← Back to ATLAS

ATLAS — Privacy Policy

Effective date: June 24, 2026 Last updated: July 20, 2026

This Privacy Policy explains how CupidCoach LLC, a Wyoming limited liability company doing business as "ATLAS" ("ATLAS," "we," "us," or "our"), collects, uses, shares, and protects personal information when you use the ATLAS fitness coaching platform, including our website at https://builtbyatlas.org, our installable progressive web app (PWA), any future native iOS or Android applications, and related features and services (collectively, the "Service").

Because the Service involves sensitive health and fitness information — including body metrics, progress and body photos, food and training logs, and synced wearable health metrics — we treat that information as sensitive / special-category personal data and apply heightened protections. Please read this Policy together with our [Terms of Service](/terms).


1. Who We Are / Data Controller

1.1. The data controller (and, where applicable, the "business" under US law) responsible for your personal information is:

CupidCoach LLC (operating as ATLAS)
1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801, USA
Email: support@builtbyatlas.org
Privacy contact: support@builtbyatlas.org

1.2. EU/UK representative and DPO. We have not appointed a Data Protection Officer and not appointed an EU/UK representative under Article 27 GDPR/UK GDPR.

1.3. For most processing we act as a controller. Where we process information on behalf of a coach or business customer, we may act as a processor; different terms may apply in that case.


2. Scope

2.1. This Policy applies to personal information we process about: (a) visitors to our website/app; (b) registered users and subscribers; (c) coaches and prospective coaches (in part); and (d) people whose information is included in User Content.

2.2. The Service is intended for users 18 and older in (primarily) the United States and the United Kingdom. See Section 14 (Children).

2.3. This Policy does not apply to third-party services we link to or that you connect (such as wearables or app stores), which have their own privacy practices. See Section 6.


3. What We Collect

We collect the following categories of personal information, depending on how you use the Service:

3.1. Account and profile data. Name, email address, username, password/credentials (managed via our authentication provider), date of birth or age-verification signal (to confirm you are 18+), profile photo, time zone, language, country, subscription tier, and preferences/settings.

3.2. Health and fitness data (sensitive / special-category). This is core to the Service and includes:

3.3. Wearable / health-sync data. If you choose to connect a wearable device or health platform — including Apple Health (HealthKit) on iOS — we may receive metrics such as steps, activity, heart rate, heart-rate variability, sleep, calories burned, and similar health data, subject to your authorization and the third party's terms. Health-sync data (including HealthKit data) is used only to provide the Service's features to you; it is never used for marketing or advertising and never shared with third parties for such purposes.

3.4. Payment data. When you subscribe, payment is processed by a third-party, PCI-compliant payment processor. We do not collect or store your full payment-card number. We may receive limited billing information from the processor, such as your name, billing country/postal code, the last four digits and type of card, subscription status, and transaction history, to manage your subscription.

3.5. Communications data. Messages, weekly check-ins, support requests, video-call participation (we do not record video calls by default; if recording is ever enabled, you will be notified in advance and, where required, asked to consent), community posts/comments, and content you send to coaches or staff. In particular:

3.6. Device and usage data. IP address, device and browser type, operating system, device identifiers, app version, pages/features used, actions taken, referring URLs, crash and diagnostic logs, and timestamps. Collected via our analytics and infrastructure providers.

3.7. Cookies and similar technologies. Cookies, local storage, SDKs, and similar technologies used for authentication, security, preferences, and analytics. See Section 13.

3.8. Coarse / approximate location. We may infer coarse location (for example, country or region) from your IP address or billing information for pricing currency, security, and compliance. We do not collect precise GPS location unless you explicitly enable a feature that requires it.

3.9. AI inputs and outputs. The content you submit to AI Features (food descriptions, photos of food or labels, body metrics, questions) and the outputs generated (estimates, suggestions). See Section 5.

3.10. Information from others. If a coach or another user includes information about you in their content, or if you are invited to a group, we may receive information that way.

3.11. Menstrual cycle data (optional, opt-in only). If you register as female, you may optionally enable cycle tracking. The feature is off by default and activates only after you give explicit, separate consent on a dedicated consent screen — independent of your acceptance of the Terms or this Policy.

3.12. Coach visibility of health and activity data (on by default, with opt-out). If you have a coach, your coach needs visibility of your data to deliver the coaching service.

We do not intentionally collect government-ID numbers, precise geolocation tracking, or payment-card numbers, and we ask that you not submit sensitive information we do not request.


4. How and Why We Use Your Information, and Legal Bases

4.1. We use personal information for the purposes below. Where the UK GDPR / EU GDPR applies, we rely on the legal bases noted. For special-category (health) data, our primary basis is your explicit consent (GDPR Article 9(2)(a)), in addition to a basis under Article 6.

PurposeWhat we doGDPR Art. 6 basisArt. 9 basis (health data)
Provide the ServiceCreate/maintain your account; deliver nutrition/training/coaching features; generate targets; store logs and photos; sync wearablesPerformance of a contract (6(1)(b))Explicit consent (9(2)(a))
AI FeaturesProcess inputs to estimate calories/macros, recognize foods, transcribe voice, power AI assistant/copilotContract (6(1)(b)); legitimate interests (6(1)(f))Explicit consent (9(2)(a))
Coaching & communicationsEnable messaging, check-ins, video calls, content deliveryContract (6(1)(b))Explicit consent (9(2)(a))
Coach visibility of health & activity dataShow your synced health metrics and in-app activity to your coach so they can coach you (on by default; opt-out in Settings — Section 3.12)Performance of the coaching contract (6(1)(b))Explicit consent (9(2)(a)), collected when you connect a health source
Payments & subscriptionsProcess payments, manage renewals, prevent fraud (via our payment processor)Contract (6(1)(b)); legitimate interests (6(1)(f))n/a
Service improvement & analyticsUnderstand usage, debug, improve features and safetyLegitimate interests (6(1)(f)); consent where required for analytics cookiesExplicit consent where health data is involved
Security & abuse preventionProtect accounts, detect fraud/abuse, enforce TermsLegitimate interests (6(1)(f)); legal obligation (6(1)(c))Substantial public interest / consent (as applicable)
Customer supportRespond to requests and troubleshootContract (6(1)(b)); legitimate interests (6(1)(f))Explicit consent where health data is involved
Marketing & communicationsSend service emails (always) and, with consent where required, marketingConsent (6(1)(a)) for marketing; legitimate interests for service messagesn/a
Legal & complianceComply with law, respond to lawful requests, establish/defend legal claimsLegal obligation (6(1)(c)); legitimate interests (6(1)(f))Establishment/exercise/defense of legal claims (9(2)(f))

4.2. Legitimate interests. Where we rely on legitimate interests, we balance them against your rights and interests. You may object as described in Section 9.

4.3. Consent and withdrawal. Where we rely on consent (including explicit consent for health data and consent for certain cookies/marketing), you may withdraw it at any time (Section 9). Withdrawal does not affect processing before withdrawal, and may limit or prevent your use of health-dependent features.

4.4. No automated decisions with legal effect. AI Features generate estimates and suggestions for your review; we do not make decisions producing legal or similarly significant effects about you solely by automated means without a lawful basis and appropriate safeguards.


5. AI Processing

5.1. To provide AI Features, the inputs you submit — including food descriptions and photos, photos of nutrition labels, voice/natural-language input, body metrics, and questions to the AI assistant — are transmitted to and processed by third-party AI / machine-learning service providers to generate outputs such as calorie/macro estimates, food recognition, transcriptions, and plan/meal suggestions.

5.2. Purpose limitation. We use AI providers to process your inputs only to provide the requested features. We seek to use providers under agreements that restrict their use of your inputs (for example, not using your content to train their general models without authorization).

5.3. Sensitive inputs. Because AI inputs may include health/special-category data and body photos, we process them under your explicit consent (Section 4) and treat them as sensitive. Do not submit information to AI Features that you are not comfortable processing in this way.

5.4. International transfers. AI processing may occur in the United States or other countries. See Section 7.

5.5. Accuracy. AI outputs are estimates and general guidance, may be inaccurate, and must be verified by you, as explained in the [Terms of Service](/terms).

5.6. Proactive analysis ("ATLAS Intelligence" briefs). The Service generates proactive daily and weekly analysis briefs from your logged data (nutrition, training, habits, readiness, wearable metrics you have synced, and — only if you have enabled cycle tracking — your derived cycle phase). Briefs are generated by the AI providers described above under the same protections and purpose limitations, are visible only to you inside the app, and are never used for advertising or shared with other users. Push-notification text announcing a brief never includes your health specifics.


6. Sharing and Sub-Processors

6.1. We do not sell your personal information (see Section 11). We share personal information only as described here:

6.2. Service providers / sub-processors. We use trusted vendors to operate the Service. They process personal information on our behalf under contract and may only use it to provide services to us. Current (or planned) sub-processors include:

Category of service providerPurpose
Payment processingProcess subscription payments and manage billing (a PCI-compliant processor; we never handle full card numbers)
AI / machine-learning servicesGenerate AI features — calorie/macro estimates, food recognition from photos/labels, voice transcription, and the AI assistant/copilot — from the inputs you submit
Cloud hosting & databaseHost the Service and securely store your account and app data
Authentication / identityVerify your identity and secure your sign-in
Email & SMS deliverySend transactional emails, reminders, and notifications
Product analyticsUnderstand usage and improve the Service
Media storage & streamingStore and serve images and videos (e.g., progress photos, demo videos)
SchedulingPower coaching-call booking

We engage these providers under contracts that require them to safeguard your information and use it only to provide services to us. We may change providers from time to time; we describe them here by category rather than by name.

6.3. Coaches and other users. If you have a coach or are in a group/community, we share relevant information (for example, your logs, check-ins, progress photos, and messages) with your coach and, where you choose, with group members or the community feed — according to your settings and choices. You control what you post publicly. Your coach's default visibility of your synced health data and in-app activity — and the Settings toggle that turns it off — is described in Section 3.12; cycle data remains separately opt-in (Section 3.11). Direct messages with your coach are also visible to authorized platform administrators, as described in Section 3.5.

6.4. Connected third parties. If you connect a wearable or health platform, data flows according to your authorization and that third party's terms.

6.5. Legal and safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith it is necessary to comply with law, enforce our Terms, protect the rights, safety, or property of ATLAS, users, or the public, or detect and prevent fraud or security issues.

6.6. Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy or a successor policy with comparable protections.

6.7. With your direction. We share information at your request or with your consent.

6.8. Aggregated / de-identified data. We may create and use aggregated or de-identified information that does not identify you, and we will not attempt to re-identify it except as permitted by law.

6.9. Video calls (third-party rooms). One-on-one coaching calls take place in third-party video rooms — currently Jitsi Meet (meet.jit.si) — opened from the app. When you join a room, the room provider processes data (such as your IP address, device information, and the call's audio/video streams) under its own privacy policy, which we encourage you to review. We do not record calls and do not receive recordings, and calls do not use or collect phone numbers.

6.10. Testimonials (only with your consent). With your prior consent, we may feature member transformations — for example, a photo, your first name, and a quote — on our public landing page or in marketing materials. Consent is optional, is never a condition of the Service, and can be withdrawn at any time by emailing support@builtbyatlas.org; we will then remove the testimonial from the pages we control within a reasonable time. Legal basis: consent (GDPR Article 6(1)(a) and, for any health-related content such as transformation photos, explicit consent under Article 9(2)(a)).

6.11. Feature previews use sample data. Previews of paid features shown to free or lower-tier users are populated with sample, illustrative data only. We never use your real personal data — or any other member's — to advertise or preview features to other users (testimonials under Section 6.10, which require consent, are the only exception).


7. International Data Transfers

7.1. We are based in the United States, and personal information is stored and processed in the US and potentially in other countries where our sub-processors operate.

7.2. If you are in the UK, the EU/EEA, or another region with data-transfer restrictions, transferring your information to the US and elsewhere means it may be processed in a country that may not provide the same level of data protection as your home country.

7.3. Where required, we implement appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum/IDTA, and we assess our providers' protections. You may request information about these safeguards using the contact details in Section 16.


8. Data Retention

8.1. We retain personal information for as long as needed to provide the Service, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements.

8.2. General periods:

8.3. We may retain limited information after deletion where necessary to comply with law, prevent fraud or abuse, enforce our Terms, or establish, exercise, or defend legal claims. When information is no longer needed, we delete or de-identify it.


9. Your Rights

9.1. Depending on where you live and applicable law, you may have the following rights regarding your personal information:

9.2. How to exercise. Submit a request via in-app privacy controls, by emailing support@builtbyatlas.org, or by post (Section 16). We may need to verify your identity before acting. You may use an authorized agent where the law allows, with proof of authorization.

9.3. Timing. We respond within the time required by applicable law (generally within one month under UK/EU GDPR, extendable for complex requests; within 45 days under CCPA/CPRA, extendable by another 45 days). Requests are free except where the law permits a reasonable fee for excessive or repetitive requests.

9.4. Appeals (US states). Where state law provides a right to appeal a decision on your request, you may appeal by contacting support@builtbyatlas.org; we will respond as required by law.


10. California Privacy Rights (CCPA / CPRA)

10.1. If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights:

10.2. We do NOT sell your personal information, and we do not "sell" or "share" it for cross-context behavioral advertising as those terms are defined under the CPRA.

10.3. Sensitive personal information. Health and fitness data we collect may be "sensitive personal information." We use it only to provide the Service and related purposes permitted by the CPRA, and not for purposes requiring a "limit" right. We do not use or disclose it to infer characteristics about you.

10.4. Categories. The categories of personal information we collect, the purposes, sources, and recipients are described in Sections 3, 4, and 6. We disclose personal information to service providers/sub-processors for business purposes (Section 6).

10.5. Exercising rights. Use the methods in Section 9.2. We will verify your request and respond within CCPA timelines. You may designate an authorized agent.


11. Washington My Health My Data Act (and Similar Consumer-Health Laws)

11.1. The Washington My Health My Data Act ("MHMD Act") and similar laws (for example, Nevada SB 370, and the consumer-health provisions of other US state laws) provide heightened protections for "consumer health data." Much of the data we process (body metrics, nutrition and training logs, progress photos, and wearable health metrics) may qualify as consumer health data.

11.2. Consent. We collect and process consumer health data only with your consent for the purposes described in this Policy, and we obtain separate authorization before any sharing or sale that is not otherwise exempt. We do not sell consumer health data.

11.3. Your consumer-health rights. Where the MHMD Act (or a similar law) applies, you have the right to: (a) confirm whether we collect, share, or sell your consumer health data and access it; (b) withdraw consent to its collection and sharing; and (c) request that we delete your consumer health data. We will honor deletion requests and notify our processors/affiliates to delete it, subject to limited legal exceptions.

11.4. No geofencing. We do not use geofences around healthcare facilities to track or collect consumer health data or to send related advertising.

11.5. Exercising rights. Use the methods in Section 9.2 / Section 16. A dedicated consumer-health rights contact is support@builtbyatlas.org.


12. UK / EU GDPR Rights and Complaints

12.1. If you are in the UK, the EU, or the EEA, you have the GDPR/UK GDPR rights listed in Section 9, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

12.2. For special-category (health) data, we rely on your explicit consent (Article 9(2)(a)) or another applicable Article 9 condition. You may withdraw consent at any time (Section 9.1).

12.3. Right to complain. You have the right to lodge a complaint with a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) — https://ico.org.uk, helpline 0303 123 1113. In the EU/EEA, you may contact your local data protection authority. We would, however, appreciate the chance to address your concerns first via support@builtbyatlas.org.

12.4. EU/UK representative. We have not appointed an Article 27 representative.


13. Cookies and Analytics

13.1. We use cookies and similar technologies (local storage, SDKs, pixels) for: (a) strictly necessary purposes (authentication, security, load balancing); (b) functional purposes (remembering preferences); and (c) analytics (understanding usage and improving the Service, via our analytics provider).

13.2. What we actually use. The Service uses strictly necessary cookies/local storage (authentication via our identity provider, security, session state) and first-party product analytics. We do not run third-party advertising cookies or cross-site tracking pixels. Because the non-essential technologies we use are limited to first-party analytics, we do not currently operate a separate cookie banner; where a regulator requires consent for analytics in your region, contact us and we will honor an opt-out (Section 9).

13.3. Do Not Track / Global Privacy Control. We do not currently respond to browser "Do Not Track" signals. Because we do not sell or share personal information for cross-context behavioral advertising, Global Privacy Control (GPC) opt-out-of-sale signals do not change our processing; where a GPC signal must be honored as an opt-out under applicable law, we treat it accordingly.

13.4. Analytics providers. Our analytics provider(s) process device and usage data on our behalf; we configure them to limit data collection where feasible, and health data — including all cycle-tracking data — is never sent to analytics. See Section 6 for the provider list.

13.5. The cookies and similar technologies we use, their purposes, and their general durations are described in this Section 13; for questions about a specific cookie, contact support@builtbyatlas.org.


14. Children

14.1. The Service is for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18.

14.2. We operate a hard age gate at registration (Section 2 of the [Terms of Service](/terms)). If we learn that we have collected personal information from a person under 18, we will delete it and terminate the account.

14.3. If you believe a minor has provided us personal information, contact support@builtbyatlas.org and we will take appropriate steps. (We also comply with the US Children's Online Privacy Protection Act (COPPA), which concerns children under 13; the Service is not intended for anyone under 18.)


15. How to Delete Your Account

15.1. In-app self-service deletion. You can delete your account at any time using the account-deletion feature in your account settings (provided in-app, as required by Apple's App Store guidelines for accounts created in the app). This initiates deletion of your account and associated personal information.

15.2. By request. You may also request deletion by emailing support@builtbyatlas.org or writing to the postal address in Section 16. We may verify your identity before acting.

15.3. What happens. Upon a verified deletion request, we delete or de-identify your personal information within the period described in Section 8, except information we must retain to comply with law, complete transactions, prevent fraud/abuse, ensure security, or establish/exercise/defend legal claims. Backups are purged on our normal backup cycle. We will instruct relevant sub-processors to delete your information where required.

15.4. Effect on subscription. Deletion ends future access; it does not by itself entitle you to a refund or relieve minimum-term obligations already incurred (see the [Terms of Service](/terms)).

15.5. Cycle data (standalone deletion). Independently of account deletion, you can permanently erase all cycle-tracking data at any time using the "Delete all cycle data" control in Settings — see Section 3.11. This works even if you keep your account and every other feature.


16. Contact and How to Exercise Your Rights

16.1. To exercise any right, ask a question, or raise a concern about privacy, contact us:

Privacy — CupidCoach LLC (operating as ATLAS)
Email (privacy): support@builtbyatlas.org
General: support@builtbyatlas.org
Post: 1309 Coffeen Ave, Ste 1200, Sheridan, WY 82801, USA
Website / in-app privacy controls: https://builtbyatlas.org

16.2. We will respond within the timeframes required by applicable law (Section 9.3) and may need to verify your identity. If you are in the UK/EU and unsatisfied, you may complain to the ICO or your local authority (Section 12.3).


17. Security

17.1. We implement technical and organizational measures designed to protect personal information, including encryption in transit (TLS) and, where appropriate, at rest, access controls and least-privilege practices, authentication via a dedicated provider, secure cloud infrastructure, logging and monitoring, and use of PCI-compliant payment processing so we do not handle card numbers.

17.2. No method is perfectly secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for content you choose to share with coaches, groups, or the community.

17.3. We restrict access to personal information to personnel and providers who need it to operate the Service and who are bound by confidentiality obligations.


18. Data Breach Notification

18.1. We maintain procedures to detect, investigate, and respond to security incidents. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals as required by applicable law, including:

18.2. Notifications will describe, to the extent known, the nature of the incident, the information involved, likely consequences, and steps we are taking and that you can take. We will keep records of breaches as required.


19. Changes to This Policy

19.1. We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email and/or in-app notice) and update the "Last updated" date before the changes take effect.

19.2. Where required by law, we will obtain your consent to material changes affecting how we use sensitive or health data. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy, except where consent is required.

19.3. We encourage you to review this Policy periodically. Prior versions are available on request.