1. What ATLAS is
ATLAS reads your bank and credit card accounts and tells you what your money is doing — where it goes, what repeats, what is due, and what you could do about it. It is read-only. It cannot move money, make a payment, or change anything at your bank.
2. What we collect
Financial data, through Plaid. When you connect an account, Plaid asks your bank for permission on your behalf. We then receive:
- account names, types, balances and the last four digits of card numbers
- transaction history, up to two years — date, amount, merchant, category
- credit card details: statement balances, due dates, minimum payments, APRs
- investment holdings and their values, if you connect such an account
- the location of a transaction, when your bank supplies one
You never give ATLAS your banking password. The sign-in happens on your bank's own page, inside Plaid. We never see it, and neither does anyone here.
Your email address. It is the name you sign in with, so it is required when you create an account, and it is used for one other thing: resetting your password if you forget it. We send you nothing else — no newsletter, no product mail, no reminders. You are asked to confirm it by opening a link we send, and until you do, it cannot be used to reset anything. One address belongs to one account.
If you made an ATLAS account before this was required, you signed in with a passkey and a handle instead, and that continues to work exactly as it did.
Details you choose to give us. Your legal name and phone number are optional. Nothing in the app requires them, and no feature is withheld if you leave them blank.
Technical data we need to work. A handle you pick, credentials that prove it is you (a hash of your password, a passkey's public key, or a device secret held in your phone's secure hardware), a hash of your PIN, your device's timezone, and — if you turn on notifications — a push token.
Usage events — that something happened, never what it was about. ATLAS records a short list of named events: which screen you opened, whether connecting a bank succeeded or failed, whether you asked the assistant a question, whether you subscribed. Each record holds four things — the event's name, whether it came from iOS, Android or the web, the app version, and the time. Nothing else.
There is no field for an amount, a merchant, an account name, or the text of anything you typed, so none of that can be recorded even by accident. The list of possible events is fixed in the code, and anything not on it is discarded rather than stored. These records are deleted after ninety days.
Crash reports — what broke, never whose phone. If the app fails, it sends ATLAS a description of the failure: the error's name and message, where in the code it happened, which version of the app and of iOS or Android it was running on, and the time. No account, no device identifier, no network address and no session is attached, so a report cannot be traced back to you, and the message is scrubbed of anything resembling an email address or a long number before it is stored. These reports go to ATLAS's own servers and to nobody else — there is no third-party crash or analytics service in the app. They are deleted after thirty days.
Badges, and the days you checked in. ATLAS gives out badges — some earned from something true about your money, some as an occasional surprise. Holding one means three rows exist: which badge you have and when it arrived, whether you have looked at it yet, and, for the streak badges, the calendar dates on which you opened your report.
Those dates are dates and nothing else. No time of day, no device, no session, no note of what you looked at — a streak needs to know which days, and that is all that is stored. They are kept for thirty-five days and then deleted, because the longest streak ATLAS rewards is three weeks and a record that outlives the question it answers is a record of your habits rather than a badge.
The badges themselves stay while your account does, since they are yours to keep. Sharing one is something you do, not something we do: the picture is drawn on your phone, handed to whichever app you choose, and never sent to us. We do not know which badges you share or where.
Looking around without an account. The opening screen has a button, "Look around first", that shows you the whole app on sample data without asking you for anything. Behind it, ATLAS makes a temporary account of its own — a random name, no password, no passkey, no email — and fills it with the same sample figures the "Explore with sample data" option uses. Nothing you type goes into it, because there is nothing to type. It cannot connect a bank, import a statement, subscribe, or be given an email address or password; every one of those is refused, so a look-around account can never become a route to anybody's money. It is deleted automatically six hours after it was made, whether or not you are still using it.
Card names we do not recognise. ATLAS can tell you which card in your wallet earns the most somewhere, which it can only do for cards whose rates it knows. When it meets one it does not, it records the product's name — "Some Bank Rewards Visa" — and a count of how many times it has been seen, so we know which to research next. That list is not linked to any account: there is no column that could say whose card it was, and a count cannot be turned back into a person.
Location — not collected, and the app cannot ask. ATLAS does not use your location, and this is not a promise about our intentions. The code that could have read it is gone: a card-reminder feature that would have noticed when you arrived at a shop where another card in your wallet earns more was built, never switched on, and has now been removed along with the libraries it needed. The app no longer contains anything that can request your location, and it declares to Android that the location permissions must be stripped from it in case a future dependency tries to add them back.
If that feature ever returns, this section will describe exactly what it collects before it ships, not after.
If you join the mailing list. The website has a form asking to be told when ATLAS is released. If you use it, we store your email address, which of the two forms you used, and the date — and nothing else. There is no name, no profile, and no link to an ATLAS account; the list lives in its own table and is never matched against anyone's. It is used to send you one email when ATLAS is in the app stores, and you can unsubscribe from any email we send. Your address is never sold, never shared, and never passed to an advertiser. Joining the list is entirely optional and creates no account.
Statements you import. If you import a bank statement as a file instead of connecting the bank, the rows become transactions like any other, and the file's name is kept beside them so you can tell one import from another. The file itself is read once and not stored.
3. Who else sees it
Plaid connects to your bank and supplies the data above. Their handling is covered by their own policy at plaid.com/legal.
Anthropic, when you use the CFO. This deserves to be stated plainly rather than buried: asking ATLAS a question sends a summary of your finances to Anthropic's Claude model so it can answer.
That summary is computed figures rather than your raw transaction history, but it is detailed, and the honest version of this list is longer than the one that sounds better. It contains your income and spending averages; your accounts and cards with their labels, balances, rates and limits; upcoming due dates and minimum payments; the bills that recur and what they cost; the categories you spend in; the merchants you spend the most at; the label your bank puts on the money coming in, which for many people is where they work; fees you have paid; your net worth, cash runway and what is safe to spend; a debt payoff plan if you have debt; the goals you have set and how much of each month goes to them; and a handful of ratios worked out from the figures above — your savings rate, how much of your income is already committed to recurring bills, how much of your credit limits you are using, and how steady your income is month to month.
It does not contain your name, email address, phone number, account numbers, card numbers — not even the last four digits — or any credential. Anthropic processes it to generate a reply. If you never open the Ask tab, none of this is ever sent.
Expo, to deliver push notifications. A notification carries only its own title and text — for example, that a card is due, or that a spending limit is close. No account data travels with it.
RevenueCat — no longer used, and named here because it once was. It handled receipts when subscriptions were bought inside the app store. Subscriptions are now bought through Stripe, no version of ATLAS you can install sends it anything, and what it received historically was an anonymous account identifier and a purchase id, never your accounts or your spending.
Stripe takes the payment. Subscribing opens Stripe's own checkout page in your browser, outside the app, and your card details are typed there. ATLAS never sees your card number and never stores it — what comes back to us is your email address as Stripe holds it, confirmation that the payment succeeded, and when the subscription renews. Stripe is a payment processor and holds your card under its own privacy policy, not ours.
Amazon Web Services sends the two emails described above — confirming your address, and resetting your password. Amazon receives the address and the text of that message, which contains your handle and a single-use link. It receives nothing about your accounts, your balances or your spending. AWS already holds the key that protects your bank tokens, so this adds a service from a provider already involved rather than a new company.
Nobody else. We do not sell your data, share it with advertisers, or use it to build a profile for anyone but you. There is no analytics or advertising SDK in ATLAS — no Google Analytics, no Firebase, no advertising network, nothing of that kind, and no plan to add one. The usage events described in §2 are written to ATLAS's own database and are readable by nobody outside it.
Where it is stored. Starlight AI Inc. is a Canadian company, but your data is not held in Canada. ATLAS runs on Vercel, and the database is Neon Postgres in a United States region (AWS US East, Ohio). Plaid, Anthropic, Stripe, Amazon Web Services and RevenueCat also process in the United States. This means your information is subject to US law while it is there, including lawful access requests made to those providers by US authorities. We would rather write that down than let you assume a Canadian company keeps its data in Canada.
4. How it is protected
- Two factors, always; a third if you want it. Something you know (your password) and something you know again (a six-digit PIN), both checked on our server, both locked after five wrong answers. A passkey — something you have — is optional, and once an account has one it is required of that account every time. Bank data is unreachable without every factor the account has.
- Bank tokens are encrypted with AES-256-GCM before they are stored, under keys that can be held in a cloud key management service and rotated without downtime. Each ciphertext is bound to the record it belongs to, so a copied row will not decrypt anywhere else.
- PINs and passwords are hashed with scrypt and a per-user salt, the password at a higher work factor than the PIN. We cannot read either. Five wrong answers to either one locks the account for fifteen minutes.
- Transport is HTTPS throughout.
- Your bank password is never involved, so it cannot be lost from here.
No system is perfect, and saying otherwise would be dishonest. What we can say is that the sensitive material is encrypted at rest, the credentials are held on your device rather than ours, and access requires both factors.
If something goes wrong. If we believe your data has been reached by someone who should not have reached it, we will tell you — in the app and by email — within 72 hours of forming that belief, not of finishing the investigation. We will say what happened, what data was involved, what we have done, and what you should do. Where the law requires it we will also notify the Office of the Privacy Commissioner of Canada, and we keep a record of every breach whether or not it reaches that threshold.
5. How long we keep it
Your data stays while your account exists. Delete your account and the financial data goes with it — transactions, balances, tokens, goals, limits and places, all removed. Disconnecting a single bank removes that bank's accounts and transactions and revokes our access at Plaid, leaving the rest of your account intact.
A look-around account goes soonest: six hours after it was made, along with its sample data, whether or not anyone is still using it. Nothing in it was ever yours.
The dates you checked in go sooner still: thirty-five days, swept automatically, whether or not you do anything. The badges you have earned stay as long as the account does.
Alerts we have sent you are kept for six months and then deleted. The record of which card you said you would cover goes six months after that bill was due. A card's statement-by-statement utilisation is kept for two years, which is as far back as your report looks.
Usage events go sooner: they are deleted ninety days after they are recorded, whether or not you do anything, and they go with your account if you delete it first. Crash reports go sooner still, after thirty days; they were never attached to an account, so there is nothing to delete with it. The record of an unrecognised card name outlives an account because it was never attached to one — it is a list of card products to research, and by the time it is written there is nothing in it that points at anybody.
Deletion is immediate and cannot be undone. One honest caveat: our database provider keeps short-term backups, as any serious provider does, so deleted rows persist in those backups until they age out on the provider's schedule. Nothing restores them into the app, and we have no process that would bring an account back — but "deleted" means gone from the running system straight away and gone from the backups shortly after, and we would rather say so than imply otherwise.
6. What you can do
See it. Everything ATLAS knows is in the app; there is no hidden profile.
Correct it. Your details are editable in You → View details.
Delete it. Disconnect a bank, or delete your account entirely.
Take it elsewhere. You → Your data → Download my data gives you everything we store, as one JSON file, without asking anyone.
Turn things off. Under You → What I can interrupt you about, each kind of notification is independent — statement-close warnings, spending limits, and the two that are not warnings at all. Turning one off leaves the rest alone. The CFO is separate again: nothing is sent to Anthropic unless you open the Ask tab and type.
One exception, and it is deliberate. Security alerts — a new device on your account, a run of failed PIN attempts — are always sent and cannot be switched off. They exist to reach you when somebody else is in your account, and an alert the intruder can silence first is not an alert. The database itself refuses to store that preference.
Depending on where you live you may have further rights — access, correction, deletion, portability, or objection. We offer all of them to everyone, wherever you live, rather than only where a law compels us. Most you can exercise yourself in the app, immediately and without asking. For anything else write to avash@starlightaiinc.com and we will respond within 30 days, usually far sooner.
7. Children
ATLAS is not for people under 18 and we do not knowingly collect their data.
8. Changes
If this policy changes in a way that affects what we collect or who sees it, we will say so in the app before the change takes effect — not quietly, and not only here.
9. Contact
Starlight AI Inc. avash@starlightaiinc.com 34 Agincourt Drive, Toronto, Ontario M1S 1M3, Canada
Security. If you have found a vulnerability, write to avash@starlightaiinc.com. Tell us what you found and how to reproduce it. We will acknowledge you within 72 hours. We will not pursue you for reporting a problem you found in good faith and did not exploit.