export a copy for our records as required for audit purposes, then permanently delete your account and its associated data. We will confirm once it is done. If you would also like your login removed, so that signing in again creates a brand-new account rather than reconnecting, say so in your request.

Security

OAuth tokens are encrypted at rest (AES-256-GCM), and data is isolated per account with database-level row security — one tenant’s data is never queryable from another’s context. No method of storage or transmission is perfectly secure, but we work to protect your data.

Where we process data, and your regional rights

Nuncio’s infrastructure runs in the United States, and your data is processed and stored there. If you or your customers are located in the European Economic Area, the UK, or Switzerland, you have rights under the GDPR — including access, correction, deletion, and portability of your data. If you are a California resident, you have similar rights under the CCPA, including the right to know what personal information we hold and to request its deletion. We handle every request the same way, wherever it comes from: email hello@attomik.co and we will respond through the deletion process described above.

Your rights

You can request a copy of your data or its deletion at any time by emailing hello@attomik.co. You can disconnect Google or Microsoft access yourself, at any time, from your account’s own permissions settings.

Contact

Questions about this policy? Email hello@attomik.co.