Privacy Policy

Effective date: June 7, 2026 · Atlas Biometrics LLC

Atlas Biometrics is athletic self-tracking software — not a medical provider, not a HIPAA-covered entity, and not a clinical medical record system. This policy explains how we separate login identity from sensitive tracking data, how we encrypt logs at rest, and what you can expect when you use the platform.

Platform encryption status

Live status from the Atlas API infrastructure layer.

Checking…
Overview Two-vault design Tracking profiles Encryption at rest Forum identity AI coach Billing Your choices Legal scope

1. Overview

We collect the minimum data needed to operate your account, process subscriptions, and store your personal athletic tracking logs. Because tracking data can be sensitive, we architect the platform so that identity data and tracking data live in separate logical vaults with different access patterns and encryption keys.

Plain language summary: Your email pays the bill. Your measurements live under a pseudonymous profile — and, when enabled on the server, those logs are encrypted with a key that is not used for login or database access.

2. Two-vault architecture

Atlas stores data in two distinct categories:

Identity vault Login & billing

Email address, password hash, Stripe customer and subscription identifiers, account creation date, and session authentication tokens.

Tracking vault Goals & daily logs

Stated goals, baselines, PLE/MRV/RLE/RRV measurements, estimated latency, readiness scores, compliance flags, session load entries, and protocol state tied to a pseudonymous profile ID.

How they connect

When you register, Atlas creates a random UUID tracking profile and links it to your user account through a single internal reference (tracking_profile_id). That link exists so you can sign in and view your own data. It is not exposed in tracking API responses, coach context, or community surfaces.

If someone accessed a database export containing only tracking tables, they would see pseudonymous IDs and encrypted payloads — not email addresses — unless they also compromised the identity vault and the mapping layer together.

3. Pseudonymous tracking profiles

Each member receives a forum username (for example, Atlas-A1B2C3) that acts as a public-facing pseudonym. This username:

  • Is used for community forum display when forum access is enabled.
  • May appear in embedded protocol coach context as a display label.
  • Is never substituted for your email or legal name on public pages.

You can change or regenerate your forum username from My Account. Your email remains private to the identity vault.

4. Encryption at rest (tracking vault)

When the server is configured with a dedicated tracking vault key (ATLAS_TRACKING_VAULT_KEY), Atlas encrypts sensitive tracking payloads before writing them to PostgreSQL:

  • Algorithm: AES-256-GCM with a unique initialization vector per record.
  • Goal data: Stored in metric_goals_enc on your tracking profile.
  • Daily logs: Stored in tracking_metrics_enc on each daily metrics row.
  • Plaintext clearing: After encryption, corresponding plaintext measurement columns are cleared in the database.

Separate keys by design

The tracking vault key is not derived from your password, JWT signing secret, or database credentials. Compromise of one layer does not automatically decrypt the other.

Operator note: If encryption is not yet enabled on a deployment, the platform may store tracking data in plaintext at rest while still keeping identity and tracking logically separated. Check the status badge at the top of this page or My Account for your environment.

5. Community forum & public identity

Forum access is gated by an active subscription tier. Atlas may host community discussion on Circle or on the built-in Atlas forum, depending on deployment configuration.

  • On Atlas dashboard and coach surfaces, only your forum username pseudonym is used — not your email, real name, or internal account ID.
  • When Circle is enabled, community posts live on Circle’s platform and are subject to Circle’s privacy policy in addition to this policy.
  • Members typically access Circle with the same email used for Atlas billing unless single sign-on is configured separately.

Do not post information in community spaces that you would not want associated with your pseudonym or member profile. Treat community posts as semi-public content.

6. Embedded protocol coach (AI)

The dashboard includes an optional AI coach that receives contextual protocol state to personalize guidance — schedule phase, nutrient timing, and your latest self-reported tracking entries.

  • Coach context uses your forum pseudonym when a display name is needed.
  • Coach context does not include your email, password, or Stripe identifiers.
  • Medical guardrails block diagnostic or treatment requests in both directions.
  • Coach responses are educational and protocol-oriented — not medical advice.

7. Billing & payment processing

Subscriptions are processed by Stripe. Atlas stores Stripe customer and subscription IDs in the identity vault to manage your membership tier (Base Protocol, Sonic Hybrid add-on, or Maintenance Plan).

Atlas does not store full payment card numbers. Card data is handled directly by Stripe under their privacy and security programs. Use Stripe’s customer portal from My Account to update payment methods or cancel subscriptions.

8. Your choices & account controls

  • View & update goals: Workstation dashboard and My Account.
  • Change forum username: My Account → Community Forum Identity.
  • Change password: My Account → Security.
  • Manage billing: My Account → Membership & Billing (Stripe portal).
  • Display units: Preferences for length, pressure, and mass units are stored with your tracking profile.

To request account deletion or export of your data, contact Atlas Biometrics support through your registered email. Deletion removes the identity vault link; encrypted tracking rows may be orphaned or purged according to retention policy.

9. Legal scope & health data

Atlas Biometrics provides personal logging, data tracking, and educational telemetry for athletic pelvic-core conditioning. The platform does not diagnose, treat, cure, or prevent disease and does not provide clinical medical advice.

Atlas Biometrics LLC is not a HIPAA-covered entity and does not operate as a medical record system. Our privacy architecture is designed to reduce identifiability and protect sensitive self-reported logs — especially in the event of a database breach — but it is not a substitute for legal compliance review in regulated healthcare contexts.

Changes to this policy

We may update this policy as the platform evolves. Material changes will be reflected by updating the effective date at the top of this page. Continued use of Atlas after changes constitutes acceptance of the revised policy.

10. Contact

Questions about this privacy policy or how your data is handled may be directed to [email protected]. Subscription terms are in our Terms of Service.

← Back to Atlas home  ·  Sign in  ·  My Account

EDUCATIONAL DATA LOGISTICS DISCLAIMER

The Atlas Biometrics platform is designed for personal logging and educational telemetry — not medical diagnosis or treatment. Consult a healthcare professional before advanced conditioning programs.

Legal & Access

  • Privacy Policy
  • Terms of Service
  • Create Account
  • Sign In
© 2026 Atlas Biometrics LLC. Registered in Wyoming. All rights reserved.