Privacy Policy
Last updated: September 11, 2026
The short version
1. What we collect
Account data: the email and display name you provide, your date of birth (collected to confirm you meet our minimum age and to limit public social features to adults), the biological sex you select during onboarding (used to pick your 3D anatomy model, scale achievement thresholds, and normalize XP), plus your Atlas user id, authentication tokens, and the country we infer from your IP at signup (two-letter code only).
Workout data: the exercises, sets, reps, weights, rest times, notes, and dates you log; the templates and splits you create; achievements you unlock; per-muscle XP totals; and (for premium features) body measurements you choose to record.
Device and usage data: approximate location (derived from your IP for rate-limiting and abuse prevention - we do not retain precise GPS), browser / OS user-agent, app version, and timestamps of events like opens, screen views, and feature usage. If you turn on notifications in the mobile app, we also store a push notification token issued by your device operating system against your account, so we can deliver notifications to that device. You can revoke it at any time by turning notifications off in your device settings.
Location during a cardio session you start (premium, on your phone or watch): When you start a GPS-tracked run, walk, ride, or other outdoor movement session in the Atlas mobile app or on the Atlas watch app (Apple Watch / Wear OS), your device shares your precise location with the app for as long as that session is active so Atlas can measure your distance and pace in real time. This happens only while a session you started is running - including with the screen off - and stops the moment you finish it. Your coordinates never leave your device as a route: Atlas adds them up into a single distance number (for example, "3.20 mi") and stores only that total alongside the workout. We do not store or upload your path, route, or a map of where you went. You grant this with your device's standard location prompt (iOS, watchOS, Android, or Wear OS) at the start of the run and can decline or revoke it at any time - Atlas simply falls back to letting you enter your distance by hand.
Billing data: if you subscribe, your payment method is handled entirely by Apple, Google, or Stripe. We never see, receive, or store your card number or any part of it. What we keep is a customer id, a subscription id, your plan amount and billing interval, your subscription status, and your renewal and trial-end dates.
Customer support: messages you send us and any contact information you include.
Phone number (only if you opt in): Atlas has an optional phone-discoverability feature you can turn on in Settings → Social. It is off by default and available only for US and Canadian numbers. If you turn it on, you enter your own phone number so we can confirm you own it and let other lifters find you by it. To do this we send your number to our server and to our SMS provider, Twilio, which texts you a one-time verification code (standard message and data rates may apply). After you confirm the code, we store ONLY a one-way keyed hash of your number (an HMAC computed over a salted SHA-256 of the number) - we never store the raw phone number itself. We keep that hash until you delete your account. Turning phone discoverability off in Settings stops phone matching immediately: we delete the lookup entry that lets other people find you, so no one can match you by phone from that moment on. We keep the hash itself on your profile so that turning discoverability back on does not require another verification text. Deleting your account removes it entirely. We never use your phone number to message you for marketing, and we never share it with the people who find you.
Finding friends from your contacts (only if you ask): If you tap "Find friends from your contacts," Atlas reads the email addresses and phone numbers in your device contacts so it can match them against lifters who have opted in. The matching is done with one-way hashes computed on your device: your raw contacts never leave your device and are never uploaded or stored, only the hashes are sent to us to look for matches, and we never message the people in your contacts. Nothing is read from your contacts unless you start this yourself.
2. Why we use it
- Run the Service: render your dashboards, fire celebrations, generate share cards, and - for Premium subscribers - sync your data across your devices. On the free tier, your detailed workout history is stored locally on your device and is not synced to our servers; we still collect limited account, usage-analytics, and diagnostic data as described in this policy.
- Improve the product: analyze aggregate, de-identified usage so we can ship the features lifters actually use.
- Send transactional and account messages you always receive (a welcome note, receipts, password resets, billing and payment-problem notices). We may also send product and lifecycle emails (for example tips, setup and workout nudges, trial reminders, and win-backs). If you are in the US, these are on by default and every one includes a one-click unsubscribe. If you are in the EU, UK, Canada, Australia, or anywhere else, we send them only if you opt in (the checkbox at signup, or in Settings), and you can withdraw at any time. To know which rule applies, we infer your country once at signup from your IP address and store only the two-letter country code.
- Protect the Service from abuse (rate limiting, fraud detection, terms enforcement).
- Comply with legal obligations.
Legal bases. Where the GDPR or similar laws apply, we rely on: contract, to run the service you signed up for; consent, for marketing email, the analytics cookie, optional features like photos and videos you post and Apple Health / Health Connect, and your fitness and body data where explicit consent is required; legitimate interests, for abuse prevention, security, and protecting the Service; and legal obligation, for things like child-safety reporting. Where required (for example in the EU and UK), we ask for your explicit consent during onboarding before processing fitness and body data.
3. What we don't do
- We do not sell your personal information to advertisers, data brokers, or anyone else.
- We do not share your individual workout history with third parties for marketing.
- We do not place behavioral advertising cookies on our website.
- We do not run health surveillance, share data with insurers, or share data with employers.
- We do not store or share your running route, path, or GPS trail. When you track a cardio session, we keep only the total distance - never a map of where you went.
4. Sharing and third-party processors
We use carefully selected vendors to operate the Service. Each is contractually bound to use your data only as we direct:
- Supabase - hosted database + authentication.
- Stripe - payment processing for Premium.
- Apple App Store / Google Play - in-app purchases on iOS / Android.
- Vercel - hosting + edge functions.
- Upstash - hosted Redis behind our rate limiting. To count requests per caller across all of our servers we send Upstash a rate-limit key containing your IP address. It is stored only for the length of the rate-limit window and then expires automatically. It is never joined to your account or workout data.
- PostHog (when enabled) - product analytics, configured to mask personally-identifying fields.
- Resend - transactional email delivery.
- Twilio Inc. (United States) - SMS verification provider for the optional phone-discoverability feature. If you opt in, Twilio receives the phone number you choose to add, solely to text you the one-time verification code.
- RevenueCat - subscription management and purchase-entitlement validation for in-app purchases.
- Sentry - crash and error diagnostics (an error report may include your Atlas user id to help us debug).
- Amazon Web Services (AWS Rekognition) - automated image-safety classification of photos you upload. We send the image content for this check; AWS does not perform facial recognition for us and does not retain the images for its own use.
- Microsoft (PhotoDNA) - child-safety matching for photos and video frames. In the normal path we compute a PhotoDNA hash (a non-reversible fingerprint) on our own servers and send only that hash to Microsoft to check against known child sexual abuse material. If hashing is unavailable, the image itself may be sent to Microsoft's PhotoDNA service for the same check, solely to perform it.
- OpenAI (content moderation) - automated text-safety classification of captions and comments you post. We send only the text (never your account details) so it can be checked for harassment, hate, threats, sexual content, and self-harm. OpenAI does not use this text to train its models and does not retain it.
- Cloudflare - content delivery and network security, and video hosting: videos you upload are encoded, stored, and streamed by Cloudflare Stream on our behalf.
- GIPHY - the optional GIF picker for comments and posts. GIF searches are proxied through our server (GIPHY does not receive your identity from the search), but a chosen GIF is displayed directly from GIPHY’s content network, so your device requests it from GIPHY and GIPHY may receive your IP address when a GIF loads. GIF searches are limited to GIPHY’s “pg-13” content rating or below; higher ratings are excluded.
Apple Health and Android Health Connect. If you choose to connect Atlas to Apple Health or Android Health Connect (an explicit opt-in in Settings), the workouts you finish on your phone are written to that health platform so they appear in your health timeline and contribute to your activity totals. A workout you finish on an Apple Watch or Wear OS watch is written by the watch app on that device instead, governed by the permissions you grant that app in your health app rather than by the Atlas setting. If you start a workout on a watch and finish it on your phone, the phone writes it and the Atlas setting applies. Apple and Google process that data under their own privacy policies. Atlas does not use your health data for advertising, and you can disconnect at any time in Settings.
We may also share data when required by law, in connection with a merger or acquisition (in which case we'll notify you), or to protect the rights, property, or safety of Atlas, our users, or the public. Where we believe in good faith it is required by law or necessary to prevent harm (especially in child-safety matters), we may preserve and disclose your content and account identifiers - including your email, IP address, and device or user-agent - to NCMEC and to law enforcement without prior notice to you.
5. Public profiles and share cards
atlas.sigmatools.io/u/[handle]and generate share cards (PNG images) of your achievements. These surfaces show level, achievement counts, body-atlas heatmaps, and top lifts you have chosen to highlight. A share card never shows individual session weights, body measurements, photos, or your email. Your profile page shows more: your profile photo, your published posts and any photos or videos attached to them, and, for anyone who can already see a post, the individual sets and weights of that workout when they expand it. Viewing a profile page requires an Atlas account; signed-out visitors see only a placeholder. Neither surface ever shows your body measurements or your email address. You control whether your profile is public from in-app settings.6. Photos and videos you upload and how we keep them safe
Some features let you upload photos and videos that can be seen by other users, including media you attach to workout posts and comments and the custom profile avatar you choose. Because Atlas is open to users 13 and older, we process every uploaded image, and sampled frames of every uploaded video, for safety before it can be shown to anyone else. This processing is a core part of how we operate the media features and meet our legal obligations.
- Metadata stripping. We remove EXIF and other embedded metadata - including GPS location and capture time - from your photo on upload, and we re-encode the image. The version we store and show to others does not carry the location or device metadata your camera may have embedded.
- Automated moderation. Every uploaded image, and sampled frames of every uploaded video, are checked against known child-safety hash databases before the media is shown to anyone. Photos additionally pass an automated explicit-content classifier. New uploads stay private until they pass review, and confirmed child sexual abuse material is removed and reported to the National Center for Missing and Exploited Children (NCMEC). Text you post (captions and comments) is likewise checked by an automated classifier for harmful content before it goes live.
- Possible human review. If an image is flagged or a check is uncertain, it is held and may be manually reviewed by us before any decision to show or remove it.
Legal basis. Where the GDPR or similar laws apply, we process uploaded images to perform our contract with you (to provide the photo features you use) and on the basis of our legitimate interest in keeping the Service and our community safe. Detecting and reporting CSAM is also a legal obligation. If we identify apparent CSAM, we preserve the relevant content and account information and report it to the National Center for Missing & Exploited Children (NCMEC) and cooperate with law enforcement as required by US law.
Retention of photos. Photos you upload are retained while your account is active. When you delete your account, we remove your uploaded photos from our production systems, with backups expiring on the schedule described in the Retention section below. We may retain content and related records longer where required to comply with law, including material preserved or reported in connection with a CSAM report.
For the plain-language rules on what you may and may not upload, see our Community Guidelines.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your account and personal data (the "right to erasure");
- Export your data in a machine-readable format;
- Object to certain processing or restrict it;
- Lodge a complaint with your local data-protection authority.
You can exercise the access, export, and deletion rights yourself from Settings → Subscription & data. JSON and CSV export run immediately on-device. Deleting your Atlas account cancels a subscription purchased directly through Atlas on the web. It does not cancel an Apple App Store or Google Play subscription. Store subscriptions must be canceled in the applicable store subscription settings. It also removes your profile from our servers and signs you out. If you cannot open the app, see how to delete your account. For anything else, email privacy@sigmatools.io and we will respond within 30 days.
If you are in the EU or UK, you can also lodge a complaint with your local supervisory authority. If you are in Canada or Australia, you have equivalent rights under PIPEDA and the Australian Privacy Principles. The data controller is SigmaTools, LLC, 2041 Rufe Snow Drive, Suite 101 PMB 1018, Keller, TX 76248, USA.
US state privacy rights (California and others). If you are a California resident, or live in a state with a comparable law, you also have the right to know the categories of personal information we collect and disclose, to delete it, to correct it, to opt out of any sale or sharing of it, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do NOT sell your personal information, and we do NOT share it for cross-context behavioral advertising. You can manage your privacy choices, including analytics, any time in Settings → Privacy.
Global Privacy Control. We honor the GPC browser signal: when your browser sends GPC, we treat it as an automatic opt-out of analytics and of any sharing of your data with third parties. Syncing your workouts to Apple Health or Health Connect on your own device is not affected. Workouts you finish on your phone stay off unless you switch that setting on. A workout you finish on a paired watch is written by the watch app on that device, which you control through the permissions you grant it in your health app rather than through Atlas.
Watch apps. The Apple Watch / Wear OS app writes workout and live-session data directly to our servers; the phone mirrors only the current session for display.
What the in-app export covers. The instant in-app export contains the data stored on your device. For a complete copy of the personal data on our servers (for example social posts, your follow graph, and moderation or audit records), email privacy@sigmatools.io and we will provide it within 30 days.
8. Retention
9. Children's privacy
Age assurance. Atlas is for users age 13 and older. We ask for date of birth at sign up. On supported platforms, the applicable app store may provide Atlas with an age category, parental approval status, and a platform identifier used for later approval or revocation events. Atlas uses this information only for age restrictions, safety controls, and legal compliance. If a signal indicates that a user is under 13, we lock the account and begin our appeal and deletion process. If a signal indicates that a user is 13 to 17, the account remains private and is excluded from stranger discovery. We do not use age assurance information for advertising or behavioral profiling. We retain only the minimum account status and, where necessary, a purpose limited derived identifier needed to recognize later revocation events. Raw age assurance payload information is deleted when no longer needed for verification or compliance.
10. International transfers
11. Security
12. Cookies and local storage
- Essential cookies. Used to sign you in and keep your session secure. Required for the Service to work.
- Analytics cookie. With your consent, our analytics provider (PostHog) sets a first-party cookie/identifier so we can understand aggregate, de-identified product usage. It stays OFF until you turn it on: by accepting the cookie banner on the web, or in Settings → Privacy in the app. A Global Privacy Control signal keeps it off, and you can change your choice any time in Settings → Privacy.
- Local storage. The app stores data in your browser or device (for example your workout history on the free tier, your theme, and your consent choices) so it works offline and loads quickly.
- We do not use third-party behavioral advertising cookies.