Your data
A solution's structure is your work and often your client's IP. This page is the plain statement of what FM Fathom has, what it doesn't, and what you control. The short version: we hold the structure you chose to upload, we never have your records or your server, and you can delete what you gave us.
What the XML export contains
The Save as XML export describes structure: tables, fields, scripts, layouts, table occurrences, relationships, value lists, custom functions, accounts, and privilege sets. Per Claris's own documentation, it contains no record data, and account passwords never enter it at all. Your rows never leave FileMaker because they were never in the export.
What we never have
- Your
.fmp12file - Your database records
- Access to your FileMaker Server
FM Fathom only ever receives what you explicitly upload: the XML export, and server logs if you choose to add them.
Server logs
Logs are operational metadata: script names, timestamps, durations, error codes, and session information such as account names. They contain production evidence, which is why they're valuable, and they're strictly opt-in. You can delete a file's logs at any time without touching the parsed solution.
Who can see your solution
- Members of the client. Everything inside a client is shared with everyone granted access to it; see Clients and files.
- The FM Fathom team, only with your consent. When you file a bug report there's a consent checkbox, off by default, allowing us to look at the least of your solution needed to fix that bug. Unticked, we don't look.
The privacy policy is public and says the rest plainly, including this: we will never copy your work into anyone else's product, sell it, or use it to train a model.
Where it lives
Your uploads are stored in FM Fathom's hosted environment, with API keys and access keys stored encrypted (access keys are stored as hashes and checked on every request). FM Fathom runs on AWS in the US East region, and the database is backed up. One honest beta caveat: while we're in beta, we don't guarantee 100% uptime or data preservation, so keep your own copies of your exports.
Your deletion controls
- Delete a file's logs, a file, or a whole client (creator or admin).
- Delete your account yourself, from Connect to AI. Uploads are kept so filed bug reports stay investigable; ask us and we'll remove those too.
The AI side
Connectors and the built-in assistant read the same parsed structure through 24 read-only tools; nothing they do writes back. With the built-in assistant, your questions and the tool results go to the AI provider whose key you brought, under your account with them. With an external client like Claude, that client's own privacy terms apply to the conversation. FM Fathom itself trains nothing on your work.
Related
- Export your solution as XML: what's in the export
- Accounts: consent and deletion flows