Privacy Policy

    Last updated: July 2026. This policy describes how Atlarix and NorahLabs collect, use, and protect your information. For questions or requests, contact us at support@atlarix.dev.

    1. Introduction

    Atlarix is a native desktop application for AI-assisted software development. This policy applies to the Atlarix application and the website atlarix.dev. Atlarix is provided by NorahLabs. Atlarix is intended for users aged 13 and older. Users in the EU must be at least 16.

    For privacy-related questions or requests, contact us at support@atlarix.dev.

    2. Authentication

    You sign in to Atlarix via GitHub OAuth or Google OAuth, both handled through Supabase Auth. We receive:

    • Email address
    • Name
    • Profile picture

    We use this data for account identification, workspace management, profile display, support, and legal compliance. You can revoke Atlarix's access at any time in your GitHub or Google account settings.

    3. Analytics

    Desktop app: the Atlarix desktop app uses PostHog for product analytics (user actions, feature usage, session data). PostHog may collect IP address and device information. Data is processed on PostHog's servers in the EU. Analytics collection is optional and opt-in — we ask for your consent on first launch, and you can opt out at any time in Settings.

    Website: the Atlarix website (atlarix.dev) uses Google Tag Manager (GTM-N85TNSKM) and Google Analytics 4 (G-55B1YGXF4J) for site analytics; these may collect IP address and browser information per Google's policies. The website does not run PostHog.

    4. Error Monitoring

    We use Sentry for crash reporting and error monitoring. Sentry may collect device info, OS version, app version, and error stack traces. We do not intentionally collect code content in error reports.

    5. Workspace and Code Data

    Atlarix Core (default): Unless you set up your own models, Atlarix runs on Atlarix Core. Your request passes through our authenticated proxy, which verifies your account before anything is sent — we don't log or retain the request. From there it goes directly to the model provider that serves it, who processes it under their own data policy. We don't have zero-retention agreements with these providers, so we can't guarantee what they keep. See our Models page for how models are connected in Atlarix.

    Local models (you set up): Run a local model — for example through Ollama — and your code and prompts never leave your machine. Nothing is sent, stored, or logged — by us or anyone.

    Your own API key (you set up): Add your own provider key and requests go directly to the provider you chose. Atlarix acts as a local client — we never see the traffic.

    Training: We never train on your code, in any mode.

    6. Account Data

    Account data is stored securely in Supabase (servers in the US and EU). This includes:

    • Email, name, profile picture
    • Subscription tier
    • Atlarix Core prepaid credit balance and top-up / usage history
    • Onboarding state and connected extensions

    7. Payments

    Payments are handled entirely by LemonSqueezy. We do not store payment card data. LemonSqueezy is subject to its own privacy policy.

    8. Agent Integrations (Pro)

    Pro users can connect services such as Slack, Jira, Linear, Sentry, Notion, and Google Calendar by configuring MCP servers in the app. Credentials you supply (including tokens for third-party APIs) follow each server's configuration and the app's local storage model for MCP settings—they are not outsourced to a separate hosted credential service.

    Atlarix agents access these services on your behalf with your explicit consent and scoped permissions.

    9. Your Rights

    You can request access to, correction of, or deletion of your personal data by emailing support@atlarix.dev. We will process deletion requests within 30 days in line with applicable law.

    You may export your workspace configuration via the .atlarix folder at any time. You may object to analytics collection or error monitoring by opting out in Settings.

    You can revoke GitHub or Google OAuth access at any time in your respective account settings.

    10. Cookies

    The Atlarix website (atlarix.dev) uses cookies set by Google Tag Manager and Google Analytics 4 for site analytics, plus cookies needed for basic site functionality. The website does not use PostHog cookies.

    You can opt out via your browser settings or browser extensions that block analytics cookies.

    11. Data Retention

    PostHog analytics data is retained for 12 months. Sentry error data is retained for 90 days. Account data is retained until you request deletion.

    Upon a deletion request, we remove personal data within 30 days.

    12. Legal Basis

    Our data processing is based on contract performance (to provide the service) and legitimate interest (security, error monitoring, product improvement).

    Where applicable under GDPR, our legal bases are contract performance (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)). We comply with GDPR, CCPA, and other applicable data protection laws where relevant.

    13. Security

    We use encryption in transit (TLS) and at rest via Supabase, and follow least-privilege access principles. We do not store payment card data or raw OAuth tokens.

    14. Policy Changes

    We may update this policy from time to time. We will notify you of significant changes via the app or website. Continued use of Atlarix after changes constitutes acceptance of the updated policy.

    15. Contact

    For privacy questions or requests, contact us at support@atlarix.dev.

    Privacy disputes are subject to the laws of Kenya.

    The Atlarix name, logo, and all associated branding are trademarks of NorahLabs. Unauthorized use is prohibited.