What Attensira can touch, and what it never will
Attensira reads public AI answers and the accounts you connect, such as GitHub, your CMS and Search Console. It acts only within the access you grant, and new workspaces start in Draft, where nothing leaves until you approve it. Security questions go to security@attensira.com.
7 days free · card required
- ContentsRead and write
Read the files behind a page, and push our branch
- Pull requestsRead and write
Open the pull request, and read its state afterwards
- MetadataRead
Required for every GitHub App; lists the repositories you granted
No Actions, no Administration, no access to secrets.
What data does Attensira handle?
Only what it needs to read your answers and do the work, and only from accounts you chose to connect.
Your account
Stored · cards go to StripeName, email and company, to run your workspace. Card numbers go straight to Stripe and never touch our servers.
Privacy policy →Questions and answers
Stored as returnedThe questions you track and the answers ChatGPT, Perplexity, Claude, Gemini and Google AI give to them, stored as they came back so every number reads back to its sentence.
How we collect data →Accounts you connect
Their own permissionsGitHub, Webflow, WordPress, Shopify, Notion, Search Console or your mailbox. Each reaches only what its own permissions allow, and you can disconnect it at any time.
GitHub →Your AI traffic
Counted at your edgeOn Growth and Business, if you install the AI traffic middleware, requests to your site are counted at your own edge: when they arrived and which paths they asked for.
AI traffic →
What does a change that waits for you look like?
The crew opens the pull request and the checks run, but a sentence with a price, a number or a competitor's name is held as a claim. It merges only after you read it and say yes, in every mode.
Add a comparison table to /pricing
attensira4 checks passedclaim waits for you: “40% cheaper than Acme”
content/pricing.mdx
- unchanged: ## How do we compare?
- added: Teams switching from Acme pay 40% less for the same seats.
Copywriter · Wrote the comparisonExample · example workspaceWhat can the agents never do?
Every proposed change is classed from the change itself, its before and after, never by the agent about its own work.
Structured data, meta and Open Graph tags, image alt text, internal links, heading levels, whitespace.
A price, a percentage, a number with a unit, a promise word, a competitor's or product's name, rewritten heading words, any sentence.
Code blocks, source files, CI configuration and workflows, lockfiles and manifests, dotfiles, anything outside the directories you named.
What no setting changes
- Nothing is deleted irreversibly without an explicit yes.
- No mail goes from your domain without a yes. Pitches go from your own Gmail or Outlook, or not at all.
- A pull request merges only when you press Merge, or when you switched on auto-merge for safe changes, and only once GitHub says every required check passed. If your repository's own automation merges on green, it can merge one too; with GitHub draft mode on, every one opens as a draft, which most merge automation ignores.
- In Ask mode a run waits up to 7 days for you, then closes without acting and says so in your Inbox.
- Act mode is capped. By default it makes two changes a week on its own, and one per page.
How far does access to your site and tools go?
| Connection | What it can do | What it never does |
|---|---|---|
| GitHubGitHub docs | Opens pull requests on a fresh branch, labelled attensira, only in the repositories you select. Uninstalling the App ends access at once; open pull requests stay yours. | NeverPushes to your default branch, pushes twice to a branch, or touches CI configuration and workflow files.GitHub docs |
| Webflow and WordPressWebflow and WordPress docs | Changes one field at a time, as a draft in your own editor. You sign in on their side, so it never sees your password; only a safe change in Act mode publishes without you. | NeverCreates or deletes a page, asks for delete permission, or writes a field someone edited since it was read.Webflow and WordPress docs |
| API keys and sign-insAPI key docs | A key is shown once and stored as a hash; a read-only key cannot change a workspace or spend credits. Sign-in uses OAuth with PKCE and short-lived tokens. | NeverKeeps working after you revoke it: a revoked key fails on the very next request.API key docs |
Who else processes the data?
These providers help run the service and the website. The privacy policy lists the same providers, and each may use the data only to provide its part of the service.
- ClerkSign-in and account authentication
- StripePayment processing
- AutumnBilling: plans, credit balances and usage metering
- OpenAI and OpenRouterThe AI models that answer your tracked prompts and draft the work
- DataForSEOSearch results and keyword data
- context.dev and OlostepReading public web pages
- MongoDB AtlasDatabase
- RailwayApplication hosting and file storage
- VercelHosting for this website
- ResendTransactional email
- SentryError monitoring
- PostHogProduct and website analytics, and the support chat
- Google AnalyticsWebsite analytics, loaded through Google Tag Manager
- Vercel AnalyticsWebsite page views, without cookies
Security questions
How does Attensira handle my data?
What permissions does the Attensira GitHub App ask for?
Can Attensira change code or CI on my repository?
Does Attensira sell my data?
Is there a data processing agreement?
How do I cut off Attensira's access?
See the approvals on your own site.
Start the trial in Draft, where nothing leaves your workspace without your yes, or book a demo and ask us anything on this page.
7 days free · card required