Privacy Policy

Last updated: July 27, 2026 · Effective immediately

Table of Contents

  1. Introduction & Scope
  2. Information We Collect
  3. How We Use Your Information
  4. Cookies & Local Storage
  5. Third-Party Services
  6. Data Retention
  7. Where Your Data Lives
  8. Your Rights & Choices
  9. Children's Privacy
  10. Security
  11. International Data Transfers
  12. Changes to This Policy
  13. Contact

1.Introduction & Scope

This Privacy Policy describes how Atlas Gateway ("we", "us", or "our") collects, uses, stores, shares, and protects information about you when you use our service at atlasbrain.cloud and related URLs (the "Service").

By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this Policy, you must not use the Service.

This Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.

2.Information We Collect

We collect the following categories of information. We collect only what we need to operate the Service, and we limit collection to the minimum necessary for the purposes described in this Policy.

A. Information you provide directly

B. Information collected automatically

What we DO NOT collect We do not collect biometric data, government identifiers, financial account numbers, or special-category personal data. We do not read your email inbox, contacts, or any other Google data beyond the basic profile fields listed above. Prompt and response content is collected only as described in the "Improvement Data" bullet above and Section 3 — it is pseudonymized, is never sold, and any individual request can be excluded with the "store": false opt-out.

3.How We Use Your Information

We use the information we collect for the following purposes:

We do not sell your personal information to third parties. We do not share your prompts or responses with anyone other than the third-party AI provider necessary to fulfill your request.

Data use for service improvement & model training

To improve answer quality, the Service logs the content of requests and responses ("Improvement Data"): the prompts and other inputs you submit, the AI outputs returned, the model used, token counts, latency, and processing metadata (such as internal routing depth and confidence level). Improvement Data is used to train, fine-tune, calibrate, and evaluate our own answer-quality and routing systems — most importantly the Atlas Alloy deliberation system. In addition, where we have a good-faith reason to suspect fraud, abuse, or a violation of our Terms of Service, authorized administrators may review the Improvement Data records associated with the account under investigation in order to investigate the issue and enforce our Terms; every such review is internally logged. Improvement Data is never sold, never shared with advertisers, never provided to the upstream AI model providers, and never used to train any third party's models.

The Service also records anonymized quality signals about how requests are processed: routing decisions, automated quality scores, agreement metrics, confidence levels, latency, and error categories. If you use the feedback controls (such as thumbs up / thumbs down on an answer), you are choosing to share that rating with us (opt-in by use); ratings are joined to the quality record and the Improvement Data record of the answer they rate. A notice in the dashboard and app informs you of these practices; your acknowledgment is recorded against your account.

4.Cookies & Local Storage

The Service uses minimal cookies and browser storage:

StoragePurposeDuration
atlas_key (sessionStorage / localStorage)Stores your API key so the dashboard can authenticate API callsSession (cleared on logout) or 365 days (localStorage fallback)
atlas_ref (localStorage)Stores referral code if you arrived via a referral link30 days
notif_pref (localStorage)Stores your notification permission statePersistent until cleared
Third-party advertising cookies (Google AdSense and, on ad-supported pages, other ad networks)Serving, personalizing (with consent where required), and measuring advertisementsSet by the ad vendor; see opt-outs below

Advertising. Ad-supported areas of the Service — our public pages and the ad-based earning features shown to Free tier users — display advertising from third-party networks, including Google AdSense, Monetag, and Adsterra. These vendors use cookies and similar technologies to serve and measure ads:

Outside of advertising, we do not use marketing trackers or cross-site analytics tools — no Google Analytics, no Facebook Pixel, or similar.

5.Third-Party Services

To provide the Service, we share limited data with the following categories of third parties. Each is bound by their own privacy practices, which we encourage you to review.

ServiceData SharedPurpose
Google OAuthYour Google profile (name, email, picture)Account authentication
Cloudflare (Workers, KV, R2)All service data, hosted at the edgeHosting and storage infrastructure
AI Provider (upstream inference service)Your prompts, model parameter, your IPRouting AI inference requests to third-party models
Turso (database hosting)Pseudonymized Improvement Data (prompts, outputs, processing metadata — see Section 3)Storage of service-improvement & model-training records under our control
PaddleYour email, billing address, payment method tokenProcessing credit/debit card, Apple Pay, Google Pay subscriptions
NOWPaymentsYour email, payment amount, crypto addressProcessing cryptocurrency payments
Google AdSenseYour IP, user agent, ad interaction data, advertising cookie identifiersServing and measuring ads on our public pages
MonetagYour IP, user agent, ad interaction eventsServing ads to Free tier users
AdsterraYour IP, user agent, ad interaction eventsServing ads to Free tier users (when enabled)
HilltopAdsYour IP, user agent, ad interaction eventsServing rewarded video ads to Free tier users
ShrinkMe.ioYour IP, referrerURL-shortener ad network for bonus credits
Cuty.ioYour IP, referrerURL-shortener ad network for bonus credits

AI Providers: When you make a request, the prompt you submit and your IP address are transmitted to the relevant underlying AI provider (which may include, but is not limited to, OpenAI, Anthropic, Google, DeepSeek, Zhipu AI, or other inference services) solely to fulfill your request. Each provider has its own data-handling policy. We do not control what those providers do with your prompts once forwarded.

Model Identification Disclaimer The names of AI models displayed on the Service (such as "GPT-5.5", "Claude Opus 4.8", "Deepseek v4 Flash", or any other model name) are labels used for identification only. We do not represent, warrant, or guarantee that any model named is affiliated with, endorsed by, or produced by any specific company or organization. The actual behavior, capabilities, and characteristics of any model are determined solely by the underlying third-party inference provider, and may change at any time without notice. The Service is a routing and management layer only and does not develop, train, fine-tune, or directly control any AI model made available through the Service.

6.Data Retention

We retain personal data only for as long as necessary to provide the Service and for legitimate business purposes, in accordance with the following schedule:

Data CategoryRetention PeriodReason
Account profile (name, email)Until account deletion + 30 daysAccount operation, reactivation grace period
API request metadata (model, tokens, latency, status)90 daysAnalytics, abuse detection, dispute resolution
Improvement Data (pseudonymized prompt/response content — Section 3)Up to 24 monthsTraining and calibrating our own answer-quality systems
Rate-window counters (5h, 7d)Auto-expiring (5h, 7d)Real-time rate limiting only
Bonus-credit balanceUntil used or forfeitedBonus program operation
Billing records (subscription, invoices)7 yearsTax and accounting law (Pakistan + international)
Support emails3 yearsCustomer service history
Device signature (SHA-256 hash — Section 2)Until account deletion + 30 daysEnforcing one free account per person
Atlas Studio feedback (text + opt-in diagnostics — Section 2)90 daysFixing problems and improving the desktop app
Atlas Studio usage diagnostics (beta; counts, last errors, version/OS — Section 2)30 daysFinding what breaks in the beta
Audit logs (admin actions, abuse flags)2 yearsSecurity and compliance
Backups30 days rollingDisaster recovery

After the applicable retention period expires, we will delete or irreversibly anonymize the data, except where retention is required by law.

7.Where Your Data Lives

The Service is hosted on Cloudflare's global edge network. Your data is stored in Cloudflare's distributed KV (key-value) data store, which replicates data across multiple geographic regions for performance and reliability. As of this Policy, Cloudflare's data centers span the Americas (primarily the United States), Europe (primarily the European Union), and Asia-Pacific (including Singapore, Tokyo, and Sydney). Your data may be processed in any of these regions, and we do not restrict storage to any specific region.

The AI providers we route to may process your prompts in their own data centers, which may be in the United States, the European Union, or other regions. Each provider publishes its own data-location disclosures.

8.Your Rights & Choices

You have the following rights with respect to your personal data:

To exercise any of these rights, email support@atlasbrain.cloud or atlascore.pk@gmail.com from the email address associated with your account. We will respond within 30 days. We may need to verify your identity before acting on your request.

Account Deletion: You may delete your account at any time via the dashboard (Account page) or by emailing support@atlasbrain.cloud or atlascore.pk@gmail.com. Deletion is permanent and cannot be undone. We will delete your account data within 30 days, except for billing records (retained 7 years per tax law) and data we are legally required to retain.

9.Children's Privacy

The Service is not directed to children under 13 and we do not knowingly collect personal data from children under 13. If we learn that we have inadvertently collected personal data from a child under 13, we will delete it as soon as possible. If you believe a child under 13 has provided us with personal data, please contact support@atlasbrain.cloud or atlascore.pk@gmail.com.

Users between 13 and 18 may use the Service only with the verifiable consent of a parent or legal guardian, who must accept our Terms on the minor's behalf.

10.Security

We take reasonable administrative, technical, and physical measures designed to protect your personal data from unauthorized access, use, disclosure, alteration, or destruction. These measures include:

No system is 100% secure Despite our efforts, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security of your data. To the maximum extent permitted by law, we disclaim any liability for unauthorized access to your data that occurs despite our reasonable security measures.

11.International Data Transfers

Because the Service is hosted on Cloudflare's global edge network and uses third-party providers in multiple countries, your data may be transferred to and processed in countries other than your country of residence, including the United States, Singapore, the European Union, and others. By using the Service, you consent to the transfer of your data to countries that may have different data-protection laws than your home jurisdiction.

For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms provided by our processors. For transfers involving Pakistan-based users, we comply with the Pakistan Personal Data Protection Bill and any successor legislation.

12.Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via email and an in-dashboard banner at least 14 days before they take effect. The "Last updated" date at the top of this Policy indicates when the most recent changes were made.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you must stop using the Service and may request account deletion.

13.Contact

If you have any questions, requests, or complaints about this Privacy Policy or our data practices, please contact us:

We will acknowledge your inquiry within 5 business days and respond substantively within 30 days.