Atlas

Privacy Policy

Updated 2026-09-19

This policy explains what Atlas collects, why, where it goes, and what you can demand about it.

1. What we collect

Account: your email and your password. The password is held by the authentication service in hashed form — Atlas cannot read it.

Profile: name, nationality, where you live now, your work-authorisation situation, the role you are after, experience, education, skills, languages, and the CV text you upload or paste. A CV photo, if you want one.

Journey: your goal, the phases of the plan, the gaps found, the tasks, the deadlines, and the record of what you completed and when.

Applications and network: the companies you track, the stage of each application, your notes, the company dossiers generated, the contacts you record, outreach messages, and — in interview preparation — the predicted questions, your own answers, and the critiques of them.

Documents: the CVs and cover letters you generate or edit in the app.

Conversations: the questions you ask Atlas and the answers you receive.

Preferences: language, theme, and default daily capacity.

AI usage: for each call we record which feature ran, how many tokens it used, whether it succeeded, and when. That is what powers the usage panel and cost control.

Technical data: server error and access logs, needed to run and diagnose the service.

2. Sensitive data

Atlas does not ask for sensitive data — health, religion, political opinion, racial origin, sex life, union membership.

Several fields are free text, and a CV can contain that kind of information. Sensitive data entered by the user is handled like the rest of the material, including being sent to the artificial-intelligence provider to generate what was requested.

The CV photo is optional, and the service works without it.

3. What we use it for

To run the service: build and update your journey, generate documents, suggest companies and contacts, answer your questions, and keep your progress between sessions.

To control cost and abuse: measure AI consumption per account and apply the limits described in the Terms.

For security: detect unauthorised access, failures, and automated use of the service.

For operational email: address confirmation, password recovery, and notices about relevant changes.

We do not use your data for advertising, we do not profile you for third parties, and we sell none of it to anyone.

5. Who else receives your data

Google, through the Gemini API. When you ask for something that depends on artificial intelligence, the content that request needs is sent to Google: your CV text on import, your profile and goal when building the journey, or the text of your question when you ask Atlas. Some of those calls use web search to ground the answer, and in that case a query derived from your request also reaches the search service. Google's processing follows its own API terms.

Supabase, which hosts the database, authentication, and the files you upload, such as the CV photo.

The application's hosting provider, which serves requests and keeps technical logs.

There is no other recipient. Atlas does not sell data, does not share it with advertisers, and does not use it to train a model of its own.

6. International transfer

The providers above run servers outside Brazil, including in the United States. Using Atlas means your data may be processed in those countries.

The transfer is necessary to perform the contract with you, under art. 33 of the LGPD.

7. How long we keep it

Your profile, journey, documents and conversations are kept while the account exists. You can delete much of that content inside the app.

AI usage records — feature, tokens, outcome and date — are kept for up to 12 months for cost and abuse control, even after you delete the content that produced them. They hold no text from your request.

Once the account is deleted, those records stay with no link to it: no account identifier and no email, only feature, model, tokens, outcome and date.

Server technical logs are kept briefly, only as long as diagnosis and security require.

Once you ask for your account to be deleted, we erase the data within 30 days, except what the law requires us to keep.

8. Your rights

The LGPD gives you: confirmation that we process your data, access to it, correction of what is wrong, anonymisation or deletion of what is unnecessary, portability, information about who we share it with, and withdrawal of consent.

Some of these rights can be exercised directly in the app: the profile is editable, the journey can be restarted, documents and conversations can be deleted, and the usage panel shows what was consumed.

Deleting the whole account is done inside the app, in Settings, under the danger zone. It is immediate: the account and its content are erased in the same request.

9. Security

Every row in the database is protected by an access policy in the database itself, tied to your user: a request authenticated as you cannot reach another person's data.

Traffic is encrypted in transit, the password is stored hashed by the authentication service, and reaching the files you upload requires authentication.

No system is immune. If an incident happens with real risk to your rights, we will notify you and the competent authority, as the LGPD requires.

10. Cookies

Atlas uses strictly necessary cookies only: the authentication session cookie that keeps you signed in, and the one that remembers your chosen language.

There is no advertising, social, or cross-site tracking cookie. The app loads no third-party analytics.

11. Children

Atlas is meant for people 18 and older and does not knowingly collect data from children. If we identify such an account, it will be closed and the data erased.

12. Changes to this policy

This policy can change. The date at the top of the page marks the current version, and we tell you in the app when a change matters.