This Privacy Policy describes how Atlas Gateway ("we", "us", or "our") collects, uses, stores, shares, and protects information about you when you use our service at atlasbrain.cloud and related URLs (the "Service").
By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this Policy, you must not use the Service.
This Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
We collect the following categories of information. We collect only what we need to operate the Service, and we limit collection to the minimum necessary for the purposes described in this Policy.
"store": false opt-out.
We use the information we collect for the following purposes:
We do not sell your personal information to third parties. We do not share your prompts or responses with anyone other than the third-party AI provider necessary to fulfill your request.
To improve answer quality, the Service logs the content of requests and responses ("Improvement Data"): the prompts and other inputs you submit, the AI outputs returned, the model used, token counts, latency, and processing metadata (such as internal routing depth and confidence level). Improvement Data is used to train, fine-tune, calibrate, and evaluate our own answer-quality and routing systems — most importantly the Atlas Alloy deliberation system. In addition, where we have a good-faith reason to suspect fraud, abuse, or a violation of our Terms of Service, authorized administrators may review the Improvement Data records associated with the account under investigation in order to investigate the issue and enforce our Terms; every such review is internally logged. Improvement Data is never sold, never shared with advertisers, never provided to the upstream AI model providers, and never used to train any third party's models.
"store": false in any API request body and that request's content is not retained. The request is otherwise processed normally, at no penalty.The Service also records anonymized quality signals about how requests are processed: routing decisions, automated quality scores, agreement metrics, confidence levels, latency, and error categories. If you use the feedback controls (such as thumbs up / thumbs down on an answer), you are choosing to share that rating with us (opt-in by use); ratings are joined to the quality record and the Improvement Data record of the answer they rate. A notice in the dashboard and app informs you of these practices; your acknowledgment is recorded against your account.
The Service uses minimal cookies and browser storage:
| Storage | Purpose | Duration |
|---|---|---|
atlas_key (sessionStorage / localStorage) | Stores your API key so the dashboard can authenticate API calls | Session (cleared on logout) or 365 days (localStorage fallback) |
atlas_ref (localStorage) | Stores referral code if you arrived via a referral link | 30 days |
notif_pref (localStorage) | Stores your notification permission state | Persistent until cleared |
| Third-party advertising cookies (Google AdSense and, on ad-supported pages, other ad networks) | Serving, personalizing (with consent where required), and measuring advertisements | Set by the ad vendor; see opt-outs below |
Advertising. Ad-supported areas of the Service — our public pages and the ad-based earning features shown to Free tier users — display advertising from third-party networks, including Google AdSense, Monetag, and Adsterra. These vendors use cookies and similar technologies to serve and measure ads:
Outside of advertising, we do not use marketing trackers or cross-site analytics tools — no Google Analytics, no Facebook Pixel, or similar.
To provide the Service, we share limited data with the following categories of third parties. Each is bound by their own privacy practices, which we encourage you to review.
| Service | Data Shared | Purpose |
|---|---|---|
| Google OAuth | Your Google profile (name, email, picture) | Account authentication |
| Cloudflare (Workers, KV, R2) | All service data, hosted at the edge | Hosting and storage infrastructure |
| AI Provider (upstream inference service) | Your prompts, model parameter, your IP | Routing AI inference requests to third-party models |
| Turso (database hosting) | Pseudonymized Improvement Data (prompts, outputs, processing metadata — see Section 3) | Storage of service-improvement & model-training records under our control |
| Paddle | Your email, billing address, payment method token | Processing credit/debit card, Apple Pay, Google Pay subscriptions |
| NOWPayments | Your email, payment amount, crypto address | Processing cryptocurrency payments |
| Google AdSense | Your IP, user agent, ad interaction data, advertising cookie identifiers | Serving and measuring ads on our public pages |
| Monetag | Your IP, user agent, ad interaction events | Serving ads to Free tier users |
| Adsterra | Your IP, user agent, ad interaction events | Serving ads to Free tier users (when enabled) |
| HilltopAds | Your IP, user agent, ad interaction events | Serving rewarded video ads to Free tier users |
| ShrinkMe.io | Your IP, referrer | URL-shortener ad network for bonus credits |
| Cuty.io | Your IP, referrer | URL-shortener ad network for bonus credits |
AI Providers: When you make a request, the prompt you submit and your IP address are transmitted to the relevant underlying AI provider (which may include, but is not limited to, OpenAI, Anthropic, Google, DeepSeek, Zhipu AI, or other inference services) solely to fulfill your request. Each provider has its own data-handling policy. We do not control what those providers do with your prompts once forwarded.
We retain personal data only for as long as necessary to provide the Service and for legitimate business purposes, in accordance with the following schedule:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account profile (name, email) | Until account deletion + 30 days | Account operation, reactivation grace period |
| API request metadata (model, tokens, latency, status) | 90 days | Analytics, abuse detection, dispute resolution |
| Improvement Data (pseudonymized prompt/response content — Section 3) | Up to 24 months | Training and calibrating our own answer-quality systems |
| Rate-window counters (5h, 7d) | Auto-expiring (5h, 7d) | Real-time rate limiting only |
| Bonus-credit balance | Until used or forfeited | Bonus program operation |
| Billing records (subscription, invoices) | 7 years | Tax and accounting law (Pakistan + international) |
| Support emails | 3 years | Customer service history |
| Device signature (SHA-256 hash — Section 2) | Until account deletion + 30 days | Enforcing one free account per person |
| Atlas Studio feedback (text + opt-in diagnostics — Section 2) | 90 days | Fixing problems and improving the desktop app |
| Atlas Studio usage diagnostics (beta; counts, last errors, version/OS — Section 2) | 30 days | Finding what breaks in the beta |
| Audit logs (admin actions, abuse flags) | 2 years | Security and compliance |
| Backups | 30 days rolling | Disaster recovery |
After the applicable retention period expires, we will delete or irreversibly anonymize the data, except where retention is required by law.
The Service is hosted on Cloudflare's global edge network. Your data is stored in Cloudflare's distributed KV (key-value) data store, which replicates data across multiple geographic regions for performance and reliability. As of this Policy, Cloudflare's data centers span the Americas (primarily the United States), Europe (primarily the European Union), and Asia-Pacific (including Singapore, Tokyo, and Sydney). Your data may be processed in any of these regions, and we do not restrict storage to any specific region.
The AI providers we route to may process your prompts in their own data centers, which may be in the United States, the European Union, or other regions. Each provider publishes its own data-location disclosures.
You have the following rights with respect to your personal data:
To exercise any of these rights, email support@atlasbrain.cloud or atlascore.pk@gmail.com from the email address associated with your account. We will respond within 30 days. We may need to verify your identity before acting on your request.
Account Deletion: You may delete your account at any time via the dashboard (Account page) or by emailing support@atlasbrain.cloud or atlascore.pk@gmail.com. Deletion is permanent and cannot be undone. We will delete your account data within 30 days, except for billing records (retained 7 years per tax law) and data we are legally required to retain.
The Service is not directed to children under 13 and we do not knowingly collect personal data from children under 13. If we learn that we have inadvertently collected personal data from a child under 13, we will delete it as soon as possible. If you believe a child under 13 has provided us with personal data, please contact support@atlasbrain.cloud or atlascore.pk@gmail.com.
Users between 13 and 18 may use the Service only with the verifiable consent of a parent or legal guardian, who must accept our Terms on the minor's behalf.
We take reasonable administrative, technical, and physical measures designed to protect your personal data from unauthorized access, use, disclosure, alteration, or destruction. These measures include:
Because the Service is hosted on Cloudflare's global edge network and uses third-party providers in multiple countries, your data may be transferred to and processed in countries other than your country of residence, including the United States, Singapore, the European Union, and others. By using the Service, you consent to the transfer of your data to countries that may have different data-protection laws than your home jurisdiction.
For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms provided by our processors. For transfers involving Pakistan-based users, we comply with the Pakistan Personal Data Protection Bill and any successor legislation.
We may update this Privacy Policy from time to time. Material changes will be announced via email and an in-dashboard banner at least 14 days before they take effect. The "Last updated" date at the top of this Policy indicates when the most recent changes were made.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you must stop using the Service and may request account deletion.
If you have any questions, requests, or complaints about this Privacy Policy or our data practices, please contact us:
support@atlasbrain.cloud or atlascore.pk@gmail.com (privacy, data rights, and general support)We will acknowledge your inquiry within 5 business days and respond substantively within 30 days.