Privacy Policy
Last updated: May 27, 2026
1. Who we are
Atlas ("we", "us", "Atlas") is the legal entity that operates the Atlas service and acts as the data controller for personal data processed through it. This policy explains what data we collect, why we collect it, the legal basis on which we rely, and your rights over it.
2. What we collect
- Account data: your email address, name, and profile photo (if provided via Google).
- Content you create: tasks, goals, habits, notes, events, and chat messages you enter into Atlas.
- Usage data: anonymous analytics about how the app is used (page views, feature use) to improve the product.
- Payment data: collected and processed by Paddle.com, our Merchant of Record. We receive only limited information (such as country, plan, and last 4 digits) and never see or store your full card details.
3. How we use it and our legal basis
- To run the service (sign-in, sync, AI features) — legal basis: performance of our contract with you.
- To send transactional emails (password resets, billing receipts) — legal basis: performance of contract and legal obligation.
- To secure the service and prevent fraud or abuse — legal basis: our legitimate interests.
- To improve Atlas based on aggregate, anonymous usage — legal basis: our legitimate interests.
We do not sell your data and we do not train public AI models on it.
4. AI processing
When you use the AI chat or daily brief, your relevant data (recent tasks, goals, notes, etc.) is sent to a third-party AI provider to generate a response. Providers we use are contractually bound not to retain or train on your data.
5. Who we share data with
- Paddle.com — our Merchant of Record and payment processor, which handles checkout, billing, tax, invoicing, and refunds.
- Hosting and infrastructure providers (database, file storage, email delivery) acting as our processors.
- AI providers as described in section 4.
- Authorities where we are legally required to disclose data.
6. Storage, security and retention
Your data is encrypted in transit (TLS) and at rest. Access is restricted by row-level security so only you can read or modify your own content.
We retain account and content data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain certain records (for example, billing and tax records kept by Paddle for up to 10 years to meet legal obligations). Backups are rotated and fully purged within 90 days.
7. Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict, port, or object to processing of your personal data, and to withdraw consent or lodge a complaint with your local supervisory authority. You can export, edit, or delete any data you create at any time from within the app. To exercise any other right, contact us at the address below and we will respond within one month.
8. Cookies
We use only strictly necessary cookies for sign-in and session management. No third-party advertising cookies.
9. Contact
Questions? Email hello@atlas.app.
