Privacy Policy
Atlas is a strength-training and nutrition tracker for iPhone, built by Mark Eskandar. This policy covers your Atlas account, which keeps a synced copy of what you log, the rest of the app, and this website. It is written from the source rather than from a template, so everything below is a statement about how Atlas actually behaves.
The short version
You sign in to Atlas with Google or with a code sent to your email. Your account keeps a copy of what you log — workouts, foods, weigh-ins, your profile and goals — so it is backed up and the same on every device you sign in on. That copy is stored with Supabase, in Canada, and only your signed-in devices can read it.
Apple Health data is never uploaded. Neither is a meal photo: if you turn on photo logging, a photo is sent through Atlas's server to Google's Gemini so the foods on it can be identified, and Atlas does not store it. Food searches and barcodes go to public food databases so they can answer, with nothing identifying you attached.
There are no analytics, no advertising, no trackers, and no third-party SDKs. Your data is not sold or shared for marketing.
You can delete your account and everything synced to it from the app, in Settings → Account → Delete account, or ask for it without the app.
Your account
Everyone who uses Atlas signs in. That is what lets you log from any of your devices and get your history back on a new phone.
What your account holds
- Your email address, and which way you signed in (Google or an email code). If you sign in with Google, Supabase receives the account identifier and the basic profile Google shares with any sign-in (typically your name and profile picture); Atlas does not use them
- Training — every lift with its sets, weights and reps; your split days; the warm-up and training-target settings
- Food — your food library and saved recipes, diary entries, water, and your calorie and macro goals with their history
- Body — the weigh-ins you log, and your profile: name, bodyweight, height, birth year, sex, activity level and units
- A few app settings that should follow you between devices, such as your accent colour and the weekly check-in’s state
- A random device identifier, one per install, stored with each change so a sync problem can be traced to the device that caused it. It is generated by Atlas and is not your phone’s hardware or advertising identifier
Each record also carries the time it was last changed, which is how two devices agree on the newer version.
Some things stay on the phone and are never synced: whether Atlas is in Food or Weights mode, a workout that is in progress, whether photo logging is turned on, the local activity log, and anything from Apple Health.
Why
Only to back up your log and keep it the same on every device you sign in on. Atlas’s suggestions are still worked out on the device from your own history; nothing is analysed on the server.
Where it is stored, and who can read it
Your account and its records are stored by Supabase in its Canada (Central) region, over encrypted connections. The database only lets a signed-in person read and change their own records. Changes reach your other signed-in devices live, through Supabase.
Once a night the database is copied, encrypted, and kept as a private backup on GitHub for 30 days, so a failure on Supabase’s side cannot lose your log. The copy is encrypted before it is stored, and it is opened only to restore the database.
Supabase also keeps the operational records any sign-in service keeps, such as when an account signed in and the IP address it came from, under its own policy.
How long it is kept
For as long as you have an account. When you delete it, the account and every record synced to it are removed from the database straight away. Copies inside the nightly backups roll off as those backups expire, within 30 days.
Deleting your account
- In the app: Settings → Account → Delete account. It removes your account and everything synced to it, on every device. You choose whether to keep the data on the phone you are holding or erase it too
- Without the app: atlaslifts.app/delete-account, or email [email protected] from the address you sign in with
Signing out does not delete anything: the data stays on the phone and in your account.
Sign-in providers
If you sign in with Google, Google knows you signed in to Atlas, under its own privacy policy. Sign in with Apple is planned; when it arrives the same will be true of Apple. The email code is sent by Supabase’s sign-in service, delivered through Resend (which sees your email address and the code, under its own policy).
The rest of the app
Everything from here to “Exports you initiate” describes the iPhone app apart from your account.
What Atlas stores on your device
Everything you log is kept in Atlas’s own storage on your iPhone, so the app works without a connection. The synced records listed above are also in your account. These stay on the phone only:
- Health readings you have granted Atlas access to (see below)
- A local activity log — a technical record of app events (launches, crashes, sets logged, storage failures) used to diagnose problems. It records what the app did, not what you searched for. It stays on the device unless you choose to export it
- Device-only settings — Food or Weights mode, a workout in progress, and the photo-logging switch
Deleting Atlas deletes what is on the phone, not your account. Settings → Reset all data erases your profile, training and food. While you are signed in, it asks which of two things you mean:
- Sign out and clear this phone — signs you out, then erases them on this phone only. Nothing is deleted from your account or your other devices. Sign in again and it all comes back
- Erase everywhere — deletes your profile, training and food from your account and from every device signed in to it. Your account itself stays, empty. This can’t be undone
When you are not signed in, a reset erases this phone only.
What leaves your device, and when
Foods that ship with the app — these never leave
Atlas includes a copy of the most-scanned foods from Open Food Facts, so the common case can be searched with no connection at all. Those searches make no request: there is nothing to send, because the answer is already on your phone. The data is used under the Open Database License (ODbL) and is credited in the app under Settings → Food data.
Food search and barcode scanning
When you search for a food or scan a barcode, Atlas sends that search term or that barcode number to three public food databases so they can return matching results:
| Service | Operator | What it receives |
|---|---|---|
| Open Food Facts | Open Food Facts (non-profit) | Your search term or scanned barcode |
| FoodData Central | U.S. Department of Agriculture | Your search term |
| fatsecret | FatSecret (Secret Industries Pty Ltd) | Your search term or scanned barcode, or a restaurant chain's name |
What is sent is limited to the search term or barcode, plus a generic identifier for the app itself. No name, no account, no device identifier, and nothing else you have logged is included. These requests happen only when you search or scan; Atlas does not pre-fetch or crawl anything in the background.
Restaurant menus. When you open a restaurant chain in Places (McDonald's, Tim Hortons and so on), Atlas asks fatsecret for that chain's menu, sending only the chain's name. The menu is held in memory while the app is open and is not saved to your device.
As with any internet request, these services will see the IP address your request comes from. That is a property of how the internet works, not something Atlas adds. Each service handles what it receives under its own privacy policy, linked above.
A food you save goes into your food library, which is stored on the device and synced to your account like the rest of your log, so re-logging it requires no further lookup.
Apple Watch
If you use Atlas on Apple Watch, the watch and your iPhone exchange sets, foods and the current workout directly, over Apple's WatchConnectivity link between your own two devices. That exchange does not pass through any server of ours; what the phone then records syncs to your account like anything else you log.
Photo logging
Photo logging is off until you turn it on. Atlas asks first, and says what leaves your phone, the first time you tap the camera beside food search. You can turn it off again in Settings → Photo logging.
When you take or choose a meal photo, Atlas resizes it to about 1024
pixels on its longest side and re-encodes it from the pixels, which
removes its metadata, including any location. It is sent over HTTPS
through a small function on this website's server
(atlaslifts.app/api/vision) to
Google's Gemini API, whose
model names the foods it can see and estimates each portion in grams. If you
are in a Place, the names on that Place's menu go with it as hints.
After Atlas shows its guess you can add an optional description
in your own words (for example “2 eggs, toast with butter”),
up to 300 characters. If you do, the photo is sent again with your
description and the names from the first guess, handled the same way,
and not stored. Leave it empty and nothing extra is sent. Nothing else is sent: no name, no account, no device identifier,
and nothing you have logged.
- The photo, and your description if you wrote one, are not stored by Atlas — not on your phone, not on the server, not in your account. The server passes them on and keeps no copy or log of either
- While Atlas is in testing it uses Gemini's free tier, under which Google may use the photo to improve its products, as described in the Gemini API terms. Before Atlas launches publicly it will move to Gemini's paid tier, where Google does not use it that way, and this page will say so. If that matters to you, leave photo logging off
- Atlas matches each food against its own food data and works out the calories itself; the photo service is never asked for calories
- Nothing is logged until you confirm the items and portions on the “Is this your plate?” screen. The diary entries you confirm sync like any others; the photo does not
Nothing else
Apart from your account’s sync, the food lookups and photo logging, Atlas makes no network requests. There is no analytics endpoint, no crash reporting service, and no advertising network.
Apple Health
If you grant permission, Atlas reads sleep, steps, active energy, heart rate and bodyweight from Apple Health to inform your dashboard and recommendations. It also reads your workouts, only to avoid saving a lifting session that another app has already recorded.
If you turn on Save to Apple Health (off unless you switch it on), Atlas also writes to Health on your device: your lifting sessions as strength-training workouts, the energy, protein, carbohydrate and fat of the food you log, and the weigh-ins you log. Editing or deleting an entry in Atlas updates or removes what it wrote. Only the phone where you logged an entry writes it to Health; entries that arrive from your other devices through sync are never written to Health again.
- Reading and writing are separate permissions, both optional; Atlas works without either
- Health data is used and written on the device. It is never uploaded to your account or sent anywhere else
- You can revoke access at any time in Settings → Health → Data Access & Devices → Atlas, and turn off saving in Atlas under Settings → Apple Health. What Atlas already wrote stays in Health until you delete it there
- Health data is never used for advertising or shared with anyone
Camera
Atlas uses the camera for two purposes. Reading a barcode: recognition happens on the device, and only the decoded barcode number is used, to look the product up as described above. Photo logging, if you turn it on: the meal photo is sent to be identified as described under Photo logging. In both cases no photo or video is stored or saved to your library.
Widgets and Lock Screen
Atlas writes a small summary — the next lift, your streak, calories remaining — into a shared container on your device so its widgets and Live Activity can show it. This container is local to your iPhone and never leaves it.
Exports you initiate
Atlas can export a backup of your data, a CSV of your workouts and food diary, and separately its activity log, through the standard iOS share sheet. This only ever happens when you tap an export button and choose a destination.
Once you send a file to another app or service — iCloud Drive, Files, email, anywhere else — that copy is governed by that destination's terms, not by this policy. Atlas has no visibility into it.
This website
This site is served by Cloudflare. It runs no analytics and no third-party scripts. Two forms on it send what you type to Mark.
The TestFlight invite form
When you ask for a TestFlight invite, the form sends your name, email address, and — if you filled them in — your device and what you train to a small function running on Cloudflare. Your country, as Cloudflare reports it from your connection, is included so a reply can be timed sensibly.
That function does two things with it:
- Stores it in Cloudflare KV, so a request cannot be lost if the email fails to arrive.
- Emails it to Mark, delivered by Resend.
No script from anyone else runs in your browser. The form posts to this same site. The only onward call happens on the server, after your request has already left your machine.
Invite requests are deleted within 12 months of being received, or sooner if you ask. The date is fixed rather than tied to when TestFlight opens, because that date is not currently ours to set — Apple Developer Program enrolment is still pending, so there is no TestFlight round yet to anchor a promise to.
The account deletion form
The form on the delete-account page sends the email address you enter, anything you add in the note, and your country as Cloudflare reports it, the same way: stored in Cloudflare KV and emailed to Mark through Resend. Mark replies to that address to confirm the account is yours before deleting anything. The request itself is kept, as a record that the deletion was asked for and done, and deleted within 12 months.
Asking for it back, precisely
Email [email protected] and we will delete the stored record and the email itself. Two honest caveats, because a deletion promise broader than we control is not worth making:
- Resend retains its own delivery logs under its policy, and we cannot delete those on your behalf.
- If a reply has already been sent, that thread lives in a normal mailbox and is deleted with it.
There is no mailing list, no sequence, and no newsletter. Nothing about the website is used for advertising.
Who handles your data
| Company | What for | What it handles |
|---|---|---|
| Supabase | Accounts, sign-in and sync (Canada Central region) | Your account and synced records |
| GitHub | Nightly database backups, kept 30 days | Encrypted copies of the database |
| Sign-in, if you choose Google; photo logging, if you turn it on | That you signed in to Atlas; the meal photo and any description you add | |
| Cloudflare | This website and its forms; relaying photo-logging requests | What you send through the site’s forms or functions |
| Resend | Delivering sign-in codes, and the website’s forms to Mark | Your email address and sign-in code; what you typed into a form |
The food databases in the table above receive search terms and barcodes only. When Sign in with Apple arrives, Apple will be added here.
What we do not do
- We do not sell, rent, or share your data with anyone beyond the companies named above, and they handle it only to provide their part of Atlas.
- We do not track you across apps or websites.
- We do not show advertising.
- We do not use your data to train machine-learning models. The one exception is outside our hands and temporary: while Atlas is in testing, Google may use photos sent for photo logging, as described under Photo logging.
- We do not build a profile of you. The app's suggestions are computed on your device from your own logged history.
Children
Atlas is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has made an account, email the address below and it will be deleted.
Your rights
- Access and portability — export a backup or a CSV from Settings, or ask us for a copy of what your account holds
- Correction — edit or delete any entry directly in the app; the change syncs to your account
- Deletion — Settings → Account → Delete account, or without the app
If you would like any of that confirmed in writing, or something done that the app cannot do, contact us at the address below.
Changes to this policy
If this policy changes in a way that affects what happens to your data, the "last updated" date above will change and the revised policy will be published at the same address before the change takes effect.
Contact
Questions about this policy or about privacy in Atlas: [email protected]
Atlas is an independent app. Open Food Facts, USDA FoodData Central and fatsecret are separate services referenced here because Atlas queries them on your behalf; they are not affiliated with Atlas.