Atlas Back to Atlas

Privacy Policy

Last updated: 4 October 2026

Atlas is a strength-training and nutrition tracker for iPhone, built by Mark Eskandar. This policy covers your Atlas account, which keeps a synced copy of what you log, the rest of the app, and this website. It is written from the source rather than from a template, so everything below is a statement about how Atlas actually behaves.

The short version

You sign in to Atlas with Google or with a code sent to your email. Your account keeps a copy of what you log — workouts, foods, weigh-ins, your profile and goals — so it is backed up and the same on every device you sign in on. That copy is stored with Supabase, in Canada, and only your signed-in devices can read it.

Apple Health data is never uploaded. Neither is a meal photo: if you turn on photo logging, a photo is sent through Atlas's server to Google's Gemini so the foods on it can be identified, and Atlas does not store it. Food searches and barcodes go to public food databases so they can answer, with nothing identifying you attached.

There are no analytics, no advertising, no trackers, and no third-party SDKs. Your data is not sold or shared for marketing.

You can delete your account and everything synced to it from the app, in Settings → Account → Delete account, or on this website with a code sent to your email.

Your account

Everyone who uses Atlas signs in. That is what lets you log from any of your devices and get your history back on a new phone.

What your account holds

Each record also carries the time it was last changed, which is how two devices agree on the newer version.

Some things stay on the phone and are never synced: whether Atlas is in Food or Weights mode, a workout that is in progress, whether photo logging is turned on, the local activity log, and anything from Apple Health.

Why

Only to back up your log and keep it the same on every device you sign in on. Atlas’s suggestions are still worked out on the device from your own history; nothing is analysed on the server.

Where it is stored, and who can read it

Atlas’s accounts, sign-in and sync run on Supabase, a hosted database and sign-in service. Your account and its records are stored in Supabase’s Canada (Central) region. Supabase handles them on Atlas’s behalf, under its data processing terms, and does not use them for its own purposes. Supabase is a US company, so it and the providers it relies on may reach the data from other countries to run the service.

Everything travels over encrypted connections. The database only lets a signed-in person read and change their own records. Changes reach your other signed-in devices live, through Supabase.

Sign-in records

Like any sign-in service, Supabase keeps a record of account activity: when an account asks for a code, signs in or signs out, with the IP address and the app or browser the request came from. These records are used only to keep accounts secure and to look into sign-in problems.

Supabase keeps its service logs under its own retention rules; on Atlas’s current plan, the logs Atlas can see cover only the last day. A history of sign-ins may also be kept in the account database itself, and so in its backups. That history is not removed automatically when an account is deleted: email support@atlaslifts.app and we will remove yours.

Backups

Once a night the database (your account and every synced record) is copied, encrypted, and kept as a private backup on GitHub for 30 days, so a failure on Supabase’s side cannot lose your log. The copy is encrypted before it leaves for GitHub and is opened only to restore the database. On Atlas’s current plan Supabase keeps no backups of its own, so these are the only copies.

How long it is kept

For as long as you have an account. When you delete it, in the app or on the website, the account and every record synced to it are removed from the database straight away. Copies inside the nightly backups expire with those backups, within 30 days.

Deleting your account

Either way, data already on a phone stays there until you erase it in the app or delete the app. Signing out does not delete anything: the data stays on the phone and in your account.

Sign-in providers

If you sign in with Google, Google knows you signed in to Atlas, under its own privacy policy. Sign in with Apple is planned; when it arrives the same will be true of Apple. Email codes, including the one the delete-account page sends, are sent by Supabase’s sign-in service and delivered through Resend (which sees your email address and the code, under its own policy).

The rest of the app

Everything from here to “Exports you initiate” describes the iPhone app apart from your account.

What Atlas stores on your device

Everything you log is kept in Atlas’s own storage on your iPhone, so the app works without a connection. The synced records listed above are also in your account. These stay on the phone only:

Deleting Atlas deletes what is on the phone, not your account. Settings → Reset all data erases your profile, training and food. While you are signed in, it asks which of two things you mean:

When you are not signed in, a reset erases this phone only.

What leaves your device, and when

Foods that ship with the app — these never leave

Atlas includes a copy of the most-scanned foods from Open Food Facts, so the common case can be searched with no connection at all. Those searches make no request: there is nothing to send, because the answer is already on your phone. The data is used under the Open Database License (ODbL) and is credited in the app under Settings → Food data.

Food search and barcode scanning

When you search for a food or scan a barcode, Atlas sends that search term or that barcode number to three public food databases so they can return matching results:

ServiceOperatorWhat it receives
Open Food Facts Open Food Facts (non-profit) Your search term or scanned barcode
FoodData Central U.S. Department of Agriculture Your search term
fatsecret FatSecret (Secret Industries Pty Ltd) Your search term or scanned barcode, or a restaurant chain's name

What is sent is limited to the search term or barcode, plus a generic identifier for the app itself. No name, no account, no device identifier, and nothing else you have logged is included. These requests happen only when you search or scan; Atlas does not pre-fetch or crawl anything in the background.

Restaurant menus. When you open a restaurant chain in Places (McDonald's, Tim Hortons and so on), Atlas asks fatsecret for that chain's menu, sending only the chain's name. The menu is held in memory while the app is open and is not saved to your device.

As with any internet request, these services will see the IP address your request comes from. That is a property of how the internet works, not something Atlas adds. Each service handles what it receives under its own privacy policy, linked above.

A food you save goes into your food library, which is stored on the device and synced to your account like the rest of your log, so re-logging it requires no further lookup.

Apple Watch

If you use Atlas on Apple Watch, the watch and your iPhone exchange sets, foods and the current workout directly, over Apple's WatchConnectivity link between your own two devices. That exchange does not pass through any server of ours; what the phone then records syncs to your account like anything else you log.

Photo logging

Photo logging is off until you turn it on. Atlas asks first, and says what leaves your phone, the first time you tap the camera beside food search. You can turn it off again in Settings → Photo logging.

When you take or choose a meal photo, Atlas resizes it to about 1024 pixels on its longest side and re-encodes it from the pixels, which removes its metadata, including any location. It is sent over HTTPS through a small function on this website's server (atlaslifts.app/api/vision) to Google's Gemini API, whose model names the foods it can see and estimates each portion in grams. If you are in a Place, the names on that Place's menu go with it as hints. After Atlas shows its guess you can add an optional description in your own words (for example “2 eggs, toast with butter”), up to 300 characters. If you do, the photo is sent again with your description and the names from the first guess, handled the same way, and not stored. Leave it empty and nothing extra is sent. Nothing else is sent: no name, no account, no device identifier, and nothing you have logged.

Nothing else

Apart from your account’s sync, the food lookups and photo logging, Atlas makes no network requests. There is no analytics endpoint, no crash reporting service, and no advertising network.

Apple Health

If you grant permission, Atlas reads sleep, steps, active energy, heart rate and bodyweight from Apple Health to inform your dashboard and recommendations. It also reads your workouts, only to avoid saving a lifting session that another app has already recorded.

If you turn on Save to Apple Health (off unless you switch it on), Atlas also writes to Health on your device: your lifting sessions as strength-training workouts, the energy, protein, carbohydrate and fat of the food you log, and the weigh-ins you log. Editing or deleting an entry in Atlas updates or removes what it wrote. Only the phone where you logged an entry writes it to Health; entries that arrive from your other devices through sync are never written to Health again.

Camera

Atlas uses the camera for two purposes. Reading a barcode: recognition happens on the device, and only the decoded barcode number is used, to look the product up as described above. Photo logging, if you turn it on: the meal photo is sent to be identified as described under Photo logging. In both cases no photo or video is stored or saved to your library.

Widgets and Lock Screen

Atlas writes a small summary — the next lift, your streak, calories remaining — into a shared container on your device so its widgets and Live Activity can show it. This container is local to your iPhone and never leaves it.

Exports you initiate

Atlas can export a backup of your data, a CSV of your workouts and food diary, and separately its activity log, through the standard iOS share sheet. This only ever happens when you tap an export button and choose a destination.

Once you send a file to another app or service — iCloud Drive, Files, email, anywhere else — that copy is governed by that destination's terms, not by this policy. Atlas has no visibility into it.

This website

This site is served by Cloudflare. It runs no analytics and no third-party scripts. The TestFlight invite form sends what you type to Mark; the delete-account page talks to Atlas’s account service directly.

The TestFlight invite form

When you ask for a TestFlight invite, the form sends your name, email address, and — if you filled them in — your device and what you train to a small function running on Cloudflare. Your country, as Cloudflare reports it from your connection, is included so a reply can be timed sensibly.

That function does two things with it:

No script from anyone else runs in your browser. The form posts to this same site. The only onward call happens on the server, after your request has already left your machine.

Invite requests are deleted within 12 months of being received, or sooner if you ask. The date is fixed rather than tied to when TestFlight opens, because that date is not currently ours to set — Apple Developer Program enrolment is still pending, so there is no TestFlight round yet to anchor a promise to.

The delete-account page

The delete-account page sends nothing to this site’s server and stores nothing. Its script, served from this site, connects your browser straight to Supabase, the same service the app signs in with, in three steps: the email address you enter, to ask for a code; the code, to prove the address is yours; and the deletion itself. The page never creates an account. If no account uses that address, no code is sent. Supabase records these steps like any sign-in, with your IP address, as described under Sign-in records.

Asking for it back, precisely

Email support@atlaslifts.app and we will delete the stored invite request and the email itself. Two honest caveats, because a deletion promise broader than we control is not worth making:

There is no mailing list, no sequence, and no newsletter. Nothing about the website is used for advertising.

Who handles your data

CompanyWhat forWhat it handles
Supabase Accounts, sign-in, sync and account deletion (data stored in its Canada Central region) Your account and synced records; sign-in records, including IP addresses
GitHub Nightly database backups, kept 30 days Encrypted copies of the database
Google Sign-in, if you choose Google; photo logging, if you turn it on That you signed in to Atlas; the meal photo and any description you add
Cloudflare This website and its invite form; relaying photo-logging requests What you send through the invite form or the photo-logging function
Resend Delivering sign-in and deletion codes, and the invite form to Mark Your email address and sign-in code; what you typed into a form

The food databases in the table above receive search terms and barcodes only. When Sign in with Apple arrives, Apple will be added here.

What we do not do

Children

Atlas is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has made an account, email the address below and it will be deleted.

Your rights

If you would like any of that confirmed in writing, or something done that the app cannot do, contact us at the address below.

Changes to this policy

If this policy changes in a way that affects what happens to your data, the "last updated" date above will change and the revised policy will be published at the same address before the change takes effect.

Contact

Questions about this policy or about privacy in Atlas: support@atlaslifts.app


Atlas is an independent app. Open Food Facts, USDA FoodData Central and fatsecret are separate services referenced here because Atlas queries them on your behalf; they are not affiliated with Atlas.