Privacy policy
This document explains what data Atlas AI processes, why, how long it keeps it, who it shares it with, and what you can demand about it. It is written to describe the system as it actually works, not to generically cover every hypothetical case.
Spanish is the reference language for this document. This English version is provided for convenience; in case of discrepancy, the Spanish text prevails.
1. Who the controller is
The controller of the data described in this document is Alejandro Olmedo, a natural person operating Atlas AI as a personal project, resident in Mexico for the purposes of notices.
Contact for any privacy-related matter: alejandro.olmedo14@gmail.com.
Atlas AI is not a company, has no employees, and sells no service. No data protection officer has been appointed, because the nature and volume of the processing does not require one.
2. What Atlas AI is and who this policy covers
Atlas AI is a personal tool that automates the generation and publication of social media content. It is
registered with Meta as a developer application with the public identifier 1583910826653085.
Its operating model is deliberately closed:
- There is a single administrator user: the controller identified above. There is no account registration and no third-party login.
- The system operates exclusively on Facebook Pages and Instagram Business accounts where the Page owner has voluntarily granted the controller an administrator role, through Meta's official tools.
- No Page or account is accessed without that prior role. Removing the role cuts off access immediately and permanently.
This policy applies to you if:
- You own or administer a Facebook Page or Instagram Business account that has been onboarded into Atlas AI.
- You are the controller, whose own Meta account data is also processed here.
- You visit this website (see section 14).
Atlas AI does not process your data. It does not read comments, does not read messages, and does not download follower lists or individual-level audience statistics. All it does on the Page is create posts, and only with prior human approval. Any data Meta processes about you because you use Facebook or Instagram is governed by Meta's privacy policy, not this one.
3. Data that is processed
The inventory below is exhaustive. If a data item is not in this table, the system does not store it.
| Category | Specific data | What for |
|---|---|---|
| Page identity | Facebook Page identifier, public name, username, category, list of permissions granted to the administrator, and the identifier and username of the linked Instagram Business account if one exists. | Knowing which Pages can be operated on, and routing each post to the correct destination. |
| Access credentials | The controller's user access token and one Page access token per managed Page, stored encrypted. Alongside them: issue date, expiry date, the permissions they carry, and a cryptographic fingerprint that allows changes to be detected without decrypting anything. | Authenticating calls to Meta's API and detecting when a token has expired or been revoked. |
| Editorial configuration | Time zone, language, style or tone guidance, and publishing time preferences per Page. | Making generated content sound consistent with each Page and publishing it at a sensible hour. |
| Candidate content | Title, summary, text excerpt, author, date, link, and reference image of articles and posts retrieved from public sources such as RSS feeds or news APIs. | Serving as raw material for post proposals. |
| Generated content | Post copy, hashtags, links, image generation instructions, generated images, and the state each proposal is in. | Enabling human review, publishing what is approved, and keeping a history. |
| Publication record | The post's identifier on the social network, permalink, API version used, date and time, and a copy of the request and response exchanged with Meta with credentials stripped out. | Being able to edit or delete the post later, avoiding duplicates, and keeping a record of what was published. |
| Technical logs | Scheduled task runs, errors, response times, AI model usage counters, and state transitions of each proposal. | Diagnosing failures, preventing duplicate posts, and monitoring resource consumption. |
| Deletion requests | Confirmation code, app-scoped user identifier, the channel the request arrived through, status, and dates. | Evidencing that a deletion request was received and handled. |
4. Data that is NOT collected
This section matters as much as the previous one. Atlas AI does not:
- Read or store comments, reactions, private messages, or Page conversations.
- Download follower lists, contact details, or audience demographics.
- Query individual-level user statistics or build behavioural profiles of third parties.
- Process special categories of data: health, ethnic origin, religious beliefs, political or trade union affiliation, sexual orientation, biometric or genetic data.
- Process payment, banking, or card data.
- Sell, rent, or transfer data to third parties for commercial gain.
- Use data for advertising or ad targeting.
- Train its own artificial intelligence models on this data.
5. Where the data comes from
- Meta's official API (Graph API). Page data and tokens are obtained by querying the Pages the controller administers. Meta only returns those where a role has actually been granted.
- The Page owner. Editorial configuration and style guidance are entered manually, based on what the owner indicates.
- Public content sources. RSS feeds, news APIs, and publicly accessible websites.
- The system itself. Generated copy, images, and all technical logs are produced by Atlas AI.
6. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Managing Pages and publishing content to them | Consent of the Page owner, given unambiguously by granting the administrator role and requesting that their Page be onboarded into the tool. |
| Storing and refreshing access tokens securely | Necessary to provide the above. Without a token there is no access, and without encryption there is no responsible custody. |
| Generating content proposals with AI | Legitimate interest of the controller in operating their own tool, within the scope authorised by the Page owner. |
| Keeping technical and publication records | Legitimate interest in security, traceability, and preventing duplicate or unauthorised posts. |
| Handling data deletion requests | Compliance with legal obligations and with Meta's platform policies. |
Data is not used for any purpose other than those listed. In particular, it is not used to make automated decisions with legal effects on any person.
7. Use of artificial intelligence
Content is drafted by a language model. It is worth being precise about what that entails:
- What is sent to the model. The text of candidate content obtained from public sources, and the Page's style guidance. Access tokens, keys, and personal data of Page followers are never sent.
- Which provider is used. Currently the only active artificial intelligence provider is Cloudflare Workers AI, which runs the models inside Cloudflare's own infrastructure. The architecture allows other providers to be added in future; if that happens, this policy will be updated before the change goes live, and section 8 will reflect the new recipient.
- Mandatory human review. No model output is published automatically. Every proposal passes through explicit approval by the administrator.
- Generated content can be inaccurate. Language models can produce false statements. Human review before publication exists precisely for that reason, and ultimate editorial responsibility rests with whoever approves.
8. Who the data is shared with
There is no sale or transfer of data. The only third parties involved are infrastructure providers and the destination platform itself, all of them necessary for the tool to function:
| Recipient | What it receives | Why |
|---|---|---|
| Meta Platforms, Inc. | The content that is published, and the authenticated calls needed to read Page data and to create, edit, or delete posts. | It is the destination platform. Facebook and Instagram are Meta's: without sending it the content there is no post. |
| Cloudflare, Inc. | All data described in section 3. It acts as the provider of hosting, database, processing queues, and AI model execution. | It is the infrastructure the entire system runs on. |
| Public content sources | Nothing. The relationship is read-only: the system downloads openly published content and sends no data back. | Obtaining candidate topics. |
Data could also be disclosed to competent authorities if there were a legal obligation to do so. That has not occurred as of the date of this version.
9. International transfers
Meta Platforms and Cloudflare are companies headquartered in the United States operating globally distributed infrastructure, so data may be processed outside the European Economic Area. Both providers offer recognised transfer mechanisms, including standard contractual clauses, on the terms published in their respective privacy policies and data processing addenda.
The controller does not carry out any additional transfer of data to third countries on their own initiative.
10. Retention periods
| Data | Period |
|---|---|
| Access tokens | As long as the Page remains managed. When the administrator role is removed, when the token stops being valid, or when deletion is requested, the encrypted material is deleted and the credential is marked as revoked. |
| Page identity data | As long as the Page remains managed. Once access is gone, the record is marked inactive and kept only to preserve the consistency of the publication history, until deletion is requested. |
| Publication record | Indefinitely, as a record of what was published, unless deletion is requested. |
| Discarded candidate content | Purged automatically once obsolete or discarded, by a periodic cleanup task. |
| Prompts and outputs sent to AI models | Approximately 90 days. After that the text is deleted and only aggregate metrics are kept, with no content. |
| Technical execution logs | Approximately 30 days. |
| This website's logs | No logs of our own are generated. Cloudflare network technical logs are governed by Cloudflare's own periods. |
| Deletion requests | Indefinitely, in minimal form (confirmation code, dates, status), because they are the evidence that the request was handled. |
Backups. The database has point-in-time recovery with a 7-day window, and periodic manual exports are taken and kept outside the system. A deletion may take until those copies expire, or are replaced by a later export, to fully propagate.
11. Security measures
- Encryption of credentials at rest. Access tokens are stored encrypted with AES-256-GCM. The encryption key is not in the database: it lives in the platform's secret manager, separate from the data it protects.
- Encryption bound to its record. Each token is encrypted cryptographically bound to the identifier of the Page it belongs to. Ciphertext copied into another record cannot be decrypted, and any tampering with the fields that identify it is detected.
- Tokens never travel in the URL. They are always transmitted in the request body or in the authorization header, so they never end up in logs or referrer headers.
- Tokens are never logged. Credentials are stripped from requests and responses before any diagnostic record is written.
- Encryption in transit. All communications use TLS. This site is served exclusively over HTTPS, with HSTS enabled.
- Minimal access. Only the controller has access to the system. Administration routes require authentication and there is no third-party access.
- Credential rotation. A documented procedure exists for rotating tokens and encryption keys, applied both preventively and immediately upon any suspicion of exposure.
- If decryption fails, the credential is marked invalid and no longer used. There is no fallback mode that operates on plaintext tokens.
No measure guarantees absolute security. If a breach affecting your data occurred, you would be notified by email and the competent authorities would be notified where applicable law requires it.
12. Your rights
As the owner of a Page onboarded into the system, you may exercise the following rights:
- Access. Obtain a copy of all data the system holds about your Page.
- Rectification. Correct any inaccurate data, including the editorial configuration.
- Erasure. Request deletion of the data. The procedure is detailed on the data deletion page.
- Portability. Receive your data in a structured, machine-readable format.
- Restriction and objection. Ask for content generation or publication on your Page to be suspended while the data is retained.
- Withdraw consent. At any time and without needing to justify it. The fastest and most direct route is to remove the administrator role from your Page settings in Meta: that cuts off access instantly, without depending on anyone.
- Complaint. Lodge a complaint with the data protection supervisory authority of your country of residence.
To exercise any of them, write to alejandro.olmedo14@gmail.com stating the name and identifier of the Page. Requests are handled within a maximum of 30 calendar days. Exercising these rights is free of charge.
13. Data deletion
The concrete procedure, with exact steps and deadlines, is on a separate page because Meta requires a dedicated URL: data deletion instructions.
14. Cookies and tracking on this website
This website uses no cookies. It also uses no local storage, no tracking pixels, no analytics, no advertising, and no third-party hosted resources: no remote fonts, no external libraries, no scripts. It does not execute JavaScript at all.
You are not asked for any data, there are no forms, and no visit profile is created. Cloudflare, as network provider, processes technical connection data — such as the IP address — in order to deliver the page and protect it against abuse; that processing is governed by Cloudflare's privacy policy.
15. Minors
Atlas AI is not directed at minors and does not knowingly process minors' data. Operating a Facebook Page or an Instagram Business account requires meeting Meta's age requirements.
16. Compliance with Meta's policies
Atlas AI's use of Meta's platforms is subject to the Meta Platform Terms and the Meta Developer Policies. In particular:
- Only the permissions strictly necessary to publish and manage Pages are requested.
- Data obtained from the platform is used solely for the purposes declared in section 6.
- Platform data is not transferred to data brokers, ad networks, or monetisation services.
- Access tokens are held encrypted and are not shared with anyone.
17. Changes to this policy
When this policy changes, the date in the header will be updated and the version number incremented. If the change is material — for example, adding a new artificial intelligence provider or a new processing purpose — it will be communicated by email to the owners of affected Pages before it takes effect.
18. Contact
For any privacy question, to exercise your rights, or to report a security issue: alejandro.olmedo14@gmail.com.
Document applicable under the laws of Mexico, without prejudice to the rights granted to you by the data protection legislation of your place of residence.