Privacy
Atlas collects as little as it can. You can use every part of it without an account, and nothing about you is sold, shared for advertising or used to track you.
In short
- No cookies, no analytics, no ads, no trackers.
- Your progress lives in your browser. It leaves it only if you sign in to sync it.
- Search questions are sent to our search function without anything that identifies you; your IP address is only used, scrambled, to limit abuse, and deleted within minutes.
- Account and synced data are stored in the EU (Frankfurt).
Who is responsible
The data controller is Christoffer Maintz Andersen. Questions and requests about your data:cmaintz@outlook.com
What we process, and why
Visiting the site
- What
- Your IP address and the pages you request.
- Why
- To deliver the pages and keep the hosting secure.
- Where, and who processes it
- GitHub Pages (GitHub, Inc., USA) logs every visit to its sites. We cannot see or switch off these logs.
- Legal basis
- Legitimate interest (GDPR Art. 6(1)(f)): running a secure website.
- How long
- Decided by GitHub - see GitHub's privacy statement.
Search by meaning
- What
- What you type in the search box, when it reads like a question (three or more words) or matches no term name. Searches for a name are handled in your browser and not sent.
- Why
- To find terms that match what you mean.
- Where, and who processes it
- Our search function at Supabase (Frankfurt, EU) turns the text into numbers using Cloudflare Workers AI. Cloudflare receives only the text - no IP address, account or other identifier - and may process it outside the EU. Please do not type personal information into the search box.
- Legal basis
- Legitimate interest (Art. 6(1)(f)): answering the search you asked for.
- How long
- We do not store the question, and we use no Cloudflare storage, so nothing is kept there. Cloudflare states that it does not use it to train models. Supabase keeps short technical request logs (about one day on our plan).
Protecting search from abuse
- What
- A scrambled form (SHA-256 hash) of your IP address and a count of your searches in the current minute. Your IP address itself is never stored. Because an IP address can in principle be guessed back from its hash, we treat the hash as personal data.
- Why
- To allow at most 30 searches a minute per visitor, so no one can use up the free service for everyone.
- Where, and who processes it
- Our database at Supabase (Frankfurt, EU), in a table only the search function can reach.
- Legal basis
- Legitimate interest (Art. 6(1)(f)): preventing abuse.
- How long
- Each per-minute counter expires 2 minutes after it starts and is deleted within 15 minutes. A site-wide daily total, which contains no identifier, is deleted after 2 days.
Your account (optional)
- What
- What your sign-in provider (GitHub or LinkedIn) shares when you sign in: your email address, account ID, name or username and profile picture link. Supabase also records your sign-in sessions and a log of sign-in events, including the IP address and browser used.
- Why
- To know that it is you, so your progress can follow you between devices. We show only your email address; we use nothing else.
- Where, and who processes it
- Supabase (Frankfurt, EU), as our data processor.
- Legal basis
- Performance of the service you signed up for (Art. 6(1)(b)).
- How long
- Until you ask us to delete your account. Sessions end when you sign out.
Synced progress (optional)
- What
- The same progress kept in your browser (answers per term, when each is due, the status you set, and when), plus when it was last changed.
- Why
- To keep your progress in step across your devices.
- Where, and who processes it
- Supabase (Frankfurt, EU). Only you can read or change your own row.
- Legal basis
- Performance of the service you signed up for (Art. 6(1)(b)).
- How long
- "Delete my synced data" empties it at once. An empty marker with the time of deletion remains, so other devices cannot upload the progress again, until your account is deleted.
Emails you send us
- What
- Your email address and what you write.
- Why
- To answer you, for example a request to delete your account.
- Where, and who processes it
- Our mailbox (Microsoft Outlook).
- Legal basis
- Legitimate interest (Art. 6(1)(f)) in answering, or a legal obligation (Art. 6(1)(c)) when you use your rights.
- How long
- As long as needed to handle your request.
What is stored in your browser
Atlas sets no cookies. It keeps the items below in your browser’s storage. They stay on your device (only your progress is synced, and only if you sign in), and you can remove them at any time by clearing the site data in your browser.
| Name | Kept in | Purpose |
|---|---|---|
| atlas:learner:v2 | localStorage | Your study progress: which terms you have answered, when they are due again, and the status you gave them. Synced only if you sign in. |
| atlas.recent | localStorage | The last few terms you opened, for "Recently viewed" on the front page. |
| atlas.langSuggest.dismissed | localStorage | That you closed the suggestion to read the site in Danish. |
| atlas.theme | localStorage | The colour theme you picked (light or dark). Not set while you follow your system setting. |
| atlas.explorer.legend | localStorage | Whether you left the Explorer legend open or closed. |
| atlas.tour | localStorage | Where you are in the guided tour, so it can continue on the next page. |
| atlas.tour.done | localStorage | That you finished or turned off the tour, so it is not offered again. |
| atlas.tour.snoozed | sessionStorage | That you chose "not now" for the tour. Gone when you close the tab. |
| atlas.probe | localStorage | Written and removed at once, to check that the browser allows storage. |
| atlas:account:notice | localStorage | Only with an account: a note that you were signed out because your synced data was deleted on another device. |
| sb-<project>-auth-token | localStorage | Only while signed in: your sign-in session (set by Supabase), so you stay signed in. Removed when you sign out. |
| sb-<project>-auth-token-…-code-verifier | localStorage | Only during sign-in: a one-time secret that proves the sign-in was started in this browser. Removed when sign-in completes. |
Every item is either strictly necessary for something you asked for or remembers a choice you made, so under the ePrivacy rules (in Denmark, the cookie order - cookiebekendtgørelsen) no consent is needed and there is no cookie banner. Atlas uses no analytics, advertising or tracking. If that ever changes, we will ask for your consent first.
Who else is involved
- GitHub, Inc. (GitHub Pages) - Hosts the website and logs visits (USA). Also a sign-in provider, if you choose GitHub.
- Supabase, Inc. - Accounts, synced progress and the search function; data stored in Frankfurt (EU). Our data processor.
- Cloudflare, Inc. (Workers AI) - Turns search questions into numbers. Receives only the question text, never who asked.
- LinkedIn - Sign-in provider, only if offered and you choose it. Like GitHub when you sign in with GitHub, LinkedIn is responsible for your account there and learns that you signed in to Atlas.
Your rights
- Access: email us and we send you everything we hold about you.
- Rectification: your progress is yours to change on the site; your name and email come from your sign-in provider, so change them there - or email us.
- Erasure: "Delete my synced data" on the account page removes your progress from the server at once. To delete your account itself (email address and sign-in records), email us.
- Portability: "Download my progress" on the account page saves your progress as a JSON file.
- Objection and restriction: you may object to processing based on legitimate interest, or ask us to restrict it - email us.
We answer within one month. cmaintz@outlook.com
Complaints
You can complain to the Danish Data Protection Agency (Datatilsynet). We would appreciate hearing from you first.Complain to Datatilsynet
Changes
If what we collect changes, this page changes first, with a new date at the top.