ChangelogRadar — Privacy Policy
Effective date: July 18, 2026
This Privacy Policy explains how The Atlas Project ("we," "us," "our") handles personal information in connection with ChangelogRadar at changelogradar.the-atlas-project.net (the "Service"). It applies to the Service and our marketing site. It does not cover third-party services you connect to (such as the calendar client you subscribe the .ics feed in), which have their own policies.
Our posture, honestly stated: essential cookies only; no analytics or advertising pixels; no "sale" of personal information; data-subject requests handled by email. Every statement here is meant to be true of how the Service actually behaves. If our behavior changes, we will update this Policy.
§P1 Our role
For your account and billing data, and for the operation of the Service generally, we act as a controller. ChangelogRadar processes dependency manifests, stack lists, and vendor selections you submit — not personal data held on behalf of your own customers — so ChangelogRadar is not a "processor-role" product and no data-processing addendum applies. (Please do not paste personal data, secrets, or credentials into a manifest; a manifest should contain package names and versions only.)
§P2 Personal information we collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, password or OAuth identity, workspace settings | you, at signup (via Supabase auth) |
| Billing data | plan, billing email, partial card metadata, transaction history | you and Stripe (we do not store full card numbers) |
| Usage & device data | log events, feature usage, IP address, timestamps, error logs | automatically, to run and secure the Service |
| Scan data | the dependency manifest you paste and the derived result; for anonymous scans, a hash of your dependency set and the originating IP address (for rate-limiting and abuse prevention); for logged-in scans, your saved scan history | you |
| Your configurations | tracked vendors, stack lists, watches, .ics feed tokens, webhook endpoints (Team) | you |
| Support data | messages you send us and our correspondence | you |
| Essential cookies | Supabase authentication-session cookie | your browser session |
A dependency manifest generally contains package names and versions, not personal information. To the extent you include personal information in what you submit, it is processed as described here.
We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this ever changes, we will update this Policy and, where required, obtain consent first.
§P3 How and why we use personal information
- Provide the Service — authenticate you, parse your manifest, match it against our curated archive, build your Sunset Calendar and change feed, and deliver results and the
.icsfeed. - Billing — process subscriptions via Stripe.
- Communicate — send transactional and service messages (receipts, security notices, product notices) and the email digest and alerts you enable, via Resend. Marketing email, if any, is sent only where permitted and with an unsubscribe option.
- Secure and maintain — rate-limit anonymous scans, detect and mitigate abuse, debug errors, and protect the Service and its users.
- Comply — meet legal obligations and enforce our Terms.
- Improve — understand feature usage in aggregate and improve archive coverage. We do not use the content you submit to train generalized AI models.
Note on our use of AI. ChangelogRadar uses an Anthropic model to summarize, date, and classify vendor changes when building the public archive. That processing operates on public vendor source material (changelogs, release notes, pricing pages) — not on your account data or the manifests you submit. Your submitted content is not sent to an AI model to build your results and is not used to train any model.
§P4 Legal bases (GDPR / UK GDPR)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, rate-limit, and improve the Service, and for limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax and records).
§P5 Subprocessors and service providers
ChangelogRadar uses the following subprocessors. We enter data-processing terms with them where required and require appropriate safeguards.
| Subprocessor | Function |
|---|---|
| Vercel | Application hosting and edge delivery |
| Supabase | Database and authentication |
| Stripe | Payment processing and subscription billing |
| Resend | Transactional/service email, digests, and alerts |
| Anthropic | AI model used to classify and summarize public vendor changes for the archive (does not process your submitted content) |
| Upstash | Rate-limiting store (processes IP address / request metadata to throttle abuse) |
| Sentry | Error monitoring (may incidentally include IP address and technical context in error events) |
| Better Stack | Uptime and availability monitoring |
We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.
§P6 Cookies and similar technologies
We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in, and a short-lived signed cookie used to bind an anonymous scan to your session if you create an account. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.
§P7 Retention
We keep account and billing data for as long as your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure. Saved scans and configurations are retained per your settings and are deleted or de-identified on request or on Account closure. Anonymous scan records and the associated IP address are retained only as long as needed for rate-limiting and abuse prevention, then purged or de-identified on our ordinary cycle. Residual backups are purged on our ordinary cycle; records we must keep by law are retained as required.
§P8 Security
We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege, row-level security in our database, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe). No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.
§P9 Your privacy rights
§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority.
§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, and correct your personal information, and to opt out of "sale" or "sharing." We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes that would require a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.
§P9.3 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law.
§P10 International data transfers
We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.
§P11 Children
The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).
§P12 Changes to this Policy
We may update this Policy. We will post the new version with a revised effective date and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.
§P13 Contact
Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].
Last updated: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net
This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.