Home
← Routr Atlas

EARLY-ACCESS NOTICE · 13 SEPTEMBER 2026

Trust, data & limitations

Atlas helps record and review decisions. It does not establish legal eligibility or replace a qualified adviser.

Account and case access

Account workspaces use Sign in with ChatGPT through the hosting platform. Atlas does not collect your password. Cases belong to the signed-in account and remain private unless the owner creates an invitation. Viewer and reviewer access applies to the individual case. Only its owner can edit or delete it.

An existing-access case link is different from an invitation. It holds an opaque case identifier and section name, not a grant token or case text. The recipient still needs current account permission. Opening that link performs the normal authorized case read and never adds a member or records a review. Keep identifiers and links private.

What is stored

The application stores your account identifier and display name with case content, source links, review events and version snapshots in its hosting database. It records the author of each saved version. Invitation tokens are stored as hashes and expire after seven days. Links allow their holder to accept access once, so share them privately.

A case-creation retry receipt stores an account ID, random request ID, content fingerprint, case ID and timestamps, not a second copy of the case text. It is valid for seven days. Expired receipts are removed on the next keyed creation request, not by a guaranteed daily deletion job; inactive receipt rows can remain longer. A receipt remains after case deletion until that cleanup, so a delayed retry cannot recreate the deleted case during the receipt validity window. Each account is limited to 1,000 unexpired creation receipts.

The application uses OpenAI Sites hosting and its Cloudflare-backed runtime. This release does not promise a specific country of data storage. It has no added advertising analytics, payment collection or AI processing of case contents. Hosting providers may retain operational logs under their own terms. Platform administrators can operate the hosting environment; “private” does not mean end-to-end encrypted.

Permitted early-access use

Use public-source research and non-sensitive business scenarios. Do not enter passports, bank statements, credentials, special-category personal data, privileged material or confidential client files. Commercial processing of sensitive information requires a separate data-processing agreement, retention policy, provider review and security assessment before onboarding.

Review safeguards

Saving an edit creates a new version and removes the effect of any prior peer review. A separate invited account can record an optional peer review of the current saved version. Atlas requires complete case fields, current supporting sources and satisfied dependencies before recording that review. It cannot verify the reviewer's professional qualifications or the truth of a manually entered claim. A review event is not government approval, certification or legal advice.

Public-source research, software demonstrations and decision preparation can proceed without hiring an expert. Professional conclusions remain outside this self-service scope. A passing preparation check is not a legal clearance, certification or prediction of application success.

Export, retention and deletion

Download a case as JSON, its brief as text, or print the brief to PDF. The owner can delete a case and its history from the application database in Access. Versions remain until deletion; this release does not apply an automatic retention schedule. Deletion is not a promise of immediate removal from all hosting-provider backups or logs. The service worker does not cache account pages or APIs. Internet access is required for account data.

Browser-tab draft recovery

While editing, Atlas attempts to keep one unsaved case draft per account in this browser tab's session storage (a separate slot is used for practice mode). It is not encrypted, is not a server save, may be restored by your browser after a crash, and is not guaranteed to survive closing the tab. Use only non-sensitive content. Recovery is offered rather than silently overwriting a saved version. Drafts with a different base version recover as a new case. Saving, confirmed discard, case deletion or Atlas sign-out clears the current recovery slot. Unfinished source/gate form fields are included in recovery and new backups, but remain unsaved form content until added to a case. Browser storage limits can prevent recovery; export JSON as your portable backup. A backup checksum detects changed bytes in its canonical content, not malicious authorship, true claims or valid professional approval.

Recovery records are treated as untrusted local input. Only validated case fields are restored; unknown fields, including embedded access or review metadata, are discarded. Case fields use normal schema trimming, while a genuinely unfinished blank title and the separate unfinished form can remain for you to complete. This is content recovery, not authentication, permission restoration or proof of authorship.

AI preparation and disclosure

No model is connected and no case data is transmitted to an AI provider. The optional lab builds a local packet of selected research and validates a proposal pasted by the user. Profile, constraints, owner names, access and history are excluded, but free text may still contain personal information. Inspect every field; this is not anonymisation. Packets and proposals are capped at 60 KB; optional full response checks are capped at 100 KB and reject incomplete or refused outputs. Cryptographic digests bind proposals to a draft and research selection, not to a trusted author. Matching excerpts are not independent fact checking. Lab inputs stay in memory when changing case sections, but are not part of case backup, server versions or browser-tab recovery. Separate unencrypted lab-notes JSON can be copied and restored only against the matching case snapshot; it restores inputs, not validation or approvals. Reloading or closing the page can still lose uncopied notes. The browser may suppress unsaved-work warnings.

Connection and response safeguards

The workspace client uses a 30-second deadline, a 1 MB response bound and response-shape validation before replacing local case data. It does not automatically retry writes. A timeout, malformed reply or server error can leave the outcome unknown even when the server completed the action. Inspect saved state before a manual retry. Cancellation of the browser request cannot undo a completed server operation. These controls do not add offline synchronisation. In the current app, an unchanged manual creation retry in the same page reuses a request ID; the server returns the existing case instead of creating another while its seven-day receipt is valid. Changing content, refreshing the page, using an old client without request IDs or waiting beyond that window can start a new creation intent. Always inspect saved state first.

Current limits

Operator and contact

Routr Consulting Ltd hosts the project. Questions, privacy requests and security reports: info@routrconsulting.com. Do not email secrets or personal documents in a security report.

Open workspaceUsage guide