Privacy policy
Last updated: 20 September 2026
This policy explains what personal data this Atlas installation processes, why, for how long, who receives it and what rights you have.
Who is responsible
Alex Szabo
Alex Szabo
Email: alex@tailored.hu
For questions about your data or to exercise your rights, write to the address above. The operator has not appointed a data protection officer because the law does not require one here.
Two roles: our data and your organization's data
For your account, security, billing, analytics and feedback, the operator decides why and how data is processed and is the controller under the GDPR. This policy describes that processing.
The content an organization keeps in Atlas, such as tasks, comments, chat messages and files, belongs to that organization. Where the organization is a business or another body, it is the controller for that content and the operator processes it only on the organization's instructions, under the data processing agreement. Questions about such content are best sent to your organization's admin first. Where a private person uses Atlas for personal purposes, the operator is the controller for that content as well.
What we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name, username, email address, password (stored only as a hash), language, role | Your account and signing in | Contract, Art. 6(1)(b) GDPR |
| Tasks, goals, features, comments, chat messages, pull requests, reviews, notes, uploaded files | The work you and your organization do in Atlas | Contract, Art. 6(1)(b); your organization's legitimate interest in organizing its work, Art. 6(1)(f) |
| Author name and email address in commits pushed to a git repository, also of people who have no Atlas account | Showing the history of a repository | Legitimate interest of the organization in a complete history, Art. 6(1)(f). The data comes from the person who pushed the commits |
| Sessions, two-factor settings, personal access tokens, sign-in provider links | Keeping your account secure | Contract, Art. 6(1)(b); legitimate interest in security, Art. 6(1)(f) |
| Audit log of changes, without names or email addresses | Tracing security incidents and changes to the organization | Legitimate interest in security, Art. 6(1)(f) |
| Email address of someone who was invited | Sending the invitation | Legitimate interest of the inviting organization, Art. 6(1)(f). The address comes from the member who sent the invitation |
| IP address and email address, stored only as a hash | Limiting repeated sign-in, sign-up, upload and similar attempts | Legitimate interest in security, Art. 6(1)(f) |
| Request paths without personal parts, timings, and faults on the server and in your browser: the message, where in the code it happened, the address of the page with its personal parts removed, and a pseudonym instead of your identity when you are signed in | Operating the service and finding faults | Legitimate interest in a working service, Art. 6(1)(f). You can object at any time by writing to the address above |
Each request to Atlas and to our website: the page address without personal parts or parameters, time, response time, status, browser and operating system, and a code that changes every day, made from your IP address and a secret key. On the website also the address of the linking site and campaign tags (utm_source, utm_medium, utm_campaign) |
Keeping the service fast and available, and counting website visits and where they come from | Legitimate interest in a working service and in knowing how people find us, Art. 6(1)(f). You can object at any time by writing to the address above |
| Actions you take, such as "task created", with your role and a pseudonym instead of your identity | Finding out which features are used and where errors occur | Legitimate interest in improving the service, Art. 6(1)(f). You can object at any time by writing to the address above |
| Pages you open in the browser, their loading times and errors, and a replay of your visit, under a pseudonym; your browser's IP address as it reaches the monitoring endpoint | Browser monitoring, only if you allowed it | Consent, Art. 6(1)(a) GDPR and § 165(3) TKG 2021. You can withdraw it at any time under Account → Privacy |
| Membership and payment status, the buying admin's email address, customer and subscription IDs | Billing an organization's membership, where enabled | Contract, Art. 6(1)(b) |
| A feedback message you send us with the feedback button, with the page you were on, your username and your browser and screen size | Reading and answering your feedback | Legitimate interest in improving the service, Art. 6(1)(f). It is sent by email to the operator and kept in that mailbox until handled |
If you allow browser monitoring, your visit can be recorded and replayed: where you click, scroll and go, and how the page was laid out at the time. The text on the page, such as names and messages, and what you type into fields are replaced with placeholder characters before anything leaves your browser, and clicks are described without the text of the button. Without your consent nothing is recorded, and withdrawing consent stops recording at once. A page that breaks is reported either way, because a fault nobody hears about is never fixed: that report names what broke and where, stores nothing in your browser, and carries no name, email address or IP address of yours.
Within an organization, every member can see the name, username and email address of the other members, and the content the organization keeps in Atlas.
Do you have to provide the data
You need a name, a username, an email address and a password to have an account; without them Atlas cannot be used. Everything else is optional. Nothing here is required by law.
Automated decisions
Atlas makes no automated decisions about people and builds no profiles of individuals. Its statistics describe teams, departments and repositories.
Cookies and browser storage
Atlas stores only what it needs to work. This requires no consent under § 165(3) TKG 2021.
| Name | Kind | Purpose | Kept |
|---|---|---|---|
atlas_session |
Cookie | Keeps you signed in | At most 30 days |
atlas_locale |
Cookie | Remembers the language you chose | Until you change or delete it |
atlas_time_zone |
Cookie | Shows dates and times in your own time zone | One year |
atlas_oauth |
Cookie | Protects signing in with GitHub or Google while it is under way | Minutes, deleted after sign-in |
atlas_two_factor |
Cookie | Keeps your sign-in going between the password and the code step | At most 5 minutes |
atlas_hidden_groups |
Cookie | Remembers which task groups you hid | One year |
atlas_analytics_consent |
Local storage | Remembers whether you allowed browser monitoring | Until you change or delete it |
atlas_theme |
Local storage | Remembers light or dark mode | Until you change or delete it |
Browser monitoring stores its own identifiers in the browser, but only after you allowed it.
Who receives data
- The operator's own servers. Atlas, its database, file storage and telemetry (OpenObserve) run on infrastructure the operator controls, rented from IONOS SE (Montabaur, Germany) in its data centers in Germany. IONOS provides the servers, disks and the storage for backups and processes data only on the operator's behalf. Backups are encrypted before they leave the server.
- Email delivery. Verification, invitation, password reset and feedback emails are handed to the operator's mail provider, which processes them on the operator's behalf.
- GitHub and Google, only if you choose to sign in with them. They receive the sign-in request and return your account ID and email address. Both are based in the United States; transfers rely on the EU–US Data Privacy Framework, under which both are certified.
- Creem (Armitage Labs OÜ, Tallinn, Estonia), only when an organization buys a membership. Creem is the merchant of record: it sells the membership in its own name and processes payment details as an independent controller under its own privacy policy. Atlas passes on the buyer's email address and the organization's ID. Atlas never sees card or bank details.
No data is sold, and no data is used for advertising. Apart from sign-in with GitHub or Google, no data leaves the European Union.
How long we keep it
| Data | Kept until |
|---|---|
| Account data | You delete your account, or an admin removes you |
| Content of an organization | A member deletes it, or the organization is deleted |
| Commit author names | The repository is deleted |
| Membership and payment status | The organization is deleted |
| Sessions | They expire, after at most 30 days |
| Password reset and verification links | They are used or expire, after at most one day |
| Invitations | Accepted or declined, or 30 days after they expire; invitations expire after 7 days |
| Hashed IP and email addresses for rate limits | At most one hour |
| Read notifications | 90 days after they were read |
| Uploaded files | No text in Atlas links to them, at the earliest a week after the upload |
| Audit log | 365 days |
| Telemetry | The period the operator set for each stream in OpenObserve, at most 30 days |
| Backups | Up to 30 days, and up to 7 further days as a recoverable copy at the backup storage |
Backups contain everything above. Data you delete disappears from Atlas at once and from the backups when they expire, after at most 37 days.
When an account is deleted, its name, email address, password, sign-in links, tokens, notes, reactions and uploaded files are removed. Comments, messages and reviews stay in their conversations, attributed to "Deleted user", because other members still rely on them. Commits pushed to a git repository cannot be changed; they are only removed with the repository.
Invoices and payment records are kept by Creem. Where the operator has to keep business records, Austrian law requires seven years (§ 132 BAO).
Your rights
You have the right to access your data (Art. 15), to have it corrected (Art. 16) — name and username can be changed under Account → Profile —, to have it erased (Art. 17) — under Account → Privacy —, to restrict processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent, you can withdraw it at any time without affecting what happened before.
To exercise these rights, contact alex@tailored.hu. We answer within one month.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular where you live or work. For the operator it is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at).
Children
Atlas is not intended for people under 16.
Changes
We update this policy when the way Atlas processes data changes, and change the date at the top. Material changes are announced in Atlas.