Atlas policy / Version 1
Atlas privacy
Public curriculum and private learning evidence remain different systems with different permissions.
- Applies
- Web, desktop, curriculum, accounts
- Updated
- August 12, 2026
- Status
- Pre-launch policy
Without an account
Canonical lessons, maps, labs, projects, and local browser progress are available without an identity. Local state stays in that browser unless the learner explicitly signs in and migrates it.
With an account
Supabase stores learner-owned progress events, mastery snapshots, notes, bookmarks, and project records. Row-level security restricts those records to the authenticated learner.
Private sources
Cloud intake is subscriber-only and opt-in. Original filename, MIME type, size, SHA-256 hash, owner, retention, and extraction provenance are recorded. Active content is never inline-rendered or executed.
Desktop keys
Local provider keys remain in the operating-system keychain and never sync to Supabase or Ephemerent.