Hesper Atlas

Privacy Policy

What Hesper Atlas collects, why, who processes it, and the rights you have over your data.

Last updated: September 1, 2026 · Terms of Service · Back to the app

This policy explains how we, the data controller for Hesper Atlas, handle your personal data. The short version: we collect the minimum needed to run an account-based subscription service, we use only essential first-party cookies, and we never sell your data.

1Data we collect

DataWhere it comes from
Email addressYou, when you create an account. Used to sign you in and to contact you about your account.
Password (hash only)You, at signup. We store only a salted cryptographic hash, never the password itself.
Subscription statusStripe, our payment processor. We store your plan, billing period, and a Stripe customer reference. We never see or store your full card number.
Favorites / watchlist & app settingsYou, as you use the app (e.g. starred tickers, theme preference, portfolio capital input).
Telegram chat ID (optional)You, only if you connect Telegram to receive daily alert pushes. Removable at any time in Settings.
API key metadata (optional)You, if you create a key for an AI agent: its label, non-secret display prefix, creation and last-used times, and call count. We store only a cryptographic hash of the full key and show the secret once when it is created.
OAuth agent connections (optional)You and the client you choose: the client name, registered redirect URLs, connection and last-used times, authorized signals:read scope, and token-family metadata. Authorization codes, access tokens and refresh tokens are opaque and stored only as cryptographic hashes. They are never shown on your account page.
Partner details (optional)You, only if you join our partner (affiliate) program: your legal name, country, and payout method (e.g. PayPal or bank details), needed to pay commissions and meet tax-reporting duties. Not collected for ordinary accounts.
Server and MCP request logsAutomatically: IP address, timestamps, requested paths, user-agent, status and response time. For MCP calls, application telemetry may also record the declared client name/version, protocol operation, selected tool and anonymous/API-key/OAuth access tier. It does not write the surrounding prompt or tool arguments to application telemetry logs.

When you connect Hesper Atlas through an external AI agent, that provider processes your conversation under its own privacy policy. Hesper Atlas normally receives only the MCP tool request the agent selected and the small typed arguments required by that tool, not the surrounding conversation. The request is processed to return the answer; only the metadata described above is retained in application telemetry.

Unless you join the partner program, we do not collect names, addresses, government IDs, brokerage credentials, or holdings data, and we do not track you across other websites.

2Purposes & legal bases (GDPR)

PurposeLegal basis (Art. 6 GDPR)
Providing the service: account login, watchlists, signals, API access, subscription management, billingContract (Art. 6(1)(b)), needed to deliver what you signed up for.
Sending daily alerts via TelegramContract / consent: this feature runs only if you opt in; disconnecting Telegram stops the processing.
Security, abuse prevention, debugging (server logs)Legitimate interests (Art. 6(1)(f)): keeping the service secure and working.
Tax and accounting records of paymentsLegal obligation (Art. 6(1)(c)).
Service emails about material changes to terms, prices, or this policyContract / legal obligation. We do not send marketing emails without separate consent.

3Processors & recipients

We share data only with the processors needed to run the service, under data-processing agreements:

Where a processor is located outside the EU/EEA, transfers rely on appropriate safeguards such as EU Standard Contractual Clauses or an adequacy decision.

An AI client or agent that you independently choose is not a Hesper Atlas processor. Review that provider's privacy and retention terms before sending it personal or confidential information.

We do not sell or rent personal data, and we do not share it with advertisers or data brokers. We disclose data beyond the processors above only if legally required (e.g. a valid court order) or in a business transfer, in which case this policy continues to apply.

4Retention

5Your rights

If you are in the EU/EEA or UK (and in many other jurisdictions), you have the right to:

To exercise any of these rights, email support@hesperatlas.com. We respond within one month.

6Cookies

Hesper Atlas uses first-party cookies only:

We use no advertising trackers, no analytics cookies, and no third-party tracking pixels. Locally stored preferences (such as your light/dark theme choice) stay in your browser and are never transmitted to us.

7Security

Passwords are stored only as salted hashes. Full API-key secrets, OAuth authorization codes, access tokens and refresh tokens are stored only as cryptographic hashes; OAuth uses PKCE S256, exact resource binding and refresh-token rotation. Traffic is encrypted in transit with TLS and access to production data is restricted. No internet service can guarantee absolute security. If a breach affects your personal data, we will notify you and the competent authority as required by law.

8Children

The service is not directed at children and may not be used by anyone under 18. We do not knowingly collect data from minors; if you believe a minor has created an account, contact us and we will delete it.

9Changes to this policy

We may update this policy as the service evolves. The "Last updated" date above always reflects the current version, and we will notify you (by email or in-app notice) before material changes take effect.

10Contact & data controller

Data controller: Hesper Atlas, Zurich, Switzerland.
Privacy contact: support@hesperatlas.com