Atlas Privacy Policy
Effective: August 1, 2026 · Last updated: September 22, 2026 Applies to: heyatlas.org and the Atlas application
1. Who we are
Atlas is an AI chief of staff for founder-led teams, operated by Divitiae Holding LLC, a California limited liability company doing business as Atlas. You can reach us at privacy@heyatlas.org.
This policy explains what we access, why, how long we keep it, and how you get rid of it.
2. What Atlas connects to, and why
Atlas only reads what you explicitly connect. Nothing is accessed until you complete that connector's consent flow, and you can disconnect any connector at any time.
Google Workspace
| Scope | What it lets Atlas read | Why Atlas needs it |
|---|---|---|
gmail.readonly |
Message metadata, subjects, and content in your mailbox | Detects unanswered messages and open commitments for Follow-Up Radar; supplies context for your Daily Brief and meeting prep |
gmail.send |
Nothing. This permission only sends — it grants no read access at all | Sends a reply that you have read and individually approved. See below |
calendar.events.readonly |
Event times, titles, attendees, descriptions | Builds meeting preparation and the meetings section of your Daily Brief |
openid, email |
Your email address and account identifier | Signing you in and matching your account |
Atlas can send one thing, and only with your explicit approval each time.
gmail.send is the single write permission Atlas requests anywhere in your Google account.
It cannot modify, label, archive or delete any message, and Atlas requests no permission that
would allow it to.
Sending is gated on you, individually, every time:
- You press Draft reply on a follow-up. Atlas writes a draft — it does not send it.
- The draft waits on your Approval Desk, where you see the original message and the proposed reply side by side.
- You may edit the reply freely. You cannot change the recipient or the conversation — only the words — so an approved reply always goes to the person who wrote to you.
- Nothing leaves your account until you press Approve & send.
Atlas never sends automatically, on a schedule, in bulk, or without that specific approval. There is exactly one code path in Atlas capable of sending, and it refuses to run on anything you have not approved.
Atlas requests no calendar write permission. It cannot create, change, accept or delete an event.
Removed in this version: drive.metadata.readonly. Atlas requested it from the beginning
and never used it — no part of Atlas has ever read anything from Google Drive. It has been
removed from the permissions Atlas asks for. If you connected Atlas before 14 August 2026, you
granted it; reconnecting will drop it.
Microsoft 365
| Scope | What it lets Atlas read | Why Atlas needs it |
|---|---|---|
Mail.Read |
Message metadata, subjects, and content in your mailbox | Detects unanswered messages and open commitments for Follow-Up Radar; supplies context for your Daily Brief and meeting prep |
Mail.Send |
Nothing. This permission only sends — it grants no read access at all | Sends a reply that you have read and individually approved, on the same Approval Desk described above |
Calendars.Read |
Event times, titles, attendees, descriptions | Builds meeting preparation and the meetings section of your Daily Brief |
User.Read |
Your name, email address, and account identifier | Identifies which mailbox was connected |
offline_access |
Nothing. Issues the refresh token that keeps the connection alive | So you are not asked to sign in again every day |
Mail.ReadWrite is deliberately not requested. That scope would grant read, write and
delete across every message in your mailbox. Mail.Send authorizes sending only. Atlas
requests the narrower one, accepts the resulting limitations in how replies thread, and does
not widen the grant to work around them.
Atlas requests no calendar write permission on Microsoft 365. It cannot create, change, accept or delete an event.
Sending is gated exactly as it is on Google: Atlas drafts, the draft waits on your Approval Desk where you see the original and the proposed reply side by side, you may edit the words but not the recipient, and nothing leaves your account until you press Approve & send.
Slack
channels:history, channels:read, users:read, team:read — messages and channel
metadata from channels Atlas has been added to, used to detect commitments and follow-ups.
Atlas does not read private channels or direct messages it has not been explicitly added to.
Asana
| Scope | What it lets Atlas read | Why Atlas needs it |
|---|---|---|
tasks:read |
Title, description, assignee, due date and completion state of tasks assigned to you | Detects commitments that are open or overdue, so Follow-Up Radar can surface work that has slipped |
projects:read |
The name of the project a task belongs to | So a follow-up arrives with the context it belongs to, rather than as a bare task title |
workspaces:read |
The names of the Asana workspaces you belong to | Required to look up your tasks at all |
users:read |
Your name and email address, and the names of task assignees | Identifies which Asana account was connected and who owns a task |
Atlas requests no write permission on Asana. It cannot create, change, complete, comment on or delete a task.
Atlas reads only the tasks assigned to you, and only those that are still incomplete. It does not read your organisation's other tasks, and it does not read completed work.
stories:read is deliberately not requested. That scope would let Atlas read every
comment on every task you can see. Atlas does not need it to notice that a task is overdue,
so it does not ask for it. If a future feature needs task comments, Atlas will ask you to
reconnect and you will see the added permission on Asana's consent screen before you approve
it.
GoHighLevel
Connected per client sub-account, by pasting a private integration token rather than through a consent screen. A token of that kind is scoped by GoHighLevel to exactly one sub-account: there is no mechanism by which an agency could grant Atlas access to its whole book of clients, and Atlas does not ask for one.
| Scope | What it lets Atlas read | Why Atlas needs it |
|---|---|---|
contacts.readonly |
Name, email, phone, company and tags of contacts in that sub-account | Puts a person's name on a message, opportunity or appointment instead of an opaque id, so a follow-up says who it is about |
conversations.readonly |
The list of message threads, and who each one is with | Without it there is no way to reach the messages themselves |
conversations/message.readonly |
The text of SMS, email and chat messages in those threads, their direction, and whether delivery succeeded | The commitment itself — what was actually said and promised |
opportunities.readonly |
Opportunity name, value, pipeline stage, owner and dates | Detects a deal that has stalled, and who owns it where GoHighLevel records an owner |
calendars.readonly |
The names of the booking calendars in that sub-account | GoHighLevel has no way to ask for every appointment at once — appointments are read one calendar at a time, so Atlas has to know which calendars exist |
calendars/events.readonly |
Appointments booked through GoHighLevel: title, time, status, who it is with | Shows GoHighLevel appointments alongside your other meetings, and detects upcoming ones that have not been confirmed |
locations.readonly |
The sub-account's own id and name | Confirms which client the token belongs to before anything is stored, and names it in the app |
users.readonly |
Names and email addresses of staff users in that sub-account | Puts the right person's name on a commitment instead of an opaque id |
Atlas requests no write permission on GoHighLevel. It cannot send a message, move an opportunity, book an appointment, change a contact, or create an invoice.
Atlas is not answering your phone. This connector reads what happened in GoHighLevel after the fact. Calls are answered by GoHighLevel, by your agency, or by you.
GoHighLevel fixes a token's scopes at the moment it is created. If a future feature needs a permission not in the table above, it cannot be added quietly — a new token has to be created with the new box ticked, and someone has to paste it in.
Meeting notetakers you already use (Fathom, Fireflies)
If you connect one, Atlas reads meeting summaries and action items to build recaps. Transcription happens in the tool you already use — Atlas does not join or record those meetings.
Transcripts you give Atlas directly
You can paste or upload a transcript of a meeting you already have. Atlas treats it the same way as one from a connected notetaker: it builds a recap and extracts action items. Nothing is fetched from anywhere — the content is what you supplied, and it is stored until you delete it (§8).
Atlas Notetaker
Atlas Notetaker joins, records and transcribes meetings — and only the meetings you switch it on for. It is off by default and enabled per meeting. There is no setting that captures your whole calendar, and no meeting is captured because of how it was scheduled or which platform it is on.
When you enable it for a meeting, an Atlas bot joins the call as a visible participant, named so that everyone present can see it is there. It captures the call's audio, that audio is turned into text, and then the audio is discarded. Atlas stores no recordings of any kind, and instructs the capture provider to erase its copy once the transcript has been retrieved. What remains is the transcript and the recap built from it, both of which you can delete at any time (§8).
Obtaining consent is yours, not ours. Recording laws differ by jurisdiction, and in some places every participant must agree before a call may be recorded. Atlas makes the bot visible to the room and records that you enabled capture, but it cannot obtain consent on your behalf and does not claim to. You are responsible for having it.
3. Google Limited Use commitment
Atlas's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Atlas:
- uses Google user data only to provide and improve the user-facing features described in this policy;
- does not transfer Google user data to third parties except as necessary to provide those features (see Section 5), for security purposes, or to comply with applicable law;
- does not use Google user data for advertising of any kind;
- does not allow humans to read Google user data, except with your explicit consent for specific messages (for example, when you ask our support team to investigate a problem), where necessary for security purposes such as investigating abuse, or to comply with applicable law;
- does not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
4. How Atlas uses AI, and what that means for your data
Atlas uses large language models to generate briefs, meeting preparation, meeting recaps, and answers to questions about your workspace. To do that, relevant excerpts of your connected data are sent to our AI provider (Anthropic) for processing at the moment you request the feature or your scheduled brief runs.
Meeting transcripts are part of that. A recap is built by sending the transcript — whether it came from a notetaker you connected, from a file you supplied, or from Atlas Notetaker — to Anthropic to be summarized and to have decisions and action items pulled out of it. Long transcripts are sent in full rather than in excerpts, because a summary of a meeting cannot be built from a fragment of it. The three commitments below apply to that content exactly as they apply to everything else.
Three commitments about that processing:
- Your data is not used to train models. Content sent to Anthropic through their API is not used to train their models. Atlas does not train any model on customer data, and does not fine-tune models on your content.
- Retrieved content is treated as data, never as instructions. Atlas's prompts explicitly instruct the model to ignore any instructions embedded in your email, documents, or messages. This defends against a malicious sender attempting to manipulate Atlas through content you receive.
- AI cannot act on your behalf without approval. No AI output causes an external action — no email sent, no task created, no record updated — unless you individually review and approve it first.
5. Sub-processors
Atlas shares data with these providers only to operate the service:
| Provider | Purpose | Data involved |
|---|---|---|
| Anthropic | AI inference for briefs, search, and meeting prep | Excerpts of connected workspace content, at request time |
| Neon | Managed PostgreSQL database | All stored application data |
| Railway | Website and application hosting | Data in transit; request logs |
| Inngest | Background job scheduling | Job metadata and identifiers, not message content |
| Resend | Transactional email | Name, email address, and application contents of people who submit the fit form at heyatlas.org/operations — sent as the notification to us and the confirmation to them. Not connected workspace content, message bodies, or credentials |
| Sentry | Error monitoring | Error type, message and stack trace; the URL of the page or endpoint that failed; server runtime details; and approximate country. Not message content, email addresses, credentials, request bodies, or session recordings |
| Recall.ai | Joining and transcribing meetings, only for meetings you enable Atlas Notetaker on | The meeting link, the name the bot displays, the call's audio while it is in progress, and the transcript it produces. Atlas retrieves the transcript and then instructs Recall to erase its copy of the media. Not your email, your connected workspace content, or any meeting you did not enable capture for |
We do not sell your data. We do not share it with advertisers. There is no advertising in Atlas.
6. What Atlas stores
- Connected content: normalized copies of the emails, calendar events, messages, and file metadata Atlas has read, so briefs and search work without re-fetching constantly.
- Meeting transcripts: the text of meetings you pasted, uploaded, or captured with Atlas Notetaker, including who said what where the source provides it. Text only — no audio or video recordings are stored, at any point, in any form.
- Derived content: briefs, detected commitments, memory items, meeting recaps and the action items extracted from them, and suggestions.
- Account data: your email, name, organization memberships, and roles.
- Operational records: usage events for billing, and an immutable audit log of sensitive actions.
- Credentials: OAuth tokens, encrypted with AES-256-GCM. Tokens are never stored in plaintext and never written to logs.
7. Separation between your personal and work accounts
Atlas is built so one person can hold both a personal account and membership in one or more company accounts, without those contexts mixing.
- Every piece of data belongs to exactly one account context and is enforced at the database level by row-level security, not only in application code.
- A connector you add in your personal account is invisible from any company account, and vice versa.
- An organization administrator cannot see into your personal account — not even its existence or metadata.
- Atlas does not search, retrieve, or generate across account boundaries.
If you leave an organization, your access to that organization's data ends and the connectors you added there stop syncing. Your personal account is unaffected.
8. Retention and deletion
- Twelve-month cap on connected content. Emails, calendar events, messages and file metadata Atlas has synced are automatically deleted 12 months after Atlas received them, along with any commitments Atlas derived from them. This runs daily and is not something you need to request.
- What outlives that window, and why. Distilled memory — the facts, decisions and preferences Atlas has learned about how you work — and the briefs Atlas generated for you are kept until you delete them or delete your account. They contain no copy of the original message and cannot be reconstructed from one. This is what lets Atlas still know a decision you made two years ago without still holding the email it was made in.
- Meeting transcripts and recaps. A transcript you paste, and a recap Atlas builds from a notetaker you have connected, are kept until you delete them or delete your account — they are not covered by the twelve-month cap above, because they are content you gave Atlas directly rather than content Atlas synced from a connected account.
- Delete a meeting: every meeting has a Delete control on its own page. It removes the transcript, the recap, and the action items Atlas extracted, and Atlas keeps no copy of the words. Anything you explicitly confirmed and put on your Follow-Up Radar stays there as your own tracked work, with its link to the deleted meeting cleared; you can dismiss it from Radar separately. Atlas tells you at the time if anything survived that way.
- Disconnect a connector: syncing stops immediately and stored credentials are deleted, including revoking Atlas's access at Google, Microsoft, or Slack.
- Delete your account: all content, derived data, and credentials are deleted. Audit log entries and billing records are retained where required by law.
9. Security
- All data encrypted in transit (TLS) and at rest.
- OAuth tokens encrypted with AES-256-GCM through a single controlled access path.
- Tenant isolation enforced by PostgreSQL row-level security, with an automated isolation test suite that blocks any release that would break it.
- Audit logging of sensitive events, insert-only at the database level.
- No external write action can execute without an explicit approval record.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly and as required by applicable law.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data. Contact privacy@heyatlas.org and we will respond within the timeframe applicable law requires.
California residents. Under the CCPA/CPRA you have the right to know what personal information we collect and why, to request deletion of it, to request correction of it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. Atlas contains no advertising. Categories collected are listed in Section 6; the purposes are in Sections 2 and 4; the recipients are in Section 5.
Individuals in the EEA and UK. Where GDPR applies, our legal basis for processing your connected content is performance of our contract with you (Article 6(1)(b)), and for security and abuse prevention our legitimate interests (Article 6(1)(f)). You may access, correct, delete, port, or restrict processing of your data, and may lodge a complaint with your supervisory authority. Data is processed in the United States; where required, transfers rely on the Standard Contractual Clauses maintained by our sub-processors.
11. Children
Atlas is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.
12. Changes
We will post changes here and update the "Last updated" date. Material changes affecting how we use your connected data will be notified by email before taking effect.
13. Contact
Divitiae Holding LLC (dba Atlas) 405 8th St Huntington Beach, CA 92648 United States
privacy@heyatlas.org