Privacy Policy
Last updated: 13 August 2026
Atlas is a strength-training and nutrition tracker for iPhone, built by Mark Eskandar. This policy describes exactly what the app does with your data. It is written from the app's source code rather than from a template, so everything below is a statement about how Atlas actually behaves.
The short version
Atlas has no accounts, no backend, and no servers operated by us. Everything you log — workouts, sets, foods, weight, notes — is stored on your iPhone and stays there. We cannot see it, because there is nowhere for it to go.
The only data that leaves your device is what you type into food search, or the barcode you scan. Those go to three public food databases so they can answer. Nothing identifying you goes with them.
There are no analytics, no advertising, no trackers, and no third-party SDKs.
One exception, and it is on this website rather than in the app: if you ask for a TestFlight invite, the form sends what you typed to Mark. What happens to it.
What Atlas stores on your device
All of the following is kept in Atlas's own storage on your iPhone and is never uploaded anywhere:
- Training data — exercises, sets, weights, reps, your split, session outcomes and any note you write at the end of a session
- Nutrition data — your food library, saved recipes, diary entries, water, and the calorie and macro goals you set
- Profile — name, bodyweight, height, birth year, sex and activity level. These are used to estimate your energy needs; that calculation happens on the device
- Health readings you have granted Atlas access to (see below)
- A local activity log — a technical record of app events (launches, crashes, sets logged, storage failures) used to diagnose problems. It records what the app did, not what you searched for. It stays on the device unless you choose to export it
If you delete Atlas, all of it is deleted with the app. You can also erase everything from inside the app: Profile → Reset all data.
What leaves your device, and when
Food search and barcode scanning
When you search for a food or scan a barcode, Atlas sends that search term or that barcode number to three public food databases so they can return matching results:
| Service | Operator | What it receives |
|---|---|---|
| Open Food Facts | Open Food Facts (non-profit) | Your search term or scanned barcode |
| FoodData Central | U.S. Department of Agriculture | Your search term |
| fatsecret | FatSecret (Secret Industries Pty Ltd) | Your search term or scanned barcode |
What is sent is limited to the search term or barcode, plus a generic identifier for the app itself. No name, no account, no device identifier, and nothing else you have logged is included. These requests happen only when you search or scan — Atlas does not pre-fetch, crawl, or sync anything in the background.
As with any internet request, these services will see the IP address your request comes from. That is a property of how the internet works, not something Atlas adds. Each service handles what it receives under its own privacy policy, linked above.
Results you save are stored on your device from then on, so re-logging a food you have used before requires no further request.
Nothing else
Atlas makes no other network requests. There is no analytics endpoint, no crash reporting service, no advertising network, and no account server.
The TestFlight invite form
This is the one place this website collects anything, and it is worth being exact about, because everything else on this page says the opposite.
When you ask for a TestFlight invite, the form sends your name, email address, and — if you filled them in — your device and what you train to a small function running on Cloudflare, which forwards them to Mark as an email. Your country, as Cloudflare reports it from your connection, is included so a reply can be timed sensibly.
- No script from anyone else runs in your browser. The form posts to this same site. The only onward call happens on the server, after your request has already left your machine.
- Two companies handle it in transit — Cloudflare, which hosts this site, and Resend, which delivers the email. Neither is asked to profile you, and nothing is stored in a database.
- It ends up in a mailbox. After that it is an email Mark has, kept until the TestFlight round it belongs to is over.
- Nothing is added to a mailing list. There is no list, no sequence, and no newsletter. You will hear about TestFlight, and otherwise not at all.
- Ask and it is gone. Email support@atlaslifts.app and the request is deleted.
None of this touches the app. Atlas itself still has no accounts and no backend; this form is a website feature, and it exists because "email me" was a worse experience than a form.
Apple Health
If you grant permission, Atlas reads sleep, steps, active energy, heart rate and bodyweight from Apple Health to inform your dashboard and recommendations.
- Access is read-only and entirely optional; Atlas works without it
- Health data is used on the device and is never transmitted anywhere
- You can revoke access at any time in Settings → Health → Data Access & Devices → Atlas
- Health data is never used for advertising or shared with anyone
Camera
Atlas uses the camera for one purpose: reading a barcode. Recognition happens on the device. No photo or video is stored, saved to your library, or transmitted. Only the decoded barcode number is used, and only to look the product up as described above.
Widgets and Lock Screen
Atlas writes a small summary — the next lift, your streak, calories remaining — into a shared container on your device so its widgets and Live Activity can show it. This container is local to your iPhone and never leaves it.
Exports you initiate
Atlas can export a backup of your data, and separately its activity log, through the standard iOS share sheet. This only ever happens when you tap the export button and choose a destination.
Once you send a file to another app or service — iCloud Drive, Files, email, anywhere else — that copy is governed by that destination's terms, not by this policy. Atlas has no visibility into it.
What we do not do
- We do not sell, rent, or share your data. There is no mechanism by which we could; we never receive it.
- We do not track you across apps or websites.
- We do not show advertising.
- We do not use your data to train machine-learning models.
- We do not build a profile of you. The app's suggestions are computed on your device from your own logged history.
Children
Atlas is not directed at children under 13, and we do not knowingly collect information from them. Since the app collects nothing centrally, there is no data for us to hold or delete on request — deleting the app removes everything.
Your rights
Because your data never reaches us, the usual access, correction, portability and deletion rights resolve on the device itself:
- Access and portability — export a backup from Profile → Export a backup
- Correction — edit or delete any entry directly in the app
- Deletion — Profile → Reset all data, or delete the app
We hold no copy to produce, correct, or erase. If you would like that confirmed in writing, contact us at the address below.
Changes to this policy
If this policy changes in a way that affects what happens to your data, the "last updated" date above will change and the revised policy will be published at the same address before the change takes effect.
Contact
Questions about this policy or about privacy in Atlas: support@atlaslifts.app
Atlas is an independent app. Open Food Facts, USDA FoodData Central and fatsecret are separate services referenced here because Atlas queries them on your behalf; they are not affiliated with Atlas.