Legal

Privacy Policy

What Atlas collects, what becomes public, which companies receive information and why, how long things are kept, and what you can do about any of it. Every provider named here is one Atlas actually uses.

1. The short version

2. Account and sign-in

Atlas uses Supabase for authentication. Atlas itself implements no password logic: it does not hash, store or ever see your password.

3. Your profile

Your profile is public. Once you claim a username, the fields you have filled in are visible to anyone who opens your profile page, and to visitors browsing Community.

Public if you provide them:

Not public: your email address, your password, your billing details, your private Drafts, and anything you have not filled in. Every field is optional, and the Page Editor says so where you edit it.

If you change your username, Atlas keeps a record of the previous one so that links people already have keep working. Previous handles are part of your public identity in the same way the current one is.

4. Projects, files and links

Atlas stores what you upload and the details you give a Project — its title, description, tool tag and cover image. What happens next depends on the kind of Project, and the differences are the point:

A private Draft stays private. Publishing is a separate, deliberate action, and putting a Project into Community Creations is a second one again — see §7.

5. World generation

When you generate a world, Atlas records that the generation happened and what was asked for — the world format, store scale, demand level, location count, history length and variation seed — together with the job's status, which plan it was charged against, and which billing period it belongs to. That record is what makes a world yours: it is how Atlas knows whose job a download belongs to and how much of an allowance is left.

The configuration is sent to the Atlas generation service, which builds the world. Generated worlds are synthetic and contain no real personal data. Atlas does not read, analyse or profile you from the configurations you choose.

You alone can see and download your generations. A request for a job that is not yours is refused, and is refused in a way that does not reveal whether it exists.

6. Billing

Stripe is Atlas's payment processor. Card details are entered on pages Stripe hosts. Atlas never receives, sees or stores a card number, expiry date or security code, and this site loads no Stripe JavaScript and contains no card form.

Atlas stores, for each subscriber:

Your email address is passed to Stripe so receipts can reach you. Stripe handles that information under its own privacy policy and keeps its own payment records, including after an Atlas account is closed — see §14.

7. Community and social activity

Public: your comments, shown with your username and picture on the Project they were posted to; the Like and comment counts on a Project; and the follower and following counts on a profile. A Project you opt into Community appears as a card in Community Creations and may be selected for a Featured shelf.

Not public: which Projects you personally have liked and who exactly follows whom. Atlas publishes counts, not lists — there is no follower list and no "liked by" list anywhere on the site. Your own Like state is shown to you on your own screen so a button can look right.

Community discovery is opt-in per Project and can be withdrawn. Unticking it removes the Project from Community and from any Featured shelf; unpublishing removes it from the public web entirely.

8. Reports and moderation

When you report a Project or a comment, Atlas records what you reported, the reason you chose, any note you wrote, and that it was you who reported it. Reporter identity is stored so that abuse of the report mechanism can be seen.

Reports are never public. No page shows them, no count of them appears anywhere, and the person reported is not told who reported them. They are readable only by Atlas.

Atlas also keeps a record of the moderation actions it takes — what was done, to what, when and why. That record is operational and is not published. If a Project of yours is subject to a safety hold, its edit screen tells you the level of the hold; an operator's internal note is not shown.

9. Malware scanning

Atlas serves files that strangers uploaded, so those files are scanned for known malware before they can be published. This section is separate from the service-provider list below because it involves your file leaving Atlas.

The scanning provider is Cloudmersive. When you upload a file that Atlas will make available to other people, that file is transmitted over an encrypted connection to Cloudmersive's virus-scanning API, and Cloudmersive returns a verdict. Atlas uses the verdict to decide whether the file may be published, and stores the verdict — not the file — alongside the Project.

What is scanned:

What is not scanned, and why:

Atlas fails closed: if a scan cannot establish that a new upload is clean — because it was refused, timed out, or came back uncertain — the Project stays a private Draft and cannot be published. You can ask Atlas to run the check again from the Project's edit screen.

A clean scan is not a guarantee of safety. It means a scanner recognised nothing in those exact bytes. It says nothing about whether a macro is trustworthy, whether a document is accurate, or whether a file is appropriate to open. Atlas does not certify files and does not describe any file as safe.

Only the file's bytes are sent. No Atlas account identifier, no Project identifier, no email address and no other information about you accompanies it. Cloudmersive states that its scanning API is stateless and retains no payload after the transaction; that is the provider's representation, Atlas cannot verify it independently, and it is repeated here as a representation rather than as an Atlas guarantee.

10. Service providers

These are the companies that receive information in order for Atlas to work. Each is listed because it is actually in use today. Atlas does not sell or rent personal information, and does not share it for advertising.

Atlas may also disclose information where the law requires it, or where it is necessary to investigate a security incident or a violation of the Terms.

11. Cookies and browser storage

Atlas sets no advertising or tracking cookies. There is one cookie and a small amount of browser storage, in two clearly different kinds: essential storage that makes the site work, and two optional analytics entries that exist only if you accept analytics.

The essential entries do not wait on your permission, because none of them is used for tracking, advertising or measurement — they are what makes the site work. The optional analytics entries are different, and Atlas asks first. You are shown one banner, on your first visit, and analytics does not run — and neither optional entry is written — unless you accept it. §12 describes exactly what it collects, and you can change or withdraw your answer at any time from the control in the footer of any page.

12. Analytics and advertising

Atlas runs no advertising. There is no advertising pixel and no third-party marketing tag on any page, and nothing follows you to another site.

Atlas uses one analytics provider, PostHog, and only if you accept it. On your first visit you are asked. Until you accept, no analytics or session-replay data is collected and nothing is sent to PostHog at all. If you decline, nothing is sent and every part of Atlas continues to work exactly as it otherwise would — nothing on this site is withheld from people who say no.

PostHog is the analytics provider. Data is processed in PostHog's United States region. PostHog is a processor acting for Atlas and is listed in §10 alongside the other service providers.

Atlas's own application log does not record visitor IP addresses (§13), and that remains true. PostHog is a different matter, and it would be wrong to imply otherwise. If you accept analytics, your browser connects directly to PostHog, so PostHog receives your IP address as an unavoidable part of that connection and derives an approximate location — country and region — from it. The same is true of every service provider your browser or Atlas's servers connect to, including the site's host and network edge, which see the address of every request whether or not you accept analytics.

If you accept analytics and you are signed in, it is — by an account number, never by your email address. Atlas gives PostHog the internal identifier of your Atlas account: a random-looking code such as 3f8c1d92-7b4e-4a1f-9c05-2e6d84b7a013. It is meaningless outside Atlas's own systems, and it is the only thing about your account that is sent.

Atlas never sends your email address, your name, your username, your profile link, your plan, or anything about your Projects or worlds as your analytics identity. Not as the identifier, and not alongside it.

It happens only after you accept. If you have not answered the analytics question, or you declined, nothing is sent at all — signed in or not — because PostHog is never started. If you are signed in and then accept, the link is made at that point. If you accept and are not signed in, your activity stays under a random browser identifier until you sign in.

Why: so Atlas can answer questions about the product that are otherwise unanswerable — how many people who sign up go on to generate their first world, where people get stuck, which sources bring people who stay, how often generation fails, and whether a change made things better. It is used to improve Atlas. It is not used for advertising, it is not sold, and it is not shared with anyone beyond the providers in §10.

Signing out breaks the link. When you sign out, Atlas tells PostHog to forget the connection and start over, and the "how you found Atlas" entry in §11 is deleted from your browser. If someone else signs in on the same browser afterwards, their activity is recorded against their own account and never merged with yours — and the record of how you arrived stays with your account, never theirs.

Session replay is unchanged by this. Everything you type is still masked, private Draft content is still excluded from recordings, the account email shown in the header is still masked, and sign-in links and tokens are still stripped from every address before it is sent. Being identified does not make a recording show more.

Analytics sets no cookies. PostHog is configured to use local storage only. Your answer to the analytics question, and — if you accept — PostHog's random device and session identifiers plus the "how you found Atlas" entry, are the whole of it. All three are itemised in §11.

You can change your mind at any time, in either direction, from the control in the footer of any page — it is also the control that reopens this choice if you dismissed it. Withdrawing takes effect immediately: collection and session replay stop, the "how you found Atlas" entry in §11 is deleted from your browser, the page reloads so that nothing already running can continue, and nothing further is sent. Withdrawal stops future collection and clears that local entry; it does not delete what PostHog already collected while you had accepted. To have that removed as well, ask — see §15.

Session replay recordings are retained for up to 30 days and are then deleted by PostHog. Atlas is on PostHog's Free plan, whose replay retention is 30 days; Atlas does not extend it.

Analytics events are kept for as long as the Atlas PostHog project is configured to keep them. That period is set inside PostHog rather than by Atlas, and this page does not state a figure for it, because Atlas has not confirmed one. Naming a period nobody has checked would be worse than saying so. Deletion of analytics data on request is covered in §15.

Deleting your Atlas account does not automatically delete analytics data already held by PostHog, and this page will not pretend otherwise. Deletion removes your Atlas account and the records listed in §16 — including the "how you found Atlas" record kept against your account — and your browser's own copy of that entry goes with the sign-out that follows. Analytics events and recordings already collected against your account number remain in PostHog until they expire under the retention described above.

Atlas has not yet automated their removal. Ask, and they will be deleted — see §15. Building that into account deletion is planned, and this paragraph changes when it exists.

If Atlas adds or changes an analytics provider, this section will name the provider and describe what it collects before it is switched on.

13. Logs, abuse signals and security

Atlas's own application log records what happened — which endpoint was called, what it decided, and errors — and is deliberately narrow about who. It does not record visitor IP addresses. Render and Cloudflare keep their own infrastructure logs as any host does, and those are outside Atlas's control.

To stop one person creating many accounts for many free worlds, Atlas records two signals when a free world is claimed: a value derived from your browser's device identifier, and a value derived from the network address the request arrived from. Both are stored only as keyed one-way digests — no raw address and no raw device identifier is stored anywhere, and neither appears in any response Atlas gives. These records are readable by nobody through the site, and they are deleted with the account.

Atlas limits how often an account can post, follow, upload, publish or report. The counters are keyed by an opaque digest rather than by your account, so they are not a record of who was throttled.

No service is perfectly secure, and Atlas does not claim to be. Atlas holds no security certification and makes no compliance claim under HIPAA, PCI DSS, SOC 2, ISO 27001 or any similar regime. To report a security problem, write to support@atlasworldbuilder.com.

14. How long things are kept

Atlas keeps information for as long as your account exists, and then deletes it as described in §16. Rather than quote retention periods Atlas has no mechanism to enforce, this section says what actually governs each kind of record:

15. Your rights and controls

Most of what a privacy request would ask for is something you can do yourself, immediately:

Depending on where you live you may also have rights to access, correction, deletion, portability, restriction or objection, and the right to complain to a data-protection authority. To make a formal request, write to hello@atlasworldbuilder.com from the address on your account. Atlas may need to confirm that the request is really yours before acting on it.

16. Deleting your account

Delete account lives on your Account page. It asks you to type the email address on the account, and it cannot be undone. Here is exactly what happens, in order:

What does not go: Stripe's own payment and invoice records, which it keeps under its own obligations; Atlas's record of any moderation actions taken, which does not identify a reporter; backups, which expire on their own schedule; anything another person had already downloaded, which was never Atlas's to recall; and — if you accepted analytics — the analytics events and session recordings already held by PostHog against your account number, which are not deleted automatically and are removed on request (§12, §15).

If a step fails partway, nothing is left in an unsafe state: your work stops being public before anything is deleted, and running the deletion again continues from where it stopped.

17. International users

Atlas is available internationally, and the providers listed in §10 operate infrastructure in several countries. Using Atlas means your information may be processed in a country other than your own, including the United States.

18. Children

Atlas is for people aged 18 and over. Atlas does not knowingly collect information from anyone under 18. If you believe a child has created an account, write to hello@atlasworldbuilder.com and it will be removed.

19. Changes

This policy may change. The effective date and version at the top of the page change with it, and a material change will be announced before it takes effect.

20. Contacting us

Privacy questions and formal privacy requests: hello@atlasworldbuilder.com. Account, billing and security reports: support@atlasworldbuilder.com. The full list of Atlas addresses is on the Contact page.