Skip to content
Attesko
The map 01 How it works 02 The ledger 03 Get early access →

Legal

Privacy Policy

Last updated 5 August 2026 · Attesko is pre-launch

Attesko watches how a business already works so it can take over its most repetitive tasks. That means it sees real screens belonging to real people, which puts a heavier obligation on this page than most software carries. What follows is what we record, what we destroy before it is ever stored, and what we have deliberately made impossible to build.

Attesko is not yet generally available. No production capture is enabled, and no customer data is being processed. This page describes how the product is built to behave and will be updated before anyone's data is collected.

Who we are

Attesko provides software that a business owner installs on the computers their team already uses. In this policy, "we" and "Attesko" mean the company; "the business" means a customer organization; and "you" may mean either a business owner or a member of their staff, because the two have meaningfully different relationships with this product.

When a business uses Attesko, the business is the controller of the work data captured on its computers and Attesko is the processor acting on its instructions.

What Attesko records

From desktop computers

On computers where the business has installed the agent and the person using it has been shown the staff notice, Attesko periodically captures a screen image and a small amount of context: the application in the foreground, the window title, the document address in a browser, and whether keyboard or pointer activity occurred.

Activity is recorded only as the fact that it happened. Attesko does not record keystrokes, and does not store what was typed.

From email and calendar

Where a business connects a Google or Microsoft account, Attesko reads calendar entries and message metadata and content in order to recognise recurring work. This access is read-only and is granted by the business, which can revoke it at any time from its Google or Microsoft account settings.

About the account

Names, work email addresses, the company domain, a mobile number for owners who choose approvals by text, and records of what was proposed, approved, declined, and done.

What is destroyed before it is stored

Redaction happens on the computer itself, in the capture process, before anything is written to disk or transmitted. This is a deliberate ordering: material is destroyed rather than collected-then-filtered, so a fault in this system loses data instead of leaking it.

  • Payment card numbers are detected and masked in the image. A candidate number is only treated as a card if it passes a checksum, so ordinary long numbers are not silently destroyed.
  • Social security numbers and credential fields — passwords, API tokens, and text labelled as secret — are masked in the same pass.
  • Capture suspends entirely, rather than capturing and filtering, whenever the operating system reports secure input is active, which is what happens when a password field has focus.
  • Capture also suspends for private and incognito browsing, password managers, and a conservative list of personal contexts including personal email, banking, and health portals.

Web addresses are stripped of user information, query strings, and fragments before storage, and window titles that appear sensitive are redacted.

What Attesko will never do

Attesko does not measure people. It measures work. There are no activity scores, no productivity metrics, no per-person time tracking, and no comparisons between colleagues.

This is not a setting that could be switched on later. Person-level performance measures have no place to exist in our data model, and our test suite fails the build if code is added that tries to create one. If a business owner asks us for a productivity report on their staff, the answer is that the product cannot produce one.

Every member of staff is shown this at install, in these words: "Attesko watches work tasks to take the boring ones off your plate. It never reports on people — no activity scores, no time tracking on you."

We also do not sell personal information, share it with advertisers, or use one business's data to serve another. What moves between customers is our own understanding of what a category of task looks like — never a business's data, customers, or messages.

We do not use customer data to train machine-learning models.

Rights of staff whose screens are captured

If you work at a business using Attesko, the software is on your computer because your employer put it there. We think that obliges us to you directly, not only to them.

  • You are shown a written notice before capture begins.
  • A capture indicator is visible on your computer whenever capture is active.
  • You can pause capture yourself, without asking anyone. A pause that needs permission is not a pause, and your employer is not notified when you use it.
  • You can see what is being recorded and what is being suspended, without going through your employer.
  • Paused time is reported to your employer as a gap in coverage, never attributed to you as an individual.

How long anything is kept

Screen images are the most sensitive thing Attesko handles and are treated accordingly. A captured image is deleted as soon as the system has finished deriving a description of the work from it, and every image carries a hard ceiling of 30 days regardless. Deletion happens only after the derived description has been safely stored, so a failure mid-way loses the image rather than losing the meaning of the work.

What remains after that is a description of the work — that a booking was transcribed to a calendar, for example — and not a picture of anyone's screen.

A business can ask us to delete its data at any time by writing to the address below.

Who else touches the data

Attesko runs on infrastructure operated by Railway, and uses an AI model provider to convert screen images into descriptions of work. Providers are bound by contract to process data only on our instructions, and are not permitted to use it to train their models.

We will name our model provider on this page before production capture is enabled for any customer.

We do not otherwise disclose personal information, except where we are legally required to.

Security

Capture is encrypted on the computer before it leaves it, and is transmitted over encrypted connections. Each business's data is isolated from every other, and cross-business access is treated as a build failure rather than a review comment.

Children

Attesko is software for businesses and is not directed at anyone under 18. We do not knowingly collect information from children.

Changes to this policy

When this policy changes materially, we will update the date at the top and notify the businesses using Attesko before the change takes effect.

Contact

Questions about this policy, requests to access or delete data, and concerns from staff at a business using Attesko all go to the same place, and staff enquiries are not routed through the employer.

privacy@attesko.com

Attesko
How it works The map The ledger Privacy Terms Contact

Pre-launch. Every figure marked * is illustrative — nothing on this page is a customer result.

attesko — The Quiet Employeeattesko — The Quiet Employee attesko — The Quiet Employeeattesko — The Quiet Employee