---
title: "Privacy Policy · Agentic Atlas"
description: "What the Agentic Atlas records when you read it or when your agent consults it, what it never records, and how to opt out."
canonical: "https://agentic-atlas.dev/privacy"
last-updated: "2026-09-23"
---

From the publisher

# Privacy Policy

Published by Avery Jones · Updated October 1, 2026

There is no account to make, nothing to sign in to, and nothing here is sold. This page states exactly what the site records, why, and how to stop it — for the pages you read and for the transport your agents call.

This policy covers `agentic-atlas.dev`, its hosted MCP service, and the Agentic Atlas plugin for ChatGPT and Codex. Avery Jones operates the publication and is responsible for its data handling. Privacy questions and requests go to [hello@agentic-atlas.dev](mailto:hello@agentic-atlas.dev).

## The short version

Reading the Atlas is anonymous. No account, no sign-in, no newsletter wall, no advertising, and no third-party tracker running in your browser. GoatCounter counts page views and agent tool calls, anonymous server-side usage events show which parts of the publication are used, and one cookie remembers whether you chose the light or the dark plate. Nothing else about you is collected, and no data about you is sold, rented, or shared for advertising.

## When you read a page

Human pages carry a counter from [GoatCounter](https://www.goatcounter.com/), an analytics service chosen because it sets no tracking cookies and builds no cross-site profile. The script is served from this domain rather than from the analytics host, so what your browser requests is a first-party address on `agentic-atlas.dev` and nothing else. What a count carries is the page path, the referring page if you arrived from one, and the coarse browser and screen facts the script reads — enough to know which plates are read and on what kind of device, and not enough to identify you.

Your network address is forwarded to the analytics service with the count so it can attribute the view to a country rather than to this server, and so the publisher's own visits can be excluded. GoatCounter's handling of that value is governed by [its own privacy policy](https://www.goatcounter.com/help/privacy), not by this page. This site keeps no visitor database of its own.

## Usage events

Alongside those counts, this server sends anonymous usage events to PostHog, hosted in the European Union, wherever the publisher has configured a project to receive them; with no project configured the server sends nothing. Each event carries a daily hash that nobody — the publisher included — can reverse, what was used such as the tool or page, the client product name, and timing. It does not carry a query, an argument, or a request or response payload as the caller supplied it; only bounded facts such as a word count or a published content identifier can be derived from them.

The network address is forwarded with the event so PostHog can attribute it to a country and a state or province. The publisher runs that project with PostHog's [Discard client IP data setting](https://posthog.com/tutorials/web-redact-properties#hiding-customer-ip-address), under which PostHog drops the address before the event is stored, so what the publisher reads back is the attributed place rather than the address. That setting belongs to the PostHog project rather than to this server's code, so it is stated here as the publisher's policy for the project and not as something this server can check. A Human page read from a browser that sends **Do Not Track** or **Global Privacy Control** produces no page event; API, discovery, NLWeb, and MCP usage events remain counted.

These events are sent by the server. No PostHog script runs in your browser and PostHog sets no cookie; the plate preference described below remains the site's only cookie.

## The one cookie

A single cookie, `atlas_projection`, records whether you are reading in the light plate or the dark one. It holds one of exactly two words, it is set only when you use the projection control, it is scoped to this site, and it lasts a year because a reading preference is not a session. It carries no identifier, and nothing on this site reads it except the code that decides which plate to draw. There is no consent banner because there is nothing here to consent to: delete the cookie and the site simply forgets which plate you preferred.

## When your agent consults the Atlas

The MCP transport is open and unauthenticated: there is no key to issue, so there is no account to attach a call to, and it carries no rate limit. Tool calls are counted the same way page views are — the tool that was invoked, the calling client's user-agent string, and the network address the call arrived from — so the publisher can tell which parts of the grammar are actually used. The content of a consultation is not stored: the arguments you pass and the payloads returned are not recorded, retained, or used to train anything. The Atlas is a read-only publication, and nothing an agent asks it changes what it serves anyone else.

Agent calls also produce the server-side usage events described above. An event names the tool and the client product, its timing and outcome, and bounded structural facts; it never sends the query text, the full arguments, the request body, or the returned payload.

The bundled plugin skills instruct your agent to keep artifact contents in its working context and send only generic design vocabulary and Atlas identifiers to the hosted service. The service receives the tool arguments needed to answer a call, but does not retain their contents. ChatGPT, Codex, and any other client you use handle your conversation and local files under their own privacy policies; this policy describes the Atlas service's handling of calls it receives.

## Server logs

Like any web server, this one writes an access log: the path, the HTTP method and status, how long the response took, the user-agent, and which Release the response was served from. Railway hosts the application and Vercel routes requests to it; these hosting providers also process network addresses and request metadata to deliver and protect the service. The publisher reads logs only to diagnose faults and outages. They are never joined to the analytics counts, and they are not used to build a profile of a reader.

## Recipients and data retention

GoatCounter receives page and tool counts to measure readership and tool use. PostHog receives the reduced usage events described above to understand which parts of the publication are useful. Railway and Vercel process requests and operational logs to host, route, secure, and troubleshoot the service. These are the service providers used for those purposes; the publisher does not sell data or share it for advertising.

- **Consultation contents:** tool arguments and returned payloads are processed to answer the request and are not stored or retained by Atlas.
- **GoatCounter counts:** both the page counter and the agent counter currently have automatic deletion disabled, so their analytics records are retained indefinitely until the publisher deletes them or closes the counter account. Individual pageview records are enabled. GoatCounter holds the network address and user-agent mapping in memory for up to eight hours to recognize repeat visits; it does not store those raw values in its analytics database. After account deletion, backups may retain data for up to 30 days. See [GoatCounter's privacy policy](https://www.goatcounter.com/help/privacy).
- **PostHog usage events:** the current Free plan provides a one-year event query window. That window limits which events can be queried; it is not a promise that older stored events are deleted. The publisher has no separate scheduled deletion of these events; stored data remains until it is deleted or the project is closed. The network address is discarded before event storage, as described above. See PostHog's [event retention rules](https://posthog.com/docs/data/events-retention) and [data deletion controls](https://posthog.com/docs/privacy/data-storage).
- **Application logs:** Railway's current Hobby plan provides seven days of log history. Railway states that upgrading a plan can restore older history, so this access window is not a guarantee of deletion after seven days. Its published plan windows extend up to 90 days. See [Railway's log retention rules](https://docs.railway.com/observability/logs#log-retention).
- **Edge logs:** Vercel's current Hobby plan provides one hour of runtime log history and 12 hours of observability history. Higher plans can expose older history, so these are access windows rather than deletion guarantees; Vercel publishes windows up to 30 days. See its [runtime log limits](https://vercel.com/docs/logs/runtime#limits) and [observability limits](https://vercel.com/docs/observability/observability-plus#limitations).
- **Reading preference:** the `atlas_projection` cookie expires after one year, or sooner if you delete it.

The publisher does not keep a separate visitor database. Provider retention and deletion controls are operated by the providers, rather than enforced by the Atlas application. This page will be updated if the publication's providers, plans, or data-handling practices change.

## Opting out

Any content blocker that blocks the counter request stops the GoatCounter page count. Reading with JavaScript disabled stops that counter and costs you nothing: every page on this site renders in full without it, and the Markdown dialect at `Accept: text/markdown` never carries a counter. Server-side usage events do not depend on JavaScript; for Human page reads, a browser sending Do Not Track or Global Privacy Control is omitted from the page events. Those signals do not suppress API, discovery, NLWeb, or MCP usage events. For agent traffic, the MCP transport records no more than described above and there is nothing to disable — the payloads are the same either way.

## Questions, corrections, removals

If something here is wrong, unclear, or has drifted from what the site actually does, say so and it will be corrected: [hello@agentic-atlas.dev](mailto:hello@agentic-atlas.dev). The same address handles any request to remove data associated with you, though in most cases the honest answer will be that none was collected. See the [contact page](https://agentic-atlas.dev/contact) for the other ways to reach the publisher.