This Privacy Policy explains how Atlas AI services, including our Telegram assistant, website, and other Atlas applications (collectively, "Atlas AI", "we", "us", or "our"), collect, use, store, share, and protect your information when you interact with our services.
1. Data We Collect
Atlas AI processes the following data to provide our services:
- Messages: Your text and voice messages are processed by our backend and AI providers to generate responses. Conversation context is stored temporarily (up to 60 messages for Pro users) to maintain multi-turn dialogue within a chat session.
- Long-term Memory: With your consent (via automatic preference detection or the
/remember command), the assistant may store up to 20 short facts about you (such as your name, preferences, or ongoing projects) to personalize future replies. You can inspect these anytime with /memory and delete them with /forget. - Usage Data: Message count, image count, subscription tier, and referral activity are tracked to enforce rate limits, prevent abuse, and manage your account.
- Telegram User ID: Your Telegram user ID, first name, and username (if public) are stored to identify your account and associate your preferences and settings.
- Payments: Telegram Stars transaction records (amount, tier, period) are stored to verify and manage your active subscription. We do not process or store payment card details.
- Reminders & Routines: Scheduled reminder text, delivery times, and recurring routine definitions are stored until delivered, modified, or cancelled.
- Feedback: Messages submitted via
/feedback are stored so our team can review bug reports and feature requests. - Connected Google Data: If you voluntarily connect your Google Account, we access and process Google user data strictly as described in Section 5 below.
2. How We Use Your Data
We use collected data solely to deliver, maintain, and improve requested Atlas AI functionality:
- Generating AI responses to your prompts and queries
- Personalizing responses using your configured long-term memory facts
- Enforcing rate limits, usage tiers, and subscription entitlements
- Processing Telegram Stars subscription transactions and managing tier access
- Maintaining conversational context across turns within a chat session
- Delivering scheduled reminders, daily briefings, and routine notifications at requested times
- Processing bug reports, inquiries, and feedback submitted through our support channels
- Tracking referral activity and awarding referral bonuses
- Fulfilling user-requested email and calendar actions as detailed in Section 5
3. Data Storage & Architecture
User account profiles, short-term conversational history, memory facts, reminders, and payment logs are stored in a secure PostgreSQL database hosted on Supabase. Data is retained for as long as your account remains active or until you request deletion. Sensitive credentials (such as Google OAuth tokens) are encrypted at rest using AES-256-GCM. We do not persistently store raw email message bodies or full calendar databases; email and calendar information is fetched ephemerally on-demand.
4. General Third-Party Services
Atlas AI relies on reputable third-party infrastructure providers to operate:
- Cloud Compute & Hosting (Vercel): Application backend and serverless API execution. Subject to Vercel's Privacy Policy.
- Database Hosting (Supabase): Persistent PostgreSQL database hosting for account records and encrypted tokens. Subject to Supabase's Privacy Policy.
- AI Model Providers: We use third-party AI APIs (including DeepSeek, and where configured as fallbacks, Groq, Google Gemini, and OpenAI) to generate conversational responses. Each provider processes message inputs strictly to return completions.
- Image Generation (Pollinations.ai): Free image generation utility when invoked by the user.
- Messaging Platform (Telegram): User interface delivery, messaging transport, and Telegram Stars checkout. Subject to Telegram's Privacy Policy.
5. Google User Data (Gmail & Google Calendar)
This section specifically discloses how Atlas AI accesses, uses, stores, shares, and protects data received from Google APIs in compliance with the Google API Services User Data Policy.
5.1 Google Data We Access
Atlas AI accesses your Google Account data only after you grant explicit authorization through Google's official OAuth 2.0 consent screen. We request only the minimum necessary permissions:
https://www.googleapis.com/auth/gmail.readonly — Read-only access to view email messages and settings.https://www.googleapis.com/auth/gmail.send — Permission to send emails on your behalf strictly upon your explicit confirmation.https://www.googleapis.com/auth/calendar.events.owned — View, create, edit, and delete events on your owned primary Google Calendar.
Depending on the features you invoke, the specific categories of Google user data accessed are:
- Account Identifier: Your connected Google email address, used to bind your Google connection to your Atlas AI account.
- Email Metadata: Message headers (sender, recipient, date, subject line), message and thread identifiers, labels, and unread status.
- Email Content: Message snippets and email body text (plain text or HTML), accessed strictly on-demand when you ask to read, inspect, search, or summarize specific emails.
- Outbound Email Details: Recipient email address, subject line, and message body drafted by you or generated for your review.
- Calendar Events: Event title/summary, start and end dates/times, location, description, attendee email addresses, and event identifiers on your primary calendar.
- OAuth Credentials: Ephemeral access tokens, refresh tokens, token expiration timestamps, and granted scope lists.
5.2 How We Use Google Data
Google user data is used solely to provide user-facing productivity features explicitly initiated or configured by you:
- Displaying unread message counts, inbox overviews, and recent email summaries when you invoke
/email or ask about your inbox. - Searching your inbox and retrieving specific email threads based on your queries.
- Generating concise summaries of long emails or compiling morning email briefings when requested or scheduled.
- Confirmed Email Sending: Drafting emails based on your instructions and transmitting them via Gmail strictly after you click an explicit confirmation button in the chat interface. Atlas AI never sends an email autonomously or without prior interactive user confirmation.
- Displaying your upcoming calendar events and daily schedule overviews.
- Creating, updating, or deleting calendar events on your primary calendar at your instruction.
5.3 Sharing, Transfer, and Third-Party Disclosures
We do not sell Google user data, nor do we disclose it for advertising purposes.
- No Sale: Atlas AI does NOT sell, rent, lease, or monetize Google user data under any circumstances.
- No Advertising or Data Brokers: Atlas AI does NOT share Google user data with third-party advertisers, ad networks, data brokers, or information resellers.
- No Unrelated Uses: Atlas AI does NOT use Google user data for advertising, retargeting, credit scoring, market research, or any purpose other than providing user-requested assistant features.
Google user data may be transmitted only to service providers acting on Atlas AI's behalf as necessary to execute user-requested features:
- AI Model Providers (DeepSeek, and where configured as fallbacks, Groq, Google Gemini, OpenAI): When you ask Atlas AI to summarize an email, analyze inbox contents, or review calendar events, relevant email text, snippets, or event details are transmitted in real-time as prompt context to our AI model API to generate the response. These providers process data strictly to return the immediate completion.
- Cloud Compute & Hosting (Vercel): Atlas AI's serverless backend runs on Vercel infrastructure, which executes the API handlers communicating with Google APIs, securely decrypts OAuth tokens in memory for the duration of the request, and returns responses.
- Database Hosting (Supabase / PostgreSQL): Supabase hosts our persistent database. It stores your account identifier, connected Google email address, and AES-256-GCM encrypted OAuth tokens. Supabase stores encrypted credentials; email contents and calendar event databases are not persistently stored.
- Messaging Platform (Telegram): Email summaries, unread counters, send confirmation prompts, and calendar schedules requested by you are delivered to your Telegram chat.
5.4 AI & Machine Learning Model Training Prohibition
Atlas AI does not use or transfer Google Workspace API data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
Google user data is shared with service providers only when necessary to provide user-requested Atlas features and in accordance with applicable agreements, security controls, and Google's Limited Use requirements.
5.5 Storage & Security
- Zero Password Access: Authentication is handled exclusively through Google OAuth 2.0 PKCE. Atlas AI never sees, requests, or stores your Google account password.
- Encryption at Rest: OAuth access tokens and refresh tokens are encrypted at rest using industry-standard AES-256-GCM authenticated encryption before being saved in our database. Encryption keys are securely managed via server environment variables and never exposed to clients.
- Encryption in Transit: All data transmitted between Atlas AI, Google APIs, third-party service providers, and users is encrypted using Transport Layer Security (TLS / HTTPS).
- Data Minimization: Atlas AI does not store persistent local archives of your email inbox, message bodies, or calendar history. Messages and events are retrieved ephemerally on-demand to fulfill individual requests.
5.6 Retention & Deletion of Google Data
- Retention Period: Encrypted OAuth credentials and connection metadata are retained only for as long as your Google Account remains connected to Atlas AI, as needed to provide the service.
- Disconnection Purge: When you disconnect your account via the
/disconnectemail command, Atlas AI immediately calls Google's revocation endpoint to invalidate your tokens and permanently deletes all stored tokens, credentials, and email account records from our database. - Chat History Erase: Ephemeral email summaries or calendar details displayed in your active chat session can be erased from short-term context at any time by issuing
/clear. - Account Deletion: You can request full account deletion at any time via
/feedback or by contacting support. All account records and associated data are permanently purged within 30 days.
5.7 Revoking Google Access
You retain complete, permanent control over Atlas AI's access to your Google Account at all times:
- Within Atlas AI: Send the
/disconnectemail command at any time to immediately revoke tokens with Google and wipe stored credentials. - Through Google: You can view and revoke Atlas AI's permissions at any time directly through your Google Account Security Permissions page. Once revoked, Atlas AI cannot access any Google data.
5.8 Google API Limited Use Disclosure
Atlas AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Payments
Subscriptions and one-time purchases are processed through Telegram Stars. We do not collect, process, or store payment card numbers, bank details, or billing addresses. Transaction records (Stars amount, subscription tier, and active period) are stored in our database solely to verify and administer your subscription status.
7. Data Deletion & User Controls
You have direct, immediate control over your data through dedicated bot commands:
/clear — Erases your short-term conversational session context./forget — Permanently deletes all long-term memory facts stored about you./cancelreminder — Cancels your most recent pending reminder./disconnectemail — Revokes Google OAuth tokens and permanently purges connected email credentials.
To request full account deletion, including all profile data, memory facts, reminders, and history, submit a request via /feedback or contact us directly. All associated data will be permanently and irreversibly purged within 30 days.
8. Security Practices
We implement industry-standard administrative, physical, and technical safeguards to protect your personal information:
- Encrypted database connections (SSL/TLS) to managed PostgreSQL on Supabase.
- AES-256-GCM authenticated encryption at rest for third-party OAuth credentials.
- Strict environment-variable management for API keys and encryption secrets with zero client-side exposure.
- HTTPS/TLS encryption for all external API and web communications.
- Role-based access controls and secret authentication tokens on administrative API endpoints.
While we take rigorous measures to safeguard your information, no transmission over the Internet or electronic storage system is completely impenetrable, and we cannot guarantee absolute security.
9. Contact & Privacy Inquiries
For privacy inquiries, data access requests, or deletion assistance, contact our team:
- Telegram Support: @ziadahmed20
- Direct Bot Command:
/feedback [your message] - Website: https://atlas-ai-agent.site