Atlas Privacy Policy — Draft
Scope
This draft covers the planned Atlas website, applications, devices, AI features and connected services. Features may run locally or require cloud services. Actual collection depends on the version, permissions and integrations enabled. The operator’s registered identity and contact details have not been supplied for Atlas. Nanolite app operator details are not automatically Atlas operator details.
Accounts and user content
Where implemented, Atlas may process account identifiers, profile details, subscription status, support history, prompts, conversations, files, images, notes and instructions. Third-party sign-in may provide permitted identity details. The supplied draft states that plaintext passwords are not intentionally stored; this must be verified against production authentication.
Voice, screen and computer access
Enabled voice features may process microphone audio locally or through speech providers. Authorised computer tasks may require selected file contents, screen images, application state or clipboard information. Access should be limited to the requested task and platform permissions. This draft does not authorise unattended access to all files or continuous recording.
Cameras, devices and location
If enabled and authorised, camera features may process images or video, device integrations may process sensor states and commands, and location features may process approximate or precise location. Camera access should not imply continuous monitoring unless the user expressly enables such functionality. Biometric identification requires its own disclosures and legal assessment before introduction.
Connected services
Authorised connections may expose contacts, calendar events, email contents and attachments, social-media information, business records, financial information or voluntarily supplied health/wellness information. Permissions must identify the actual data access. Unavailable integrations should not be represented as collecting these categories.
Memory
If persistent memory is implemented, it may retain selected preferences, instructions, projects and previous context. The release must explain what is stored, where, and how users can view, correct, disable and delete it. Memory should not be the only record of critical information.
Technical and website data
Device, browser, IP address, diagnostics, security events and usage information may be processed by enabled services. Cookies, analytics and marketing technologies must be listed according to the deployed website, with required consent or opt-out controls. Their existence is not verified by this draft.
Purposes and AI processing
Information supports requested tasks, authentication, synchronisation, personalisation, support, subscriptions, reliability and security. Cloud AI requests may transmit relevant content to the selected provider. Production providers, processing countries and their data-use terms must be disclosed. Local-only processing should not be claimed for a cloud task.
Training and disclosure
The owner-supplied draft proposes no training of general-purpose public AI models on private user content without appropriate disclosure and consent. This commitment must match provider contracts and actual settings. Necessary service providers, user-authorised recipients and legally required disclosures may receive information. Proposed no-sale commitments must be checked against any advertising or sharing arrangement.
Retention and rights
Retention must be limited to a documented purpose, including lawful billing, security or dispute requirements. Production periods and backup expiry remain unconfirmed. Applicable rights may include access, correction, deletion, portability, withdrawal, objection or appeal. US state, European and UK rights apply only when the relevant laws cover the operator and processing.
Deletion and international processing
Account deletion must have an actual in-app and web request route before launch. Disconnecting Atlas does not delete data held by an independent provider. Local files may require separate device cleanup. Cross-border processing must be assessed using the actual countries and required safeguards.
Children and sensitive data
The age threshold and any family features must be decided before launch. Unnecessary sensitive data should not be requested. Health, financial, communications, surveillance and biometric features require feature-specific assessment. No compliance certification is implied.
Security and changes
Appropriate technical and organisational safeguards must be verified in production. No absolute security guarantee is made. Material changes require suitable notice and consent where applicable. A confirmed Atlas privacy contact must be added before this draft becomes effective.