Home / Privacy Policy
Privacy Policy
This policy describes how Atlas AG LLC (“we”, “us”) processes personal data when you use Disclosure Ledger at https://discloseledger.com. It is not legal advice.
Controller
Atlas AG LLC, Melba, ID 83641, United States. Contact: hello@discloseledger.com. Product: Disclosure Ledger (https://discloseledger.com).
Purposes
We process data to operate the declaration and audit-trail service: create and display public disclosure records, provide CSV export, manage the free-tier gate and (when configured) billing, keep security and operational logs, and respond to privacy requests.
Legal bases
Depending on the processing: performance of a contract or steps prior to a contract (providing the service you request); legitimate interests (security, abuse prevention, product improvement that does not override your rights); and, where required, consent (for optional contact email used beyond core record creation).
Data we process
- Content hash (SHA-256), file name, size, and MIME type you submit with a record
- Self-reported AI declaration, optional notes, and provenance scan summary (method, details, signals)
- Optional contact email, if you provide one
- Technical logs (e.g. IP, user agent, timestamps) as needed for hosting, security, and debugging
Image bytes are not uploaded in this MVP — hashing and provenance scanning run in your browser. Only the hash and your declaration metadata are stored.
Retention
Public disclosure records are retained as an audit trail for as long as the service operates the public ledger, unless we are required or lawfully asked to remove or restrict personal data that is not essential to the public record. Optional contact email is kept for account or billing follow-up until no longer needed. Technical logs are kept for a shorter operational period.
Processors
We use Vercel for hosting and delivery. When Stripe is configured, Stripe processes payment-related data. Other subprocessors may be added; we will update this policy when material changes occur.
International transfers
The operator is based in Idaho, United States. Data may be processed in the US and, depending on hosting configuration, in the EU (for example if the deployment region is set to Frankfurt / EU). Where transfers leave the EEA/UK, appropriate safeguards may apply under applicable law.
Your rights
Subject to applicable law (including GDPR where it applies), you may request access, rectification, erasure, restriction, portability, and objection, and you may lodge a complaint with a supervisory authority. Contact hello@discloseledger.com. You may also use our privacy-request endpoint where available.
Public records caveat
Disclosure records you publish are designed to be publicly viewable at /r/[id] (and via CSV/JSON APIs without contact email). Do not include personal data in notes or file names that you do not want public. Contact email is not included in public CSV or public JSON exports.
What this product is not
Disclosure Ledger is not an EU AI Act Article 50 compliance product, does not verify or cryptographically sign images, and does not provide legal advice.