Last updated September 27, 2026
This Privacy Policy explains how Atlaso Labs Inc. ("Atlaso", "we", "us", "our") collects, uses, shares, and protects personal data when you use the Atlaso memory layer: our dashboard, brain/API, Connectors, and CLI (together, the "Service"). In plain English: when you sign up we hold your account details with our authentication provider; when you connect a tool, the Memories you create or that our Connectors capture are stored on Atlaso's servers so they can sync across your sessions and devices, with a copy also kept on your own machine; we use specialist sub-processors (listed below) to run the Service; we run no advertising technology at all (the one advertising pixel we previously used was removed on September 22, 2026); we measure how our website and dashboard are used with Google Analytics and PostHog, which store nothing in your browser unless you press Accept all in our cookie banner, never record a session replay on the dashboard, and do not load in the browser for anyone whose browser sends a Global Privacy Control signal; we also count page views and measure page speed with tools from Vercel and Cloudflare that set no cookies and store nothing in your browser (Section 4); we do not sell your personal data, we do not operate a training endpoint, and we do not train any AI models on your Memory; Atlaso's own AI features run on open models hosted by Fireworks AI with zero data retention (Section 6 lists every feature that uses it); and you have rights to access, correct, and delete your data. On every plan, including Free, Atlaso sends selected Memory text to Fireworks AI's zero-retention open models to write your dashboard greeting and Ambient Memory summaries; our earlier policy wrongly said Free Memory was never sent to an AI model. Please read the full policy for the details, including the important explanation of where your Memories actually live.
Data controller: Atlaso Labs Inc., a Delaware C-Corporation.
Postal address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States
Contact (all enquiries: privacy and data-rights requests, general and legal notices, support and billing): support@atlaso.ai
EU / UK data subjects: You can direct any question or request about your personal data to support@atlaso.ai.
India (Digital Personal Data Protection Act, 2023): You can raise any privacy question or grievance with us at support@atlaso.ai.
If you have questions about this policy or how we handle your personal data, contact us at support@atlaso.ai.
This policy applies to personal data we process about:
It does not cover third-party websites, tools, or AI models you choose to use alongside Atlaso, which are governed by their own privacy policies.
We want to be precise about where your data lives, because it matters.
When you connect a tool, your Memories are stored on Atlaso's servers so they can sync across your sessions and devices. A local copy is also kept on your machine. Your Memory is only purely local in these situations:
On the Free tier, your single active tool is cloud-linked, so its Memory syncs to and persists on Atlaso's servers as normal operation. Memory persists on our servers on both Free and Pro. The dashboard greeting and Ambient Memory summaries may use selected Memory text on every plan, including Free. Automatic enrichment, "Ask your memory", and Ambient Memory distillation for connected tools are Pro features. Section 6 explains which features send text to an AI model.
In short: Atlaso is cloud-synced memory with a local mirror, not a purely local-only product. We have written this policy to reflect that accurately.
| Category | What it includes | When collected | Where it is stored |
|---|---|---|---|
| Account data | Email address and a user id | At signup | Clerk |
| Profile data | First and last name | After signup, if you add them | Clerk |
| Authentication credentials | Passkeys (optional) | If you enable passkey login | Clerk |
| Plan & billing identifiers | Your plan (free/paid) and your Stripe customer id | When you subscribe | Clerk metadata and Neon (user_plan) |
| Device data | A server-minted device_id, a user-chosen device label, and a last_seen timestamp | When you run atlaso connect | Neon (device_registry). We do not perform any hardware fingerprinting. |
| Local auth file | { server, token, user_id, device_id } | On connect | On your own machine, at ~/.atlaso/auth.json |
| Payment data | Card details, billing address, and subscription state | At checkout | Stripe only; card data never touches Atlaso systems |
| Memory / Content | Facts, decisions, preferences, gotchas, and auto-captured conversation snippets (your text plus a truncated assistant reply); may contain code or project facts | When you deposit a Memory or a Connector captures one | Server-side per-user database (the canonical copy), a local ~/.atlaso/cache.db mirror, and transiently in the Neon enrichment queue (cleared after processing) |
| Contact and waitlist data | Your name, email address and message when you use our contact form; your email address and the plan when you press Notify me for a plan that is not open yet | When you send the form or join a waitlist | Our support inbox, delivered by Resend. Waitlist addresses are also kept on that plan's contact list in Resend. |
| Usage data | Content-free activity counters used to measure daily/monthly active usage | On activity | Neon (usage_event, daily_active). These never contain prompt or code content. |
| Dashboard usage events | Sign-up, setup and upgrade steps in the dashboard, identified by your pseudonymous user id, with the limited properties listed in the note below. Never Memory content, searches, questions or anything you type. | While you use the dashboard at app.atlaso.ai, and once from our servers when a Pro subscription starts | PostHog (US Cloud) |
| IP address | Your network IP | Per request | Used only in memory for rate-limiting, not stored in our application database. IPs are inevitably present in the operational logs of our infrastructure providers (Render, Vercel, Cloudflare, Neon, Clerk, Stripe). |
| Campaign attribution data | The campaign parameters in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_content, utm_term), an advertising click identifier if the link carried one, the referring website, the landing page, and a first-touch timestamp | When you arrive at atlaso.ai from a tagged link, an ad, or another website, only if you press Accept all in our cookie banner (a direct visit collects nothing), and again at signup if you create an Account | The atl_attr first-party cookie in your browser (90 days), and, if you sign up, one row against your user id in Neon (user_attribution) |
| Your cookie choice | Whether you pressed Accept all or Necessary only in our cookie banner | When you answer the banner, or change your answer | The atl_consent first-party cookie in your browser (6 months), shared across atlaso.ai and app.atlaso.ai. It holds only that one word. Until September 23, 2026 we instead set an atl_geo cookie holding a coarse region (eu or row); it is no longer set, and our website deletes any remaining copy. |
We run no advertising technology. Until September 22, 2026 our marketing website loaded a single Reddit advertising pixel for visitors outside the EU/EEA/UK/Switzerland. It has been removed, and nothing on our website or dashboard now sends anything to an advertising network. On our marketing website at atlaso.ai, two things remain:
atl_attr cookie above is set by us only after you press Accept all, and read only by us. If you create an Account while it is present, we store the campaign details against your user id so we can measure how many signups (and later, subscriptions) a campaign produced. We do not share that record with any third party, and it is not used to track you across other websites.Dashboard analytics at app.atlaso.ai. The dashboard sends product-usage events to PostHog (US Cloud) so we can understand the sign-up, setup and upgrade steps: for example, that an Account was created, a setup step was viewed, a tool was connected, the upgrade dialog was opened, or a checkout was started. These events are identified by your internal Atlaso user id, which is pseudonymous, and never by your name or email address. Each event carries only: the event type; the page path, with any ids removed; the tool you connected; your plan and billing interval; the number of tools you have connected; the date (not the time) you signed up; a count of your Memories; which setup step, screen or button the event came from; your cookie-banner answer; and the standard technical details PostHog's software adds (random session and device identifiers, the browser's user-agent string, browser and version, operating system and version, device type and model, screen and window size, language, time zone, and the referring page, reduced the same way as the page path). Events never include the content of your Memories, your searches, your questions, or anything you type. There is no session replay and no automatic click capture on the dashboard: only the events described here are sent, and a filter in the dashboard drops anything else before it leaves your browser. Requests go through our own address, app.atlaso.ai/ingest, which removes your cookies and sign-in credentials before passing them to PostHog.
The dashboard also reads our own atl_attr attribution cookie once, at signup.
Cookieless page counting and page-speed measurement, on both. On our website and our dashboard we also use Vercel Web Analytics and Cloudflare Web Analytics, and on our website Vercel Speed Insights. They count page views and visits and measure how fast pages load. Depending on the tool, each page view sends the page address, the referring page, your browser, operating system and device type, page-load timings, and an approximate location worked out from your request. They set no cookies and store nothing in your browser. Vercel Web Analytics identifies a visitor by a hash created from the incoming request and discards that visitor session after 24 hours; Cloudflare states that its tool does not fingerprint visitors and does not log query strings. Because nothing is read from or stored on your device, these tools run for every visitor, whatever you choose in our cookie banner and whether or not your browser sends Global Privacy Control. Vercel (which hosts our website and dashboard) and Cloudflare are our sub-processors and are listed as such.
Full detail on both, including how to block them, is in our Cookie Policy.
Connectors may capture text that inadvertently contains secrets (API keys, tokens, passwords). Our system assumes this can happen and scrubs detected secrets before storage (on every ingress and on enriched output, using a fail-closed redaction process). This means secret material may be transiently present in transit before it is redacted. Please do not rely on this scrubbing as a guarantee, and do not use Atlaso to store regulated or highly sensitive data (see Section 11 and our Acceptable Use Policy).
We do not knowingly collect special categories of data (e.g., health, biometric, or government-ID data) and ask that you do not store such data in your Memories.
We use Sentry to find and fix errors in the dashboard and our brain/API. Error events can include a stack trace, the page or API route, and technical details about the browser, device, or service. We configure Sentry not to store IP addresses in these events and not to attach your account id, email address, or name. We do not intentionally send Memory content or request bodies in error reports.
Our role. For the Memory and account data of individual Free and Pro users, Atlaso is the data controller: we determine the purposes and means of processing, and this Privacy Policy governs that relationship. The processor/controller framing in our Data Processing Addendum (and its Standard Contractual Clauses) applies only where we process personal data on behalf of a business customer; it does not apply to individual users, whose safeguards are described here.
The legal ground we rely on for a given purpose depends on where you are. We describe the same processing activities below, region by region, because the applicable law differs.
Where the GDPR or UK GDPR applies, we rely on the following lawful bases:
| Purpose | What we do | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Provide the Service | Create and manage your Account; store, sync, retrieve, and inject your Memories; register and manage your Devices | Performance of a contract (Art. 6(1)(b)) |
| Authentication & security | Verify your identity, manage sessions and passkeys, prevent abuse and fraud, enforce rate limits | Performance of a contract; legitimate interests in securing the Service (Art. 6(1)(f)) |
| Billing & subscriptions | Process payments, manage your Pro subscription, calculate taxes | Performance of a contract; compliance with legal/tax obligations (Art. 6(1)(c)) |
| AI features provided as part of the Service | Process selected stored Memory text to generate the dashboard greeting and Ambient Memory summaries on every plan, including Free; on Pro, also provide enrichment, "Ask your memory", and Ambient Memory distillation. An Ask question is sent with recalled Memory when you use Ask. | Performance of a contract (Art. 6(1)(b)); see Sections 6 and 7 |
| Product analytics | Count content-free daily/monthly active usage, and measure website and dashboard usage via Google Analytics and PostHog | Consent (Art. 6(1)(a)) for Google Analytics, for analytics cookies and browser storage, and for session replay on our website, all of which run only after you press Accept all; legitimate interests (Art. 6(1)(f)) for content-free usage counts, cookieless page counting on our website before or without consent, cookieless page counting and page-speed measurement by Vercel and Cloudflare on our website and dashboard, pseudonymous dashboard usage events that store nothing in your browser, and the single subscription-started event sent from our servers |
| Error reporting | Receive technical error reports from the dashboard and brain/API to diagnose and fix faults | Legitimate interests in securing and repairing the Service (Art. 6(1)(f)). You may object at any time by emailing support@atlaso.ai. |
| Campaign measurement | Record in a first-party cookie which campaign you arrived from and, if you sign up, store it against your Account so we can tell which campaigns work | Consent (Art. 6(1)(a)) for setting the cookie, which happens only after you press Accept all; legitimate interests in measuring the effectiveness of our own marketing (Art. 6(1)(f)) for the record kept with your Account |
| Communications | Respond to contact and support requests and email you to confirm we received them; send account, service and billing emails; email you when a plan whose waitlist you joined opens. We send these emails through Resend (Section 8). | Performance of a contract; legitimate interests; for a waitlist, your request (consent, Art. 6(1)(a)), which you can withdraw by replying to any waitlist email |
| Legal compliance | Comply with applicable law and respond to lawful requests | Legal obligation (Art. 6(1)(c)); legitimate interests |
No advertising technology is used in these regions, or anywhere. As of September 22, 2026 we run no advertising or cross-site tracking technology at all, so no data about any visitor reaches an advertising network and no consent-based advertising processing takes place. The campaign-measurement row above covers only our own first-party attribution record.
Analytics storage and your consent. On our website and dashboard, nothing for analytics is stored on or read from your device until you press Accept all in our cookie banner. Before that, and if you choose Necessary only, PostHog stores nothing on the device, Google Analytics does not load, and no session replay is recorded (Section 4). You can withdraw consent at any time, as easily as you gave it, from the cookie button on any page of our website; we then delete the analytics cookies and storage from your browser, and the dashboard does the same the next time one of its pages loads.
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing as described in Section 12. Where we rely on consent (for example, certain optional features), you may withdraw it at any time without affecting prior processing.
For data principals in India, the DPDP Act recognizes consent and a set of enumerated legitimate uses as the grounds for processing; it does not recognize performance-of-contract or legitimate-interests as separate bases. Accordingly, for Indian users we process your personal data on the basis of your consent, obtained through an itemized notice at the point of collection, and on the DPDP-enumerated legitimate uses where they apply (for example, where you have voluntarily provided data for a specified purpose, or to comply with law). You may withdraw your consent at any time (see Sections 12.3 and 12.1), which does not affect processing carried out before withdrawal. See Section 12.3 for our Data Fiduciary duties and grievance-redressal contact.
Where US state privacy laws or the laws of other jurisdictions apply, we process your personal data as permitted under those laws to provide, secure, bill for, and improve the Service, to communicate with you, and to comply with legal obligations, as described above. See Section 12.2 for US state-specific rights.
Atlaso involves AI processing in two ways.
(a) Your own model, at your direction. When you use a Connector, your Content is routed through the AI model you have chosen to use, such as Claude or GPT, as part of how that tool works. That processing is governed by your relationship with that model provider.
(b) Atlaso's model provider, Fireworks AI. Atlaso's AI features run on open models hosted on Fireworks AI's serverless platform, with zero data retention. Fireworks does not log or store the text we send or the results it returns: the text exists only in memory while the request runs and is discarded when it finishes. Where prompt caching is used, some of it may stay in that temporary memory for a few minutes before it is cleared. Fireworks keeps only technical metadata, such as the number of tokens in a request. It does not use this text to train or improve its models, because that requires an explicit opt-in, which Atlaso has not given. Fireworks runs its service on servers in the United States.
Atlaso sends selected stored Memory text to Fireworks for the dashboard greeting and Ambient Memory summaries on every plan, including Free. On Pro, Fireworks also powers nightly Memory enrichment, "Ask your memory", and Ambient Memory distillation for connected tools. One-line Memory headlines and Memory labelling may also use Fireworks if enabled.
The greeting uses selected stored Memory text. Ambient dashboard summaries use short, memory-derived candidates. Enrichment and Ask can use stored captures and related or recalled Memories. When you use Ask, your question is also sent to Fireworks and processed the same way, under the same zero-retention terms. Recognized secrets are removed from Memory when it is captured.
Fireworks describes these terms in its data-handling documentation and its privacy policy. We use chat completions, not Fireworks' stored Responses API, for these features.
The previous Privacy Policy wrongly said Free-plan Memory was never sent to a language model. This corrects the description of a practice already in place; it does not announce a new use of Free-plan Memory.
We do not operate a training endpoint and we do not train Atlaso models on your Memory. On every plan, selected Memory text is sent to Fireworks AI for the features described in Section 6, where it is processed on open models with zero data retention. We use that processing to generate your results, not to train AI models. Fireworks does not use this text to train or improve its models, because that requires an explicit opt-in, which Atlaso has not given.
We believe this is a meaningful difference from some competitors that take broad licenses to train on user content. We do not.
We use the trusted service providers below to operate the Service. Each is bound by data-protection terms appropriate to its role. Our current list:
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Clerk | Authentication, session, and profile | Email, user id, name, passkeys, plan and Stripe-customer-id metadata | USA |
| Stripe | Payment processing and subscription billing | Email, card/payment data, billing address, subscription state | USA |
| Neon | Brain metadata database and transient enrichment queue | Token hashes, device registry, plan, usage counters, OAuth state, and transient raw capture text | USA |
| Fireworks AI | Open-model processing with zero data retention for the dashboard greeting and Ambient Memory summaries on every plan; enrichment, Ask and Ambient distillation on Pro; optional headlines and labelling if enabled | Selected stored Memory text, including captures and recalled Memories, and your Ask question. Recognized secrets are removed from Memory when it is captured. Fireworks does not log or store this text: it exists only in memory while the request runs, prompt caching may keep some of it for a few minutes, and Fireworks keeps only technical metadata such as token counts. | United States (Fireworks servers) |
| OpenRouter, routing to MiniMax M3 | Optional Ask Atlaso product-question assistant on atlaso.ai | A visitor's question and recent conversation turns. Atlaso does not attach account records, dashboard data or stored Memories. Text a visitor types may itself contain personal data. Requests specify zero-data-retention routing and deny provider data collection. | Provider processing location not verified |
| Render | Hosting the brain (all server-side Memory and metadata) | All server-side data at rest | USA |
| Vercel | Hosting the website and dashboard; cookieless page counting (Vercel Web Analytics) on both, and page-speed measurement (Vercel Speed Insights) on the website | Request data and served content. For measurement: the page address, referring page, browser, operating system, device type, approximate location and page-load timings, with nothing stored in your browser. | USA |
| Cloudflare, Inc. | Cookieless page counting and page-speed measurement (Cloudflare Web Analytics) on the website and dashboard | The page address, referring page, browser and device details, and page-load timings, with nothing stored in your browser. Cloudflare does not log query strings. | USA |
| Google LLC (Google Analytics) | Website and product analytics (aggregate usage measurement) | Online identifiers (cookie IDs), device/browser info, pages viewed, approximate (city-level) location, and, for signed-in dashboard users, a pseudonymous user id and plan tier. Loaded on the website and the dashboard only after you press Accept all, and never where GPC is present. | USA |
| PostHog, Inc. | Product analytics for the marketing website and the dashboard; heatmaps and session replay on the marketing website only | Online identifiers (a random visitor id; on the dashboard, your pseudonymous user id), device/browser info, pages viewed, and measured interactions. On the dashboard, only the usage events described in Section 4: never Memory content, searches, questions or anything you type, and no session replay. With your consent (Accept all), on the website only, this may include a session replay of movement through a page, with every input masked and the contact form and Ask Atlaso box excluded entirely. Without it, nothing is stored on the device and no replay is recorded. Never loaded in the browser where GPC is present; one server-side event when a Pro subscription starts (plan and billing interval) is sent regardless. | USA |
| Sentry (Functional Software, Inc.) | Error and crash monitoring for the dashboard and brain/API | Error events, stack traces, page or API routes, and technical browser, device and service details. Atlaso configures Sentry not to store IP addresses in these events and does not attach an account id, email address or name. Memory content and request bodies are not intentionally sent. | United States |
| Resend (Resend, Inc.) | Transactional email delivery: contact-form and waitlist confirmations, waitlist updates, account and billing emails, and delivery of contact-form and waitlist messages to our support inbox | Email address, name, and the message content of the emails we send (a confirmation can quote the message you wrote to us). Waitlist addresses are kept on that plan's contact list until you ask to leave it. | USA |
For the maintained, dated list and a way to subscribe to changes, see our Sub-processors List. We use Google Analytics and PostHog for usage analytics, Vercel and Cloudflare for the page and speed measurements described above, and Sentry for error reporting. Ask Atlaso uses OpenRouter and a routed MiniMax model as described above. Resend delivers the emails we send you: the reply confirming we received your message, waitlist confirmations and updates, and account and billing emails. We do not use any other email vendor.
We have no advertising partner. Earlier versions of this policy disclosed Reddit, Inc. as an advertising partner and independent controller in respect of a pixel on our marketing website. That pixel was removed on September 22, 2026. We now use no advertising vendor of any kind, and no third party receives data from us as an independent controller. The service providers listed above process data to provide their services to us under the arrangements described on our Sub-processors List.
Atlaso is a US company with operations and personnel in India. Our infrastructure and service providers may process personal data in the United States, India, and other locations where they operate. Fireworks states its servers are in the United States. We have not verified the downstream host used for an Ask Atlaso request. The location column in Section 8 distinguishes known locations from those still to be confirmed.
Transfers from the EEA and UK require a valid transfer mechanism where the destination lacks an adequacy decision. We are finalizing the applicable Standard Contractual Clauses, UK Addendum, assessments and related instruments for the relevant transfers. We do not represent that every instrument is already executed. For information about the safeguards applicable to your data, contact support@atlaso.ai.
We retain personal data for as long as needed to provide the Service and for the purposes described in this policy.
atl_attr cookie expires from your browser after 90 days; where a signup was attributed to a campaign, that single row is retained for the life of the Account and deleted with it on a verified deletion request.Deletion and retraction paths:
Erasure and Fireworks. A feature in Section 6 sends text to Fireworks when it runs. Fireworks does not log or store that text: it exists only in memory while the request runs, and prompt caching may keep some of it for a few minutes before it is cleared. Atlaso does not use Fireworks as a store for your Memory, so deleting a Memory removes it from Atlaso's canonical store under the process above. The technical metadata Fireworks keeps, such as token counts, is not affected by deleting a Memory.
Legal-hold and preservation carve-out. Where we are legally required to preserve data, for example to comply with a legal hold, a law-enforcement preservation request, a subpoena or court order, our obligations to report and preserve suspected illegal content (including the preservation duties under 18 U.S.C. §2258A), or to establish, exercise, or defend legal claims, we may suspend deletion of the affected data for as long as the preservation obligation lasts, even if you have asked us to delete it. We delete the data once the obligation ends.
We take reasonable and appropriate technical and organizational measures to protect personal data. These measures, implemented among others, currently include:
sk-, GitHub, AWS, Google, and Slack tokens; JWTs; bearer tokens; credentials embedded in URIs; high-entropy blobs) on every ingress and on enriched output. The redaction process is designed to fail closed: if a check cannot complete, the content is treated as if it contained a secret rather than passed through. As noted in Section 4, secret material may be transiently present in transit before it is redacted, so this is not a guarantee.user_id; per-project visibility is designed to fail closed; cross-user access attempts return a 404.Encryption. Data is encrypted in transit (HTTPS everywhere; Neon connections require SSL). At rest, data is protected by our infrastructure providers' provider-level encryption (Neon, Render). We do not apply application-level field encryption to Memory content, so please do not describe Atlaso as applying its own at-rest encryption to your Memories.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Do not store regulated data (such as health information or payment-card data) in your Memories unless separately contracted with us.
Breach notification. In the event of a personal-data breach, we will assess and notify as required by applicable law, in-product and/or by email where available. In particular:
You have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority in your country of residence or work.
To exercise these rights, contact support@atlaso.ai. We will respond within the timeframes required by law (generally one month under the GDPR).
We provide notice at collection through this policy. California residents have the right to know/access, delete, and correct personal information, and to limit the use of sensitive personal information.
We do not sell your personal information, as that term is defined under the CCPA/CPRA, and we have not done so in the preceding 12 months.
"Sharing" for cross-context behavioral advertising. We do not share personal information for cross-context behavioral advertising. Between August 1, 2026 and September 22, 2026, our marketing website loaded a Reddit advertising pixel for visitors outside the EU/EEA/UK/Switzerland whose browsers were not sending an opt-out signal. Through that pixel Reddit received online identifiers and the fact of a visit, and used them for advertising measurement and to build advertising audiences. We treated that as "sharing" under the CCPA/CPRA and said so plainly. That pixel was removed on September 22, 2026 and no such sharing now takes place. We did not share personal information for that purpose before August 1, 2026 either, and the dashboard at app.atlaso.ai has never carried advertising technology in any region.
How to opt out. We treat the Global Privacy Control (GPC) signal as a valid opt-out request and act on it directly: when your browser sends GPC, our analytics provider PostHog is not loaded at all on our website or dashboard, so your browser stores no identifier, records no session replay and sends no event, and Google Analytics does not load on our website or dashboard. The one exception is the single "subscription started" event our server sends when a Pro subscription starts (plan and billing interval), which does not come from your browser and so is sent regardless of GPC (Section 4). GPC does not switch off the cookieless page counting and page-speed measurement by Vercel and Cloudflare (Section 4), which stores nothing in your browser. You can also choose Necessary only in our website's cookie banner, or opt out by emailing support@atlaso.ai.
We will not discriminate against you for exercising your rights. To make a request, contact support@atlaso.ai.
Other US states. Comprehensive privacy laws in states including Virginia, Colorado, Connecticut, Texas, and Oregon (among others) give residents comparable rights: to access, correct, delete, and obtain a portable copy of their personal data, to opt out of sale/targeted advertising/certain profiling, and, in several states, to appeal a decision on a rights request. Some of these laws apply regardless of a business's size or revenue (for example, Texas and Oregon have no such thresholds). If you are a resident of one of these states, you may exercise your rights by contacting support@atlaso.ai, and we will honor them as required by your state's law. Your browser's Global Privacy Control signal is honored in every region, not only California: where it is present, neither PostHog nor Google Analytics loads in your browser on our website or dashboard.
For data principals in India, Atlaso acts as a Data Fiduciary and processes your personal data on a consent-based model (with the enumerated legitimate uses where they apply), as described in Section 5.2. In that role we take on the Data Fiduciary duties under the Act, including maintaining the accuracy and security of your data, using it only for the notified purpose, and erasing it when the purpose is served or you withdraw consent (subject to Section 10's legal-hold carve-out).
If you are in India, you have the right to access a summary of your personal data and our processing, to correction and erasure, to grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity. Because our processing is based on your consent, you may withdraw that consent at any time by contacting support@atlaso.ai; withdrawal does not affect processing carried out before it.
Children. We require verifiable parental consent before processing the personal data of anyone under 18 (see Section 13), and we do not track, profile, or serve targeted advertising to children.
Grievance redressal. You can raise any privacy grievance with us at support@atlaso.ai, and we will work to resolve it. If your grievance is not resolved, you may complain to the Data Protection Board of India.
To protect your data, we may need to verify your identity before fulfilling a request. We will only use information provided in a request to verify and respond to it.
The Service is not directed to children, and you must meet the minimum age set out in Section 3 of our Terms of Service to use it: at least 13 years old, and where local law requires a higher age or parental involvement (16 in parts of the EU/EEA, and under 18 in India), only with the verifiable consent of a parent or guardian. We do not knowingly collect personal data from children below the applicable age without the required parental consent. If you believe a child has provided us with personal data without that consent, contact support@atlaso.ai and we will delete it.
We use essential authentication cookies (set by Clerk), a functional theme preference stored in your browser's local storage, and Google Analytics 4 cookies for aggregate usage analytics. On our marketing website, we ask first: a cookie banner offers Accept all or Necessary only, and Google Analytics, PostHog's cookies and session replay, and our atl_attr attribution cookie are used only after you press Accept all. We store your answer in our own atl_consent cookie. We load no advertising pixel and no third-party advertising cookies anywhere. The dashboard at app.atlaso.ai follows the same answer: it runs no session replay, loads Google Analytics and lets PostHog store an identifier in your browser only after you press Accept all, loads neither where GPC is present, and reads our own atl_attr cookie once at signup, which is shared across atlaso.ai and app.atlaso.ai. Without Accept all, the dashboard still sends PostHog the pseudonymous usage events described in Section 4, with nothing stored in your browser. On both our website and dashboard, the page counting and page-speed measurement we use from Vercel and Cloudflare sets no cookies and stores nothing in your browser. For the full detail, including how to change your answer or block each of these, see our Cookie Policy.
If Atlaso is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, personal data (including your Memories and account data) may be transferred or disclosed as part of that transaction or diligence, as a business asset. Any acquirer or successor will remain bound by the commitments in this Privacy Policy, or we will require it to honor equivalent protections, and we will notify you (in-product and/or by email where available) of any change in ownership or use of your personal data, and of any choices you may have, as required by applicable law.
We may update this Privacy Policy from time to time. When we make a material correction or change, we update the date above and give appropriate direct notice. The date and substance of a correction do not make earlier processing newly authorized.
Change log
Questions about this policy? Contact us at support@atlaso.ai.