Privacy Policy
Atlas · Effective June 25, 2026
This policy explains what Atlas collects, why, and the choices you have. It covers the Atlas web application operated by the Atlas operator.
Information we collect
- Account information. Your email address and display name, provided when you sign up or sign in with Google.
- Your content. The notes, papers and uploaded PDFs, highlights, tasks, collections, tags, and folders you create or import. This is the substance of your library and is stored so the service can show it back to you.
- Technical & operational data. Privacy-preserving audit records of actions like AI requests, rate-limit events, and errors. These deliberately exclude your note/paper contents, prompts, answers, keys, and tokens.
- AI provider keys. If you use the AI features, your provider API key is stored only in your browser's local storage and sent directly with each AI request. We do not store it on our servers or in our logs.
How we use information
To operate and secure the service: to authenticate you, store and display your library, provide search and AI features you invoke, enforce rate limits and abuse protections, and diagnose problems. We do not sell your personal information, and we do not use your private content to train models.
Service providers and third parties
- Supabase — database, authentication, and file storage (hosts your account and content).
- Vercel — application hosting and content delivery.
- Google — only if you choose "Continue with Google" for sign-in.
- Your chosen AI provider (e.g. OpenAI) — when you use an AI feature, the relevant text (your prompt and the retrieved context) is sent to the provider whose key you supplied, under that provider's terms. AI features are off until you add a key.
- Scholarly metadata sources (e.g. Crossref, arXiv, Wikipedia) — queried to look up paper metadata or open-access text. These lookups send the identifier or query you provide, not your personal information.
Cookies and local storage
We use storage strictly to run the app — your authenticated session and preferences (such as your AI key and editor settings) are kept in your browser. We do not use third-party advertising or cross-site tracking cookies.
Publishing and sharing
You can choose to publish a note to a public web page or share an item for review via a link. Content you publish or share is exposed to anyone with the link or URL, by your action. You can unpublish or revoke access at any time.
Data retention and deletion
We keep your content while your account is active. Deleted items move to Trash and can be restored until they are purged. You can ask us to delete your account and associated content at any time (see "Your rights"); backups are then cycled out on the provider's schedule.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise these by contacting us at privacy@atlas.app; where the option is available in the app, you can also export your data or delete your account from Settings.
Security
Access to your data is enforced at the database layer (row-level security), data is encrypted in transit (TLS) and at rest by our providers, and uploads are validated. No system is perfectly secure, but we work to protect your information and to limit what each component can access.
International transfers
Our providers may process and store data in regions outside your own. Where required, such transfers rely on appropriate safeguards.
Children
Atlas is not directed to children and is not intended for anyone under the age required to consent to data processing in their country.
Changes
We may update this policy; material changes will be reflected in the effective date above and, where appropriate, communicated in the app.
Contact
Questions or requests: privacy@atlas.app. See also our Terms of Service.