Atlas Limits
Privacy policy
This policy describes the data processed for the Atlas Limits website and for the Atlas Limits Android application. It is independent of the legal notice.
Atlas Limits does not create a reader account. No personal data is sold.
Scope
It covers use of the website in French and English, the public forms on that website, and the Android reading application. The application does not offer a newsletter subscription.
The publisher, the nature of the publications and the conditions of use are described in the legal notice.
Browsing
Atlas Limits processes the IP address and the request metadata needed to deliver pages and protect the service. Hosting is provided through Cloudflare. The retention period of the host logs is not set in Atlas Limits’ code and is not stated here.
A search on the website or in the application sends the search term, the language and the filters needed to display results. These elements are not stored as a search history in the editorial database.
Cookies and similar technologies
The public website sets one preference cookie, ao_locale, when the reader chooses a language. It contains only fr or en, lasts one year, and is not an advertising identifier.
The public pages do not install an audience-measurement script or an advertising script.
The editorial administration, which is separate from public reading, uses its own session cookies. They are not set by reading an article or by the Android application. They last seven days.
Newsletter and Resend
Newsletter subscription is optional. It asks for an email address, the language of the mailing and consent. The public form does not record a name.
Atlas Limits keeps the address, the language, the subscription status, the associated dates and the hash of the unsubscribe token, in order to send the newsletter and to honour a request to stop it.
Mailing is sent through Resend. Delivery, bounce and complaint notices update the status of the address. Atlas Limits keeps the type of notice, a provider message identifier and a hash of the notification, not the body of the message.
Each mailing contains an unsubscribe link. Using it stops later mailings. The address is kept with the status unsubscribed. The link does not erase it.
A signup limiter stores a hash calculated from the IP address and a counter of attempts. Those rows are not an account and are not deleted automatically.
Ask Atlas and OpenAI
Ask Atlas is an optional feature of the website. A question is sent to Atlas Limits systems. When the feature is active, it is sent to OpenAI in order to produce the answer. Excerpts from the Atlas Limits corpus that are needed for the answer may accompany the question. From a publication, the identifier of that public page may also be sent so that the answer can refer to it.
The browser may attach up to six messages from the same visit. That history stays in the memory of the page. It is not written to the editorial database and disappears when the page is closed.
When the feature is active, the configuration in use asks the API not to retain the Response as application state where that option applies. The provider may nevertheless retain some data temporarily under its own security, abuse-prevention and retention terms.
To limit abuse, Atlas Limits computes a pseudonymised fingerprint from the IP address. That fingerprint is used for security and to limit the number of requests. It is not a user account. The IP address is not sent in clear text to OpenAI for this purpose. When an Ask request is sent to OpenAI, a security identifier derived from that fingerprint may accompany the request in order to prevent or detect abuse. That identifier is not an Atlas account, an advertising identifier, or a permanent device identifier.
Under the current implementation, the text of Ask questions is not stored in the Atlas Limits editorial database.
In the Android application, the question is sent only when the mobile feature is enabled. When it is not enabled, the request is refused before a fingerprint is calculated and before any question is sent to OpenAI. When it is enabled, the question follows the same processing as on the website.
Android application
The application does not create an account. Language, appearance, text size, bookmarks, reading progress and downloads remain on the device. Android backup of the application is disabled.
The reader can remove one download or clear downloads in the application. That deletion happens on the device. A message to Atlas Limits does not erase it remotely.
To display the catalogue, the application sends Atlas Limits, over HTTPS, the language, the page, the filters, the search term and the identifier of the requested article. Images are loaded from media.atlaslimits.com. These elements are not stored as a history in the editorial database.
Providers
Cloudflare routes and protects the website. The retention period of its logs is not stated here.
OpenAI produces the Ask Atlas answer when the feature is active. Its own security and abuse-prevention periods remain applicable. Asking the API not to retain the Response as application state is not an absence of retention at the provider.
Resend sends the newsletter.
No personal data is sold. Atlas Limits does not pass this data to an advertising network.
Security
Public exchanges use HTTPS. Administration is limited to authorised people. The unsubscribe token is stored only as a hash. The newsletter and Ask Atlas forms accept only requests that come from the website. When the Android application sends an origin, only the expected origins are accepted.
Limiters reduce abuse of signup and of Ask Atlas. They are not a reader account.
Retention
The retention period of the host logs is not stated here. Data processed by OpenAI and by Resend remains subject to their own periods, which are not set in this policy.
The language cookie remains for one year in the browser, unless the reader deletes it. The administration cookies last seven days.
Ask Atlas rate-limit rows are deleted when a later Ask request runs and their last update is older than 48 hours. That deletion does not start by itself if no new request arrives. It does not delete the newsletter signup limiter rows.
Ask Atlas hourly aggregates older than 90 days are deleted when a new aggregate is recorded. They record a language, a result and a duration. They contain neither the text of a question nor an IP address.
An address subscribed to the newsletter is kept for that service, including after unsubscription, until a deletion request has been carried out. No automatic erasure period is implemented.
The signup journal keeps a hash of the address and the outcome of the request, not the content of a message. No automatic period is defined for that journal.
Rights
Anyone may ask Atlas Limits which newsletter data is held, ask for the address or the language to be corrected, object to further mailings, or request deletion. The request does not require an account.
It is sent to contact@atlaslimits.com. The unsubscribe link stops mailings without erasing the address.
Data deletion
To request deletion of data, write to Atlas Limits and state that the request is for deletion. If it concerns the newsletter, give the address concerned. There is no separate form and no account page.
Address for the request: contact@atlaslimits.com.
The unsubscribe link stops mailings immediately and keeps the address. Erasure of the stored address is not a self-service control. The service does not apply an automatic processing deadline, so no response time is stated here.
The request may concern the newsletter record Atlas Limits holds, that is the address, the language, the status and the associated dates, and the sending rows that contain that address.
It does not erase what Atlas Limits does not hold as a profile. Bookmarks, downloads, reading progress and settings remain on the device and are removed in the application. The text of Ask questions is not stored in the editorial database. Search terms are not kept there as a history.
Ask Atlas rate-limit rows older than 48 hours are removed by the technical rule described above, when a later Ask request runs. Aggregates older than 90 days are removed when a new aggregate is recorded. These records are not accounts and cannot be selected from an email address.
Copies that OpenAI or Resend may keep under their own terms, and host logs whose retention period is not stated, are not erased by this request. The signup journal, limited to a hash and the outcome, has no automatic period and is not erased by a scheduled process.
Contact
Questions about this policy can be sent to contact@atlaslimits.com.
The Contact us page gives the same address and the official website.