Legal

Privacy

Your source code, your secrets and your requests stay on your machine. This page says what that means precisely, and what little else exists.

Last updated 30 August 2026

The short version

Atlas reads your backend where it already is. The analyser runs on your own computer, or in your own browser tab, and hands the result back to you. There is no server of ours that receives your source code, and no copy of it anywhere we control.

The rest of this page is the detail behind that sentence, and the short list of ordinary things a website does.

What never reaches us

None of the following is transmitted to Atlas, stored by Atlas, or visible to anyone who works on Atlas:

  • Your source code, and any file in the folder you scan.
  • The endpoints, schemas and database tables the analyser discovers.
  • Environment variables and their values — API keys, tokens, database URLs, anything you put in an environment.
  • The requests you send, their headers and bodies, and the responses you get back.
  • File paths, repository names and project names from your machine.

This is not a promise about our intentions; it is a consequence of where the code runs. The analyser executes on your machine and writes its output next to your project. There is no channel from it back to us, so there is nothing for us to be careless with.

Where your work is kept

In your project folder

Scanning a folder writes one directory into it, .atlas.api/, holding the discovered endpoints and the requests you save. It is plain JSON you can read, delete, or commit alongside your code. Atlas writes a .gitignore inside it that excludes environments.json, because an environment usually holds a real token and should not be committed by accident.

In your browser

Collections, environments, saved responses and your list of recent projects are held in this browser’s own storage (IndexedDB). They do not leave it, which also means they do not follow you to another browser or another machine, and clearing your site data erases them. Your theme choice is kept the same way.

In your own repository

When you commit your API description, it goes to your repository using the Git credentials already on your machine. No token is created, and none is stored by us or held in the page.

Website analytics

This site measures its own traffic with Vercel Analytics and Google Analytics: page views, which pages are read, roughly which country a visit came from, browser and screen size, and which site linked here. It tells us which parts of the product people reach, and it is the same measurement almost every website performs. Google Analytics sets a cookie; Vercel Analytics does not.

These record pages and clicks, never content. Nothing from the list under What never reaches us is passed to them, because none of it is available to the page in the first place. If you block analytics, everything in Atlas works exactly as it does otherwise.

The mailing list

If you give us an email address for release notes, we store the address, the date, and the page you gave it on. It is used to send release notes and nothing else. We do not sell or share it, and it is not connected to anything you scan or test — there is no identifier joining the two. Every email carries a one-click unsubscribe link, and you can write to the support address in the footer to be removed.

Sending requests

The request panel sends real HTTP requests to whatever host you name. That is the point of the feature, and it is the one case where your data leaves your machine — to the server you chose, not to us. Requests to localhost and private networks go through the agent running on your own computer, so they never traverse the internet at all.

Importing a repository

One path works differently and is worth stating plainly. If you ask Atlas to import a repository by name, that repository is downloaded to our server and analysed there, because your browser cannot clone it. The download is deleted after the analysis and its contents are not retained. If you connect a GitHub account to reach a private repository, the access token is held in an httpOnly cookie that the page cannot read, and it is used only for the imports you ask for.

Scanning a folder on your own machine does none of this. If your code cannot leave your network, that is the path to use.

Deleting everything

Delete the .atlas.api/ folder inside a project to erase everything about that project. Clear this site’s data in your browser to erase collections, environments and saved responses. Neither has a copy on our side to expire, so there is no request to make. To leave the mailing list, use the unsubscribe link or write to us.

Licensing

The Atlas agent — the process you run on your own machine — is open source under the MIT licence, so you can read exactly what it does before you run it. The analyser it contains is proprietary and ships as a build artifact.

Getting in touch

Questions about anything on this page, or a request to remove data, go to the support address in the footer of every page.