ATLAS
Capabilities Agents Trust Use cases
Launch Atlas

LEGAL

Privacy Policy

Last updated: September 2026

This is a plain-language description of how Atlas Vault currently handles information, published as a product baseline for our beta. It has not been reviewed by an attorney and is not a substitute for legal advice. It will be replaced with a formal, counsel-reviewed policy before general commercial availability.

Who this covers

This policy covers two separate things people sometimes conflate: (1) the public marketing site at atlasvault.co, and (2) the Atlas Vault application itself, which your organization deploys and controls. We describe both below because what happens to information is genuinely different between them.

The public marketing site

If you submit the "Request a demo" form, we collect exactly what the form asks for: your name, work email, and company are required; phone number, company size, area of interest, and a free-text message are optional. We also record a hashed (not raw) form of the IP address the request came from and the browser's user-agent string, solely to detect and rate-limit abuse of the form.

We do not use third-party analytics, advertising pixels, or session-replay scripts on the marketing site.

The Atlas Vault application

Atlas Vault is designed to be deployed on infrastructure your organization controls. When your organization runs Atlas, the application processes:

  • Account information — email address, display name, and a securely hashed password (never the password itself) for each user your organization creates.
  • Organization and workspace structure — the organizations, workspaces, and role assignments your administrators configure.
  • Vault content — documents, files, and other company knowledge your organization uploads, and the text/data extracted from them for search and retrieval.
  • Conversations — the questions your users ask Atlas and the answers Atlas gives, stored so conversation history remains available.
  • Agent activity — configurations, run history, findings, and knowledge proposals for any scheduled Agents your organization sets up.
  • Authentication and session records — session identifiers and sign-in metadata needed to keep accounts secure (see the Trust page for detail on how sessions are protected).
  • Technical and log information — ordinary application logs generated in the course of operating the service.

What stays local, and what doesn't

Atlas Vault's core intelligence — the language model that reads your documents and writes answers, and the vector search that retrieves relevant passages from your Vault — runs on infrastructure your organization controls. In a typical self-hosted deployment, that means document content, conversation content, and account data do not get sent to an external AI provider to generate answers.

That is not true of every feature. Atlas Vault's Web Research capability, when a question actually needs current public information, sends search queries to public search infrastructure and retrieves content from public websites over the internet — that is how it works, and we are not going to describe it as "local" when it isn't. Web Research is only invoked when a request genuinely calls for it, and it only touches the public web, never your Vault content, as part of that outbound request.

We do not currently claim, and you should not assume, that literally nothing ever leaves the machine running Atlas Vault. The accurate statement is: your Vault content and conversations are not sent to an external AI provider for core answer generation, and any outbound network activity (Web Research) is scoped to public information retrieval, not your private company knowledge.

Third-party service providers

We do not currently have any confirmed third-party data processors to disclose here (for example, no external analytics vendor, no external CRM, and no payment processor exist in the product today). If and when Atlas Vault integrates a third-party service that processes your data, this policy will be updated to name it before that integration goes live.

Retention

Atlas Vault does not currently enforce an automatic data-retention or deletion schedule. Account data, Vault content, and conversation history persist until an administrator removes them through the product, or until your organization's deployment is decommissioned. We consider a formal retention policy a pre-commercial item still to be defined, not something we're going to promise a specific number for tonight.

Security

See the Security & Trust page for a plain-language description of how accounts, sessions, and access control work. Passwords are hashed with Argon2 and are never stored or logged in plain text.

Your choices

Because Atlas Vault is deployed and administered by your own organization, most day-to-day choices — who has an account, what they can access, when data is deleted — are controlled by your organization's own administrators, not by us directly. If you're an individual user with a question about your own data within an Atlas Vault deployment, the fastest path is your organization's Atlas administrator.

Contacting us

We do not yet have a dedicated legal or privacy contact address to publish here — that's a pre-commercial gap we're tracking, not an oversight we're hiding. Until it's in place, the Request a demo form on our homepage reaches a real inbox and is the current way to reach us with a privacy question.

Changes to this policy

We may update this policy as the product changes. We'll update the "Last updated" date above when we do.

ATLAS VAULT
Privacy · Terms · Security & Trust © Atlas Vault