Atlas Privacy Policy

Effective: August 1, 2026 · Last updated: September 22, 2026 Applies to: heyatlas.org and the Atlas application


1. Who we are

Atlas is an AI chief of staff for founder-led teams, operated by Divitiae Holding LLC, a California limited liability company doing business as Atlas. You can reach us at privacy@heyatlas.org.

This policy explains what we access, why, how long we keep it, and how you get rid of it.

2. What Atlas connects to, and why

Atlas only reads what you explicitly connect. Nothing is accessed until you complete that connector's consent flow, and you can disconnect any connector at any time.

Google Workspace

Scope What it lets Atlas read Why Atlas needs it
gmail.readonly Message metadata, subjects, and content in your mailbox Detects unanswered messages and open commitments for Follow-Up Radar; supplies context for your Daily Brief and meeting prep
gmail.send Nothing. This permission only sends — it grants no read access at all Sends a reply that you have read and individually approved. See below
calendar.events.readonly Event times, titles, attendees, descriptions Builds meeting preparation and the meetings section of your Daily Brief
openid, email Your email address and account identifier Signing you in and matching your account

Atlas can send one thing, and only with your explicit approval each time.

gmail.send is the single write permission Atlas requests anywhere in your Google account. It cannot modify, label, archive or delete any message, and Atlas requests no permission that would allow it to.

Sending is gated on you, individually, every time:

  1. You press Draft reply on a follow-up. Atlas writes a draft — it does not send it.
  2. The draft waits on your Approval Desk, where you see the original message and the proposed reply side by side.
  3. You may edit the reply freely. You cannot change the recipient or the conversation — only the words — so an approved reply always goes to the person who wrote to you.
  4. Nothing leaves your account until you press Approve & send.

Atlas never sends automatically, on a schedule, in bulk, or without that specific approval. There is exactly one code path in Atlas capable of sending, and it refuses to run on anything you have not approved.

Atlas requests no calendar write permission. It cannot create, change, accept or delete an event.

Removed in this version: drive.metadata.readonly. Atlas requested it from the beginning and never used it — no part of Atlas has ever read anything from Google Drive. It has been removed from the permissions Atlas asks for. If you connected Atlas before 14 August 2026, you granted it; reconnecting will drop it.

Microsoft 365

Scope What it lets Atlas read Why Atlas needs it
Mail.Read Message metadata, subjects, and content in your mailbox Detects unanswered messages and open commitments for Follow-Up Radar; supplies context for your Daily Brief and meeting prep
Mail.Send Nothing. This permission only sends — it grants no read access at all Sends a reply that you have read and individually approved, on the same Approval Desk described above
Calendars.Read Event times, titles, attendees, descriptions Builds meeting preparation and the meetings section of your Daily Brief
User.Read Your name, email address, and account identifier Identifies which mailbox was connected
offline_access Nothing. Issues the refresh token that keeps the connection alive So you are not asked to sign in again every day

Mail.ReadWrite is deliberately not requested. That scope would grant read, write and delete across every message in your mailbox. Mail.Send authorizes sending only. Atlas requests the narrower one, accepts the resulting limitations in how replies thread, and does not widen the grant to work around them.

Atlas requests no calendar write permission on Microsoft 365. It cannot create, change, accept or delete an event.

Sending is gated exactly as it is on Google: Atlas drafts, the draft waits on your Approval Desk where you see the original and the proposed reply side by side, you may edit the words but not the recipient, and nothing leaves your account until you press Approve & send.

Slack

channels:history, channels:read, users:read, team:read — messages and channel metadata from channels Atlas has been added to, used to detect commitments and follow-ups. Atlas does not read private channels or direct messages it has not been explicitly added to.

Asana

Scope What it lets Atlas read Why Atlas needs it
tasks:read Title, description, assignee, due date and completion state of tasks assigned to you Detects commitments that are open or overdue, so Follow-Up Radar can surface work that has slipped
projects:read The name of the project a task belongs to So a follow-up arrives with the context it belongs to, rather than as a bare task title
workspaces:read The names of the Asana workspaces you belong to Required to look up your tasks at all
users:read Your name and email address, and the names of task assignees Identifies which Asana account was connected and who owns a task

Atlas requests no write permission on Asana. It cannot create, change, complete, comment on or delete a task.

Atlas reads only the tasks assigned to you, and only those that are still incomplete. It does not read your organisation's other tasks, and it does not read completed work.

stories:read is deliberately not requested. That scope would let Atlas read every comment on every task you can see. Atlas does not need it to notice that a task is overdue, so it does not ask for it. If a future feature needs task comments, Atlas will ask you to reconnect and you will see the added permission on Asana's consent screen before you approve it.

GoHighLevel

Connected per client sub-account, by pasting a private integration token rather than through a consent screen. A token of that kind is scoped by GoHighLevel to exactly one sub-account: there is no mechanism by which an agency could grant Atlas access to its whole book of clients, and Atlas does not ask for one.

Scope What it lets Atlas read Why Atlas needs it
contacts.readonly Name, email, phone, company and tags of contacts in that sub-account Puts a person's name on a message, opportunity or appointment instead of an opaque id, so a follow-up says who it is about
conversations.readonly The list of message threads, and who each one is with Without it there is no way to reach the messages themselves
conversations/message.readonly The text of SMS, email and chat messages in those threads, their direction, and whether delivery succeeded The commitment itself — what was actually said and promised
opportunities.readonly Opportunity name, value, pipeline stage, owner and dates Detects a deal that has stalled, and who owns it where GoHighLevel records an owner
calendars.readonly The names of the booking calendars in that sub-account GoHighLevel has no way to ask for every appointment at once — appointments are read one calendar at a time, so Atlas has to know which calendars exist
calendars/events.readonly Appointments booked through GoHighLevel: title, time, status, who it is with Shows GoHighLevel appointments alongside your other meetings, and detects upcoming ones that have not been confirmed
locations.readonly The sub-account's own id and name Confirms which client the token belongs to before anything is stored, and names it in the app
users.readonly Names and email addresses of staff users in that sub-account Puts the right person's name on a commitment instead of an opaque id

Atlas requests no write permission on GoHighLevel. It cannot send a message, move an opportunity, book an appointment, change a contact, or create an invoice.

Atlas is not answering your phone. This connector reads what happened in GoHighLevel after the fact. Calls are answered by GoHighLevel, by your agency, or by you.

GoHighLevel fixes a token's scopes at the moment it is created. If a future feature needs a permission not in the table above, it cannot be added quietly — a new token has to be created with the new box ticked, and someone has to paste it in.

Meeting notetakers you already use (Fathom, Fireflies)

If you connect one, Atlas reads meeting summaries and action items to build recaps. Transcription happens in the tool you already use — Atlas does not join or record those meetings.

Transcripts you give Atlas directly

You can paste or upload a transcript of a meeting you already have. Atlas treats it the same way as one from a connected notetaker: it builds a recap and extracts action items. Nothing is fetched from anywhere — the content is what you supplied, and it is stored until you delete it (§8).

Atlas Notetaker

Atlas Notetaker joins, records and transcribes meetings — and only the meetings you switch it on for. It is off by default and enabled per meeting. There is no setting that captures your whole calendar, and no meeting is captured because of how it was scheduled or which platform it is on.

When you enable it for a meeting, an Atlas bot joins the call as a visible participant, named so that everyone present can see it is there. It captures the call's audio, that audio is turned into text, and then the audio is discarded. Atlas stores no recordings of any kind, and instructs the capture provider to erase its copy once the transcript has been retrieved. What remains is the transcript and the recap built from it, both of which you can delete at any time (§8).

Obtaining consent is yours, not ours. Recording laws differ by jurisdiction, and in some places every participant must agree before a call may be recorded. Atlas makes the bot visible to the room and records that you enabled capture, but it cannot obtain consent on your behalf and does not claim to. You are responsible for having it.

3. Google Limited Use commitment

Atlas's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Atlas:

4. How Atlas uses AI, and what that means for your data

Atlas uses large language models to generate briefs, meeting preparation, meeting recaps, and answers to questions about your workspace. To do that, relevant excerpts of your connected data are sent to our AI provider (Anthropic) for processing at the moment you request the feature or your scheduled brief runs.

Meeting transcripts are part of that. A recap is built by sending the transcript — whether it came from a notetaker you connected, from a file you supplied, or from Atlas Notetaker — to Anthropic to be summarized and to have decisions and action items pulled out of it. Long transcripts are sent in full rather than in excerpts, because a summary of a meeting cannot be built from a fragment of it. The three commitments below apply to that content exactly as they apply to everything else.

Three commitments about that processing:

  1. Your data is not used to train models. Content sent to Anthropic through their API is not used to train their models. Atlas does not train any model on customer data, and does not fine-tune models on your content.
  2. Retrieved content is treated as data, never as instructions. Atlas's prompts explicitly instruct the model to ignore any instructions embedded in your email, documents, or messages. This defends against a malicious sender attempting to manipulate Atlas through content you receive.
  3. AI cannot act on your behalf without approval. No AI output causes an external action — no email sent, no task created, no record updated — unless you individually review and approve it first.

5. Sub-processors

Atlas shares data with these providers only to operate the service:

Provider Purpose Data involved
Anthropic AI inference for briefs, search, and meeting prep Excerpts of connected workspace content, at request time
Neon Managed PostgreSQL database All stored application data
Railway Website and application hosting Data in transit; request logs
Inngest Background job scheduling Job metadata and identifiers, not message content
Resend Transactional email Name, email address, and application contents of people who submit the fit form at heyatlas.org/operations — sent as the notification to us and the confirmation to them. Not connected workspace content, message bodies, or credentials
Sentry Error monitoring Error type, message and stack trace; the URL of the page or endpoint that failed; server runtime details; and approximate country. Not message content, email addresses, credentials, request bodies, or session recordings
Recall.ai Joining and transcribing meetings, only for meetings you enable Atlas Notetaker on The meeting link, the name the bot displays, the call's audio while it is in progress, and the transcript it produces. Atlas retrieves the transcript and then instructs Recall to erase its copy of the media. Not your email, your connected workspace content, or any meeting you did not enable capture for

We do not sell your data. We do not share it with advertisers. There is no advertising in Atlas.

6. What Atlas stores

7. Separation between your personal and work accounts

Atlas is built so one person can hold both a personal account and membership in one or more company accounts, without those contexts mixing.

If you leave an organization, your access to that organization's data ends and the connectors you added there stop syncing. Your personal account is unaffected.

8. Retention and deletion

9. Security

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you promptly and as required by applicable law.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data. Contact privacy@heyatlas.org and we will respond within the timeframe applicable law requires.

California residents. Under the CCPA/CPRA you have the right to know what personal information we collect and why, to request deletion of it, to request correction of it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. Atlas contains no advertising. Categories collected are listed in Section 6; the purposes are in Sections 2 and 4; the recipients are in Section 5.

Individuals in the EEA and UK. Where GDPR applies, our legal basis for processing your connected content is performance of our contract with you (Article 6(1)(b)), and for security and abuse prevention our legitimate interests (Article 6(1)(f)). You may access, correct, delete, port, or restrict processing of your data, and may lodge a complaint with your supervisory authority. Data is processed in the United States; where required, transfers rely on the Standard Contractual Clauses maintained by our sub-processors.

11. Children

Atlas is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.

12. Changes

We will post changes here and update the "Last updated" date. Material changes affecting how we use your connected data will be notified by email before taking effect.

13. Contact

Divitiae Holding LLC (dba Atlas) 405 8th St Huntington Beach, CA 92648 United States

privacy@heyatlas.org