Privacy policy

This document explains what data Atlas AI processes, why, how long it keeps it, who it shares it with, and what you can demand about it. It is written to describe the system as it actually works, not to generically cover every hypothetical case.

Reference language

Spanish is the reference language for this document. This English version is provided for convenience; in case of discrepancy, the Spanish text prevails.

1. Who the controller is

The controller of the data described in this document is Alejandro Olmedo, a natural person operating Atlas AI as a personal project, resident in Mexico for the purposes of notices.

Contact for any privacy-related matter: alejandro.olmedo14@gmail.com.

Atlas AI is not a company, has no employees, and sells no service. No data protection officer has been appointed, because the nature and volume of the processing does not require one.

2. What Atlas AI is and who this policy covers

Atlas AI is a personal tool that automates the generation and publication of social media content. It is registered with Meta as a developer application with the public identifier 1583910826653085.

Its operating model is deliberately closed:

This policy applies to you if:

If you follow one of these Pages

Atlas AI does not process your data. It does not read comments, does not read messages, and does not download follower lists or individual-level audience statistics. All it does on the Page is create posts, and only with prior human approval. Any data Meta processes about you because you use Facebook or Instagram is governed by Meta's privacy policy, not this one.

3. Data that is processed

The inventory below is exhaustive. If a data item is not in this table, the system does not store it.

Categories of data stored by Atlas AI.
Category Specific data What for
Page identity Facebook Page identifier, public name, username, category, list of permissions granted to the administrator, and the identifier and username of the linked Instagram Business account if one exists. Knowing which Pages can be operated on, and routing each post to the correct destination.
Access credentials The controller's user access token and one Page access token per managed Page, stored encrypted. Alongside them: issue date, expiry date, the permissions they carry, and a cryptographic fingerprint that allows changes to be detected without decrypting anything. Authenticating calls to Meta's API and detecting when a token has expired or been revoked.
Editorial configuration Time zone, language, style or tone guidance, and publishing time preferences per Page. Making generated content sound consistent with each Page and publishing it at a sensible hour.
Candidate content Title, summary, text excerpt, author, date, link, and reference image of articles and posts retrieved from public sources such as RSS feeds or news APIs. Serving as raw material for post proposals.
Generated content Post copy, hashtags, links, image generation instructions, generated images, and the state each proposal is in. Enabling human review, publishing what is approved, and keeping a history.
Publication record The post's identifier on the social network, permalink, API version used, date and time, and a copy of the request and response exchanged with Meta with credentials stripped out. Being able to edit or delete the post later, avoiding duplicates, and keeping a record of what was published.
Technical logs Scheduled task runs, errors, response times, AI model usage counters, and state transitions of each proposal. Diagnosing failures, preventing duplicate posts, and monitoring resource consumption.
Deletion requests Confirmation code, app-scoped user identifier, the channel the request arrived through, status, and dates. Evidencing that a deletion request was received and handled.

4. Data that is NOT collected

This section matters as much as the previous one. Atlas AI does not:

5. Where the data comes from

6. Purposes and legal bases

Purpose Legal basis
Managing Pages and publishing content to them Consent of the Page owner, given unambiguously by granting the administrator role and requesting that their Page be onboarded into the tool.
Storing and refreshing access tokens securely Necessary to provide the above. Without a token there is no access, and without encryption there is no responsible custody.
Generating content proposals with AI Legitimate interest of the controller in operating their own tool, within the scope authorised by the Page owner.
Keeping technical and publication records Legitimate interest in security, traceability, and preventing duplicate or unauthorised posts.
Handling data deletion requests Compliance with legal obligations and with Meta's platform policies.

Data is not used for any purpose other than those listed. In particular, it is not used to make automated decisions with legal effects on any person.

7. Use of artificial intelligence

Content is drafted by a language model. It is worth being precise about what that entails:

8. Who the data is shared with

There is no sale or transfer of data. The only third parties involved are infrastructure providers and the destination platform itself, all of them necessary for the tool to function:

Recipient What it receives Why
Meta Platforms, Inc. The content that is published, and the authenticated calls needed to read Page data and to create, edit, or delete posts. It is the destination platform. Facebook and Instagram are Meta's: without sending it the content there is no post.
Cloudflare, Inc. All data described in section 3. It acts as the provider of hosting, database, processing queues, and AI model execution. It is the infrastructure the entire system runs on.
Public content sources Nothing. The relationship is read-only: the system downloads openly published content and sends no data back. Obtaining candidate topics.

Data could also be disclosed to competent authorities if there were a legal obligation to do so. That has not occurred as of the date of this version.

9. International transfers

Meta Platforms and Cloudflare are companies headquartered in the United States operating globally distributed infrastructure, so data may be processed outside the European Economic Area. Both providers offer recognised transfer mechanisms, including standard contractual clauses, on the terms published in their respective privacy policies and data processing addenda.

The controller does not carry out any additional transfer of data to third countries on their own initiative.

10. Retention periods

Data Period
Access tokens As long as the Page remains managed. When the administrator role is removed, when the token stops being valid, or when deletion is requested, the encrypted material is deleted and the credential is marked as revoked.
Page identity data As long as the Page remains managed. Once access is gone, the record is marked inactive and kept only to preserve the consistency of the publication history, until deletion is requested.
Publication record Indefinitely, as a record of what was published, unless deletion is requested.
Discarded candidate content Purged automatically once obsolete or discarded, by a periodic cleanup task.
Prompts and outputs sent to AI models Approximately 90 days. After that the text is deleted and only aggregate metrics are kept, with no content.
Technical execution logs Approximately 30 days.
This website's logs No logs of our own are generated. Cloudflare network technical logs are governed by Cloudflare's own periods.
Deletion requests Indefinitely, in minimal form (confirmation code, dates, status), because they are the evidence that the request was handled.

Backups. The database has point-in-time recovery with a 7-day window, and periodic manual exports are taken and kept outside the system. A deletion may take until those copies expire, or are replaced by a later export, to fully propagate.

11. Security measures

No measure guarantees absolute security. If a breach affecting your data occurred, you would be notified by email and the competent authorities would be notified where applicable law requires it.

12. Your rights

As the owner of a Page onboarded into the system, you may exercise the following rights:

To exercise any of them, write to alejandro.olmedo14@gmail.com stating the name and identifier of the Page. Requests are handled within a maximum of 30 calendar days. Exercising these rights is free of charge.

13. Data deletion

The concrete procedure, with exact steps and deadlines, is on a separate page because Meta requires a dedicated URL: data deletion instructions.

14. Cookies and tracking on this website

This website uses no cookies. It also uses no local storage, no tracking pixels, no analytics, no advertising, and no third-party hosted resources: no remote fonts, no external libraries, no scripts. It does not execute JavaScript at all.

You are not asked for any data, there are no forms, and no visit profile is created. Cloudflare, as network provider, processes technical connection data — such as the IP address — in order to deliver the page and protect it against abuse; that processing is governed by Cloudflare's privacy policy.

15. Minors

Atlas AI is not directed at minors and does not knowingly process minors' data. Operating a Facebook Page or an Instagram Business account requires meeting Meta's age requirements.

16. Compliance with Meta's policies

Atlas AI's use of Meta's platforms is subject to the Meta Platform Terms and the Meta Developer Policies. In particular:

17. Changes to this policy

When this policy changes, the date in the header will be updated and the version number incremented. If the change is material — for example, adding a new artificial intelligence provider or a new processing purpose — it will be communicated by email to the owners of affected Pages before it takes effect.

18. Contact

For any privacy question, to exercise your rights, or to report a security issue: alejandro.olmedo14@gmail.com.

Document applicable under the laws of Mexico, without prejudice to the rights granted to you by the data protection legislation of your place of residence.