Privacy Notice
Last updated: 4 August 2026
Atlaset helps you organise financial, ownership and legacy information. We have designed the service so that most sensitive content is encrypted in your browser before it is stored.
This Privacy Notice explains what information we process, why we process it, who may receive it and what rights you have.
1. Who is responsible for your information?
Atlaset is operated by:
Whimsy OÜ
Registry code: 17495721
Jalgpalli tn 21
11312 Tallinn
Estonia
Whimsy OÜ is responsible for the processing described in this Notice. References to “Atlaset”, “we” or “us” mean Whimsy OÜ.
For privacy questions or requests, contact atlaset@proton.me.
This Notice applies to the Atlaset website, application and related communications.
2. What information do we process?
Account and security information
We process information needed to create, secure and operate your account, including:
- Your email address and account identifier.
- Authentication and session information.
- Security settings and account activity.
- Account creation, update and acceptance records.
Your email address and authentication information are required to create and use an Atlaset account.
Information you add to Atlaset
Atlaset lets you organise information about assets, liabilities, accounts, documents, people, organisations and related matters.
Most sensitive content is encrypted in your browser before it is stored. This includes most financial details, names, notes, documents and private personal information.
Some information remains readable where necessary to operate the service. This includes account information, record types, connections between records, dates, settings and technical or organisational metadata.
This means that Atlaset may be unable to read the name or value of an encrypted record while still being able to see its general type and how it is organised within your map.
Technical information
When you visit or use Atlaset, we and our service providers may process technical information such as:
- Your IP address.
- Browser, device and network information.
- Requested pages or application functions.
- Authentication and security events.
- Error and diagnostic information.
We use this information to provide, secure and maintain Atlaset.
Communications
When you contact us, we process your email address, message, attachments and any other information you choose to provide.
We also process the information needed to send and deliver account, security, guardian, recovery and legacy-access messages.
Guardian and legacy information
When guardian or legacy-access features are used, we may process names, email addresses, relationships, invitation details and the status of related requests or actions.
3. How does Atlaset AI use information?
Atlaset’s AI features are optional and operate only when you submit a request.
Depending on your request, Atlaset may temporarily decrypt and send:
- Your prompt.
- Relevant conversation context.
- Selected information from your map.
- Calculations needed to answer your question.
- A document you explicitly submit for analysis.
This information is sent in readable form through OpenRouter to an approved AI model provider.
Atlaset configures these requests to use zero-data-retention processing. Under the configured privacy controls:
- Prompt and response content is not retained after processing.
- Prompt and response content is not used for model training.
- Limited technical information about the request may be retained, such as usage, model and performance information.
Atlaset does not automatically send your entire account or encrypted database to the AI provider.
If you save an AI conversation, Atlaset stores the conversation encrypted within your account.
For current information about the AI providers available through Atlaset, contact us.
4. Why do we process personal data?
We process personal data for the following purposes and legal reasons:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account | Performance of our contract with you |
| Providing maps, documents, recovery, exports and other requested features | Performance of our contract with you |
| Processing an AI request you submit | Performance of our contract with you |
| Authenticating users and protecting accounts | Performance of our contract and our legitimate interests in securing Atlaset |
| Preventing misuse, fraud and security incidents | Our legitimate interests in protecting Atlaset, its users and their information |
| Diagnosing errors and maintaining the service | Our legitimate interests in keeping Atlaset reliable and improving its operation |
| Operating guardian and legacy-access workflows | Our legitimate interests in providing the requested functionality |
| Responding to support, feedback and privacy messages | Performance of our contract, our legitimate interests in supporting users, or compliance with legal obligations |
| Complying with the law and handling legal claims | Compliance with legal obligations and our legitimate interests in establishing, exercising or defending legal claims |
Where we rely on legitimate interests, we consider whether the processing is necessary and whether those interests are outweighed by the rights of the people concerned.
Atlaset does not make decisions about people that produce legal or similarly significant effects solely through automated processing.
5. Information about other people
Atlaset users may add information about people who do not have Atlaset accounts, such as relatives, beneficiaries, advisers, co-owners, guardians or legacy contacts.
Where this happens, the information normally comes from the Atlaset user who added it.
Atlaset does not contact someone merely because they appear within a user’s map. We may contact them where necessary for a specific feature, such as a guardian invitation, recovery request or legacy-access notification.
Users are responsible for:
- Having a lawful reason to add another person’s information.
- Keeping that information relevant, accurate and proportionate.
- Informing the person where legally required.
- Avoiding unnecessary or excessive sensitive information.
Limited sensitive information should be added only where genuinely necessary for a supported financial, insurance, estate or legacy purpose and where the user is legally entitled to record it.
Because much of this information is encrypted, Atlaset may not know who the person is or be able to locate the information without help from the user who added it.
6. Who receives personal data?
We use the following main service providers:
- Supabase for authentication, database hosting, file storage and application infrastructure.
- Cloudflare for website and application hosting, delivery and network protection.
- OpenRouter and approved AI model providers for AI requests initiated by users.
- Resend for account, security, guardian, recovery and legacy-access emails.
- Sentry for error monitoring and service diagnostics.
- Proton Mail for support, feedback, privacy and legal correspondence.
These providers receive the information needed to perform their services on our behalf.
Further information about their purposes, processing locations and subprocessors is available by contacting us.
We may also disclose personal data where:
- We are required to do so by law or by a competent authority.
- It is necessary to protect Atlaset, its users or another person.
- It is necessary to establish, exercise or defend legal claims.
- Atlaset or its business is reorganised or transferred, subject to appropriate safeguards.
7. International transfers
Some providers or their subprocessors may process personal data outside the European Economic Area.
Where required, we protect these transfers using a legally recognised mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with additional safeguards where appropriate.
Further information about specific providers and transfer arrangements is available by contacting us.
8. How long do we keep information?
We keep personal data only for as long as it is needed for the purposes described in this Notice.
In particular:
- Account information and Atlaset content are kept while the account remains active.
- When an account is deleted, its live account data is deleted immediately through an automated process.
- Residual copies may remain in protected disaster-recovery backups for up to 14 days under normal operation.
- AI prompt and response content processed through OpenRouter is not retained after processing under the configured privacy controls.
- Security, diagnostic and email-delivery information is kept for as long as needed to operate and protect the service.
- Support, feedback and privacy correspondence is retained until manually deleted, taking account of whether it remains needed for follow-up, security, legal or record-keeping purposes.
- Information may be kept longer where required by law or reasonably necessary for a legal claim.
Provider-specific retention information is available by contacting us.
9. Browser storage and cookies
Atlaset uses first-party browser storage for:
- Authentication and session management.
- Account convenience features.
- Security and recovery workflows.
- Encryption-related functionality.
- Interface preferences.
Atlaset does not currently use advertising or analytics cookies.
If we introduce non-essential technologies that require consent, we will request that consent before using them.
10. Exports and downloaded information
Atlaset allows you to export map information and attachments.
Exports are created locally and become readable files once downloaded. They are no longer protected by Atlaset’s browser-side encryption after they leave the application.
You are responsible for protecting downloaded exports, including where you store, send or back them up.
11. How do we protect information?
Atlaset uses measures designed to protect personal data, including:
- Browser-side encryption of most sensitive content.
- Encrypted network connections.
- Access controls.
- Multi-factor authentication.
- Data minimisation.
- Security monitoring and backup procedures.
No online service can guarantee absolute security. You should protect your password, authentication methods, devices, recovery information and downloaded exports.
12. Your rights
Depending on the circumstances, you may have the right to:
- Ask whether we process personal data about you.
- Obtain access to your personal data.
- Correct inaccurate or incomplete information.
- Request deletion of your information.
- Restrict certain processing.
- Receive information you provided in a portable format.
- Object to processing based on legitimate interests.
- Withdraw consent where processing is based on consent.
- Complain to a data protection authority.
To exercise your rights, contact atlaset@proton.me.
We may need to verify your identity before responding, particularly where a request concerns sensitive account or financial information.
Atlaset’s self-service exports may not include every item of account, security or service information. You may contact us to make a complete access or portability request.
Where information was added by another user and encrypted within that user’s account, we may need that user’s cooperation to locate or understand it. This does not remove your legal rights.
You may complain to the Estonian Data Protection Inspectorate or to the data protection authority in the country where you live, work or believe your rights were infringed.
13. Changes to this Notice
We may update this Notice when Atlaset’s features, providers or legal obligations change.
Where a change materially affects how we process personal data, we will provide appropriate notice through Atlaset, by email or through another suitable method.
The date at the top shows when this Notice was last updated.