Your data and your choices.
Effective September 19, 2026. Olympus Atlas is operated by Avalon Labs LLC, a Delaware company. This policy describes the current website and research terminal.
Your privacy choices
Optional analytics is off in this browser. Atlas works either way. When enabled, HeyCatch measures visits and interactions. We do not send your name or email as analytics profile properties.
Information we handle
When you create an account, we receive your email, account ID, verified sign-in information, and profile details supplied by you or your sign-in provider. Supabase manages authentication, passwords and sessions. Atlas stores your plan, settings, alert filters, integration destinations, and API-key metadata. API keys and webhook signing secrets are stored as digests rather than recoverable keys.
If you contact support, Resend receives your email address, message, and attachments. Avoid sending passwords, API keys, financial account credentials or sensitive personal information. Support messages stay in Resend’s receiving dashboard.
Our hosting and authentication providers process request, device, IP-address and security information to operate the service. If you allow optional analytics, HeyCatch measures page visits, interactions, device/browser information and campaign attribution. Signed-in activity can be associated with your internal Atlas account ID and signup date. We do not send your name or email as analytics profile properties. Earlier analytics collected those fields; removal of historical provider data requires a privacy request.
Official-source economic releases and institutional map locations are research data. Map dots show publishers, not your location. We do not request precise device location, health data, biometrics, or financial account credentials.
Why we use it
We use account information to provide and secure access, save preferences, manage integrations, respond to support and privacy requests, and investigate abuse. Optional analytics helps us understand product use. Product-update email preferences are separate and off by default.
We do not sell personal information or use it for cross-site targeted advertising. We do not use account data to make automated decisions about credit, employment, insurance or other similarly significant eligibility. If these practices change, we will update this policy and obtain consent where required.
Who processes information
Railway hosts Atlas. Supabase provides authentication and database services. HeyCatch provides optional analytics. Resend processes account verification, recovery and support email. Stripe supports the billing integration; public paid subscriptions are currently unavailable. When you use Google sign-in, Google also processes that sign-in under its own policies.
These providers receive information needed for their functions. Providers can process data in the United States and other locations covered by their services. Hosting, authentication and analytics providers may recognize devices across online services under their own policies. Our optional analytics remains off without your choice. We do not authorize advertising use of your account information.
If enabled, a delivery integration you choose receives its destination and the required source-linked event. Automated customer email and webhook delivery remain disabled today. We may disclose information when legally required, to protect the service or others, or as part of a business transfer subject to applicable protections.
Retention and permanent deletion
We retain account information while it is needed to provide your account, resolve a request, or meet a specific legal obligation. A deletion request starts a review; it is not itself a completed deletion. After review, the live-account purge removes the sign-in, sessions, profile, preferences, API keys, billing links and account-linked delivery records. It does not merely mark those records as hidden. Shared public-source research and its revision history remain.
Support messages, historical analytics, provider logs and backup copies require separate checks. Deleted live data can remain in restricted backups until those backups expire. Backup retention and provider deletion windows are still being verified; we do not promise immediate removal from every provider or backup. Before restoring account data, we must reapply recorded deletions before reopening access.
We keep a restricted deletion work record with the account reference and contact details while resolving provider copies and recovery safeguards. Those details are removed when the checks finish. Any record retained for a legal obligation or dispute must have a documented purpose and retention period; we will explain applicable exceptions in our response. We do not describe pseudonymous account IDs as anonymous.
Access, correction, deletion and appeals
In Account, you can download an account-data file and request deletion after signing in again. The file includes Atlas account data and this browser’s saved desks; provider-held messages, analytics and security records require a separate request.
For access, correction, deletion, a portable copy, an authorized-agent request, or a privacy question, email support@olympusatlas.com. Visitors without accounts can use the same address. We verify identity proportionately before disclosing or deleting personal information. Do not send a password or identity document unless a secure verification process has specifically been arranged.
We aim to respond within 45 days, or sooner where required. If more time is legally permitted and needed, we explain the reason and timing. If a request is denied, reply with “Privacy appeal” for review and a written explanation. Applicable state law may provide additional rights, including a complaint to your state attorney general. We do not charge for ordinary requests or discriminate against you for exercising privacy rights.
Children and policy changes
Atlas is intended for adults conducting economic research and is not directed to children under 13. If you believe a child provided personal information, contact support so we can investigate and address it. We do not ask for a date of birth just to browse the site.
We publish policy changes here with a new effective date. For a material change affecting existing accounts, we will also provide a prominent product notice or email as appropriate before the new practice begins, and request consent where required.
