For the complete documentation index, see llms.txt. Every page on this site is also served as Markdown: append `.md` to any URL, or send `Accept: text/markdown`.
Skip to content

What Attensira can touch, and what it never will

Attensira reads public AI answers and the accounts you connect, such as GitHub, your CMS and Search Console. It acts only within the access you grant, and new workspaces start in Draft, where nothing leaves until you approve it. Security questions go to security@attensira.com.

7 days free · card required

Repository permissions3 requested
  • ContentsRead and write

    Read the files behind a page, and push our branch

  • Pull requestsRead and write

    Open the pull request, and read its state afterwards

  • MetadataRead

    Required for every GitHub App; lists the repositories you granted

No Actions, no Administration, no access to secrets.

Attensira GitHub App · permissions requested

What data does Attensira handle?

Only what it needs to read your answers and do the work, and only from accounts you chose to connect.

Where your data goes4 kinds of data
  • Your account

    Stored · cards go to Stripe

    Name, email and company, to run your workspace. Card numbers go straight to Stripe and never touch our servers.

    Privacy policy →
  • Questions and answers

    Stored as returned

    The questions you track and the answers ChatGPT, Perplexity, Claude, Gemini and Google AI give to them, stored as they came back so every number reads back to its sentence.

    How we collect data →
  • Accounts you connect

    Their own permissions

    GitHub, Webflow, WordPress, Shopify, Notion, Search Console or your mailbox. Each reaches only what its own permissions allow, and you can disconnect it at any time.

    GitHub →
  • Your AI traffic

    Counted at your edge

    On Growth and Business, if you install the AI traffic middleware, requests to your site are counted at your own edge: when they arrived and which paths they asked for.

    AI traffic →
From the privacy policy and the docs each card links to

What does a change that waits for you look like?

The crew opens the pull request and the checks run, but a sentence with a price, a number or a competitor's name is held as a claim. It merges only after you read it and say yes, in every mode.

Pull requestexample/marketing-site · #87

Add a comparison table to /pricing

attensira4 checks passedclaim waits for you: “40% cheaper than Acme”

content/pricing.mdx

  1. unchanged: ## How do we compare?
  2. added: Teams switching from Acme pay 40% less for the same seats.
Copywriter agentCopywriter · Wrote the comparisonExample · example workspace

What can the agents never do?

Every proposed change is classed from the change itself, its before and after, never by the agent about its own work.

How a change is classed
SafeOpens without waiting, in Act mode only

Structured data, meta and Open Graph tags, image alt text, internal links, heading levels, whitespace.

ClaimAlways waits for your yes, in every mode

A price, a percentage, a number with a unit, a promise word, a competitor's or product's name, rewritten heading words, any sentence.

NeverRefused in any mode, even with approval

Code blocks, source files, CI configuration and workflows, lockfiles and manifests, dotfiles, anything outside the directories you named.

Workspaces start in Draft · the class names the rule that decided it

What no setting changes

  • Nothing is deleted irreversibly without an explicit yes.
  • No mail goes from your domain without a yes. Pitches go from your own Gmail or Outlook, or not at all.
  • A pull request merges only when you press Merge, or when you switched on auto-merge for safe changes, and only once GitHub says every required check passed. If your repository's own automation merges on green, it can merge one too; with GitHub draft mode on, every one opens as a draft, which most merge automation ignores.
  • In Ask mode a run waits up to 7 days for you, then closes without acting and says so in your Inbox.
  • Act mode is capped. By default it makes two changes a week on its own, and one per page.

How far does access to your site and tools go?

What each connection can do, and what it never does
ConnectionWhat it can doWhat it never does
GitHubGitHub docsOpens pull requests on a fresh branch, labelled attensira, only in the repositories you select. Uninstalling the App ends access at once; open pull requests stay yours.NeverPushes to your default branch, pushes twice to a branch, or touches CI configuration and workflow files.GitHub docs
Webflow and WordPressWebflow and WordPress docsChanges one field at a time, as a draft in your own editor. You sign in on their side, so it never sees your password; only a safe change in Act mode publishes without you.NeverCreates or deletes a page, asks for delete permission, or writes a field someone edited since it was read.Webflow and WordPress docs
API keys and sign-insAPI key docsA key is shown once and stored as a hash; a read-only key cannot change a workspace or spend credits. Sign-in uses OAuth with PKCE and short-lived tokens.NeverKeeps working after you revoke it: a revoked key fails on the very next request.API key docs

Who else processes the data?

These providers help run the service and the website. The privacy policy lists the same providers, and each may use the data only to provide its part of the service.

  • ClerkSign-in and account authentication
  • StripePayment processing
  • AutumnBilling: plans, credit balances and usage metering
  • OpenAI and OpenRouterThe AI models that answer your tracked prompts and draft the work
  • DataForSEOSearch results and keyword data
  • context.dev and OlostepReading public web pages
  • MongoDB AtlasDatabase
  • RailwayApplication hosting and file storage
  • VercelHosting for this website
  • ResendTransactional email
  • SentryError monitoring
  • PostHogProduct and website analytics, and the support chat
  • Google AnalyticsWebsite analytics, loaded through Google Tag Manager
  • Vercel AnalyticsWebsite page views, without cookies

Security questions

How does Attensira handle my data?
Attensira reads public AI answers and the accounts you connect, such as GitHub, your CMS and Search Console. It acts only within the access you grant, and new workspaces start in Draft, where nothing leaves until you approve it. Security questions go to security@attensira.com.
What permissions does the Attensira GitHub App ask for?
Three: Contents (read and write), Pull requests (read and write) and Metadata (read), on only the repositories you select. There is no Actions or Administration permission and no access to secrets. If GitHub's consent screen shows anything else, it is not our App.
Can Attensira change code or CI on my repository?
No. Code blocks, source files, CI configuration, workflows, lockfiles, manifests and dotfiles are refused in every approval mode, even if you approve the change. Attensira edits only the content directories you allow.
Does Attensira sell my data?
No. Data is shared only with the providers that help run the service: the list is under 'Who else processes the data?' on this page and in section 6 of the privacy policy.
Is there a data processing agreement?
Yes. Attensira Technology OÜ acts as a processor under the GDPR for data it processes on your behalf, and the agreement is available on request from legal@attensira.com.
How do I cut off Attensira's access?
Uninstall the GitHub App, or disconnect it in the project's settings, and its access ends immediately. Disconnect a CMS from Settings, Integrations. A revoked API key fails on the next request; an OAuth sign-in already issued keeps working until its short-lived token expires.

See the approvals on your own site.

Start the trial in Draft, where nothing leaves your workspace without your yes, or book a demo and ask us anything on this page.

7 days free · card required