Skip to content

Data stewardship

Privacy Policy

Last updated: July 2026

Atlas helps commercial real estate investors organize property, lease, and rent-roll data that already lives in their own Google and Microsoft accounts. This policy explains exactly what we access, why, and the control you have.

01

Only the data sources you explicitly connect. For Google Drive and OneDrive, Atlas lists folders so you can choose a source, then reads documents only from the folders you select and their subfolders. If you turn on the optional managed email-attachment intake folder, Atlas may create and write only to that dedicated folder in your Drive or OneDrive. Gmail and Outlook use read-only mail permissions. You may narrow mail collection to a label, folder, or Gmail search scope, or let Atlas scan the mailbox and keep only property-related messages. We use this access solely to read property documents and emails for extraction. Atlas does not send mail, delete your existing source files, or modify files outside the opt-in intake folder.

02

Atlas’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request drive.readonly so Atlas can present and sync selected Drive folders, drive.file only when you enable the managed email-intake folder, and gmail.readonly to list and read messages so property-related documents can be identified. This Gmail permission is broad read-only mailbox access at the OAuth layer; Atlas lets you optionally narrow collection with a label or search query in the application. We do not use this data for advertising, and we do not sell it.

03

To structure your documents we use a third-party AI provider through a single interface configured so your content is not used to train AI models. With our current provider, content may be retained by the provider for up to 30 days for abuse monitoring only, then deleted. We make no “zero-retention,” “bank-grade,” SOC 2, or other certification claims we do not hold.

04

A lightweight first pass filters to genuinely relevant documents before anything is analyzed in depth. We never send whole inboxes or drives to any AI provider. We do not write document or email contents to application logs. If you choose private archiving, Atlas may retain the source file and bounded evidence excerpts needed to explain a proposed change; those excerpts are redacted when the associated retained version is deleted or expires.

05

The tokens that grant access to your connected accounts are encrypted at the application layer with a key held outside our database, so a database leak alone cannot reach your accounts. Every customer’s data is isolated at the database level so no other customer can read yours. Data is transmitted over TLS and stored on infrastructure with encryption at rest.

06

Atlas may apply a source-derived record only when it passes the organization's confidence threshold plus evidence, authority, business-date, and identity checks. Anything uncertain or conflicting stays in Review. Anything you correct becomes the source of truth that future syncs will not overwrite.

07

You can disconnect any source at any time to revoke our access, or delete all of your ingested and extracted data in one click from your settings. This removes connected-source records, documents, retained copies, extracted portfolio data, reviews, and AI instructions; a metadata-only audit record of the deletion remains. You may also revoke access from your Google or Microsoft account security settings.

08

Questions about this policy or your data: admin@atlasrealestate.app.