ATLASO
LabPricing
Log inGet Started

Privacy Policy

Last updated September 27, 2026

Contents

  • 1. Who We Are and How to Contact Us
  • 2. Scope
  • 3. How Your Memories Are Stored (Please Read This)
  • 4. Categories of Personal Data We Collect
  • 5. How We Use Your Data and Our Lawful Bases
  • 6. The Two AI Processing Paths
  • 7. We Do Not Train AI Models on Your Memories
  • 8. Sub-processors
  • 9. International Data Transfers
  • 10. Data Retention
  • 11. Security
  • 12. Your Rights
  • 13. Children's Data
  • 14. Cookies
  • 15. What We Never Do
  • 16. Business Transfers
  • 17. Changes to This Policy
  • 18. Related Documents

This Privacy Policy explains how Atlaso Labs Inc. ("Atlaso", "we", "us", "our") collects, uses, shares, and protects personal data when you use the Atlaso memory layer: our dashboard, brain/API, Connectors, and CLI (together, the "Service"). In plain English: when you sign up we hold your account details with our authentication provider; when you connect a tool, the Memories you create or that our Connectors capture are stored on Atlaso's servers so they can sync across your sessions and devices, with a copy also kept on your own machine; we use specialist sub-processors (listed below) to run the Service; we run no advertising technology at all (the one advertising pixel we previously used was removed on September 22, 2026); we measure how our website and dashboard are used with Google Analytics and PostHog, which store nothing in your browser unless you press Accept all in our cookie banner, never record a session replay on the dashboard, and do not load in the browser for anyone whose browser sends a Global Privacy Control signal; we also count page views and measure page speed with tools from Vercel and Cloudflare that set no cookies and store nothing in your browser (Section 4); we do not sell your personal data, we do not operate a training endpoint, and we do not train any AI models on your Memory; Atlaso's own AI features run on open models hosted by Fireworks AI with zero data retention (Section 6 lists every feature that uses it); and you have rights to access, correct, and delete your data. On every plan, including Free, Atlaso sends selected Memory text to Fireworks AI's zero-retention open models to write your dashboard greeting and Ambient Memory summaries; our earlier policy wrongly said Free Memory was never sent to an AI model. Please read the full policy for the details, including the important explanation of where your Memories actually live.

1. Who We Are and How to Contact Us

Data controller: Atlaso Labs Inc., a Delaware C-Corporation.

Postal address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States

Contact (all enquiries: privacy and data-rights requests, general and legal notices, support and billing): support@atlaso.ai

EU / UK data subjects: You can direct any question or request about your personal data to support@atlaso.ai.

India (Digital Personal Data Protection Act, 2023): You can raise any privacy question or grievance with us at support@atlaso.ai.

If you have questions about this policy or how we handle your personal data, contact us at support@atlaso.ai.

2. Scope

This policy applies to personal data we process about:

  • Visitors to atlaso.ai and users of the dashboard at app.atlaso.ai;
  • Users of the Atlaso Connectors (Claude Code, Codex, Cursor, Antigravity, OpenCode, Claude Desktop, and our MCP integration) and the Atlaso CLI; and
  • Account holders on the Free and Pro tiers.

It does not cover third-party websites, tools, or AI models you choose to use alongside Atlaso, which are governed by their own privacy policies.

3. How Your Memories Are Stored (Please Read This)

We want to be precise about where your data lives, because it matters.

When you connect a tool, your Memories are stored on Atlaso's servers so they can sync across your sessions and devices. A local copy is also kept on your machine. Your Memory is only purely local in these situations:

  • before you connect any tool to Atlaso;
  • when a tool is not your active/entitled tool; or
  • while you are offline (in which case it syncs to our servers when connectivity is restored).

On the Free tier, your single active tool is cloud-linked, so its Memory syncs to and persists on Atlaso's servers as normal operation. Memory persists on our servers on both Free and Pro. The dashboard greeting and Ambient Memory summaries may use selected Memory text on every plan, including Free. Automatic enrichment, "Ask your memory", and Ambient Memory distillation for connected tools are Pro features. Section 6 explains which features send text to an AI model.

In short: Atlaso is cloud-synced memory with a local mirror, not a purely local-only product. We have written this policy to reflect that accurately.

4. Categories of Personal Data We Collect

CategoryWhat it includesWhen collectedWhere it is stored
Account dataEmail address and a user idAt signupClerk
Profile dataFirst and last nameAfter signup, if you add themClerk
Authentication credentialsPasskeys (optional)If you enable passkey loginClerk
Plan & billing identifiersYour plan (free/paid) and your Stripe customer idWhen you subscribeClerk metadata and Neon (user_plan)
Device dataA server-minted device_id, a user-chosen device label, and a last_seen timestampWhen you run atlaso connectNeon (device_registry). We do not perform any hardware fingerprinting.
Local auth file{ server, token, user_id, device_id }On connectOn your own machine, at ~/.atlaso/auth.json
Payment dataCard details, billing address, and subscription stateAt checkoutStripe only; card data never touches Atlaso systems
Memory / ContentFacts, decisions, preferences, gotchas, and auto-captured conversation snippets (your text plus a truncated assistant reply); may contain code or project factsWhen you deposit a Memory or a Connector captures oneServer-side per-user database (the canonical copy), a local ~/.atlaso/cache.db mirror, and transiently in the Neon enrichment queue (cleared after processing)
Contact and waitlist dataYour name, email address and message when you use our contact form; your email address and the plan when you press Notify me for a plan that is not open yetWhen you send the form or join a waitlistOur support inbox, delivered by Resend. Waitlist addresses are also kept on that plan's contact list in Resend.
Usage dataContent-free activity counters used to measure daily/monthly active usageOn activityNeon (usage_event, daily_active). These never contain prompt or code content.
Dashboard usage eventsSign-up, setup and upgrade steps in the dashboard, identified by your pseudonymous user id, with the limited properties listed in the note below. Never Memory content, searches, questions or anything you type.While you use the dashboard at app.atlaso.ai, and once from our servers when a Pro subscription startsPostHog (US Cloud)
IP addressYour network IPPer requestUsed only in memory for rate-limiting, not stored in our application database. IPs are inevitably present in the operational logs of our infrastructure providers (Render, Vercel, Cloudflare, Neon, Clerk, Stripe).
Campaign attribution dataThe campaign parameters in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_content, utm_term), an advertising click identifier if the link carried one, the referring website, the landing page, and a first-touch timestampWhen you arrive at atlaso.ai from a tagged link, an ad, or another website, only if you press Accept all in our cookie banner (a direct visit collects nothing), and again at signup if you create an AccountThe atl_attr first-party cookie in your browser (90 days), and, if you sign up, one row against your user id in Neon (user_attribution)
Your cookie choiceWhether you pressed Accept all or Necessary only in our cookie bannerWhen you answer the banner, or change your answerThe atl_consent first-party cookie in your browser (6 months), shared across atlaso.ai and app.atlaso.ai. It holds only that one word. Until September 23, 2026 we instead set an atl_geo cookie holding a coarse region (eu or row); it is no longer set, and our website deletes any remaining copy.

A note on website and dashboard measurement, and campaign attribution

We run no advertising technology. Until September 22, 2026 our marketing website loaded a single Reddit advertising pixel for visitors outside the EU/EEA/UK/Switzerland. It has been removed, and nothing on our website or dashboard now sends anything to an advertising network. On our marketing website at atlaso.ai, two things remain:

  • Website analytics, via Google Analytics and PostHog. These measure how pages are used: which pages are viewed, how far down them people read, which questions they open, and whether a form succeeded. On our website, both depend on your answer to our cookie banner, and we ask everyone the same question. Until you answer, and if you choose Necessary only, Google Analytics does not load, and PostHog stores nothing in your browser, keeps no identifier that outlives the tab, does not retain your IP address, and records no session replay; it only counts page views and clicks. If you choose Accept all, Google Analytics loads, and PostHog sets a first-party identifier and may record a session replay of how a page was used. Session replay records no text you type: every input is masked, and our contact form and Ask Atlaso box are excluded from recording entirely. For any visitor whose browser sends a Global Privacy Control (GPC) signal, anywhere in the world, we treat it as Necessary only and PostHog does not load at all. You can change your answer at any time from the cookie button in the bottom-left corner of our website or Cookie settings in its footer. PostHog is our sub-processor and is listed as one.
  • Our own first-party attribution record. The atl_attr cookie above is set by us only after you press Accept all, and read only by us. If you create an Account while it is present, we store the campaign details against your user id so we can measure how many signups (and later, subscriptions) a campaign produced. We do not share that record with any third party, and it is not used to track you across other websites.

Dashboard analytics at app.atlaso.ai. The dashboard sends product-usage events to PostHog (US Cloud) so we can understand the sign-up, setup and upgrade steps: for example, that an Account was created, a setup step was viewed, a tool was connected, the upgrade dialog was opened, or a checkout was started. These events are identified by your internal Atlaso user id, which is pseudonymous, and never by your name or email address. Each event carries only: the event type; the page path, with any ids removed; the tool you connected; your plan and billing interval; the number of tools you have connected; the date (not the time) you signed up; a count of your Memories; which setup step, screen or button the event came from; your cookie-banner answer; and the standard technical details PostHog's software adds (random session and device identifiers, the browser's user-agent string, browser and version, operating system and version, device type and model, screen and window size, language, time zone, and the referring page, reduced the same way as the page path). Events never include the content of your Memories, your searches, your questions, or anything you type. There is no session replay and no automatic click capture on the dashboard: only the events described here are sent, and a filter in the dashboard drops anything else before it leaves your browser. Requests go through our own address, app.atlaso.ai/ingest, which removes your cookies and sign-in credentials before passing them to PostHog.

  • Unless you pressed Accept all in our website's cookie banner (the dashboard has no banner of its own and follows the answer you gave there), PostHog keeps its identifier in memory only, nothing for analytics is stored in your browser, Google Analytics does not load, and the dashboard tells PostHog not to use your IP address to work out your location.
  • If you pressed Accept all, PostHog stores its identifier in a first-party cookie and local storage, PostHog may work out an approximate location from your IP address, and Google Analytics loads. The random visitor id from your earlier visits to our website in the same browser is then linked to your Account, so those earlier visits (including any website session replay) become associated with it.
  • If your browser sends a Global Privacy Control signal, neither PostHog nor Google Analytics loads in the dashboard at all, whatever you chose in the banner.
  • One event is sent from our servers, not your browser. When a Pro subscription starts, our payment provider notifies our server, which sends PostHog a single "subscription started" event with your user id, the plan and the billing interval, and tells PostHog not to work out a location for it. Because it does not come from your browser, it is sent regardless of your cookie choice or Global Privacy Control setting.

The dashboard also reads our own atl_attr attribution cookie once, at signup.

Cookieless page counting and page-speed measurement, on both. On our website and our dashboard we also use Vercel Web Analytics and Cloudflare Web Analytics, and on our website Vercel Speed Insights. They count page views and visits and measure how fast pages load. Depending on the tool, each page view sends the page address, the referring page, your browser, operating system and device type, page-load timings, and an approximate location worked out from your request. They set no cookies and store nothing in your browser. Vercel Web Analytics identifies a visitor by a hash created from the incoming request and discards that visitor session after 24 hours; Cloudflare states that its tool does not fingerprint visitors and does not log query strings. Because nothing is read from or stored on your device, these tools run for every visitor, whatever you choose in our cookie banner and whether or not your browser sends Global Privacy Control. Vercel (which hosts our website and dashboard) and Cloudflare are our sub-processors and are listed as such.

Full detail on both, including how to block them, is in our Cookie Policy.

A note on secrets in captured text

Connectors may capture text that inadvertently contains secrets (API keys, tokens, passwords). Our system assumes this can happen and scrubs detected secrets before storage (on every ingress and on enriched output, using a fail-closed redaction process). This means secret material may be transiently present in transit before it is redacted. Please do not rely on this scrubbing as a guarantee, and do not use Atlaso to store regulated or highly sensitive data (see Section 11 and our Acceptable Use Policy).

We do not knowingly collect special categories of data (e.g., health, biometric, or government-ID data) and ask that you do not store such data in your Memories.

A note on error reporting

We use Sentry to find and fix errors in the dashboard and our brain/API. Error events can include a stack trace, the page or API route, and technical details about the browser, device, or service. We configure Sentry not to store IP addresses in these events and not to attach your account id, email address, or name. We do not intentionally send Memory content or request bodies in error reports.

5. How We Use Your Data and Our Lawful Bases

Our role. For the Memory and account data of individual Free and Pro users, Atlaso is the data controller: we determine the purposes and means of processing, and this Privacy Policy governs that relationship. The processor/controller framing in our Data Processing Addendum (and its Standard Contractual Clauses) applies only where we process personal data on behalf of a business customer; it does not apply to individual users, whose safeguards are described here.

The legal ground we rely on for a given purpose depends on where you are. We describe the same processing activities below, region by region, because the applicable law differs.

5.1 EU / EEA and UK (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following lawful bases:

PurposeWhat we doLawful basis (GDPR Art. 6)
Provide the ServiceCreate and manage your Account; store, sync, retrieve, and inject your Memories; register and manage your DevicesPerformance of a contract (Art. 6(1)(b))
Authentication & securityVerify your identity, manage sessions and passkeys, prevent abuse and fraud, enforce rate limitsPerformance of a contract; legitimate interests in securing the Service (Art. 6(1)(f))
Billing & subscriptionsProcess payments, manage your Pro subscription, calculate taxesPerformance of a contract; compliance with legal/tax obligations (Art. 6(1)(c))
AI features provided as part of the ServiceProcess selected stored Memory text to generate the dashboard greeting and Ambient Memory summaries on every plan, including Free; on Pro, also provide enrichment, "Ask your memory", and Ambient Memory distillation. An Ask question is sent with recalled Memory when you use Ask.Performance of a contract (Art. 6(1)(b)); see Sections 6 and 7
Product analyticsCount content-free daily/monthly active usage, and measure website and dashboard usage via Google Analytics and PostHogConsent (Art. 6(1)(a)) for Google Analytics, for analytics cookies and browser storage, and for session replay on our website, all of which run only after you press Accept all; legitimate interests (Art. 6(1)(f)) for content-free usage counts, cookieless page counting on our website before or without consent, cookieless page counting and page-speed measurement by Vercel and Cloudflare on our website and dashboard, pseudonymous dashboard usage events that store nothing in your browser, and the single subscription-started event sent from our servers
Error reportingReceive technical error reports from the dashboard and brain/API to diagnose and fix faultsLegitimate interests in securing and repairing the Service (Art. 6(1)(f)). You may object at any time by emailing support@atlaso.ai.
Campaign measurementRecord in a first-party cookie which campaign you arrived from and, if you sign up, store it against your Account so we can tell which campaigns workConsent (Art. 6(1)(a)) for setting the cookie, which happens only after you press Accept all; legitimate interests in measuring the effectiveness of our own marketing (Art. 6(1)(f)) for the record kept with your Account
CommunicationsRespond to contact and support requests and email you to confirm we received them; send account, service and billing emails; email you when a plan whose waitlist you joined opens. We send these emails through Resend (Section 8).Performance of a contract; legitimate interests; for a waitlist, your request (consent, Art. 6(1)(a)), which you can withdraw by replying to any waitlist email
Legal complianceComply with applicable law and respond to lawful requestsLegal obligation (Art. 6(1)(c)); legitimate interests

No advertising technology is used in these regions, or anywhere. As of September 22, 2026 we run no advertising or cross-site tracking technology at all, so no data about any visitor reaches an advertising network and no consent-based advertising processing takes place. The campaign-measurement row above covers only our own first-party attribution record.

Analytics storage and your consent. On our website and dashboard, nothing for analytics is stored on or read from your device until you press Accept all in our cookie banner. Before that, and if you choose Necessary only, PostHog stores nothing on the device, Google Analytics does not load, and no session replay is recorded (Section 4). You can withdraw consent at any time, as easily as you gave it, from the cookie button on any page of our website; we then delete the analytics cookies and storage from your browser, and the dashboard does the same the next time one of its pages loads.

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing as described in Section 12. Where we rely on consent (for example, certain optional features), you may withdraw it at any time without affecting prior processing.

5.2 India (Digital Personal Data Protection Act, 2023)

For data principals in India, the DPDP Act recognizes consent and a set of enumerated legitimate uses as the grounds for processing; it does not recognize performance-of-contract or legitimate-interests as separate bases. Accordingly, for Indian users we process your personal data on the basis of your consent, obtained through an itemized notice at the point of collection, and on the DPDP-enumerated legitimate uses where they apply (for example, where you have voluntarily provided data for a specified purpose, or to comply with law). You may withdraw your consent at any time (see Sections 12.3 and 12.1), which does not affect processing carried out before withdrawal. See Section 12.3 for our Data Fiduciary duties and grievance-redressal contact.

5.3 United States and other regions

Where US state privacy laws or the laws of other jurisdictions apply, we process your personal data as permitted under those laws to provide, secure, bill for, and improve the Service, to communicate with you, and to comply with legal obligations, as described above. See Section 12.2 for US state-specific rights.

6. The Two AI Processing Paths

Atlaso involves AI processing in two ways.

(a) Your own model, at your direction. When you use a Connector, your Content is routed through the AI model you have chosen to use, such as Claude or GPT, as part of how that tool works. That processing is governed by your relationship with that model provider.

(b) Atlaso's model provider, Fireworks AI. Atlaso's AI features run on open models hosted on Fireworks AI's serverless platform, with zero data retention. Fireworks does not log or store the text we send or the results it returns: the text exists only in memory while the request runs and is discarded when it finishes. Where prompt caching is used, some of it may stay in that temporary memory for a few minutes before it is cleared. Fireworks keeps only technical metadata, such as the number of tokens in a request. It does not use this text to train or improve its models, because that requires an explicit opt-in, which Atlaso has not given. Fireworks runs its service on servers in the United States.

Atlaso sends selected stored Memory text to Fireworks for the dashboard greeting and Ambient Memory summaries on every plan, including Free. On Pro, Fireworks also powers nightly Memory enrichment, "Ask your memory", and Ambient Memory distillation for connected tools. One-line Memory headlines and Memory labelling may also use Fireworks if enabled.

The greeting uses selected stored Memory text. Ambient dashboard summaries use short, memory-derived candidates. Enrichment and Ask can use stored captures and related or recalled Memories. When you use Ask, your question is also sent to Fireworks and processed the same way, under the same zero-retention terms. Recognized secrets are removed from Memory when it is captured.

Fireworks describes these terms in its data-handling documentation and its privacy policy. We use chat completions, not Fireworks' stored Responses API, for these features.

The previous Privacy Policy wrongly said Free-plan Memory was never sent to a language model. This corrects the description of a practice already in place; it does not announce a new use of Free-plan Memory.

7. We Do Not Train AI Models on Your Memories

We do not operate a training endpoint and we do not train Atlaso models on your Memory. On every plan, selected Memory text is sent to Fireworks AI for the features described in Section 6, where it is processed on open models with zero data retention. We use that processing to generate your results, not to train AI models. Fireworks does not use this text to train or improve its models, because that requires an explicit opt-in, which Atlaso has not given.

We believe this is a meaningful difference from some competitors that take broad licenses to train on user content. We do not.

8. Sub-processors

We use the trusted service providers below to operate the Service. Each is bound by data-protection terms appropriate to its role. Our current list:

Sub-processorPurposeData sharedLocation
ClerkAuthentication, session, and profileEmail, user id, name, passkeys, plan and Stripe-customer-id metadataUSA
StripePayment processing and subscription billingEmail, card/payment data, billing address, subscription stateUSA
NeonBrain metadata database and transient enrichment queueToken hashes, device registry, plan, usage counters, OAuth state, and transient raw capture textUSA
Fireworks AIOpen-model processing with zero data retention for the dashboard greeting and Ambient Memory summaries on every plan; enrichment, Ask and Ambient distillation on Pro; optional headlines and labelling if enabledSelected stored Memory text, including captures and recalled Memories, and your Ask question. Recognized secrets are removed from Memory when it is captured. Fireworks does not log or store this text: it exists only in memory while the request runs, prompt caching may keep some of it for a few minutes, and Fireworks keeps only technical metadata such as token counts.United States (Fireworks servers)
OpenRouter, routing to MiniMax M3Optional Ask Atlaso product-question assistant on atlaso.aiA visitor's question and recent conversation turns. Atlaso does not attach account records, dashboard data or stored Memories. Text a visitor types may itself contain personal data. Requests specify zero-data-retention routing and deny provider data collection.Provider processing location not verified
RenderHosting the brain (all server-side Memory and metadata)All server-side data at restUSA
VercelHosting the website and dashboard; cookieless page counting (Vercel Web Analytics) on both, and page-speed measurement (Vercel Speed Insights) on the websiteRequest data and served content. For measurement: the page address, referring page, browser, operating system, device type, approximate location and page-load timings, with nothing stored in your browser.USA
Cloudflare, Inc.Cookieless page counting and page-speed measurement (Cloudflare Web Analytics) on the website and dashboardThe page address, referring page, browser and device details, and page-load timings, with nothing stored in your browser. Cloudflare does not log query strings.USA
Google LLC (Google Analytics)Website and product analytics (aggregate usage measurement)Online identifiers (cookie IDs), device/browser info, pages viewed, approximate (city-level) location, and, for signed-in dashboard users, a pseudonymous user id and plan tier. Loaded on the website and the dashboard only after you press Accept all, and never where GPC is present.USA
PostHog, Inc.Product analytics for the marketing website and the dashboard; heatmaps and session replay on the marketing website onlyOnline identifiers (a random visitor id; on the dashboard, your pseudonymous user id), device/browser info, pages viewed, and measured interactions. On the dashboard, only the usage events described in Section 4: never Memory content, searches, questions or anything you type, and no session replay. With your consent (Accept all), on the website only, this may include a session replay of movement through a page, with every input masked and the contact form and Ask Atlaso box excluded entirely. Without it, nothing is stored on the device and no replay is recorded. Never loaded in the browser where GPC is present; one server-side event when a Pro subscription starts (plan and billing interval) is sent regardless.USA
Sentry (Functional Software, Inc.)Error and crash monitoring for the dashboard and brain/APIError events, stack traces, page or API routes, and technical browser, device and service details. Atlaso configures Sentry not to store IP addresses in these events and does not attach an account id, email address or name. Memory content and request bodies are not intentionally sent.United States
Resend (Resend, Inc.)Transactional email delivery: contact-form and waitlist confirmations, waitlist updates, account and billing emails, and delivery of contact-form and waitlist messages to our support inboxEmail address, name, and the message content of the emails we send (a confirmation can quote the message you wrote to us). Waitlist addresses are kept on that plan's contact list until you ask to leave it.USA

For the maintained, dated list and a way to subscribe to changes, see our Sub-processors List. We use Google Analytics and PostHog for usage analytics, Vercel and Cloudflare for the page and speed measurements described above, and Sentry for error reporting. Ask Atlaso uses OpenRouter and a routed MiniMax model as described above. Resend delivers the emails we send you: the reply confirming we received your message, waitlist confirmations and updates, and account and billing emails. We do not use any other email vendor.

We have no advertising partner. Earlier versions of this policy disclosed Reddit, Inc. as an advertising partner and independent controller in respect of a pixel on our marketing website. That pixel was removed on September 22, 2026. We now use no advertising vendor of any kind, and no third party receives data from us as an independent controller. The service providers listed above process data to provide their services to us under the arrangements described on our Sub-processors List.

9. International Data Transfers

Atlaso is a US company with operations and personnel in India. Our infrastructure and service providers may process personal data in the United States, India, and other locations where they operate. Fireworks states its servers are in the United States. We have not verified the downstream host used for an Ask Atlaso request. The location column in Section 8 distinguishes known locations from those still to be confirmed.

Transfers from the EEA and UK require a valid transfer mechanism where the destination lacks an adequacy decision. We are finalizing the applicable Standard Contractual Clauses, UK Addendum, assessments and related instruments for the relevant transfers. We do not represent that every instrument is already executed. For information about the safeguards applicable to your data, contact support@atlaso.ai.

10. Data Retention

We retain personal data for as long as needed to provide the Service and for the purposes described in this policy.

  • Memory content: retained for the life of your Account. There is no automated expiry of Memory content. On a verified deletion request (see Section 12) we delete it without undue delay and within the statutory timeframes that apply to you, and in any event within 30 days.
  • Account, profile, device, and plan data: retained for the life of your Account and deleted in line with a verified deletion request.
  • Transient raw capture text in the enrichment queue: cleared (set to empty) once processed.
  • Tokens: expire after 90 days; OAuth/idempotency keys are garbage-collected (approximately every 7 days).
  • Campaign attribution data: the atl_attr cookie expires from your browser after 90 days; where a signup was attributed to a campaign, that single row is retained for the life of the Account and deleted with it on a verified deletion request.
  • Waitlist sign-ups: your email address stays on the Resend contact list for that plan until you ask to leave it, by replying to any waitlist email or writing to support@atlaso.ai.
  • Billing records: retained by Stripe and by us as required for tax, accounting, and legal-compliance purposes.

Deletion and retraction paths:

  • Forget a Memory: retracts the Memory and creates a tombstone, which propagates the deletion to your other Devices.
  • Revoke / disconnect a Device: removes the device registry entry and revokes its tokens.
  • Downgrade (Pro → Free): arms an approximately 5-day grace period; expensive AI features turn off immediately; at expiry we keep your most-recent Device and disconnect the rest. Your Memories are not deleted on downgrade.
  • Account deletion: today, account deletion is handled manually on request (email support@atlaso.ai). There is no self-serve deletion button yet. On a verified request we clear your data across Clerk, Stripe, Neon metadata, and our server-side store, and we instruct our sub-processors to do the same.

Erasure and Fireworks. A feature in Section 6 sends text to Fireworks when it runs. Fireworks does not log or store that text: it exists only in memory while the request runs, and prompt caching may keep some of it for a few minutes before it is cleared. Atlaso does not use Fireworks as a store for your Memory, so deleting a Memory removes it from Atlaso's canonical store under the process above. The technical metadata Fireworks keeps, such as token counts, is not affected by deleting a Memory.

Legal-hold and preservation carve-out. Where we are legally required to preserve data, for example to comply with a legal hold, a law-enforcement preservation request, a subpoena or court order, our obligations to report and preserve suspected illegal content (including the preservation duties under 18 U.S.C. §2258A), or to establish, exercise, or defend legal claims, we may suspend deletion of the affected data for as long as the preservation obligation lasts, even if you have asked us to delete it. We delete the data once the obligation ends.

11. Security

We take reasonable and appropriate technical and organizational measures to protect personal data. These measures, implemented among others, currently include:

  • Token handling: tokens stored only as SHA-256 hashes; OAuth codes/refresh tokens hashed; plaintext device tokens held only briefly during the approve-then-consume flow.
  • Secret scrubbing: redaction of detected secrets (private keys; sk-, GitHub, AWS, Google, and Slack tokens; JWTs; bearer tokens; credentials embedded in URIs; high-entropy blobs) on every ingress and on enriched output. The redaction process is designed to fail closed: if a check cannot complete, the content is treated as if it contained a secret rather than passed through. As noted in Section 4, secret material may be transiently present in transit before it is redacted, so this is not a guarantee.
  • Authenticated connect flows: PKCE with loopback device connect (RFC 7636 / RFC 8252); an OAuth 2.1 authorization server with our own consent page, dynamic client registration, and revocation.
  • Service-to-service gating: constant-time secret comparison for web-to-brain calls.
  • Tenant isolation: per-tenant isolation by authenticated user_id; per-project visibility is designed to fail closed; cross-user access attempts return a 404.
  • Abuse controls: rate limiting, denial-of-service guards (a 64 KB text cap, a batch cap of 100, and device caps), and a data directory locked to owner-only permissions.

Encryption. Data is encrypted in transit (HTTPS everywhere; Neon connections require SSL). At rest, data is protected by our infrastructure providers' provider-level encryption (Neon, Render). We do not apply application-level field encryption to Memory content, so please do not describe Atlaso as applying its own at-rest encryption to your Memories.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Do not store regulated data (such as health information or payment-card data) in your Memories unless separately contracted with us.

Breach notification. In the event of a personal-data breach, we will assess and notify as required by applicable law, in-product and/or by email where available. In particular:

  • EU / UK (GDPR): where the breach is likely to result in a risk to individuals' rights, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33), and where the breach is likely to result in a high risk, we will notify affected individuals without undue delay (Art. 34).
  • India (DPDP Act, 2023): we will notify the Data Protection Board of India and affected data principals of a personal-data breach in the manner and timeframe required by the Act and its rules.
  • United States and other regions: we will provide any notifications required under applicable state or national breach-notification laws.

12. Your Rights

12.1 GDPR / UK GDPR (EEA and UK users)

You have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority in your country of residence or work.

To exercise these rights, contact support@atlaso.ai. We will respond within the timeframes required by law (generally one month under the GDPR).

12.2 CCPA / CPRA (California residents)

We provide notice at collection through this policy. California residents have the right to know/access, delete, and correct personal information, and to limit the use of sensitive personal information.

We do not sell your personal information, as that term is defined under the CCPA/CPRA, and we have not done so in the preceding 12 months.

"Sharing" for cross-context behavioral advertising. We do not share personal information for cross-context behavioral advertising. Between August 1, 2026 and September 22, 2026, our marketing website loaded a Reddit advertising pixel for visitors outside the EU/EEA/UK/Switzerland whose browsers were not sending an opt-out signal. Through that pixel Reddit received online identifiers and the fact of a visit, and used them for advertising measurement and to build advertising audiences. We treated that as "sharing" under the CCPA/CPRA and said so plainly. That pixel was removed on September 22, 2026 and no such sharing now takes place. We did not share personal information for that purpose before August 1, 2026 either, and the dashboard at app.atlaso.ai has never carried advertising technology in any region.

How to opt out. We treat the Global Privacy Control (GPC) signal as a valid opt-out request and act on it directly: when your browser sends GPC, our analytics provider PostHog is not loaded at all on our website or dashboard, so your browser stores no identifier, records no session replay and sends no event, and Google Analytics does not load on our website or dashboard. The one exception is the single "subscription started" event our server sends when a Pro subscription starts (plan and billing interval), which does not come from your browser and so is sent regardless of GPC (Section 4). GPC does not switch off the cookieless page counting and page-speed measurement by Vercel and Cloudflare (Section 4), which stores nothing in your browser. You can also choose Necessary only in our website's cookie banner, or opt out by emailing support@atlaso.ai.

We will not discriminate against you for exercising your rights. To make a request, contact support@atlaso.ai.

Other US states. Comprehensive privacy laws in states including Virginia, Colorado, Connecticut, Texas, and Oregon (among others) give residents comparable rights: to access, correct, delete, and obtain a portable copy of their personal data, to opt out of sale/targeted advertising/certain profiling, and, in several states, to appeal a decision on a rights request. Some of these laws apply regardless of a business's size or revenue (for example, Texas and Oregon have no such thresholds). If you are a resident of one of these states, you may exercise your rights by contacting support@atlaso.ai, and we will honor them as required by your state's law. Your browser's Global Privacy Control signal is honored in every region, not only California: where it is present, neither PostHog nor Google Analytics loads in your browser on our website or dashboard.

12.3 India: Digital Personal Data Protection Act, 2023

For data principals in India, Atlaso acts as a Data Fiduciary and processes your personal data on a consent-based model (with the enumerated legitimate uses where they apply), as described in Section 5.2. In that role we take on the Data Fiduciary duties under the Act, including maintaining the accuracy and security of your data, using it only for the notified purpose, and erasing it when the purpose is served or you withdraw consent (subject to Section 10's legal-hold carve-out).

If you are in India, you have the right to access a summary of your personal data and our processing, to correction and erasure, to grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity. Because our processing is based on your consent, you may withdraw that consent at any time by contacting support@atlaso.ai; withdrawal does not affect processing carried out before it.

Children. We require verifiable parental consent before processing the personal data of anyone under 18 (see Section 13), and we do not track, profile, or serve targeted advertising to children.

Grievance redressal. You can raise any privacy grievance with us at support@atlaso.ai, and we will work to resolve it. If your grievance is not resolved, you may complain to the Data Protection Board of India.

12.4 Verifying your request

To protect your data, we may need to verify your identity before fulfilling a request. We will only use information provided in a request to verify and respond to it.

13. Children's Data

The Service is not directed to children, and you must meet the minimum age set out in Section 3 of our Terms of Service to use it: at least 13 years old, and where local law requires a higher age or parental involvement (16 in parts of the EU/EEA, and under 18 in India), only with the verifiable consent of a parent or guardian. We do not knowingly collect personal data from children below the applicable age without the required parental consent. If you believe a child has provided us with personal data without that consent, contact support@atlaso.ai and we will delete it.

14. Cookies

We use essential authentication cookies (set by Clerk), a functional theme preference stored in your browser's local storage, and Google Analytics 4 cookies for aggregate usage analytics. On our marketing website, we ask first: a cookie banner offers Accept all or Necessary only, and Google Analytics, PostHog's cookies and session replay, and our atl_attr attribution cookie are used only after you press Accept all. We store your answer in our own atl_consent cookie. We load no advertising pixel and no third-party advertising cookies anywhere. The dashboard at app.atlaso.ai follows the same answer: it runs no session replay, loads Google Analytics and lets PostHog store an identifier in your browser only after you press Accept all, loads neither where GPC is present, and reads our own atl_attr cookie once at signup, which is shared across atlaso.ai and app.atlaso.ai. Without Accept all, the dashboard still sends PostHog the pseudonymous usage events described in Section 4, with nothing stored in your browser. On both our website and dashboard, the page counting and page-speed measurement we use from Vercel and Cloudflare sets no cookies and stores nothing in your browser. For the full detail, including how to change your answer or block each of these, see our Cookie Policy.

15. What We Never Do

  • We do not sell your personal data.
  • We run no advertising technology at all, anywhere: not on the marketing website, not on the dashboard, in no region. The one advertising pixel we previously used was removed on September 22, 2026.
  • We never share your Memory content, your account details, or your email address with an advertising network. We have no advertising network.
  • We never record a session replay on the dashboard (app.atlaso.ai), for any website visitor who has not pressed Accept all in our cookie banner, or for any visitor whose browser sends a Global Privacy Control signal. Where replay does run, it captures no text you type: every input is masked and our contact form and Ask Atlaso box are excluded entirely.
  • We do not operate a training endpoint and do not train AI models on your Memory. Selected Memory text is sent to Fireworks AI for the features listed in Section 6 on every plan, including Free. Fireworks runs these features on open models with zero data retention, and it does not use this text to train or improve its models, because that requires an explicit opt-in, which Atlaso has not given.
  • We use Sentry for error monitoring in the dashboard and brain/API. We configure Sentry not to store IP addresses in error events and do not attach your account id, email address or name. We also use Google Analytics and PostHog for usage measurement, and Vercel and Cloudflare for page and speed measurement, as listed in Section 8. Dashboard analytics do not intentionally include Memory content, searches or Ask questions. We use no advertising technology.

16. Business Transfers

If Atlaso is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, personal data (including your Memories and account data) may be transferred or disclosed as part of that transaction or diligence, as a business asset. Any acquirer or successor will remain bound by the commitments in this Privacy Policy, or we will require it to honor equivalent protections, and we will notify you (in-product and/or by email where available) of any change in ownership or use of your personal data, and of any choices you may have, as required by applicable law.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we make a material correction or change, we update the date above and give appropriate direct notice. The date and substance of a correction do not make earlier processing newly authorized.

Change log

  • September 27, 2026: We corrected an inaccurate statement that Free-plan Memory was never sent to a language model. Selected Memory text has been sent to Fireworks AI for the dashboard greeting and Ambient Memory summaries on every plan, including Free. We clarified Fireworks' data-handling terms, Ask question handling, the separate website assistant, error reporting and international transfers. We added Resend, which delivers the emails we send, including the reply confirming we received a contact-form message and waitlist confirmations.

18. Related Documents

  • Terms of Service
  • Refund & Cancellation Policy
  • Acceptable Use Policy
  • Cookie Policy
  • Sub-processors List
  • Data Processing Addendum

Questions about this policy? Contact us at support@atlaso.ai.

ATLASO

One memory for every AI tool you use.

Product

  • Pricing
  • Lab
  • Contact

© 2026 Atlaso Labs Inc. All rights reserved.

Legal & policies
Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseRefundsDPASub-processors