What we collect, and what we never do.
What we collect
- Account details — your name, work email and company, so we can open your workspace and bill the right entity.
- The files you send us — the brand assets, guidelines and license agreements you point Atlas at, and the descriptions, groupings and rights decisions the record derives from them.
- Usage — which questions are asked of the record and which tools call it, so the service stays fast and the decision trail stays complete.
Why we collect it
To build and serve your record, to scope access, and to keep the audit trail you will one day need. To reply to a demo request or a folder intake. Never to advertise, never to profile, never to sell.
What we never do
We do not train models on your assets — not ours, not anyone else's. It is a term in the contract, not a setting in an account. We do not sell data. We do not read your files for any purpose other than building the record you asked for.
Where it lives
On infrastructure we control, hosted in the EU and USA, isolated per tenant. No asset crosses into another customer's record. The full handling policy is on the Security page.
Who else sees it
Your teams, your licensees and your agencies — scoped by the permission schemes you set, the same on the app as on the MCP surfaces. Our sub-processors, listed on request. Nobody else.
How long we keep it
For as long as your record is live. Demo and prospect correspondence for as long as the conversation is active, then deleted on request. Retention windows and legal hold are supported inside the service.
Your choices
Ask us to export or hard-delete your record at any time — or reach out with any other privacy question. Write to privacy@prelight.ai for anything privacy related: deletions, exports, access requests, or how your data is handled. A record you cannot remove is a record you should not trust.