FM Fathom beta · last updated 16 August 2026
The short version.Your solution is yours. No other user of FM Fathom can see it. We will never copy your work into anyone else’s product, sell it, use it to train a model, or show it to another developer. But we are not going to pretend nobody here can see it: when you ask us to fix something, we look at what we need to in order to fix it.
When you upload a FileMaker export, we parse it and keep the structure: scripts and their steps, calculations, field and table definitions, layouts and their objects, relationships, value lists, custom menus, and the security setup. That is the product. It is also, plainly, your intellectual property, and we treat it that way.
If you upload server logs we keep what they contain, which includes who ran what and when. We also store your name and email from the account you sign in with, anything you type into discussions or the board, and any bug reports you file, including their screenshots.
We do not have and never ask for your FileMaker file itself, your data records, your server credentials, or your customers’ information. An export describes how a solution is built, not what is in it.
No other tester can see your work.Access is granted per client, and every page, search, API route and AI query is scoped to the clients you have been granted. Someone else’s account cannot reach your solution even if they know its name or address.
We can. An administrator account, which during the beta means Kevin, can reach every client on the server. There is no technical wall between us and your data, and we would rather say so than imply one exists. What there is instead is this policy and the fact that our business is worthless the moment a FileMaker developer cannot trust us.
To fix a problem you told us about, to investigate an error the software reported on its own, or if we are legally required to. That is the whole list.
You decide, per bug report. When you file one there is a tick box asking whether we may look at the least of that solution needed to fix that specific problem. It is unticked until you tick it. Leave it alone and we work from your description, your screenshots and the errors the browser recorded, and we come back and ask if that is not enough.
The permission is deliberately narrow: one report, the solution that report came from, the parts related to it, and only while it is open. It is not a setting you switch on once and forget. Each report records whether you gave it and when, and the person triaging sees that answer at the top of your report, before they decide whether to open anything.
Being straight about the limits: this is a recorded, per-incident permission, not a lock. As the section above says, an administrator can technically reach any client. What the tick box changes is that looking without asking is now a visible, deliberate act rather than an ordinary one, and it is the standard we hold ourselves to: the minimum needed, only when it is needed.
We are not browsing your work for interest, and we are not looking at solutions nobody has reported a problem with.
The assistant runs on your API key, under your own account with Anthropic, OpenAI or OpenRouter. When you ask it a question, the parts of your solution needed to answer are sent to whichever provider you chose, and their terms apply to that. We store the conversation so you can come back to it, and a record of which tools ran, how long they took and whether they failed.
If you would rather nothing left the server at all, the assistant also runs against a local model.
You can do it yourself, and you do not have to ask us. On the Workspace page, the client you created has a Delete button, and so does each file inside it. Deleting a client removes its files and everything parsed out of them. You type the name to confirm, because it cannot be undone.
You can only delete clients you created, which is the same rule that governs who you can add to them. The shared demo client belongs to nobody and cannot be deleted by anyone but us.
Your account is separate, and also yours to delete. On the Connect to AI page, under Your account. It removes your sign-in, your access to every client, and your stored keys.
What it does not remove is anything you uploaded. That is on purpose rather than a loophole: a bug report you filed last week can only be investigated if the solution it was filed against is still there. Your comments stay too, with your name on them, so a conversation does not turn into holes. If you want the uploads gone as well, delete the client first, or ask us and we will.
Uploading a new export replaces the parsed data for that file. Backups are kept for seven days, so a deletion takes up to a week to disappear everywhere.
It runs on a separate server from anything else we operate, and it is a beta in the real sense: things will break, and data could be lost to a mistake of ours. Please do not treat FM Fathom as the only copy of anything. When the beta ends we will tell you before removing anything, and you can ask for your data to be deleted at any point, during or after.
Ask, and we will answer specifically rather than pointing you back at this page. If something here does not match what you see the product doing, that is a bug in this document and we want to know.