Privacy Policy
What Atlas collects, what becomes public, which companies receive information and why, how long things are kept, and what you can do about any of it. Every provider named here is one Atlas actually uses.
1. The short version
- Atlas collects an email address, whatever you choose to put on your profile, the Projects and files you create, and the records needed to run subscriptions and keep the service safe.
- Some of that is public by design — your profile fields, your published Projects, your comments — and this policy says exactly which.
- Your email address is never published and Atlas does not sell or rent personal information to anyone.
- Files you upload for publication are sent to a third-party malware scanner before they can be published. §9 is about that in detail.
- Atlas runs no advertising and no third-party marketing pixels. Optional analytics through PostHog runs only if you accept it — nothing is collected before you answer, and declining changes nothing about what you can use. §12 is about that in detail.
- You can export your data or delete your account yourself, from your Account page.
2. Account and sign-in
Atlas uses Supabase for authentication. Atlas itself implements no password logic: it does not hash, store or ever see your password.
- Email address
- Used to identify your account, to send confirmation and password-reset messages, and to reach you about your account or subscription. Held privately; not shown on your profile or anywhere public.
- Password
- Handled by Supabase Auth. Atlas has no access to it in any form.
- Google sign-in
- If you continue with Google, Google tells Supabase your email address and basic account identifiers so an Atlas account can be created or matched. Atlas receives no access to your Google account beyond that, and stores the same email address it would have stored either way.
- Session
- Your signed-in session is issued by Supabase and kept in your browser (see §11). The Atlas server checks it with Supabase on requests that matter and holds the verified result briefly in memory, keyed by a hash of the token rather than by the token itself.
- Account identifier
- Every account has an internal identifier that Atlas uses to join your worlds, Projects, subscription and social activity together. It is not shown to you or to anybody else.
3. Your profile
Your profile is public. Once you claim a username, the fields you have filled in are visible to anyone who opens your profile page, and to visitors browsing Community.
Public if you provide them:
- username and display name;
- profile picture;
- headline and bio;
- role or field, school, and location;
- LinkedIn and personal website links;
- tools and skills;
- the theme and colours you choose for your page;
- your published Projects, and your public Project, Like and follower counts.
Not public: your email address, your password, your billing details, your private Drafts, and anything you have not filled in. Every field is optional, and the Page Editor says so where you edit it.
If you change your username, Atlas keeps a record of the previous one so that links people already have keep working. Previous handles are part of your public identity in the same way the current one is.
4. Projects, files and links
Atlas stores what you upload and the details you give a Project — its title, description, tool tag and cover image. What happens next depends on the kind of Project, and the differences are the point:
- A Publisher source workbook
- Stored in a private bucket, readable only by the Atlas server and the conversion worker. It is never published, never served to a visitor and never offered as a download.
- A Publisher published artifact
- The web dashboard built from that workbook. Private while the Project is a Draft; served publicly once you publish.
- A direct file — Excel, PDF or image
- The file itself becomes downloadable when you publish the Project. Atlas does not remove hidden sheets, formulas, macros, comments or document metadata, and does not inspect the file for personal or confidential information. Whatever is inside it is published with it.
- An external link
- Atlas stores the URL you typed and shows it on the Project page. Atlas never fetches it — there is no crawler, no preview generation and no server-side request to the destination.
- Covers and profile pictures
- Stored privately and served through Atlas. A cover is shown publicly once its Project is published; a profile picture is shown on your public profile and beside your comments.
A private Draft stays private. Publishing is a separate, deliberate action, and putting a Project into Community Creations is a second one again — see §7.
5. World generation
When you generate a world, Atlas records that the generation happened and what was asked for — the world format, store scale, demand level, location count, history length and variation seed — together with the job's status, which plan it was charged against, and which billing period it belongs to. That record is what makes a world yours: it is how Atlas knows whose job a download belongs to and how much of an allowance is left.
The configuration is sent to the Atlas generation service, which builds the world. Generated worlds are synthetic and contain no real personal data. Atlas does not read, analyse or profile you from the configurations you choose.
You alone can see and download your generations. A request for a job that is not yours is refused, and is refused in a way that does not reveal whether it exists.
6. Billing
Stripe is Atlas's payment processor. Card details are entered on pages Stripe hosts. Atlas never receives, sees or stores a card number, expiry date or security code, and this site loads no Stripe JavaScript and contains no card form.
Atlas stores, for each subscriber:
- the Stripe customer and subscription identifiers that link your Atlas account to its billing record — held server-side and never sent to your browser;
- your plan, subscription status, current billing period, and whether it is set to cancel at the end of that period;
- identifiers of the Stripe events already processed, so a repeated notification is not applied twice.
Your email address is passed to Stripe so receipts can reach you. Stripe handles that information under its own privacy policy and keeps its own payment records, including after an Atlas account is closed — see §14.
7. Community and social activity
Public: your comments, shown with your username and picture on the Project they were posted to; the Like and comment counts on a Project; and the follower and following counts on a profile. A Project you opt into Community appears as a card in Community Creations and may be selected for a Featured shelf.
Not public: which Projects you personally have liked and who exactly follows whom. Atlas publishes counts, not lists — there is no follower list and no "liked by" list anywhere on the site. Your own Like state is shown to you on your own screen so a button can look right.
Community discovery is opt-in per Project and can be withdrawn. Unticking it removes the Project from Community and from any Featured shelf; unpublishing removes it from the public web entirely.
8. Reports and moderation
When you report a Project or a comment, Atlas records what you reported, the reason you chose, any note you wrote, and that it was you who reported it. Reporter identity is stored so that abuse of the report mechanism can be seen.
Reports are never public. No page shows them, no count of them appears anywhere, and the person reported is not told who reported them. They are readable only by Atlas.
Atlas also keeps a record of the moderation actions it takes — what was done, to what, when and why. That record is operational and is not published. If a Project of yours is subject to a safety hold, its edit screen tells you the level of the hold; an operator's internal note is not shown.
9. Malware scanning
Atlas serves files that strangers uploaded, so those files are scanned for known malware before they can be published. This section is separate from the service-provider list below because it involves your file leaving Atlas.
The scanning provider is Cloudmersive. When you upload a file that Atlas will make available to other people, that file is transmitted over an encrypted connection to Cloudmersive's virus-scanning API, and Cloudmersive returns a verdict. Atlas uses the verdict to decide whether the file may be published, and stores the verdict — not the file — alongside the Project.
What is scanned:
- direct Excel workbooks (
.xlsx,.xlsm); - PDF Projects;
- image Projects;
- Project cover images;
- profile pictures.
What is not scanned, and why:
- Publisher source workbooks — they are never served to anyone, so they are not sent to any scanner. Your private workbook does not leave Atlas's infrastructure for scanning.
- Publisher-generated artifacts — Atlas builds them, so they are not uploaded content.
- External links — Atlas holds no bytes for them.
Atlas fails closed: if a scan cannot establish that a new upload is clean — because it was refused, timed out, or came back uncertain — the Project stays a private Draft and cannot be published. You can ask Atlas to run the check again from the Project's edit screen.
A clean scan is not a guarantee of safety. It means a scanner recognised nothing in those exact bytes. It says nothing about whether a macro is trustworthy, whether a document is accurate, or whether a file is appropriate to open. Atlas does not certify files and does not describe any file as safe.
Only the file's bytes are sent. No Atlas account identifier, no Project identifier, no email address and no other information about you accompanies it. Cloudmersive states that its scanning API is stateless and retains no payload after the transaction; that is the provider's representation, Atlas cannot verify it independently, and it is repeated here as a representation rather than as an Atlas guarantee.
10. Service providers
These are the companies that receive information in order for Atlas to work. Each is listed because it is actually in use today. Atlas does not sell or rent personal information, and does not share it for advertising.
- Supabase
- Authentication, database and file storage. Receives your email address, your password (which Atlas never sees), your profile, your Projects and their metadata, your uploaded files, and your social and usage records. Supabase is where nearly all Atlas data lives.
- Render
- Hosts the Atlas web service and the workbook conversion worker. Handles the traffic between your browser and Atlas, and operates its own platform-level infrastructure logs, which are outside Atlas's control.
- Cloudflare
- Sits in front of the site as its network edge, so requests to atlasworldbuilder.com pass through it, including your IP address.
- Stripe
- Payment processing, subscription management and the billing portal. Receives your email address and, directly from you on its own pages, your payment details. See §6.
- Cloudmersive
- Malware scanning of files that will be published. Receives the file's bytes and nothing else. See §9.
- Resend
- Delivers Atlas's account emails — confirmation and password reset — on Supabase's behalf. Receives the recipient address and the message.
- PostHog
- Optional product analytics and session replay, and the only provider on this list that is off by default: your browser never connects to it unless you accept analytics. Data is processed in PostHog's United States region; PostHog is a processor acting for Atlas. If you accept and are signed in, it receives the pseudonymous internal identifier of your Atlas account — never your email address. See §12.
- Two separate roles. Google sign-in, if you choose it, identifies you to Supabase (§2). Google Workspace hosts the Atlas mailbox, so if you email us, your message is stored there.
- jsDelivr and cdnjs
- Public content-delivery networks from which your browser loads two shared libraries. Loading a file from a CDN means that CDN sees your IP address and browser details, as it would for any site using one. Neither receives any Atlas account information.
Atlas may also disclose information where the law requires it, or where it is necessary to investigate a security incident or a violation of the Terms.
11. Cookies and browser storage
Atlas sets no advertising or tracking cookies. There is one cookie and a small amount of browser storage, in two clearly different kinds: essential storage that makes the site work, and two optional analytics entries that exist only if you accept analytics.
Essential storage
- Draft preview cookie
- Set only when you open a preview of your own private Draft. It is signed, scoped to that one Project's path, expires within minutes, and cannot be read by JavaScript. It is not set anywhere else on the site.
- Your session (local storage)
- Supabase keeps your signed-in session in your browser's local storage so that you stay signed in across pages and reloads. Signing out removes it.
- Device identifier (local storage)
- A random value your browser generates, stored locally and sent to Atlas only on the request that creates a world. It is used to detect one browser creating many accounts to claim many free worlds. Atlas never stores it as sent — see §13.
- Active generation (session storage)
- The identifier of a generation in progress, so that refreshing the page resumes watching it instead of starting a second one. It lasts for the browser tab's session and no longer.
- Your analytics choice (local storage)
-
One entry,
atlas.analytics-consent, holding the single wordgrantedordenied— your answer to the analytics question, so that Atlas does not ask again on every page. It is written whichever way you answer, it is never sent to Atlas's servers, and clearing your browser's site data removes it and returns you to being asked.
Optional analytics storage — only if you accept
- Analytics storage (local storage) — only if you accept
- If, and only if, you accept analytics, PostHog stores random device and session identifiers in your browser's local storage. Nothing is written before you accept. PostHog is configured to use local storage only, so it sets no cookie of any kind. See §12.
- How you found Atlas (local storage) — only if you accept
-
One entry,
atlas.attribution, written only after you accept analytics and never before. It records how you arrived: the campaign tags in the link you clicked (utm_source,utm_medium,utm_campaign,utm_content,utm_term), a creator or referral code if the link carried one (ref), the domain name of the site you came from, and the page you landed on. It is used to understand which sources bring people to Atlas.
If you sign in after accepting, Atlas keeps a copy of it against your account. Your browser marks the entry as belonging to your account and sends those same values — and nothing else, not your email and no address — to Atlas's own servers once, so that the record of how you arrived is not lost when you switch devices or clear your browser. It is sent to Atlas and to nobody else: it is not sent to PostHog, not as an event and not as a property attached to the account identifier §12 describes. Atlas keeps that copy while your account exists, uses it to understand which sources bring people who stay, and never uses it to decide what you are shown or what you pay.
What it never contains: the full address of any page, any other part of a query string, anything from a sign-in or password-reset link, your email, or anything about your Projects or worlds. Only the specific values listed above are read; everything else in a link is ignored rather than stored and filtered later.
How it changes: the first qualifying arrival is kept permanently as your first source and is never overwritten — not by a later campaign, and not by anything a page can send; a later qualifying arrival updates a separate "most recent source" value. Ordinary browsing between Atlas pages, and returning directly, change neither. Signing out deletes the entry outright, so it can never be attached to the next person who signs in on the same browser. The copy kept against your account is not deleted by signing out — it belongs to the account rather than to the sign-in — and it is removed when your account is closed (§16).
If you withdraw analytics consent, both copies go. The browser entry is deleted immediately, and Atlas deletes the copy held against your account as well. Doing that needs you to be signed in at the time, because it is the only way Atlas knows whose record to delete: if you withdraw while signed out, the browser entry still goes immediately, and the account copy is removed when you close your account or ask for it under §15. Clearing your browser's site data removes the browser entry too.
The essential entries do not wait on your permission, because none of them is used for tracking, advertising or measurement — they are what makes the site work. The optional analytics entries are different, and Atlas asks first. You are shown one banner, on your first visit, and analytics does not run — and neither optional entry is written — unless you accept it. §12 describes exactly what it collects, and you can change or withdraw your answer at any time from the control in the footer of any page.
12. Analytics and advertising
Atlas runs no advertising. There is no advertising pixel and no third-party marketing tag on any page, and nothing follows you to another site.
Atlas uses one analytics provider, PostHog, and only if you accept it. On your first visit you are asked. Until you accept, no analytics or session-replay data is collected and nothing is sent to PostHog at all. If you decline, nothing is sent and every part of Atlas continues to work exactly as it otherwise would — nothing on this site is withheld from people who say no.
Who processes it, and where
PostHog is the analytics provider. Data is processed in PostHog's United States region. PostHog is a processor acting for Atlas and is listed in §10 alongside the other service providers.
What is collected if you accept
- Product and web analytics
- Page views and page exits, so Atlas can see which pages are used and which are abandoned; and automatically captured interactions — that a button or link was clicked and which one, never what you typed into a field. The project also records aggregate interaction heatmaps and standard page-performance measurements.
- Session replay
-
A reconstruction of a visit — the pages, the layout as it rendered,
and where the pointer and scroll went — so that a confusing or broken
flow can be understood rather than guessed at. It is a rebuild from
recorded page structure, not a video or a screen recording.
Every form input is masked: passwords, email
addresses, search boxes and every other field are transmitted as
blanked-out placeholders, and their contents never leave your browser.
A small number of places where an account's email address appears as
ordinary page text — the account chip in the header, the account page,
the sign-in and password-reset confirmations — are individually masked
for the same reason.
A recording carries page addresses only in their cleaned
form. The recorder notes the address of each page it
records, and the addresses of the links and resources on it; every
one of those is cleaned the same way as the addresses described
below — fragment removed, secret-carrying parameters replaced with
[redacted]— before it is written into the recording. - Browser and device information
- Browser name and version, operating system, device type, screen and window size, language and time zone. Enough to tell a phone from a desktop and to reproduce a layout problem; not enough to identify you.
- Addresses of the pages you visit
-
The address of each Atlas page you visit, and the domain
name of the site that referred you, if any.
The address of the page that referred you is never
sent. The analytics library would ordinarily transmit it in
full, and a referring page's path and query can carry another
site's private material — a search, a document title, an internal
reference — so Atlas removes every referring-address field, and any
search keyword the library lifts out of one, before the request
leaves your browser. PostHog receives the referring site's domain
name and nothing more of it: the same limit §11 applies to Atlas's
own record of how you arrived.
Atlas page addresses are cleaned before they are sent. The fragment — everything after a#— is removed from every address, always, because that is where sign-in and password-reset links carry their tokens. Query parameters that can carry a secret or an identifier — includingcode,token,token_hash,access_token,session_idandemail— have their values replaced with[redacted]before the address is transmitted, whether the address travels with an event, with one of the library's own background requests, or inside a session replay recording. The same cleaning is applied to the address of a link you click, and to an address carried inside another address — the sign-in link on every page names the page to return to, query and all, and that inner address is cleaned too. Ordinary parameters, such as campaign tags, are kept.
Your IP address
Atlas's own application log does not record visitor IP addresses (§13), and that remains true. PostHog is a different matter, and it would be wrong to imply otherwise. If you accept analytics, your browser connects directly to PostHog, so PostHog receives your IP address as an unavoidable part of that connection and derives an approximate location — country and region — from it. The same is true of every service provider your browser or Atlas's servers connect to, including the site's host and network edge, which see the address of every request whether or not you accept analytics.
Whether it is tied to you
If you accept analytics and you are signed in, it is — by an
account number, never by your email address. Atlas gives
PostHog the internal identifier of your Atlas account: a random-looking
code such as
3f8c1d92-7b4e-4a1f-9c05-2e6d84b7a013. It is meaningless
outside Atlas's own systems, and it is the only thing about
your account that is sent.
Atlas never sends your email address, your name, your username, your profile link, your plan, or anything about your Projects or worlds as your analytics identity. Not as the identifier, and not alongside it.
It happens only after you accept. If you have not answered the analytics question, or you declined, nothing is sent at all — signed in or not — because PostHog is never started. If you are signed in and then accept, the link is made at that point. If you accept and are not signed in, your activity stays under a random browser identifier until you sign in.
Why: so Atlas can answer questions about the product that are otherwise unanswerable — how many people who sign up go on to generate their first world, where people get stuck, which sources bring people who stay, how often generation fails, and whether a change made things better. It is used to improve Atlas. It is not used for advertising, it is not sold, and it is not shared with anyone beyond the providers in §10.
Signing out breaks the link. When you sign out, Atlas tells PostHog to forget the connection and start over, and the "how you found Atlas" entry in §11 is deleted from your browser. If someone else signs in on the same browser afterwards, their activity is recorded against their own account and never merged with yours — and the record of how you arrived stays with your account, never theirs.
Session replay is unchanged by this. Everything you type is still masked, private Draft content is still excluded from recordings, the account email shown in the header is still masked, and sign-in links and tokens are still stripped from every address before it is sent. Being identified does not make a recording show more.
Cookies and storage
Analytics sets no cookies. PostHog is configured to use local storage only. Your answer to the analytics question, and — if you accept — PostHog's random device and session identifiers plus the "how you found Atlas" entry, are the whole of it. All three are itemised in §11.
Changing or withdrawing your answer
You can change your mind at any time, in either direction, from the control in the footer of any page — it is also the control that reopens this choice if you dismissed it. Withdrawing takes effect immediately: collection and session replay stop, the "how you found Atlas" entry in §11 is deleted from your browser, the page reloads so that nothing already running can continue, and nothing further is sent. Withdrawal stops future collection and clears that local entry; it does not delete what PostHog already collected while you had accepted. To have that removed as well, ask — see §15.
How long it is kept
Session replay recordings are retained for up to 30 days and are then deleted by PostHog. Atlas is on PostHog's Free plan, whose replay retention is 30 days; Atlas does not extend it.
Analytics events are kept for as long as the Atlas PostHog project is configured to keep them. That period is set inside PostHog rather than by Atlas, and this page does not state a figure for it, because Atlas has not confirmed one. Naming a period nobody has checked would be worse than saying so. Deletion of analytics data on request is covered in §15.
If you delete your Atlas account
Deleting your Atlas account does not automatically delete analytics data already held by PostHog, and this page will not pretend otherwise. Deletion removes your Atlas account and the records listed in §16 — including the "how you found Atlas" record kept against your account — and your browser's own copy of that entry goes with the sign-out that follows. Analytics events and recordings already collected against your account number remain in PostHog until they expire under the retention described above.
Atlas has not yet automated their removal. Ask, and they will be deleted — see §15. Building that into account deletion is planned, and this paragraph changes when it exists.
If Atlas adds or changes an analytics provider, this section will name the provider and describe what it collects before it is switched on.
13. Logs, abuse signals and security
Server logs
Atlas's own application log records what happened — which endpoint was called, what it decided, and errors — and is deliberately narrow about who. It does not record visitor IP addresses. Render and Cloudflare keep their own infrastructure logs as any host does, and those are outside Atlas's control.
Free-tier abuse signals
To stop one person creating many accounts for many free worlds, Atlas records two signals when a free world is claimed: a value derived from your browser's device identifier, and a value derived from the network address the request arrived from. Both are stored only as keyed one-way digests — no raw address and no raw device identifier is stored anywhere, and neither appears in any response Atlas gives. These records are readable by nobody through the site, and they are deleted with the account.
Rate limiting
Atlas limits how often an account can post, follow, upload, publish or report. The counters are keyed by an opaque digest rather than by your account, so they are not a record of who was throttled.
How things are protected
- Traffic to Atlas is encrypted in transit.
- Private and public files live in separate storage, and private buckets are reachable only by the Atlas server.
- Database access rules mean an account can read only its own rows; what a browser can read is a narrow, named set of columns.
- Every request that changes something is checked against a session verified with Supabase, and the account acted on is always the one the session resolves to — never one supplied in the request.
- Files that will be published are scanned for malware (§9).
- Payment details never reach Atlas at all.
No service is perfectly secure, and Atlas does not claim to be. Atlas holds no security certification and makes no compliance claim under HIPAA, PCI DSS, SOC 2, ISO 27001 or any similar regime. To report a security problem, write to support@atlasworldbuilder.com.
14. How long things are kept
Atlas keeps information for as long as your account exists, and then deletes it as described in §16. Rather than quote retention periods Atlas has no mechanism to enforce, this section says what actually governs each kind of record:
- Account, profile, Projects, files
- Kept until you delete them or close your account.
- Comments, Likes, follows
- Kept until you remove them or close your account.
- Generation and usage records
- Kept while the account exists; removed when it is closed.
- How you found Atlas
- Kept while the account exists, and removed when it is closed or when you withdraw analytics consent while signed in (§11). The first source is never overwritten while it is kept.
- Malware scan verdicts
- Stored with the Project they belong to and removed with it. The file itself is not retained by Atlas for scanning purposes.
- Reports and moderation records
- Reports you filed are removed when your account is closed. Atlas's record of moderation actions it took is retained as an operational and legal record, and does not name a reporter.
- Rate-limit counters
- Opaque, short-lived, and refill continuously.
- Billing records
- Stripe retains payment and invoice records under its own obligations, including after an Atlas account is closed. Atlas does not control that retention.
- Backups
- Routine backups taken by Atlas's hosting providers expire on their own schedule, so deleted content can persist in a backup for a limited period after it is gone from the live service.
Awaiting review. Atlas has not yet set fixed retention periods for logs, backups and operational records. Where a specific schedule is required, it will be set with legal advice and published here rather than estimated now.
15. Your rights and controls
Most of what a privacy request would ask for is something you can do yourself, immediately:
- See what Atlas holds
- Your profile, Projects and social activity are visible to you in the product. Request my data on your Account page downloads a JSON file containing your account details, your profile, your Projects and their metadata, your comments, the Projects you liked, your follow relationships, your subscription state and your generation history.
- Correct it
- Edit any profile field in the Page Editor; edit a Project's title, description and tool tag from its edit screen.
- Control what is public
- Clear a profile field to remove it; unpublish a Project to withdraw its public page; untick Community to remove it from discovery; delete your own comments.
- Delete
- Delete an individual Project permanently from its edit screen, or close your whole account from the Account page (§16).
Depending on where you live you may also have rights to access, correction, deletion, portability, restriction or objection, and the right to complain to a data-protection authority. To make a formal request, write to hello@atlasworldbuilder.com from the address on your account. Atlas may need to confirm that the request is really yours before acting on it.
Awaiting legal review. Which privacy regimes apply to Atlas, and the exact rights and response deadlines that follow from them, have not been determined. Atlas offers the controls above to everyone regardless.
16. Deleting your account
Delete account lives on your Account page. It asks you to type the email address on the account, and it cannot be undone. Here is exactly what happens, in order:
- Your subscription is cancelled first. If Atlas cannot cancel it, nothing is deleted and you are told — so an account can never disappear while a subscription keeps renewing.
- Every Project is unpublished, so public pages stop answering and Community and Featured entries disappear.
- The files Atlas hosts for those Projects are deleted: published artifacts, private drafts, covers and Publisher source workbooks.
- Every profile picture you ever uploaded is deleted.
- Your profile is deleted, and with it your username and username history.
- Your comments, Likes and follows are deleted. Comment counts on other people's Projects fall accordingly.
- Your generation records, abuse signals, subscription mirror, Stripe customer mapping and the record of how you found Atlas are deleted.
- Reports you filed are deleted. Reports other people filed about your content are deleted with the content.
- Your Atlas sign-in identity is deleted last.
What does not go: Stripe's own payment and invoice records, which it keeps under its own obligations; Atlas's record of any moderation actions taken, which does not identify a reporter; backups, which expire on their own schedule; anything another person had already downloaded, which was never Atlas's to recall; and — if you accepted analytics — the analytics events and session recordings already held by PostHog against your account number, which are not deleted automatically and are removed on request (§12, §15).
If a step fails partway, nothing is left in an unsafe state: your work stops being public before anything is deleted, and running the deletion again continues from where it stopped.
17. International users
Atlas is available internationally, and the providers listed in §10 operate infrastructure in several countries. Using Atlas means your information may be processed in a country other than your own, including the United States.
Awaiting legal review. The lawful basis for international transfers, and the safeguards required for them, have not been determined for Atlas.
18. Children
Atlas is for people aged 18 and over. Atlas does not knowingly collect information from anyone under 18. If you believe a child has created an account, write to hello@atlasworldbuilder.com and it will be removed.
19. Changes
This policy may change. The effective date and version at the top of the page change with it, and a material change will be announced before it takes effect.
20. Contacting us
Privacy questions and formal privacy requests: hello@atlasworldbuilder.com. Account, billing and security reports: support@atlasworldbuilder.com. The full list of Atlas addresses is on the Contact page.