A
Atlas

Privacy Policy

Last updated: October 11, 2026

Atlas ("we", "our", "the app") is a personal travel assistant that reads your flight, hotel, rental car, and train reservations from your connected email accounts and organizes them into a unified trip timeline. This policy explains what data we collect, how we use it, and the choices you have.

Atlas is operated by Ankur Thakkar as an independent developer. If you have any questions about this policy, email ankurthakkar19@gmail.com.

Information We Collect

Account information

When you sign up, we store your email address, the name you give us, and a user identifier. If you sign in with Apple or Google, we receive the name, email address and (Google only) profile photo that you allow those services to share. We do not ask for your phone number, date of birth, or any government ID.

Email access tokens

When you connect a Gmail account, Google issues OAuth tokens with read-only access. The token is kept in your device's secure keychain. When you run “Find my trips”, the app sends that short-lived token to our server with each scan request so the scan can run there; the server uses it only for that scan and does not store it. If you turn on background sync, a token is stored encrypted at rest on our servers. We never see or store your email password.

Email content (travel-related only)

Atlas searches your connected inbox for messages from travel companies or with booking words in the subject (for example “confirmation” or “itinerary”), going back up to 10 years when you run “Find my trips”. For each match it reads the subject and sender; only when those look like a travel confirmation does it read the body of that specific message and send the text to an AI model operated by Anthropic PBC to extract structured trip details (airline, flight number, dates, confirmation number, hotel name, country, etc.). We keep the IDs of messages already read so a later scan only reads new mail; we do not keep the email text. We do not read, store, or transmit the content of non-travel emails.

Extracted trip data

The structured results from parsing — airline codes, flight times, hotel names, confirmation numbers, booking amounts — are stored in our database so you can see them in the app. You can delete any trip or disconnect your email account at any time from within the app.

Emails you forward to Atlas

If you forward a confirmation to your personal Atlas address, our email provider (Cloudflare) receives that message and passes it to us. We extract the reservation, keep the sender address, subject and extracted details with the booking, and discard the rest of the message.

Things you add yourself

Trips, notes, packing lists, expenses, polls and any documents or photos you choose to upload are stored so they sync across your devices. If you invite people to a trip, they can see that trip's itinerary, polls and shared expenses.

Information that stays on your device

The emergency medical card (blood type, allergies, medications, insurance and emergency contact), your packing checklist state and appearance settings are stored only on your device. We never receive them.

AI features

When you use Ask Atlas, menu or food scanning, or restaurant and activity suggestions, the text or image you submit plus relevant trip context (such as destination and dates) is sent to Anthropic's Claude API to generate a response. We keep a daily count of AI requests per account to prevent abuse. AI output can be wrong; always confirm details with the provider.

Places you save from social media and the web

When you share a link to Atlas (from Instagram, TikTok, YouTube or a website), paste one, or email one to your Atlas address, we fetch that post's public preview information — its title, caption or description, author name and thumbnail address — the same details any link preview shows. We never download the video, and we never access your social media accounts. The link, that preview text and any note you add are sent to Anthropic's Claude API to identify the places it features. Place names are looked up on OpenStreetMap's Nominatim service to get map coordinates (only the place name and city are sent). We store the link, the places found and short descriptive tags, and use them to show your saves on matching trips and to describe your travel taste inside the app. You can delete any save at any time.

Explore (restaurants, things to do, sights)

When you open Explore for a trip, our server looks up places near that trip's hotel (or the city centre) using the Google Places API. Only the hotel name and address, or the city name, and a search phrase (such as “restaurants”) are sent — never your name or account details. Results are cached for a few days and shared between trips in the same area. If you have saved places, an AI model (Anthropic) may compare their names and categories with the nearby places to suggest a short reason a place fits your taste. Places you save from Explore are added to your Saved list.

Your swipes and taste

When you swipe right (save) or left (skip) on a place in Explore, we store that choice with the place's public details (name, type, price level, rating, photo link and the trip's city). We use it only to rank future suggestions for you and to show which restaurants you liked. You can see your saves in the app; deleting your account deletes all of it.

Booking a table by phone

If you ask Atlas to book a table, you choose the restaurants, day, time, party size and the name for the booking. Atlas does not ask for your phone number. Atlas's AI assistant then phones those restaurants one at a time and says at the start that it is an AI assistant calling on your behalf. It shares only the booking name, party size and any notes you add with the restaurant, and stops after the first confirmed table. Calls are placed through Vapi; restaurant phone numbers come from Google Places. Calls are not recorded; we keep a short written outcome (for example "booked for 8:00 PM", or other times offered) so we can show it to you and add the booking to your trip. Atlas never gives payment details or agrees to deposits.

Zion, the trip planner

When you chat with Zion inside a trip, your message, that trip's dates and plans, and the names of places you saved in that city are sent to Anthropic to write a reply, and Zion may look up places with the Google Places API (only a search phrase and the city are sent). Zion only suggests plans; nothing is added to your trip until you tap Add.

Moment Capture

Once a day during a trip, Atlas may send a notification with a question and invite you to answer with a short video. Videos you choose to record are stored privately in your Atlas account (only you can see them) and are deleted when you delete them or your account. We never use them for advertising or to train AI.

Footsteps (places you visited)

Footsteps is off unless you turn it on for a trip, and it stops when that trip ends. While it is on, Atlas uses your location in the background. Your route never leaves your phone: the app only sends a "stay" (a spot where you spent 8+ minutes and the times) to our server, which asks the Google Places API which venue is there and saves that place to your trip. You can confirm or remove any place, and turn Footsteps off at any time in the app or in iOS Settings.

Trip notes

Notes you ask Zion to keep (for example a locker code) are saved to that trip in your account and used only to answer your questions.

Website waitlist

If you join the waitlist on our website, we store your email address, a referral code, who referred you (if anyone) and a one-way hash of your IP address used only to prevent spam. We use your email only to tell you when your access is ready. Email support@atlastrips.app to be removed.

Voice companion

The microphone is used only while you hold the talk button. Your speech is converted to text by your device's speech recognition service (Apple on iOS, Google on Android), which may process audio on their servers. The resulting text — not the audio — is sent with relevant trip context to Anthropic's Claude API to answer. Atlas does not record or store audio.

Location

Atlas asks for your location only when you turn on “Near me” in the companion or ask about something nearby. Your position is rounded to about 100 meters, sent with that one question to pick from places you saved nearby, and not stored. Atlas never tracks your location in the background.

Notifications

If you turn on notifications, we store your device's push token so we can tell you when a booking is added, a save is ready, or a trip is coming up. Messages are delivered through Expo's push service and Apple Push Notification service. Signing out removes the token; you can also turn notifications off in iOS Settings.

Live flight status

For flights in your trips, Atlas looks up live status (delays, gates, terminals, cancellations, baggage carousel) from a flight-data provider, starting 24 hours before departure until shortly after landing. Only the flight number and date are sent — never your name or confirmation code.

Group trips

When you invite someone by email, we notify them if they already use Atlas. People who join a trip can see its itinerary and the places members choose to add to it. Your saved places stay private unless you add them to a shared trip.

Flight search

When you search flights, the route, dates, cabin and passenger count are sent to our fare providers (Amadeus and Seats.aero). No personal information is included.

Camera and photos

Atlas uses your camera or photo library only when you choose to scan or attach an image. We do not use your location and we do not track you across other companies' apps or websites.

Product usage and diagnostics

To understand where people get stuck and to fix bugs, the app records simple usage events (for example "signed up", "trip created", "Trip Mode opened"), error reports (error message, stack trace, app version) and any feedback you send us. These are stored in our own database, linked to your account and a random install ID, never include your email content or trip details, are not shared with third parties, and are not used for advertising or tracking across other apps.

How We Use Your Information

We use your information only to:

We do not sell your data. We do not share it with advertisers, marketers, or data brokers. We do not use your email content to train AI models.

Third-Party Services

Atlas relies on the following service providers to operate. Your data is handled by each according to their own privacy practices:

Google API Services User Data Policy

Atlas's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Data Retention

We keep your data for as long as your account is active. When you disconnect an email account from within Atlas, we delete the associated OAuth tokens and extracted trip data within 30 days. When you delete your Atlas account, we delete all associated data within 30 days.

You can delete your account and all associated data yourself at any time in You → Settings → Delete account. You can also request a full export or deletion by emailing ankurthakkar19@gmail.com; we respond within 30 days.

Your Rights

Regardless of where you live, you can ask us what data we have about you, request that we correct or delete your data, disconnect any connected email account from within the app, and delete your Atlas account entirely. If you are a resident of the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR, UK GDPR, and the CCPA respectively, including the right to lodge a complaint with a supervisory authority.

Children

Atlas is not intended for children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.

Security

Server-stored email OAuth tokens are encrypted at rest. Every database table is protected by row-level security so an account can only read its own data and the trips it has been invited to. All network traffic between the app, our servers, and third-party APIs uses TLS 1.2 or higher. We follow industry-standard practices for access control, logging, and backup, but no system is perfectly secure. If we ever discover a security incident affecting your data, we will notify you as required by applicable law.

Changes to This Policy

We may update this policy as Atlas evolves. When we do, we will update the "Last updated" date at the top and, for material changes, notify you within the app before the changes take effect.

Contact

Questions, requests, or complaints: ankurthakkar19@gmail.com · Support