Atlas policy / Version 1

Atlas privacy

Public curriculum and private learning evidence remain different systems with different permissions.

Applies
Web, desktop, curriculum, accounts
Updated
August 12, 2026
Status
Pre-launch policy

Without an account

Canonical lessons, maps, labs, projects, and local browser progress are available without an identity. Local state stays in that browser unless the learner explicitly signs in and migrates it.

With an account

Supabase stores learner-owned progress events, mastery snapshots, notes, bookmarks, and project records. Row-level security restricts those records to the authenticated learner.

Private sources

Cloud intake is subscriber-only and opt-in. Original filename, MIME type, size, SHA-256 hash, owner, retention, and extraction provenance are recorded. Active content is never inline-rendered or executed.

Desktop keys

Local provider keys remain in the operating-system keychain and never sync to Supabase or Ephemerent.