> Data Handling :: Privacy_
What AtlasTrack actually does with your data.
Last updated: September 23, 2026
The short version: signing in with Google or Microsoft does not hand your real name, email, or photo to AtlasTrack. We strip that information the moment it arrives, before it's ever displayed or stored — you pick a screen name instead, and that's what everyone (including us) sees.
Your project data — timelines, events, everything you build — stays in your browser by default. Nothing leaves your device unless you explicitly publish it or save it to a vault, and vault contents are encrypted on your device before upload, so we can't read them either.
We do not sell your data, to anyone, ever. That's not a policy that could change — it's not part of how this product makes money.
Publishing is public and effectively transfers ownership to AtlasTrack. If you publish something to the Server Library, anyone can see it, and your screen name stays on it as an author credit — but you're no longer the exclusive owner. If you want to keep something private and under your control, use a Vault instead.
Signing in with Google or Microsoft
AtlasTrack uses Firebase Authentication to handle Google and Microsoft sign-in directly in your browser — there's no AtlasTrack server in the middle of that handshake. When you sign in, the provider hands back your real name, email, and profile photo, the same way it would to any app.
We discard that immediately. As soon as sign-in completes, AtlasTrack overwrites the profile photo and display name on the account record, and none of our own application code ever reads, displays, or stores your real name, email, or photo. Instead, every account is identified only by an anonymous account ID, and you choose a screen name the first time you sign in — that's the identity AtlasTrack actually uses everywhere, including for anything published publicly.
One honest nuance: Firebase's own authentication system (which is Google's infrastructure, separate from AtlasTrack) still technically retains your account email as part of your sign-in record — that's how Firebase Auth works for any app built on it, and it's outside AtlasTrack's control. What we can tell you is that AtlasTrack's own code and database never read, store, display, or otherwise use that email. It sits in Firebase's authentication layer, untouched.
What we actually store
The only account-level information AtlasTrack's database holds is:
- Your anonymous account ID (assigned by Firebase, not derived from anything personal)
- The screen name you chose
- Basic account structure — plan tier, seat/collaborator relationships, if applicable
No email address, no real name, no profile photo. If you publish something to the public Server Library, it's attributed to your chosen screen name — never to your real identity.
Your project data
Timelines, events, maps, and everything else you build in AtlasTrack are stored locally in your browser by default — nothing is uploaded automatically, and nothing syncs to a server in the background. Your data only leaves your device when you take a deliberate action:
- Publishing to the Server Library — see below, this is a bigger commitment than it sounds.
- Saving to a Vault — your content is encrypted on your own device before it's ever sent, using a key that never leaves your browser. AtlasTrack's servers store only the encrypted result and can't read its contents.
Everything else — drafts, in-progress work, anything you haven't explicitly published or saved to a vault — simply never leaves your browser.
Publishing: be aware of what this actually means
When you publish an atlas or project to the Server Library, it becomes publicly visible to anyone — not just other AtlasTrack accounts, anyone who can reach the page. There's no private/unlisted middle ground for a published item.
Ownership is the part people don't expect: publishing effectively transfers ownership of that content to AtlasTrack. Your screen name stays attached as an author credit, and that credit isn't removed — but the underlying content is no longer exclusively yours to control once it's published. This is the tradeoff for free public hosting and distribution through the Server Library, and it's deliberately different from a Vault, which stays encrypted, private, and under your control.
If that tradeoff doesn't work for something you've built, keep it local or use a Vault instead of publishing it.
What we don't do
- We do not sell your data. Full stop — not to advertisers, not to data brokers, not to anyone, ever. This isn't a "we don't currently" statement — it isn't part of how AtlasTrack is built to make money.
- We don't run third-party analytics or ad-tracking scripts inside the app. Our public information pages (About, Features, SCE, Privacy and Terms) use Google Analytics to count visits and see where visitors come from — nothing you build or save in AtlasTrack is ever part of that.
- We don't share or hand off your account data (screen name, UID, account structure) to third parties.
- We don't read the contents of your projects unless you've explicitly published them or they're sitting in a Vault we can't decrypt anyway.
- We don't require an AI subscription or send your data to an AI provider — AtlasTrack's AI features are bring-your-own-key, meaning any data you choose to share with an LLM goes directly from your browser to the AI provider you picked, on your own account.
This is a beta
AtlasTrack is under active development. This page reflects how the product actually works today, not aspirational goals — it will be kept up to date as the product changes, and the “last updated” date above reflects the most recent real revision.
Questions
If anything here is unclear, or you want more detail on how a specific feature handles data, reach out at contact@atlastrack.org.