Privacy policy

Last updated: 20 September 2026

This policy explains what personal data this Atlas installation processes, why, for how long, who receives it and what rights you have.

Who is responsible

Alex Szabo
Alex Szabo
Email: alex@tailored.hu

For questions about your data or to exercise your rights, write to the address above. The operator has not appointed a data protection officer because the law does not require one here.

Two roles: our data and your organization's data

For your account, security, billing, analytics and feedback, the operator decides why and how data is processed and is the controller under the GDPR. This policy describes that processing.

The content an organization keeps in Atlas, such as tasks, comments, chat messages and files, belongs to that organization. Where the organization is a business or another body, it is the controller for that content and the operator processes it only on the organization's instructions, under the data processing agreement. Questions about such content are best sent to your organization's admin first. Where a private person uses Atlas for personal purposes, the operator is the controller for that content as well.

What we process and why

Data Purpose Legal basis
Name, username, email address, password (stored only as a hash), language, role Your account and signing in Contract, Art. 6(1)(b) GDPR
Tasks, goals, features, comments, chat messages, pull requests, reviews, notes, uploaded files The work you and your organization do in Atlas Contract, Art. 6(1)(b); your organization's legitimate interest in organizing its work, Art. 6(1)(f)
Author name and email address in commits pushed to a git repository, also of people who have no Atlas account Showing the history of a repository Legitimate interest of the organization in a complete history, Art. 6(1)(f). The data comes from the person who pushed the commits
Sessions, two-factor settings, personal access tokens, sign-in provider links Keeping your account secure Contract, Art. 6(1)(b); legitimate interest in security, Art. 6(1)(f)
Audit log of changes, without names or email addresses Tracing security incidents and changes to the organization Legitimate interest in security, Art. 6(1)(f)
Email address of someone who was invited Sending the invitation Legitimate interest of the inviting organization, Art. 6(1)(f). The address comes from the member who sent the invitation
IP address and email address, stored only as a hash Limiting repeated sign-in, sign-up, upload and similar attempts Legitimate interest in security, Art. 6(1)(f)
Request paths without personal parts, timings, and faults on the server and in your browser: the message, where in the code it happened, the address of the page with its personal parts removed, and a pseudonym instead of your identity when you are signed in Operating the service and finding faults Legitimate interest in a working service, Art. 6(1)(f). You can object at any time by writing to the address above
Each request to Atlas and to our website: the page address without personal parts or parameters, time, response time, status, browser and operating system, and a code that changes every day, made from your IP address and a secret key. On the website also the address of the linking site and campaign tags (utm_source, utm_medium, utm_campaign) Keeping the service fast and available, and counting website visits and where they come from Legitimate interest in a working service and in knowing how people find us, Art. 6(1)(f). You can object at any time by writing to the address above
Actions you take, such as "task created", with your role and a pseudonym instead of your identity Finding out which features are used and where errors occur Legitimate interest in improving the service, Art. 6(1)(f). You can object at any time by writing to the address above
Pages you open in the browser, their loading times and errors, and a replay of your visit, under a pseudonym; your browser's IP address as it reaches the monitoring endpoint Browser monitoring, only if you allowed it Consent, Art. 6(1)(a) GDPR and § 165(3) TKG 2021. You can withdraw it at any time under Account → Privacy
Membership and payment status, the buying admin's email address, customer and subscription IDs Billing an organization's membership, where enabled Contract, Art. 6(1)(b)
A feedback message you send us with the feedback button, with the page you were on, your username and your browser and screen size Reading and answering your feedback Legitimate interest in improving the service, Art. 6(1)(f). It is sent by email to the operator and kept in that mailbox until handled

If you allow browser monitoring, your visit can be recorded and replayed: where you click, scroll and go, and how the page was laid out at the time. The text on the page, such as names and messages, and what you type into fields are replaced with placeholder characters before anything leaves your browser, and clicks are described without the text of the button. Without your consent nothing is recorded, and withdrawing consent stops recording at once. A page that breaks is reported either way, because a fault nobody hears about is never fixed: that report names what broke and where, stores nothing in your browser, and carries no name, email address or IP address of yours.

Within an organization, every member can see the name, username and email address of the other members, and the content the organization keeps in Atlas.

Do you have to provide the data

You need a name, a username, an email address and a password to have an account; without them Atlas cannot be used. Everything else is optional. Nothing here is required by law.

Automated decisions

Atlas makes no automated decisions about people and builds no profiles of individuals. Its statistics describe teams, departments and repositories.

Cookies and browser storage

Atlas stores only what it needs to work. This requires no consent under § 165(3) TKG 2021.

Name Kind Purpose Kept
atlas_session Cookie Keeps you signed in At most 30 days
atlas_locale Cookie Remembers the language you chose Until you change or delete it
atlas_time_zone Cookie Shows dates and times in your own time zone One year
atlas_oauth Cookie Protects signing in with GitHub or Google while it is under way Minutes, deleted after sign-in
atlas_two_factor Cookie Keeps your sign-in going between the password and the code step At most 5 minutes
atlas_hidden_groups Cookie Remembers which task groups you hid One year
atlas_analytics_consent Local storage Remembers whether you allowed browser monitoring Until you change or delete it
atlas_theme Local storage Remembers light or dark mode Until you change or delete it

Browser monitoring stores its own identifiers in the browser, but only after you allowed it.

Who receives data

  • The operator's own servers. Atlas, its database, file storage and telemetry (OpenObserve) run on infrastructure the operator controls, rented from IONOS SE (Montabaur, Germany) in its data centers in Germany. IONOS provides the servers, disks and the storage for backups and processes data only on the operator's behalf. Backups are encrypted before they leave the server.
  • Email delivery. Verification, invitation, password reset and feedback emails are handed to the operator's mail provider, which processes them on the operator's behalf.
  • GitHub and Google, only if you choose to sign in with them. They receive the sign-in request and return your account ID and email address. Both are based in the United States; transfers rely on the EU–US Data Privacy Framework, under which both are certified.
  • Creem (Armitage Labs OÜ, Tallinn, Estonia), only when an organization buys a membership. Creem is the merchant of record: it sells the membership in its own name and processes payment details as an independent controller under its own privacy policy. Atlas passes on the buyer's email address and the organization's ID. Atlas never sees card or bank details.

No data is sold, and no data is used for advertising. Apart from sign-in with GitHub or Google, no data leaves the European Union.

How long we keep it

Data Kept until
Account data You delete your account, or an admin removes you
Content of an organization A member deletes it, or the organization is deleted
Commit author names The repository is deleted
Membership and payment status The organization is deleted
Sessions They expire, after at most 30 days
Password reset and verification links They are used or expire, after at most one day
Invitations Accepted or declined, or 30 days after they expire; invitations expire after 7 days
Hashed IP and email addresses for rate limits At most one hour
Read notifications 90 days after they were read
Uploaded files No text in Atlas links to them, at the earliest a week after the upload
Audit log 365 days
Telemetry The period the operator set for each stream in OpenObserve, at most 30 days
Backups Up to 30 days, and up to 7 further days as a recoverable copy at the backup storage

Backups contain everything above. Data you delete disappears from Atlas at once and from the backups when they expire, after at most 37 days.

When an account is deleted, its name, email address, password, sign-in links, tokens, notes, reactions and uploaded files are removed. Comments, messages and reviews stay in their conversations, attributed to "Deleted user", because other members still rely on them. Commits pushed to a git repository cannot be changed; they are only removed with the repository.

Invoices and payment records are kept by Creem. Where the operator has to keep business records, Austrian law requires seven years (§ 132 BAO).

Your rights

You have the right to access your data (Art. 15), to have it corrected (Art. 16) — name and username can be changed under Account → Profile —, to have it erased (Art. 17) — under Account → Privacy —, to restrict processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent, you can withdraw it at any time without affecting what happened before.

To exercise these rights, contact alex@tailored.hu. We answer within one month.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular where you live or work. For the operator it is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at).

Children

Atlas is not intended for people under 16.

Changes

We update this policy when the way Atlas processes data changes, and change the date at the top. Material changes are announced in Atlas.