Atlas Privacy Policy
Effective: August 1, 2026 · Last updated: August 2, 2026 Applies to: heyatlas.org and the Atlas application
1. Who we are
Atlas is an AI chief of staff for founder-led teams, operated by Divitiae Holding LLC, a California limited liability company doing business as Atlas. You can reach us at privacy@heyatlas.org.
This policy explains what we access, why, how long we keep it, and how you get rid of it.
2. What Atlas connects to, and why
Atlas only reads what you explicitly connect. Nothing is accessed until you complete that connector's consent flow, and you can disconnect any connector at any time.
Google Workspace
| Scope | What it lets Atlas read | Why Atlas needs it |
|---|---|---|
gmail.readonly |
Message metadata, subjects, and content in your mailbox | Detects unanswered messages and open commitments for Follow-Up Radar; supplies context for your Daily Brief and meeting prep |
calendar.readonly |
Event times, titles, attendees, descriptions | Builds meeting preparation and the meetings section of your Daily Brief |
drive.metadata.readonly |
File names, owners, and modification times — not file contents | Lets Atlas answer "where is that document" without reading your documents |
openid, email |
Your email address and account identifier | Signing you in and matching your account |
Atlas requests read-only Google scopes. It cannot send, modify, or delete anything in
your Google account under this policy version. Write scopes (gmail.send,
calendar.events) will only be requested when the Approval Desk ships, will be separately
consented, and will never execute an action you have not individually approved.
Slack
channels:history, channels:read, users:read, team:read — messages and channel
metadata from channels Atlas has been added to, used to detect commitments and follow-ups.
Atlas does not read private channels or direct messages it has not been explicitly added to.
Meeting notetakers (Fathom, Fireflies)
If you connect one, Atlas reads meeting summaries and action items to build recaps. Atlas does not record, join, or transcribe your meetings. Transcription happens in the tool you already use.
3. Google Limited Use commitment
Atlas's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Atlas:
- uses Google user data only to provide and improve the user-facing features described in this policy;
- does not transfer Google user data to third parties except as necessary to provide those features (see Section 5), for security purposes, or to comply with applicable law;
- does not use Google user data for advertising of any kind;
- does not allow humans to read Google user data, except with your explicit consent for specific messages (for example, when you ask our support team to investigate a problem), where necessary for security purposes such as investigating abuse, or to comply with applicable law;
- does not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
4. How Atlas uses AI, and what that means for your data
Atlas uses large language models to generate briefs, meeting preparation, and answers to questions about your workspace. To do that, relevant excerpts of your connected data are sent to our AI provider (Anthropic) for processing at the moment you request the feature or your scheduled brief runs.
Three commitments about that processing:
- Your data is not used to train models. Content sent to Anthropic through their API is not used to train their models. Atlas does not train any model on customer data, and does not fine-tune models on your content.
- Retrieved content is treated as data, never as instructions. Atlas's prompts explicitly instruct the model to ignore any instructions embedded in your email, documents, or messages. This defends against a malicious sender attempting to manipulate Atlas through content you receive.
- AI cannot act on your behalf without approval. No AI output causes an external action — no email sent, no task created, no record updated — unless you individually review and approve it first.
5. Sub-processors
Atlas shares data with these providers only to operate the service:
| Provider | Purpose | Data involved |
|---|---|---|
| Anthropic | AI inference for briefs, search, and meeting prep | Excerpts of connected workspace content, at request time |
| Neon | Managed PostgreSQL database | All stored application data |
| Railway | Website and application hosting | Data in transit; request logs |
| Inngest | Background job scheduling | Job metadata and identifiers, not message content |
| Resend | Sending your Daily Brief by email | Your email address and brief content |
| PostHog | Product analytics | Usage events and identifiers — not message content |
| Sentry | Error monitoring | Error traces with personal data scrubbed |
We do not sell your data. We do not share it with advertisers. There is no advertising in Atlas.
6. What Atlas stores
- Connected content: normalized copies of the emails, calendar events, messages, and file metadata Atlas has read, so briefs and search work without re-fetching constantly.
- Derived content: briefs, detected commitments, memory items, and suggestions.
- Account data: your email, name, organization memberships, and roles.
- Operational records: usage events for billing, and an immutable audit log of sensitive actions.
- Credentials: OAuth tokens, encrypted with AES-256-GCM. Tokens are never stored in plaintext and never written to logs.
7. Separation between your personal and work accounts
Atlas is built so one person can hold both a personal account and membership in one or more company accounts, without those contexts mixing.
- Every piece of data belongs to exactly one account context and is enforced at the database level by row-level security, not only in application code.
- A connector you add in your personal account is invisible from any company account, and vice versa.
- An organization administrator cannot see into your personal account — not even its existence or metadata.
- Atlas does not search, retrieve, or generate across account boundaries.
If you leave an organization, your access to that organization's data ends and the connectors you added there stop syncing. Your personal account is unaffected.
8. Retention and deletion
- Twelve-month cap on connected content. Emails, calendar events, messages and file metadata Atlas has synced are automatically deleted 12 months after Atlas received them, along with any commitments Atlas derived from them. This runs daily and is not something you need to request.
- What outlives that window, and why. Distilled memory — the facts, decisions and preferences Atlas has learned about how you work — and the briefs Atlas generated for you are kept until you delete them or delete your account. They contain no copy of the original message and cannot be reconstructed from one. This is what lets Atlas still know a decision you made two years ago without still holding the email it was made in.
- Disconnect a connector: syncing stops immediately and stored credentials are deleted, including revoking Atlas's access at Google or Slack.
- Delete your account: all content, derived data, and credentials are deleted. Audit log entries and billing records are retained where required by law.
9. Security
- All data encrypted in transit (TLS) and at rest.
- OAuth tokens encrypted with AES-256-GCM through a single controlled access path.
- Tenant isolation enforced by PostgreSQL row-level security, with an automated isolation test suite that blocks any release that would break it.
- Audit logging of sensitive events, insert-only at the database level.
- No external write action can execute without an explicit approval record.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly and as required by applicable law.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data. Contact privacy@heyatlas.org and we will respond within the timeframe applicable law requires.
California residents. Under the CCPA/CPRA you have the right to know what personal information we collect and why, to request deletion of it, to request correction of it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. Atlas contains no advertising. Categories collected are listed in Section 6; the purposes are in Sections 2 and 4; the recipients are in Section 5.
Individuals in the EEA and UK. Where GDPR applies, our legal basis for processing your connected content is performance of our contract with you (Article 6(1)(b)), and for security and abuse prevention our legitimate interests (Article 6(1)(f)). You may access, correct, delete, port, or restrict processing of your data, and may lodge a complaint with your supervisory authority. Data is processed in the United States; where required, transfers rely on the Standard Contractual Clauses maintained by our sub-processors.
11. Children
Atlas is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.
12. Changes
We will post changes here and update the "Last updated" date. Material changes affecting how we use your connected data will be notified by email before taking effect.
13. Contact
Divitiae Holding LLC (dba Atlas) 405 8th St Huntington Beach, CA 92648 United States
privacy@heyatlas.org