The things people actually ask about holding their own data.
No. Each atom is encrypted under a key only your passkey can derive — we hold sealed bytes and pointers, never plaintext. As a data-blind consent manager, being unable to read your data is both our architecture and, under the DPDP Rules, our legal obligation.
Your vault is anchored to a DID, not a single phone. Enrol a passkey on a new device to regain access; an email-gated recovery path adds a second, possession-checked route. Losing hardware doesn’t lose the vault.
Sealed blobs sit in object storage that can be pinned to your region; only authentication and concurrency metadata — plus a pointer — live in the database. The ciphertext and the key never share a home.
A vault for data, not money. Think of the key like a bank-vault key — except no one, not even us, holds a copy. You grant access; you never hand over the original.
Under India’s DPDP Act, a Consent Manager is an independent, data-principal-facing intermediary through which you give, manage, review and withdraw consent. It must be data-blind and is deliberately separate from the businesses that use your data. Atma Kosha is built to that role.
Pick a surface: a drop-in SDK, a hosted consent portal, or the pure API. Sector packs bring the purposes, notices and retention floors for your industry; the audit chain and DPB inspection come switched on. See For business.
Your DID and your atoms are exportable at any time — portability is a first-class action, not a favour. The vault is designed so you are never stranded inside it.
Yes, with children-first defaults: guardian-gated consent and a hard ban on tracking, profiling or targeting a minor — enforced by the guards, not left to a setting.
The site you’re reading makes zero third-party calls — fonts and assets are self-hosted. The vault itself shares data only on grants you make, and never with anyone you didn’t choose.