ProductAtlas In development
ExploreCreate a blueprintHow it worksDocs
Sign in

Legal ProductAtlas

Privacy Policy

How opsAI LLC handles personal data when you use ProductAtlas, written to match what the service actually does.

Effective
28 July 2026

Contents

  1. Scope and controller
  2. What we collect
  3. Why we use it
  4. Content you publish is public
  5. Usage analytics
  6. AI assistance features
  7. Who we share it with
  8. International transfers
  9. How long we keep it
  10. Your rights
  11. How we protect it
  12. Children
  13. Changes to this policy
  14. Contact

1Scope and controller

opsAI LLC, a Delaware limited liability company with its principal place of business at 13740 N Highway 183, Ste L2 #184, Austin, TX 78750, United States, is the controller for personal data processed through ProductAtlas. This policy covers the website, the public catalog, the REST API, and the MCP endpoints.

It does not cover third-party sites you reach from links in Blueprint content, or the systems of publishers who use knowledge they found here.

2What we collect

Categories of personal data
CategoryWhat it includesWhere it comes from
Account identityIdentity provider issuer and subject identifier, email address and verification state, first and last name, display name, publisher namespace, optional public bio and profile links, and optional profile photo (avatar) when you upload one.You, at registration or in account settings, or claims from our identity provider when you sign in with an external account.
Account lifecycleTerms version accepted and acceptance time, account creation and update times, last sign-in time, access state such as disabled or suspended.Generated as you use the service.
Optional publisher verificationThe exact Website, GitHub, LinkedIn, or X profile reference saved in your publisher profile; the request and decision times; immutable evidence fingerprints; administrator decision and lifecycle state; private staff rationale; and publisher feedback. The exact reference and staff rationale remain private and are not included in public pages, REST, or anonymous MCP.You provide the profile reference and request review; authorized administrators record the decision and any explicit suspension, restoration, or revocation.
Content you createBlueprint Drafts and Releases, including titles, summaries, section text, links, release notes, license and attribution choices, and uploaded Assets.You. Anything you publish becomes public.
Asset metadataFilename, media type, size, processing state, content digests, and storage keys. Binary files are stored separately.Your uploads.
Security and audit recordsWho did what and when for ownership, publishing, moderation, verification, and authorization events, including IP address and user agent.Generated automatically when a recorded action occurs.
Abuse prevention signalsIP address and normalized email address used for short-lived rate-limit counters.Your requests. Held only for the length of the rate-limit window.
Usage analyticsWhich Release was viewed or appeared in search, the channel, the UTC day, and a hashed fingerprint used only to avoid double counting.Generated as you browse. See the section below.
InvitationsNormalized email address and a hash of the invitation token for pre-release invitations.The person who invited you.
CorrespondenceMessages you send us and our replies.You.

We do not store your password. Credentials are held by our identity provider at auth.productatlas.app. We also do not persist the OAuth tokens issued during sign-in. Profile photos are collected only when you choose to upload an avatar for your public publisher profile; raw uploads stay in private quarantine until a safe derivative is ready. Optional manual publisher verification uses only a saved public profile reference; we do not collect identity documents for it. Email verification and manual publisher verification are separate.

3Why we use it

  • To provide the service: create and authenticate your account, store your Drafts, publish Releases, and serve the catalog to people and agents.
  • To keep the service safe: screen uploaded and authored content, detect abuse, apply rate limits, and investigate reports.
  • To meet our obligations: keep auditable records of ownership, publishing, moderation, and verification actions.
  • To communicate with you: email verification, invitations, and service messages.
  • To improve the product: understand which Blueprints are found and used, and give publishers aggregate insight into their own Blueprints.

Where the UK GDPR or EU GDPR applies, we rely on performance of our contract with you for account and publishing functions, on our legitimate interests in a secure and improving service for security, abuse prevention, audit, and analytics, and on legal obligation where we must retain or disclose records. Where we rely on legitimate interests, you can object using the contact details below.

We do not sell personal data, we do not use it for third-party advertising, and we do not build advertising profiles.

4Content you publish is public

A published Release is public. It carries your publisher namespace and publisher display name, and it can be retrieved by anyone, including AI agents, through the catalog, the API, and public MCP.

Releases are immutable and may already have been copied, packaged, or indexed elsewhere. Withdrawing a Release stops future distribution by us but cannot recall copies others already hold. Do not put personal data or confidential material into Blueprint content that you would not want to be permanently public.

5Usage analytics

We measure how Blueprints are discovered and retrieved so publishers can see whether their work is useful. This measurement is deliberately minimized.

  • Stored events contain the Release identifier and digest, the event kind, the channel, the UTC day, a traffic classification, and a hashed fingerprint.
  • Stored events do not contain your IP address, account identifier, user agent, session identifier, cookie value, or search text.
  • Approximate unique browser detail views use a server-derived daily key: a keyed hash of the request's network address, user agent, and UTC day. The raw inputs are discarded after hashing, no measurement cookie is set, and the key is not linkable across days without the secret and original request inputs.
  • When you follow an external link through ProductAtlas safe-link routing, we may record the destination host, the allow/warn/block decision, and a coarse reason code. We do not store the full destination path or query string for this measurement.
  • Publishers see aggregate counts for their own Blueprints. They do not see who viewed them.

Raw analytics events are deleted after 35 days and daily aggregates after 400 days. This measurement does not rely on a browser cookie; see the Cookie Notice for the essential cookies we do set.

6AI assistance features

If you use the optional metadata suggestion feature while authoring a Draft, the relevant Draft text is sent to Google's Gemini API to generate suggestions. We send it with prompt storage disabled, we mark it as untrusted input, and suggestions are returned to you rather than applied automatically.

Do not put personal data or confidential material into a Draft you intend to run this feature on. The feature is not used on visitors or on published catalog browsing.

7Who we share it with

We share personal data with service providers who process it on our behalf under contract. The current list, with the role each one plays, is on our Subprocessors page.

  • We disclose data to authorities where we are legally required to, and we push back on requests that appear overbroad.
  • We may share limited information with a party reporting abuse or asserting rights, so a complaint can be resolved.
  • If the service is transferred as part of a corporate transaction, personal data may transfer with it, subject to this policy.

8International transfers

ProductAtlas is operated from the United States, and our providers may process data in the United States and other countries. Where we transfer personal data out of the UK or European Economic Area, we rely on the transfer mechanisms offered by those providers, typically the Standard Contractual Clauses and the UK Addendum.

9How long we keep it

Retention by category
DataRetention
Account recordFor as long as your account exists, then deleted or anonymized on closure, except where we must keep records.
Published ReleasesIndefinitely, because they are immutable public artifacts other people may depend on.
Drafts and unpublished AssetsUntil you delete them or your account is closed.
Security and audit recordsRetained for security, integrity, and legal purposes. A defined retention schedule is in progress; until it is published, records are kept no longer than necessary for those purposes.
Raw analytics events35 days.
Daily analytics aggregates400 days.
Email verification tokens24 hours.
Publisher verification evidenceImmutable requests, decisions, lifecycle actions, and related audit evidence are retained for integrity, security, and legal purposes. An approved manual verification has no automatic expiry; only an explicit suspension, restoration, or revocation changes its current administrative state.
Rate-limit countersThe length of the rate-limit window, currently one hour.

10Your rights

Depending on where you live, you may have rights to access your personal data, correct it, delete it, receive a portable copy, restrict or object to processing, and withdraw consent where we rely on it.

ProductAtlas does not yet offer self-service deletion or export. Until it does, email [email protected] and we will handle your request. We will verify that the request comes from you, respond within one month, and tell you if we need longer or cannot fully comply.

Deletion has limits we want to be honest about. We cannot recall published Releases from people who already retrieved them, and we may need to keep audit and moderation records that establish who did what. Where we cannot delete, we will tell you why.

If you are in the UK or EEA you can also complain to your data protection authority. We would rather hear from you first so we can put things right.

11How we protect it

  • Traffic is served over HTTPS, and session cookies are HTTP-only, host-scoped, and same-site.
  • Secrets and credentials are held in a managed key vault, not in application configuration.
  • Uploaded files land in private quarantine storage and are screened before any derivative becomes public.
  • Sensitive fields are excluded from audit records, and logs are written to avoid capturing tokens or credentials.
  • Access to production data is limited to the people who need it.

No service can promise perfect security. If a breach affects your personal data, we will notify you and the relevant regulator where the law requires it.

12Children

ProductAtlas is not intended for children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account, contact [email protected] and we will remove it.

13Changes to this policy

We update this policy when the service changes. The effective date at the top always reflects the current version, and we will give prominent notice of material changes.

14Contact

For privacy questions or to exercise a right, email [email protected]. Service email from us is sent from [email protected].

ProductAtlasA map of what great products know.

Product

  • Explore
  • How it works
  • Docs

Legal

  • Terms
  • Privacy
  • Acceptable use
  • Cookies
  • Subprocessors

A product of opsAI LLC, makers of Toggly.