1. Introduction
Atlas ("we," "our," or "us") is a personal relationship management application that helps you visualize and nurture your social connections. We are committed to protecting your privacy and handling your personal data with transparency and care.
This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using Atlas, you agree to the practices described in this policy. If you do not agree, please discontinue use of the app.
2. Information We Collect
2.1 Account Information (Firebase Authentication)
When you sign in with Google, Firebase Authentication receives and stores your Google account email address, display name, and profile photo URL. This information is used solely to identify your account and associate locally stored data with your user ID. We do not store this information on our own servers beyond what Firebase manages on our behalf.
2.2 Contact & Relationship Data (Local Storage Only)
All contacts, relationships, circles, notes, tags, and graph configurations you create within Atlas are stored exclusively on your device using Hive, a local NoSQL database. This includes:
- Names, nicknames, birthdays, phone numbers, email addresses
- Company, social media handles, interests, and personal notes
- Custom relationship types and circle memberships
- Star Graph layout preferences and importance flags
This data is never transmitted to our servers or any third-party service, except as explicitly described in Section 2.3 (Google Drive Backup).
2.3 Google Drive Backup (Optional)
Atlas offers an optional backup feature that exports your relationship data to your personal
Google Drive. This feature uses the drive.file OAuth scope, which means Atlas
can only access files that it creates — it cannot read any other files in your Drive.
- Backup files are stored in your own Google Drive account, under your control.
- We do not retain copies of your backup data on our servers.
- You can revoke Google Drive access at any time via your Google Account settings.
- Backup is never automatic without your explicit action.
2.4 iCal / Calendar URL Fetch
If you provide an iCal URL to import calendar events (e.g., to set birthday reminders), Atlas fetches that URL directly from your device. The URL and the fetched calendar data are stored locally only. We do not proxy, log, or retain calendar URLs or event data on our servers.
2.5 Usage & Crash Data
We currently do not collect analytics or crash reports. If this changes in a future release, we will update this policy and notify you within the app before any data collection begins.
3. How We Use Your Information
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Google account email & name | Authenticate your identity; associate local data with your account | Contract performance |
| On-device contact data | Power the app's core features (graph, search, profiles) | Contract performance |
| Google Drive backup files | Restore your data on new or reset devices (user-initiated) | Consent (optional feature) |
| iCal URL data | Import calendar events for birthday/reminder functionality | Consent (user-provided URL) |
We do not use your data for advertising, profiling, or any purpose beyond operating the app.
4. Data Storage & Security
Local storage: All contact and relationship data is encrypted at rest by the operating system's device encryption (Android Full-Disk Encryption / File-Based Encryption). The Hive database files are stored in the app's private sandbox and are not accessible to other apps without root access.
Firebase Authentication: Managed by Google Firebase and subject to Google's security standards and ISO 27001 certification.
Google Drive backups: Protected by your Google account security settings (including 2FA if enabled).
We recommend enabling device screen lock and device encryption to maximize protection of your on-device data.
5. Data Sharing & Third-Party Services
We do not sell, rent, or trade your personal data. We share information only with the following service providers as necessary to operate Atlas:
| Service | Provider | Data Shared | Purpose |
|---|---|---|---|
| Firebase Authentication | Google LLC | Email, display name, UID | User authentication |
| Google Drive API | Google LLC | Backup file (user-initiated only) | Optional cloud backup |
| Google Play | Google LLC | App distribution metadata | App delivery |
All third-party providers listed above are bound by Google's Privacy Policy at policies.google.com/privacy.
We may disclose information if required by law, court order, or to protect the rights and safety of users, provided we are legally permitted to notify you of such disclosure.
6. Your Rights & Data Control
You have the following rights regarding your data:
- Access: All your data is visible directly within the app.
- Correction: Edit any contact or relationship record at any time.
- Deletion: Delete individual contacts or all data (see Section 7).
- Portability: Export your data via the VCF or Drive backup features.
- Revoke Google permissions: Revoke Firebase Auth or Drive access at any time via myaccount.google.com/permissions.
If you are located in the European Economic Area, you may have additional rights under the GDPR, including the right to lodge a complaint with a supervisory authority. Contact us at privacy@mybuilt.app to exercise any of these rights.
7. Account Deletion
You can permanently delete your Atlas account and all associated data at any time:
- Open Atlas → tap your profile avatar (top right of Home screen).
- Go to Settings → Delete Account.
- Confirm the deletion. This action is irreversible.
Upon account deletion:
- All locally stored Hive data (contacts, relationships, circles) is permanently erased.
- Your Firebase Authentication record is deleted immediately.
- Google Drive backup files created by Atlas remain in your Drive until you manually delete them, since they belong to your Google account.
If you are unable to access the app, contact us at privacy@mybuilt.app and we will manually delete your Firebase Authentication record within 30 days of verification.
8. Children's Privacy (COPPA)
If you believe a child under 13 has provided personal information through Atlas, please contact us immediately at privacy@mybuilt.app. We will promptly delete the associated account and all related data.
Users between the ages of 13 and 17 should review this policy with a parent or guardian before using the app.
9. Data Retention
On-device data: Retained until you delete specific records or delete your account, or until you uninstall the app (which clears the local Hive database).
Firebase Authentication data: Retained until you delete your account (Section 7) or revoke access via Google Account settings. Inactive accounts with no sign-in for 12 consecutive months may be deleted automatically; we will notify you by email at least 30 days in advance.
Google Drive backups: Retained in your Google Drive until you delete them. We have no control over data you store in your own Drive.
10. International Data Transfers
Atlas is operated from Taiwan. Firebase Authentication data is processed by Google LLC, which may transfer data across international borders in accordance with Google's data transfer mechanisms (including Standard Contractual Clauses for EEA users).
Your on-device Hive data never leaves your device and is not subject to international data transfers.
11. Policy Updates
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Display an in-app notification on the next app launch after the change takes effect.
- Update the "Last Updated" date at the top of this page.
- For significant changes (e.g., new data collection categories), provide at least 14 days' advance notice via email (if we have your email on file) or in-app banner.
Continued use of Atlas after the effective date of an updated policy constitutes your acceptance of the changes.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: privacy@mybuilt.app
- Response time: We aim to respond within 5 business days.
For data deletion requests, please include your account email address and the subject line "Data Deletion Request" so we can process your request promptly.