Privacy
What Automapped collects, where it goes, and what never leaves your browser.
There are two versions of Automapped, and only one of them collects anything
Automapped runs in two modes, and which one you are in decides everything on this page. The mode is not hidden: Settings tells you which one you are in.
- Without an account. Everything you enter is stored in your own browser and nothing is sent to a server. We do not receive it, cannot read it, and cannot recover it for you. Clearing your browser data deletes it.
- With an account. Your workspace is stored in our database so it opens on any device you sign in from. The rest of this page is about this mode.
What we collect
Two things, and nothing else.
Your identity, from GitHub. When you sign in, GitHub tells us your name, email address, and avatar URL, and gives us tokens that let us confirm it is still you. We never see your GitHub password. We do not read your repositories and do not ask for permission to.
What you put in a workspace. Your app's name, category and store link; the answers you give during setup; any figures you record; and everything Automapped derives from those — opportunities, experiments, diagnoses and the memory of what happened. This is your material. We process it to run the service and for no other purpose.
There is no analytics, no tracking pixel, no advertising identifier and no third-party script anywhere in Automapped. We do not know which pages you visited or how long you stayed.
Cookies
One cookie, holding your session so you stay signed in. It is set when you sign in and deleted when you sign out. There are no analytics or advertising cookies, which is why Automapped has no cookie banner — there is nothing to ask you to consent to.
Who else processes your data
Running Automapped means other companies handle some of it. These are all of them. Each one receives only what its row says.
| Who | What they get | Why |
|---|---|---|
| Vercel | Requests to the site, and server logs | Hosting |
| Neon | Everything stored: your account and your workspaces | The database |
| GitHub | The fact that you signed in | Confirming who you are |
| OpenRouter | Only the opportunity you asked for a draft of — see below | Routing that request to a model |
All of it is stored and processed in the United States. If you are in the UK or the EEA, using Automapped means your data is transferred there.
What goes to a model, exactly
Automapped can draft copy for an opportunity. That is the only feature that sends anything to a model, it never runs on its own, and it sends far less than the workspace holds.
What is sent: your app's name, category and platforms, and the one opportunity you asked about — its title, description, expected impact, and the evidence attached to it.
What is not sent: your name, your email address, your store or website link, your account identifier, your recorded revenue and install figures, and every other opportunity and experiment in the workspace.
Requests carry an instruction that the provider must not store or train on them. Providers that do not accept that are excluded, and if none remain the request fails rather than proceeding.
We record that a request happened — which model, how many tokens, what it cost and how long it took. We do not store the prompt or the reply as a log; the draft itself is saved to your workspace, where you can read it and delete it.
How long we keep it
Your workspaces stay until you delete them or ask us to delete your account. Sessions expire on their own. Records of model requests are kept as a billing and audit trail, and hold no content.
You can delete your account yourself, from Settings. It removes your account, every workspace you are the only owner of, and everything in them, immediately and permanently. A workspace you share with someone else is left alone — deleting your account must not delete a colleague's work.
One thing survives: a record that a model request was made, with its cost and token counts and no identity attached. It holds none of your content and exists so the bill can be reconciled. If you would rather it went too, email atlasgrowthos@gmail.com.
Your rights
If you are in the UK or EEA, the GDPR gives you the right to see the data we hold about you, correct it, have it deleted, object to how it is processed, and receive a copy in a portable format. If you are in California, the CCPA gives you comparable rights. We honour these requests wherever you live, because keeping two standards would be more work than keeping one.
You can already export a workspace yourself: Settings has an export that produces a JSON file of everything in it. For anything else, email atlasgrowthos@gmail.com. We will respond within 30 days. You can also complain to your data protection authority.
Our lawful basis for processing is performing the contract you enter into by using Automapped. We do not process your data for marketing and do not sell it — to anyone, under any definition of “sell”.
Security
Traffic is encrypted in transit. Your workspaces are isolated from each other at the database level rather than only in application code, so a mistake in a query cannot show you someone else's data. Access to production is limited to people who need it.
No system is perfectly secure. If you find a vulnerability, email atlasgrowthos@gmail.com and we will take it seriously.
Children
Automapped is a tool for people running software businesses. It is not intended for anyone under 16.
Changes
If this policy changes in a way that affects you, we will say so in the product rather than quietly changing the date at the bottom of this page. Automapped Growth Systems is the data controller.
The terms of service cover what Automapped does and what it does not promise.
Last updated 27 August 2026. Operated by Automapped Growth Systems. Questions about either document go to atlasgrowthos@gmail.com.