Atlas — Privacy Policy
Version 1.0 · Last updated: 14 July 2026
1. Who we are
Atlas is a personal mobile application for travel journaling, traveller community and future bookings, developed and operated by Simone Bruno ("Data Controller"). Contact: s.bruno93@icloud.com. This document describes what data we collect, how we use it, who we share it with, and your rights under EU Regulation 2016/679 (GDPR) and the California Consumer Privacy Act (CCPA/CPRA) where applicable.
2. Data we collect
- Registration: name, email, password (stored as bcrypt hash), optional avatar, country of origin, bio, username.
- User-generated content: trips, cities, photos, journals, reviews, wishlist, business profiles you create.
- Usage data: authentication tokens (JWT or Google session), gamification data (XP, coins, unlocked badges), levels, travel statistics.
- Technical logs: IP address, login/logout timestamps, user agent — retained for 90 days for security purposes.
- Payment data (only Atlas Basic subscribers): processed by Apple's App Store. We never receive nor store your payment card details; we only store the Apple transaction ID and the subscription status.
3. How we use data
- Service delivery (diary, map, community, badges)
- Transactional communications (email verification, password reset, receipts)
- Product improvement (anonymous aggregated statistics)
- Security and fraud prevention
- Compliance with legal obligations
Legal bases: performance of contract (art. 6.1.b GDPR), consent (art. 6.1.a) for optional data, legal obligation (art. 6.1.c) for billing, legitimate interest (art. 6.1.f) for security.
4. Sharing with third parties
Atlas shares data ONLY with essential technical providers:
- MongoDB / Emergent hosting — database infrastructure (EU)
- Google (optional) — only if you choose Google sign-in
- Emergent LLM — optional content translation
- Apple / Google Play — app distribution and in-app subscription processing
We do NOT sell your data. We do NOT share it for advertising purposes. Travel Cafè partners will only receive booking data you explicitly submit (future phase).
5. International data transfers
Some providers (Apple) are located in the United States. We use Standard Contractual Clauses approved by the European Commission.
6. Data retention
- Active account → duration of the relationship
- Deleted account → data removed within 30 days (excluding tax/legal logs kept for 10 years)
- Technical logs → 90 days
- Backups → rolling 30 days
7. Cookies and tracking
The Atlas mobile app does NOT use advertising tracking cookies. It only uses local secure storage for tokens and image caching for performance. No third-party analytics SDKs (no Google Analytics, no Facebook SDK).
8. Security
Passwords protected with bcrypt (12 rounds). Client-server communication always HTTPS/TLS 1.2+. JWT sessions with expiry. Isolated database environment. Encrypted backups. Data breach notification within 72h if required under GDPR.
9. Your rights (GDPR / CCPA)
- Access to your data (art. 15 GDPR)
- Rectification of inaccurate data (art. 16)
- Deletion — 'right to be forgotten' (art. 17)
- Restriction of processing (art. 18)
- Data portability (art. 20)
- Objection to processing (art. 21)
- Right to opt-out of sale/sharing (CCPA/CPRA) — we do not sell your data
- Complaint to your data protection authority (e.g. Italian Garante, EDPB member DPAs, ICO in UK)
To exercise your rights email s.bruno93@icloud.com. We respond within 30 days.
10. Minors
Atlas is intended for users aged 16 and above. We do not knowingly collect data from minors under 16 without parental consent.
11. Changes
We notify significant changes via email or in-app notification with at least 30 days' notice.
12. Contact
Data Controller: Simone Bruno
Email: s.bruno93@icloud.com
Product: Atlas — Personal Travel Diary
Supervisory Authority: Garante per la Protezione dei Dati Personali — Piazza di Monte Citorio, 121 — 00186 Rome, Italy — www.garanteprivacy.it