Last updated: May 2026. This policy explains what data HoldAtlas collects, why, and how it is used.
HoldAtlas is operated by Hanna Vasiukova.
Registered in Poland
Address: ul. Stefana Jaracza 21 m. 46, 90-261 Łódź
NIP: 7252364283
Contact: contact@holdatlas.com
Your scenario inputs (capital, country, horizon, etc.) are stored in your browser's session storage and deleted when you close the tab. We do not transmit your scenario inputs to our servers.
We also store the following values in your browser's localStorage for functional purposes — none contain personal data unless you have purchased access:
ha_display_mode — your preferred view (simple/advanced)arv_saved_scenarios — any scenarios you have saved locallyarv_agg_store — anonymised local counters of which analysis paths you viewed (feeds PostHog analytics, no personal data)arv_conversion_log — local event queue for PostHog (page views, feature interactions; sent anonymously, then cleared)arv_data_store — session payloads used for local analytics aggregation, cleared periodicallySession storage (deleted on tab close): scenario inputs (_ha_scenario), anonymous session ID (arv_session_id), share token (arv_share_token), referral source (arv_affiliate_ref).
If you use the free analysis tier, you provide an email address to receive your result. We store a one-way SHA-256 hash of your email in our key-value store (Upstash, EU) to enforce the one free scenario limit. The hash cannot be reversed to recover your email address. We do not send emails to free tier users.
If you purchase access, your email address is stored to generate a restore link and send you access confirmation via Resend (EU-based email delivery). This allows you to recover access on any device. We do not use your email for marketing without explicit consent.
After purchase or restore, we store the following values in localStorage to maintain your access state across sessions:
ha_restore_expires — expiry timestamp of your access (no personal data)ha_restore_email — your email address, stored locally to pre-fill the restore form and display confirmation in the UI. Contains personal data. Cleared when access expires.atlas_paid — fallback access flag set if payment verification encounters an error; contains no personal dataha_scenario — your last scenario parameters, restored on any device via your email linkPayments are processed by Stripe, Inc. HoldAtlas never sees or stores your card details. Stripe processes payment data under their own privacy policy and is PCI-DSS compliant. Stripe may set cookies for fraud prevention. See stripe.com/privacy.
Our hosting provider Vercel automatically logs standard server data: IP address, user agent, request path and timestamp. These logs are retained for up to 30 days for security and debugging purposes. We do not use this data for analytics or advertising.
When you dismiss the cookie notice, we store two values in localStorage: ha_cookie_ok (notice dismissed) and ha_cookie_marketing (your marketing consent choice: "1" if you clicked OK, "0" if you clicked Essential only). These values contain no personal data and are used solely to respect your preference on future visits.
We use PostHog to collect anonymised usage data: page views, feature interactions, and conversion events (e.g. when a result is generated or a purchase is completed). No advertising data is collected. Data is stored on PostHog's EU servers. PostHog does not build advertising profiles. We do not use session recording. See posthog.com/privacy.
If you click "OK" on the cookie notice, we activate Meta Pixel (Facebook Pixel) operated by Meta Platforms Ireland Ltd. Meta Pixel collects data about your visit for marketing analytics and ad measurement purposes. Meta may set cookies and track your activity across sites. This is only activated after you give explicit consent. If you click "Essential only", Meta Pixel is not activated. See facebook.com/privacy/policy.
To withdraw consent: clear your browser's localStorage (key ha_cookie_marketing) and reload the page.
Each processor operates under their own GDPR-compliant terms. By using HoldAtlas you acknowledge that your data may be processed by these third parties under their respective terms.
Enterprise clients requiring a Data Processing Agreement (DPA) or data processing addendum should contact contact@holdatlas.com.
If you are in the EU/EEA, you have the right to access, correct, or delete your personal data. To exercise these rights, email contact@holdatlas.com. We will respond within 30 days.
If you purchased access and want your email deleted, we will delete your record and revoke your access link.
arv_conversion_log, arv_data_store, arv_agg_store): cleared periodically or on next visitha_restore_expires, ha_restore_email, ha_scenario): retained until access expires (30 days for Pro, 395 days for Starter), then removedha_display_mode, ha_cookie_ok): retained until you clear browser storageWe may update this policy as the product evolves. Material changes will be noted with an updated date at the top of this page.