๐ŸŒ Italiano

Privacy Policy โ€” Atlas

Last updated: 6 September 2026

This policy describes how the Atlas application ("Atlas", "the app", "the Service") processes personal data, in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable Italian law.


1. Data controller

Axxell VAT: 03148500352 Registered office: Via Provinciale 40, 42030 Viano (RE), Italy Privacy contact email: info@axxell.ai

For any request regarding data processing, please write to the email above.


2. How it works: "local first"

Atlas is a desktop application that runs on your Mac. Most of your data (tasks, notes, clips, Atlas's personal calendar, knowledge base, learned corrections, settings, profile) is stored exclusively locally on the device, in the app data folder (~/Library/Application Support/atlas-secretary/), and is not transmitted to our servers.

Some features do require sending content to third-party cloud services to be processed (e.g. understanding your voice, generating a reply, synthesising audio). Those flows are described below.

In particular:


3. Categories of data processed

Category Examples Where
Licence & account data licence key, email, plan, subscription status, device ID (hardware), device name, last access date Our relay + Stripe
Voice data the audio of your voice while in use, and its transcription Sent for transcription (see ยง5)
Conversation content text of requests and replies, context provided to Atlas Sent to the AI model (see ยง5)
Content you ask to process extracts of emails, calendar events, contacts, files, business data you ask Atlas to read or act on Read locally; extracts sent to the AI model only if needed to reply
Business data (Business Connect) revenue, orders, clients, invoices, bank balance/transactions (open banking) Retrieved from the sources you connect; processed for insights
Technical & usage data aggregate consumption (variable cost per cycle, for fair-use), essential technical logs Our relay

Atlas does not carry out advertising profiling, does not sell data, and does not use it to train models.


4. Purposes and legal bases

Purpose Legal basis (Art. 6 GDPR)
Provide the Service's features (voice, AI, TTS, email/calendar reading, insights) Performance of the contract (6.1.b)
Licence, subscription, billing and anti-sharing device binding Performance of the contract + legal obligations (6.1.b, 6.1.c)
Fair-use and security (abuse prevention, usage calculation) Legitimate interest (6.1.f)
Access to email, contacts, calendar, files, bank account, business data Consent, via macOS permissions and the connections you voluntarily enable (6.1.a)
Support and service communications Performance of the contract / legitimate interest

You can revoke macOS permissions (Microphone, Contacts, Calendars, Full Disk Access) at any time and disconnect business/bank sources, disabling the related features.


5. External providers (processors / sub-processors)

To provide the Service we rely on the following providers, which process data on our behalf or as independent controllers for their own infrastructure. Most are based in the United States; transfers are made on the basis of the European Commission's Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework, where applicable.

Provider Function Data processed Country
Anthropic (Claude) AI model that generates replies (incl. web search) Conversation text, provided extracts USA
OpenAI Voice transcription (speech-to-text) and fallback speech synthesis Voice audio, text USA
Cartesia Speech synthesis (Atlas's voice) Text to be spoken USA
ElevenLabs Fallback speech synthesis Text to be spoken USA
Google (Cloud/Maps/Sheets) Geocoding, places/maps, optional Google Sheets link Search queries, addresses, linked sheet data USA
Spotify Music playback control (if used) Track search queries EU/USA
Enable Banking PSD2 open banking (balance and transactions, if connected) Bank account data you connect EU (Finland)
Fatture in Cloud (TeamSystem) Business invoicing data (if connected) Invoices, clients, amounts Italy/EU
Railway Hosting of our relay server (no content logging) Licence data, in-transit request traffic USA
Cloudflare (R2) Hosting of the app's download and update files Installer files (no personal data) USA/EU
Stripe Payments and subscription management (checkout and renewals) Email, payment data, tax data EU (Stripe Payments Europe, Ireland) / USA
EmailJS Delivery of contact/request forms submitted from the website Name, email and message you enter in the form USA

With the main AI providers (Anthropic, OpenAI) a DPA with EU Standard Contractual Clauses is in place, incorporated into their commercial terms, and use of data for training is disabled in our account settings. We do not transmit your data to parties other than those necessary to provide the Service.


6. Where processing takes place and non-EU transfers


7. Retention


7-bis. Website and cookies

The axxell.ai website does not use cookies โ€” neither profiling nor marketing cookies โ€” and uses no analytics or tracking tools. We store nothing in your browser (no cookies, localStorage or sessionStorage). For this reason there is no cookie consent banner: there would be nothing to consent to.

The site's graphic resources (fonts, libraries) are hosted on our own servers: browsing does not load resources from advertising or tracking networks (no remote Google Fonts, no analytics), so no IP is transferred to third parties for tracking purposes.

There is a support chat widget (our own service, hosted on Vercel): it loads to offer you support, uses no cookies, and processes only the text you type in the chat, to answer your questions.

Other data is sent from the site only on your voluntary action: if you fill in a contact/request form, the data entered (name, email, message) is delivered via EmailJS; payment takes place on Stripe (checkout.stripe.com), subject to Stripe's own privacy and cookies.


8. Your rights

Under Articles 15โ€“22 GDPR you have the right to: access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and to withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise them, write to info@axxell.ai. Much of the data can be deleted directly by you by uninstalling the app or removing the local data folder.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante, www.garanteprivacy.it).


9. Security

We adopt appropriate technical and organisational measures: encrypted communications in transit (HTTPS/TLS), third-party service keys kept server-side (relay) and not in the app, device binding to limit unauthorised licence use, protected administrative access. No system, however, is 100% secure.


10. Minors

The Service is not intended for children under 16 and does not knowingly collect their data.


11. Changes

We may update this policy. The current version is always available with its date. Material changes will be communicated via the app or by email.


Legal/privacy review is recommended, in particular for the appointment of processors under Art. 28 GDPR and the up-to-date sub-processor list.