Privacy Policy
Atlan is a product of Nonce Lab. This policy explains what we collect when your team connects a workspace, how we handle the engineering history we index, and the choices you have over it.
1. Information we collect
Account information you give us directly: your name, work email, company, and the details you submit through a demo request form.
Workspace content you choose to connect: commits, pull requests and code review comments from your Git provider; messages from the Slack channels you authorise; and issues and comments from your ticket system. Atlan indexes this history to build your decision graph.
Usage data we collect automatically: log records, device and browser information, and how people in your workspace interact with the Service.
2. How we use it
To operate and improve the Service — indexing your history, answering questions with citations, and building onboarding paths from real project history.
To secure the Service, investigate abuse, and meet our legal obligations.
To send you service communications about your account, security, and material changes to this policy.
- We never sell your data.
- We never train models on your code or conversations. Not by default, not silently — only if you give explicit, separate, written consent.
3. Processing and storage
Your data is processed on infrastructure audited to SOC 2 Type II and ISO 27001 standards.
Data is encrypted in transit with TLS 1.3 and at rest with AES-256.
Enterprise customers can deploy Atlan on-premise or self-hosted, in which case your code and conversations never leave your own infrastructure and we do not receive them at all.
4. Access control
Atlan mirrors the permissions your team already has. If a person cannot read a private repository or a closed Slack channel in the source system, Atlan will not surface its content to them.
Workspace administrators choose which sources are connected and can disconnect any of them at any time. Disconnecting a source removes its indexed content from your decision graph.
5. Sharing
We share data only with service providers who process it on our behalf under written data processing agreements, when the law requires it, or when you explicitly ask us to.
We never share one customer’s workspace data with another customer.
6. Retention
We keep your data for as long as your account is active. When you delete your account we delete your indexed content within 30 days, except where we are legally required to keep it longer.
You can request deletion of a specific connected source at any time without closing your account.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to restrict or object to how we process it, and to withdraw consent at any time.
To exercise any of these, write to privacy@nonce.ai. We answer within 30 days.
8. Cookies
We use strictly necessary cookies for sign-in and session management — the Service cannot work without them.
We use analytics cookies only with your consent, and you can change your mind at any time in your browser settings.
9. Children
Atlan is a workplace tool intended for people aged 18 and over. We do not knowingly collect personal information from children.
10. Changes to this policy
If we make a material change we will tell you by email or with a prominent notice in the product at least 30 days before it takes effect.
11. Terms of service
Access to Atlan is granted under a written agreement between your organisation and Nonce Lab. Pilot and demo access is provided as-is for evaluation, without warranty, and may be withdrawn at any time.
You are responsible for having the right to connect the sources you connect, and for the accounts your team uses to do so.
12. Contact
Privacy questions: privacy@nonce.ai
Data Protection Officer: dpo@nonce.ai