ATLAS — Privacy Policy
Effective date: June 24, 2026 Last updated: July 20, 2026
This Privacy Policy explains how CupidCoach LLC, a Wyoming limited liability company doing business as "ATLAS" ("ATLAS," "we," "us," or "our"), collects, uses, shares, and protects personal information when you use the ATLAS fitness coaching platform, including our website at https://builtbyatlas.org, our installable progressive web app (PWA), any future native iOS or Android applications, and related features and services (collectively, the "Service").
Because the Service involves sensitive health and fitness information — including body metrics, progress and body photos, food and training logs, and synced wearable health metrics — we treat that information as sensitive / special-category personal data and apply heightened protections. Please read this Policy together with our [Terms of Service](/terms).
1. Who We Are / Data Controller
1.1. The data controller (and, where applicable, the "business" under US law) responsible for your personal information is:
CupidCoach LLC (operating as ATLAS)
1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801, USA
Email: support@builtbyatlas.org
Privacy contact: support@builtbyatlas.org
1.2. EU/UK representative and DPO. We have not appointed a Data Protection Officer and not appointed an EU/UK representative under Article 27 GDPR/UK GDPR.
1.3. For most processing we act as a controller. Where we process information on behalf of a coach or business customer, we may act as a processor; different terms may apply in that case.
2. Scope
2.1. This Policy applies to personal information we process about: (a) visitors to our website/app; (b) registered users and subscribers; (c) coaches and prospective coaches (in part); and (d) people whose information is included in User Content.
2.2. The Service is intended for users 18 and older in (primarily) the United States and the United Kingdom. See Section 14 (Children).
2.3. This Policy does not apply to third-party services we link to or that you connect (such as wearables or app stores), which have their own privacy practices. See Section 6.
3. What We Collect
We collect the following categories of personal information, depending on how you use the Service:
3.1. Account and profile data. Name, email address, username, password/credentials (managed via our authentication provider), date of birth or age-verification signal (to confirm you are 18+), profile photo, time zone, language, country, subscription tier, and preferences/settings.
3.2. Health and fitness data (sensitive / special-category). This is core to the Service and includes:
- Body metrics: height, weight, body measurements, body-composition estimates, age, sex/gender (as you provide), activity level, and goals.
- Progress and body photos: images you upload to track progress, which may reveal physical characteristics and health information.
- Nutrition data: food and meal logs entered manually, via barcode scan, AI photo/label scan, or voice/natural-language; calorie and macronutrient intake and targets; dietary preferences, restrictions, allergies, and notes.
- Training data: workout plans, exercises, sets, reps, weights, and related logs.
- Habits and check-ins: habit tracking, weekly check-in responses, and self-reported wellbeing or lifestyle information you choose to share.
- Menstrual cycle data (optional, opt-in only): if you enable the optional cycle-tracking feature, the limited cycle information described in Section 3.11, which receives additional protections.
3.3. Wearable / health-sync data. If you choose to connect a wearable device or health platform — including Apple Health (HealthKit) on iOS — we may receive metrics such as steps, activity, heart rate, heart-rate variability, sleep, calories burned, and similar health data, subject to your authorization and the third party's terms. Health-sync data (including HealthKit data) is used only to provide the Service's features to you; it is never used for marketing or advertising and never shared with third parties for such purposes.
3.4. Payment data. When you subscribe, payment is processed by a third-party, PCI-compliant payment processor. We do not collect or store your full payment-card number. We may receive limited billing information from the processor, such as your name, billing country/postal code, the last four digits and type of card, subscription status, and transaction history, to manage your subscription.
3.5. Communications data. Messages, weekly check-ins, support requests, video-call participation (we do not record video calls by default; if recording is ever enabled, you will be notified in advance and, where required, asked to consent), community posts/comments, and content you send to coaches or staff. In particular:
- Direct messages with your coach. If your plan includes coach messaging, the content of your messages (and related metadata such as timestamps and read state) is stored on our systems. Coach messages are not end-to-end encrypted: they are visible to your coach and to authorized ATLAS platform administrators, and may be reviewed for support, safety, moderation, and abuse prevention. If message attachments are introduced, they will be handled the same way (including image moderation).
- Video calls. One-on-one coaching calls take place in third-party video rooms — currently Jitsi Meet (meet.jit.si) — opened from the app. We do not record calls, and we do not receive call audio or video. While you are in a room, the room provider processes your data under its own privacy policy (see Section 6.9). Calls run over the internet; no phone numbers are used or collected for calls.
3.6. Device and usage data. IP address, device and browser type, operating system, device identifiers, app version, pages/features used, actions taken, referring URLs, crash and diagnostic logs, and timestamps. Collected via our analytics and infrastructure providers.
3.7. Cookies and similar technologies. Cookies, local storage, SDKs, and similar technologies used for authentication, security, preferences, and analytics. See Section 13.
3.8. Coarse / approximate location. We may infer coarse location (for example, country or region) from your IP address or billing information for pricing currency, security, and compliance. We do not collect precise GPS location unless you explicitly enable a feature that requires it.
3.9. AI inputs and outputs. The content you submit to AI Features (food descriptions, photos of food or labels, body metrics, questions) and the outputs generated (estimates, suggestions). See Section 5.
3.10. Information from others. If a coach or another user includes information about you in their content, or if you are invited to a group, we may receive information that way.
3.11. Menstrual cycle data (optional, opt-in only). If you register as female, you may optionally enable cycle tracking. The feature is off by default and activates only after you give explicit, separate consent on a dedicated consent screen — independent of your acceptance of the Terms or this Policy.
- What we collect. Only: the date your last period started, your average cycle length, your typical period length, and the dates of periods you log. Nothing else — no symptom diaries, no basal body temperature, no sexual-activity or partner data.
- How it is protected. Your period dates and cycle parameters are encrypted at the application layer with a dedicated key (AES-256-GCM) before they are stored, in their own database tables — the database, its query logs, and its backups hold only ciphertext for these values. Derived phase context (for example, "luteal phase") may additionally appear, in readable form, inside content generated for you alone — your analysis briefs, in-app notifications, and ATLAS assistant replies — all of which are covered by the deletion controls below.
- What we use it for — and nothing else. Predicting your current cycle phase to adjust your own calorie/carbohydrate targets and training suggestions, and explaining those adjustments to you. Cycle data is never used for marketing, advertising, or promotional targeting; it is never sent to analytics providers; and it is never sold or shared with third parties beyond the processing needed to run the feature for you.
- AI features. Under your cycle consent, your derived phase only (for example, "luteal, day 22") — never your raw period dates or history — may be included in the context of your ATLAS assistant conversations and your personal analysis briefs (Section 5.6). Push-notification text never includes cycle information.
- Your coach. Your coach cannot see any cycle information unless you turn on "Share with my coach" in Settings (off by default). If you enable it, your coach sees only your current phase — never your period dates or history.
- Your controls. You can pause predictions at any time, and "Delete all cycle data" in Settings permanently erases your cycle history — your period dates, cycle parameters, derived analysis briefs, and related notifications — separately from, and without affecting, your account. Replies already sent to you by the ATLAS assistant that referenced your phase remain part of your own chat history (as disclosed on the consent screen) and are removed when your account is deleted. Declining or deleting cycle tracking never limits the rest of the Service. We retain the consent record itself (which contains no health values) to evidence lawful processing.
3.12. Coach visibility of health and activity data (on by default, with opt-out). If you have a coach, your coach needs visibility of your data to deliver the coaching service.
- What your coach sees by default. The health data you have chosen to sync — for example, sleep, resting heart rate, steps, and workouts from Apple Health (HealthKit) — and your in-app activity, such as logging streaks and adherence.
- Your controls. You can turn this off at any time with the "Share health & activity with your coach" toggle in Settings. Turning it off stops your coach from seeing this data going forward (though it may limit how effectively your coach can support you). Coaches may access this data only for coaching purposes — never for marketing, and never outside the coaching relationship.
- Legal bases. We share this data with your coach on the basis of performance of the coaching contract (GDPR Article 6(1)(b)) and, for special-category health data, your explicit consent (Article 9(2)(a)), which we collect when you connect a health source such as HealthKit. You can withdraw that consent at any time by disconnecting the source or using the toggle above (Section 9).
- Cycle data is different. Menstrual-cycle information is never included in this default sharing. It remains separately opt-in under Section 3.11: your coach cannot see any cycle information unless you additionally turn on the dedicated cycle "Share with my coach" setting.
We do not intentionally collect government-ID numbers, precise geolocation tracking, or payment-card numbers, and we ask that you not submit sensitive information we do not request.
4. How and Why We Use Your Information, and Legal Bases
4.1. We use personal information for the purposes below. Where the UK GDPR / EU GDPR applies, we rely on the legal bases noted. For special-category (health) data, our primary basis is your explicit consent (GDPR Article 9(2)(a)), in addition to a basis under Article 6.
| Purpose | What we do | GDPR Art. 6 basis | Art. 9 basis (health data) |
|---|---|---|---|
| Provide the Service | Create/maintain your account; deliver nutrition/training/coaching features; generate targets; store logs and photos; sync wearables | Performance of a contract (6(1)(b)) | Explicit consent (9(2)(a)) |
| AI Features | Process inputs to estimate calories/macros, recognize foods, transcribe voice, power AI assistant/copilot | Contract (6(1)(b)); legitimate interests (6(1)(f)) | Explicit consent (9(2)(a)) |
| Coaching & communications | Enable messaging, check-ins, video calls, content delivery | Contract (6(1)(b)) | Explicit consent (9(2)(a)) |
| Coach visibility of health & activity data | Show your synced health metrics and in-app activity to your coach so they can coach you (on by default; opt-out in Settings — Section 3.12) | Performance of the coaching contract (6(1)(b)) | Explicit consent (9(2)(a)), collected when you connect a health source |
| Payments & subscriptions | Process payments, manage renewals, prevent fraud (via our payment processor) | Contract (6(1)(b)); legitimate interests (6(1)(f)) | n/a |
| Service improvement & analytics | Understand usage, debug, improve features and safety | Legitimate interests (6(1)(f)); consent where required for analytics cookies | Explicit consent where health data is involved |
| Security & abuse prevention | Protect accounts, detect fraud/abuse, enforce Terms | Legitimate interests (6(1)(f)); legal obligation (6(1)(c)) | Substantial public interest / consent (as applicable) |
| Customer support | Respond to requests and troubleshoot | Contract (6(1)(b)); legitimate interests (6(1)(f)) | Explicit consent where health data is involved |
| Marketing & communications | Send service emails (always) and, with consent where required, marketing | Consent (6(1)(a)) for marketing; legitimate interests for service messages | n/a |
| Legal & compliance | Comply with law, respond to lawful requests, establish/defend legal claims | Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) | Establishment/exercise/defense of legal claims (9(2)(f)) |
4.2. Legitimate interests. Where we rely on legitimate interests, we balance them against your rights and interests. You may object as described in Section 9.
4.3. Consent and withdrawal. Where we rely on consent (including explicit consent for health data and consent for certain cookies/marketing), you may withdraw it at any time (Section 9). Withdrawal does not affect processing before withdrawal, and may limit or prevent your use of health-dependent features.
4.4. No automated decisions with legal effect. AI Features generate estimates and suggestions for your review; we do not make decisions producing legal or similarly significant effects about you solely by automated means without a lawful basis and appropriate safeguards.
5. AI Processing
5.1. To provide AI Features, the inputs you submit — including food descriptions and photos, photos of nutrition labels, voice/natural-language input, body metrics, and questions to the AI assistant — are transmitted to and processed by third-party AI / machine-learning service providers to generate outputs such as calorie/macro estimates, food recognition, transcriptions, and plan/meal suggestions.
5.2. Purpose limitation. We use AI providers to process your inputs only to provide the requested features. We seek to use providers under agreements that restrict their use of your inputs (for example, not using your content to train their general models without authorization).
5.3. Sensitive inputs. Because AI inputs may include health/special-category data and body photos, we process them under your explicit consent (Section 4) and treat them as sensitive. Do not submit information to AI Features that you are not comfortable processing in this way.
5.4. International transfers. AI processing may occur in the United States or other countries. See Section 7.
5.5. Accuracy. AI outputs are estimates and general guidance, may be inaccurate, and must be verified by you, as explained in the [Terms of Service](/terms).
5.6. Proactive analysis ("ATLAS Intelligence" briefs). The Service generates proactive daily and weekly analysis briefs from your logged data (nutrition, training, habits, readiness, wearable metrics you have synced, and — only if you have enabled cycle tracking — your derived cycle phase). Briefs are generated by the AI providers described above under the same protections and purpose limitations, are visible only to you inside the app, and are never used for advertising or shared with other users. Push-notification text announcing a brief never includes your health specifics.
6. Sharing and Sub-Processors
6.1. We do not sell your personal information (see Section 11). We share personal information only as described here:
6.2. Service providers / sub-processors. We use trusted vendors to operate the Service. They process personal information on our behalf under contract and may only use it to provide services to us. Current (or planned) sub-processors include:
| Category of service provider | Purpose |
|---|---|
| Payment processing | Process subscription payments and manage billing (a PCI-compliant processor; we never handle full card numbers) |
| AI / machine-learning services | Generate AI features — calorie/macro estimates, food recognition from photos/labels, voice transcription, and the AI assistant/copilot — from the inputs you submit |
| Cloud hosting & database | Host the Service and securely store your account and app data |
| Authentication / identity | Verify your identity and secure your sign-in |
| Email & SMS delivery | Send transactional emails, reminders, and notifications |
| Product analytics | Understand usage and improve the Service |
| Media storage & streaming | Store and serve images and videos (e.g., progress photos, demo videos) |
| Scheduling | Power coaching-call booking |
We engage these providers under contracts that require them to safeguard your information and use it only to provide services to us. We may change providers from time to time; we describe them here by category rather than by name.
6.3. Coaches and other users. If you have a coach or are in a group/community, we share relevant information (for example, your logs, check-ins, progress photos, and messages) with your coach and, where you choose, with group members or the community feed — according to your settings and choices. You control what you post publicly. Your coach's default visibility of your synced health data and in-app activity — and the Settings toggle that turns it off — is described in Section 3.12; cycle data remains separately opt-in (Section 3.11). Direct messages with your coach are also visible to authorized platform administrators, as described in Section 3.5.
6.4. Connected third parties. If you connect a wearable or health platform, data flows according to your authorization and that third party's terms.
6.5. Legal and safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith it is necessary to comply with law, enforce our Terms, protect the rights, safety, or property of ATLAS, users, or the public, or detect and prevent fraud or security issues.
6.6. Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy or a successor policy with comparable protections.
6.7. With your direction. We share information at your request or with your consent.
6.8. Aggregated / de-identified data. We may create and use aggregated or de-identified information that does not identify you, and we will not attempt to re-identify it except as permitted by law.
6.9. Video calls (third-party rooms). One-on-one coaching calls take place in third-party video rooms — currently Jitsi Meet (meet.jit.si) — opened from the app. When you join a room, the room provider processes data (such as your IP address, device information, and the call's audio/video streams) under its own privacy policy, which we encourage you to review. We do not record calls and do not receive recordings, and calls do not use or collect phone numbers.
6.10. Testimonials (only with your consent). With your prior consent, we may feature member transformations — for example, a photo, your first name, and a quote — on our public landing page or in marketing materials. Consent is optional, is never a condition of the Service, and can be withdrawn at any time by emailing support@builtbyatlas.org; we will then remove the testimonial from the pages we control within a reasonable time. Legal basis: consent (GDPR Article 6(1)(a) and, for any health-related content such as transformation photos, explicit consent under Article 9(2)(a)).
6.11. Feature previews use sample data. Previews of paid features shown to free or lower-tier users are populated with sample, illustrative data only. We never use your real personal data — or any other member's — to advertise or preview features to other users (testimonials under Section 6.10, which require consent, are the only exception).
7. International Data Transfers
7.1. We are based in the United States, and personal information is stored and processed in the US and potentially in other countries where our sub-processors operate.
7.2. If you are in the UK, the EU/EEA, or another region with data-transfer restrictions, transferring your information to the US and elsewhere means it may be processed in a country that may not provide the same level of data protection as your home country.
7.3. Where required, we implement appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum/IDTA, and we assess our providers' protections. You may request information about these safeguards using the contact details in Section 16.
8. Data Retention
8.1. We retain personal information for as long as needed to provide the Service, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements.
8.2. General periods:
- Account, profile, health/fitness data, photos, logs, and coach direct messages: for the life of your account, and deleted or de-identified within 30–90 days after account deletion, except where longer retention is required (see below).
- Cycle-tracking data: until you delete it with the standalone "Delete all cycle data" control in Settings, or until account deletion — whichever comes first. Deletion also erases derived analysis briefs and related notifications immediately; encrypted residues in backups are overwritten on our normal backup cycle (and remain unreadable ciphertext throughout).
- Payment/transaction records: retained as required for tax, accounting, and legal purposes, typically 6–7 years.
- Support communications: 24 months after resolution.
- Analytics/usage logs: 14–25 months, often in aggregated form.
- Backups: residual copies may persist in encrypted backups for up to 30–90 days before being overwritten.
- AI inputs/outputs: AI-generated content saved to your account (meal logs, assistant conversations, analysis briefs) is retained like other account data above. We use AI providers under commercial terms that restrict use of your inputs to providing the requested service and do not permit training their general models on your content; providers may retain inputs transiently for abuse prevention per their policies.
8.3. We may retain limited information after deletion where necessary to comply with law, prevent fraud or abuse, enforce our Terms, or establish, exercise, or defend legal claims. When information is no longer needed, we delete or de-identify it.
9. Your Rights
9.1. Depending on where you live and applicable law, you may have the following rights regarding your personal information:
- Access — obtain confirmation of and a copy of the personal information we hold about you.
- Portability / export — receive certain information in a portable, machine-readable format, and (where technically feasible) have it transmitted to another controller.
- Correction (rectification) — correct inaccurate or incomplete information.
- Deletion (erasure) — request deletion of your personal information (see Section 15), subject to legal exceptions.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Restriction — request that we restrict processing in certain circumstances.
- Withdraw consent — withdraw consent (including explicit consent for health data and consent for cookies/marketing) at any time, without affecting prior processing.
- Not be subject to certain automated decision-making — as applicable.
- Non-discrimination — we will not discriminate against you for exercising your rights.
9.2. How to exercise. Submit a request via in-app privacy controls, by emailing support@builtbyatlas.org, or by post (Section 16). We may need to verify your identity before acting. You may use an authorized agent where the law allows, with proof of authorization.
9.3. Timing. We respond within the time required by applicable law (generally within one month under UK/EU GDPR, extendable for complex requests; within 45 days under CCPA/CPRA, extendable by another 45 days). Requests are free except where the law permits a reasonable fee for excessive or repetitive requests.
9.4. Appeals (US states). Where state law provides a right to appeal a decision on your request, you may appeal by contacting support@builtbyatlas.org; we will respond as required by law.
10. California Privacy Rights (CCPA / CPRA)
10.1. If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights:
- the right to know/access the categories and specific pieces of personal information collected, the sources, purposes, and categories of third parties with whom it is shared;
- the right to delete personal information (subject to exceptions);
- the right to correct inaccurate personal information;
- the right to opt out of the "sale" or "sharing" of personal information and to limit the use of "sensitive personal information"; and
- the right to non-discrimination for exercising your rights.
10.2. We do NOT sell your personal information, and we do not "sell" or "share" it for cross-context behavioral advertising as those terms are defined under the CPRA.
10.3. Sensitive personal information. Health and fitness data we collect may be "sensitive personal information." We use it only to provide the Service and related purposes permitted by the CPRA, and not for purposes requiring a "limit" right. We do not use or disclose it to infer characteristics about you.
10.4. Categories. The categories of personal information we collect, the purposes, sources, and recipients are described in Sections 3, 4, and 6. We disclose personal information to service providers/sub-processors for business purposes (Section 6).
10.5. Exercising rights. Use the methods in Section 9.2. We will verify your request and respond within CCPA timelines. You may designate an authorized agent.
11. Washington My Health My Data Act (and Similar Consumer-Health Laws)
11.1. The Washington My Health My Data Act ("MHMD Act") and similar laws (for example, Nevada SB 370, and the consumer-health provisions of other US state laws) provide heightened protections for "consumer health data." Much of the data we process (body metrics, nutrition and training logs, progress photos, and wearable health metrics) may qualify as consumer health data.
11.2. Consent. We collect and process consumer health data only with your consent for the purposes described in this Policy, and we obtain separate authorization before any sharing or sale that is not otherwise exempt. We do not sell consumer health data.
11.3. Your consumer-health rights. Where the MHMD Act (or a similar law) applies, you have the right to: (a) confirm whether we collect, share, or sell your consumer health data and access it; (b) withdraw consent to its collection and sharing; and (c) request that we delete your consumer health data. We will honor deletion requests and notify our processors/affiliates to delete it, subject to limited legal exceptions.
11.4. No geofencing. We do not use geofences around healthcare facilities to track or collect consumer health data or to send related advertising.
11.5. Exercising rights. Use the methods in Section 9.2 / Section 16. A dedicated consumer-health rights contact is support@builtbyatlas.org.
12. UK / EU GDPR Rights and Complaints
12.1. If you are in the UK, the EU, or the EEA, you have the GDPR/UK GDPR rights listed in Section 9, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
12.2. For special-category (health) data, we rely on your explicit consent (Article 9(2)(a)) or another applicable Article 9 condition. You may withdraw consent at any time (Section 9.1).
12.3. Right to complain. You have the right to lodge a complaint with a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) — https://ico.org.uk, helpline 0303 123 1113. In the EU/EEA, you may contact your local data protection authority. We would, however, appreciate the chance to address your concerns first via support@builtbyatlas.org.
12.4. EU/UK representative. We have not appointed an Article 27 representative.
13. Cookies and Analytics
13.1. We use cookies and similar technologies (local storage, SDKs, pixels) for: (a) strictly necessary purposes (authentication, security, load balancing); (b) functional purposes (remembering preferences); and (c) analytics (understanding usage and improving the Service, via our analytics provider).
13.2. What we actually use. The Service uses strictly necessary cookies/local storage (authentication via our identity provider, security, session state) and first-party product analytics. We do not run third-party advertising cookies or cross-site tracking pixels. Because the non-essential technologies we use are limited to first-party analytics, we do not currently operate a separate cookie banner; where a regulator requires consent for analytics in your region, contact us and we will honor an opt-out (Section 9).
13.3. Do Not Track / Global Privacy Control. We do not currently respond to browser "Do Not Track" signals. Because we do not sell or share personal information for cross-context behavioral advertising, Global Privacy Control (GPC) opt-out-of-sale signals do not change our processing; where a GPC signal must be honored as an opt-out under applicable law, we treat it accordingly.
13.4. Analytics providers. Our analytics provider(s) process device and usage data on our behalf; we configure them to limit data collection where feasible, and health data — including all cycle-tracking data — is never sent to analytics. See Section 6 for the provider list.
13.5. The cookies and similar technologies we use, their purposes, and their general durations are described in this Section 13; for questions about a specific cookie, contact support@builtbyatlas.org.
14. Children
14.1. The Service is for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18.
14.2. We operate a hard age gate at registration (Section 2 of the [Terms of Service](/terms)). If we learn that we have collected personal information from a person under 18, we will delete it and terminate the account.
14.3. If you believe a minor has provided us personal information, contact support@builtbyatlas.org and we will take appropriate steps. (We also comply with the US Children's Online Privacy Protection Act (COPPA), which concerns children under 13; the Service is not intended for anyone under 18.)
15. How to Delete Your Account
15.1. In-app self-service deletion. You can delete your account at any time using the account-deletion feature in your account settings (provided in-app, as required by Apple's App Store guidelines for accounts created in the app). This initiates deletion of your account and associated personal information.
15.2. By request. You may also request deletion by emailing support@builtbyatlas.org or writing to the postal address in Section 16. We may verify your identity before acting.
15.3. What happens. Upon a verified deletion request, we delete or de-identify your personal information within the period described in Section 8, except information we must retain to comply with law, complete transactions, prevent fraud/abuse, ensure security, or establish/exercise/defend legal claims. Backups are purged on our normal backup cycle. We will instruct relevant sub-processors to delete your information where required.
15.4. Effect on subscription. Deletion ends future access; it does not by itself entitle you to a refund or relieve minimum-term obligations already incurred (see the [Terms of Service](/terms)).
15.5. Cycle data (standalone deletion). Independently of account deletion, you can permanently erase all cycle-tracking data at any time using the "Delete all cycle data" control in Settings — see Section 3.11. This works even if you keep your account and every other feature.
16. Contact and How to Exercise Your Rights
16.1. To exercise any right, ask a question, or raise a concern about privacy, contact us:
Privacy — CupidCoach LLC (operating as ATLAS)
Email (privacy): support@builtbyatlas.org
General: support@builtbyatlas.org
Post: 1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801, USA
Website / in-app privacy controls: https://builtbyatlas.org
16.2. We will respond within the timeframes required by applicable law (Section 9.3) and may need to verify your identity. If you are in the UK/EU and unsatisfied, you may complain to the ICO or your local authority (Section 12.3).
17. Security
17.1. We implement technical and organizational measures designed to protect personal information, including encryption in transit (TLS) and, where appropriate, at rest, access controls and least-privilege practices, authentication via a dedicated provider, secure cloud infrastructure, logging and monitoring, and use of PCI-compliant payment processing so we do not handle card numbers.
17.2. No method is perfectly secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for content you choose to share with coaches, groups, or the community.
17.3. We restrict access to personal information to personnel and providers who need it to operate the Service and who are bound by confidentiality obligations.
18. Data Breach Notification
18.1. We maintain procedures to detect, investigate, and respond to security incidents. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals as required by applicable law, including:
- UK/EU GDPR: notify the ICO or relevant authority without undue delay and within 72 hours where feasible, and notify affected individuals where there is a high risk to their rights and freedoms;
- US state laws (including California and Washington): notify affected residents and, where required, regulators within the timeframes those laws require.
18.2. Notifications will describe, to the extent known, the nature of the incident, the information involved, likely consequences, and steps we are taking and that you can take. We will keep records of breaches as required.
19. Changes to This Policy
19.1. We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email and/or in-app notice) and update the "Last updated" date before the changes take effect.
19.2. Where required by law, we will obtain your consent to material changes affecting how we use sensitive or health data. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy, except where consent is required.
19.3. We encourage you to review this Policy periodically. Prior versions are available on request.