Last updated: October 11, 2026
Atlas ("we", "our", "the app") is a personal travel assistant that reads your flight, hotel, rental car, and train reservations from your connected email accounts and organizes them into a unified trip timeline. This policy explains what data we collect, how we use it, and the choices you have.
Atlas is operated by Ankur Thakkar as an independent developer. If you have any questions about this policy, email ankurthakkar19@gmail.com.
When you sign up, we store your email address, the name you give us, and a user identifier. If you sign in with Apple or Google, we receive the name, email address and (Google only) profile photo that you allow those services to share. We do not ask for your phone number, date of birth, or any government ID.
When you connect a Gmail account, Google issues OAuth tokens with read-only access. The token is kept in your device's secure keychain. When you run “Find my trips”, the app sends that short-lived token to our server with each scan request so the scan can run there; the server uses it only for that scan and does not store it. If you turn on background sync, a token is stored encrypted at rest on our servers. We never see or store your email password.
Atlas searches your connected inbox for messages from travel companies or with booking words in the subject (for example “confirmation” or “itinerary”), going back up to 10 years when you run “Find my trips”. For each match it reads the subject and sender; only when those look like a travel confirmation does it read the body of that specific message and send the text to an AI model operated by Anthropic PBC to extract structured trip details (airline, flight number, dates, confirmation number, hotel name, country, etc.). We keep the IDs of messages already read so a later scan only reads new mail; we do not keep the email text. We do not read, store, or transmit the content of non-travel emails.
The structured results from parsing — airline codes, flight times, hotel names, confirmation numbers, booking amounts — are stored in our database so you can see them in the app. You can delete any trip or disconnect your email account at any time from within the app.
If you forward a confirmation to your personal Atlas address, our email provider (Cloudflare) receives that message and passes it to us. We extract the reservation, keep the sender address, subject and extracted details with the booking, and discard the rest of the message.
Trips, notes, packing lists, expenses, polls and any documents or photos you choose to upload are stored so they sync across your devices. If you invite people to a trip, they can see that trip's itinerary, polls and shared expenses.
The emergency medical card (blood type, allergies, medications, insurance and emergency contact), your packing checklist state and appearance settings are stored only on your device. We never receive them.
When you use Ask Atlas, menu or food scanning, or restaurant and activity suggestions, the text or image you submit plus relevant trip context (such as destination and dates) is sent to Anthropic's Claude API to generate a response. We keep a daily count of AI requests per account to prevent abuse. AI output can be wrong; always confirm details with the provider.
When you share a link to Atlas (from Instagram, TikTok, YouTube or a website), paste one, or email one to your Atlas address, we fetch that post's public preview information — its title, caption or description, author name and thumbnail address — the same details any link preview shows. We never download the video, and we never access your social media accounts. The link, that preview text and any note you add are sent to Anthropic's Claude API to identify the places it features. Place names are looked up on OpenStreetMap's Nominatim service to get map coordinates (only the place name and city are sent). We store the link, the places found and short descriptive tags, and use them to show your saves on matching trips and to describe your travel taste inside the app. You can delete any save at any time.
When you open Explore for a trip, our server looks up places near that trip's hotel (or the city centre) using the Google Places API. Only the hotel name and address, or the city name, and a search phrase (such as “restaurants”) are sent — never your name or account details. Results are cached for a few days and shared between trips in the same area. If you have saved places, an AI model (Anthropic) may compare their names and categories with the nearby places to suggest a short reason a place fits your taste. Places you save from Explore are added to your Saved list.
When you swipe right (save) or left (skip) on a place in Explore, we store that choice with the place's public details (name, type, price level, rating, photo link and the trip's city). We use it only to rank future suggestions for you and to show which restaurants you liked. You can see your saves in the app; deleting your account deletes all of it.
If you ask Atlas to book a table, you choose the restaurants, day, time, party size and the name for the booking. Atlas does not ask for your phone number. Atlas's AI assistant then phones those restaurants one at a time and says at the start that it is an AI assistant calling on your behalf. It shares only the booking name, party size and any notes you add with the restaurant, and stops after the first confirmed table. Calls are placed through Vapi; restaurant phone numbers come from Google Places. Calls are not recorded; we keep a short written outcome (for example "booked for 8:00 PM", or other times offered) so we can show it to you and add the booking to your trip. Atlas never gives payment details or agrees to deposits.
When you chat with Zion inside a trip, your message, that trip's dates and plans, and the names of places you saved in that city are sent to Anthropic to write a reply, and Zion may look up places with the Google Places API (only a search phrase and the city are sent). Zion only suggests plans; nothing is added to your trip until you tap Add.
Once a day during a trip, Atlas may send a notification with a question and invite you to answer with a short video. Videos you choose to record are stored privately in your Atlas account (only you can see them) and are deleted when you delete them or your account. We never use them for advertising or to train AI.
Footsteps is off unless you turn it on for a trip, and it stops when that trip ends. While it is on, Atlas uses your location in the background. Your route never leaves your phone: the app only sends a "stay" (a spot where you spent 8+ minutes and the times) to our server, which asks the Google Places API which venue is there and saves that place to your trip. You can confirm or remove any place, and turn Footsteps off at any time in the app or in iOS Settings.
Notes you ask Zion to keep (for example a locker code) are saved to that trip in your account and used only to answer your questions.
If you join the waitlist on our website, we store your email address, a referral code, who referred you (if anyone) and a one-way hash of your IP address used only to prevent spam. We use your email only to tell you when your access is ready. Email support@atlastrips.app to be removed.
The microphone is used only while you hold the talk button. Your speech is converted to text by your device's speech recognition service (Apple on iOS, Google on Android), which may process audio on their servers. The resulting text — not the audio — is sent with relevant trip context to Anthropic's Claude API to answer. Atlas does not record or store audio.
Atlas asks for your location only when you turn on “Near me” in the companion or ask about something nearby. Your position is rounded to about 100 meters, sent with that one question to pick from places you saved nearby, and not stored. Atlas never tracks your location in the background.
If you turn on notifications, we store your device's push token so we can tell you when a booking is added, a save is ready, or a trip is coming up. Messages are delivered through Expo's push service and Apple Push Notification service. Signing out removes the token; you can also turn notifications off in iOS Settings.
For flights in your trips, Atlas looks up live status (delays, gates, terminals, cancellations, baggage carousel) from a flight-data provider, starting 24 hours before departure until shortly after landing. Only the flight number and date are sent — never your name or confirmation code.
When you invite someone by email, we notify them if they already use Atlas. People who join a trip can see its itinerary and the places members choose to add to it. Your saved places stay private unless you add them to a shared trip.
When you search flights, the route, dates, cabin and passenger count are sent to our fare providers (Amadeus and Seats.aero). No personal information is included.
Atlas uses your camera or photo library only when you choose to scan or attach an image. We do not use your location and we do not track you across other companies' apps or websites.
To understand where people get stuck and to fix bugs, the app records simple usage events (for example "signed up", "trip created", "Trip Mode opened"), error reports (error message, stack trace, app version) and any feedback you send us. These are stored in our own database, linked to your account and a random install ID, never include your email content or trip details, are not shared with third parties, and are not used for advertising or tracking across other apps.
We use your information only to:
We do not sell your data. We do not share it with advertisers, marketers, or data brokers. We do not use your email content to train AI models.
Atlas relies on the following service providers to operate. Your data is handled by each according to their own privacy practices:
Atlas's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
We keep your data for as long as your account is active. When you disconnect an email account from within Atlas, we delete the associated OAuth tokens and extracted trip data within 30 days. When you delete your Atlas account, we delete all associated data within 30 days.
You can delete your account and all associated data yourself at any time in You → Settings → Delete account. You can also request a full export or deletion by emailing ankurthakkar19@gmail.com; we respond within 30 days.
Regardless of where you live, you can ask us what data we have about you, request that we correct or delete your data, disconnect any connected email account from within the app, and delete your Atlas account entirely. If you are a resident of the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR, UK GDPR, and the CCPA respectively, including the right to lodge a complaint with a supervisory authority.
Atlas is not intended for children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has provided us with personal information, please contact us so we can delete it.
Server-stored email OAuth tokens are encrypted at rest. Every database table is protected by row-level security so an account can only read its own data and the trips it has been invited to. All network traffic between the app, our servers, and third-party APIs uses TLS 1.2 or higher. We follow industry-standard practices for access control, logging, and backup, but no system is perfectly secure. If we ever discover a security incident affecting your data, we will notify you as required by applicable law.
We may update this policy as Atlas evolves. When we do, we will update the "Last updated" date at the top and, for material changes, notify you within the app before the changes take effect.
Questions, requests, or complaints: ankurthakkar19@gmail.com · Support