The short version.
- —We collect the minimum needed to match you to trials and draft appeals.
- —We never sell your data. Not to pharma. Not to insurers. Not to anyone.
- —You can delete everything in Settings → Clear My Data. Instantly.
- —Basic Mode is always available if you prefer no AI learning.
Atlas Rare is a patient navigation platform operated by SlopLens LLC, a Wyoming limited liability company. Atlas Rare does not provide medical advice, diagnosis, or treatment. We take patient privacy extremely seriously. This policy explains exactly what we collect, why, and how we protect it.
1. Who We Are
The basics: who we are and how to reach us.
Atlas Rare is operated by SlopLens LLC ("Atlas Rare," "we," "us," or "our"). We provide AI-assisted navigation support for rare disease patients, including clinical trial matching, prior authorization letter drafting (closed beta only), plain-language research summaries, specialist identification, and appointment preparation. We are incorporated in Wyoming. Our primary contact for privacy matters is support@atlasrare.org.
2. How to Delete Your Data
How to erase your information, instantly.
You can delete your personal information at any time. Go to Settings → Clear My Data. This removes your navigation history, preferences, and AI memory instantly.
To exercise any of your privacy rights, contact us at support@atlasrare.org or use the Settings menu in your account. We will respond within 30 days.
All Users
- Right to access your personal information
- Right to correct inaccurate information
- Right to request deletion of your account and personal data
- Right to opt out of research data collection at any time
- Right to opt out of marketing communications
- Right to data export: download all your data as a JSON file at any time from Settings
EU and UK Users (GDPR)
- Right to data portability (Article 20)
- Right to restrict processing (Article 18)
- Right to object to processing based on legitimate interests (Article 21)
- Right to erasure / 'Clear My Data' (Article 17) — available in Settings
- Right to lodge a complaint with your supervisory authority
- Right not to be subject to automated decision-making with legal effects without human review (Article 22) — all Atlas Rare outputs include an explanation of the basis for each result
California Users (CCPA)
- Right to know what personal information we collect and how we use it
- Right to delete personal information
- Right to opt out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
- Right to correct inaccurate personal information (CPRA amendment)
3. Our Commitment to Patient Privacy
We never store PHI. Here's what that means in practice.
Atlas Rare does not collect, store, or process Protected Health Information (PHI) as defined under HIPAA. We are not a covered entity or business associate under HIPAA at this time. We are a navigation and administrative support tool, not a healthcare provider.
We use anonymized identifiers for all patient records. No record in our system links your navigation data to your real name without your explicit consent. Your condition categories and navigation history are stored under an anonymized ID, not your name or email address.
4. Information We Collect
Here's the short list of what we actually store — it's less than you'd expect.
4.1 Information You Provide Directly
- Email address (for account creation and communications)
- Username and password (hashed, never stored in plaintext)
- Primary condition category (e.g. connective tissue disorder — not your specific diagnosis)
- Insurance type and plan category (not your policy number or member ID)
- Prior authorization history (number of denials — not specific claim details)
- Communication preferences (brief vs. detailed responses)
- Whether you have a current specialist (yes/no)
4.2 Information Collected Automatically
- IP address and browser type
- Pages visited and features used
- Session duration and interaction patterns
- Error logs
4.3 Research Data (IRB-Governed)
With your explicit consent, and only after our IRB protocol receives written approval, we may collect anonymized data about your navigation experience for research purposes. You may opt out at any time without affecting your access to navigation services.
5. How We Use Your Information
What we do with the information you give us, and nothing more.
5.1 To Provide Navigation Services
- To match you with relevant clinical trials via ClinicalTrials.gov
- To draft prior authorization appeal letter templates (closed beta users only)
- To generate plain-language summaries of relevant PubMed research
- To identify specialists with experience in your condition category
- To prepare appointment questions tailored to your situation
- To remember your preferences and history so you don't repeat yourself across sessions
5.2 Legitimate Interests
- To improve our navigation algorithms and trial matching accuracy
- To identify common insurance denial patterns to improve appeal letter effectiveness
- To protect our platform from abuse
- To understand which features are most useful to patients
6. What We Never Do
Seven things we will never do. Period.
- We never sell your information to any third party
- We never share your information with pharmaceutical companies, insurers, or healthcare providers without your explicit request
- We never store PHI as defined under HIPAA (see Section 3)
- We never use your information to make automated decisions that have legal or significant personal effects without human review
- We never use your information to train AI models for any purpose
- We never share your specific condition details with other users
- We never use your data for advertising or marketing profiling
7. Third-Party Service Providers
Who touches your data besides us — and what they're allowed to do with it.
- Anthropic — processes navigation queries via the Claude API. Data is not used for model training per Anthropic's API terms.
- AWS — stores audit logs and backups in encrypted S3 buckets (US regions only)
- Supabase — stores anonymized user records and navigation data
- Loops — sends transactional emails and outcome follow-up surveys
- Langfuse — agent monitoring and tracing (self-hosted; no data leaves our environment)
We do not use Google Analytics, advertising networks, or social media tracking pixels.
8. Clinical Data Sources
The public databases we query on your behalf.
- ClinicalTrials.gov — public US government database of clinical trials
- PubMed / NCBI — public database of peer-reviewed medical research
Queries to these databases contain only condition category terms — never your name, contact information, or identifying details.
9. International Data Transfers
If you're outside the US, here's how transfers work.
Atlas Rare is based in the United States. If you are located in the EU or UK, your information will be transferred to and processed in the United States. We rely on the European Commission's Standard Contractual Clauses (SCCs) as the legal mechanism for these transfers. A Data Processing Agreement (DPA) is available to EU users upon request at support@atlasrare.org.
10. Data Retention
How long we keep things, and what happens when you leave.
- Navigation history and preferences: duration of your account plus 2 years
- Anonymized research outcomes: up to 7 years under IRB protocol (pending approval)
- Support communications: 3 years
- Audit logs: 7 years
11. Your Privacy Rights
Every right you have, organized by where you live.
See Section 2 above for a complete list of your privacy rights organized by jurisdiction.
12. AI Memory and Personalization
How Atlas learns from your sessions — and how to turn it off.
Atlas Rare uses an AI memory layer to improve your navigation results over time. Relevant information from each session is stored under your anonymized account ID.
What is stored:
- Trial match quality: which trials scored well and which you engaged with
- Appointment history: which specialties you prepared for
- Research preferences: which condition categories and paper types were most relevant
- Prior authorization history: insurer name, condition category, citation types used (no claim IDs or PHI)
What is never stored:
- Your full name, date of birth, insurance member ID, or specific diagnosis codes
- The content of any documents you reviewed
- Any information you have not explicitly provided to Atlas Rare
Delete your AI memory at any time: Settings → AI Memory → Clear My Data. You may also enable Basic Mode to disable all memory writes.
13. Security
What we do to keep your information safe.
We implement: anonymized identifiers for all patient records, AES-256 encrypted storage at rest, row-level security ensuring no user can access another user's data, and regular security reviews. Contact support@atlasrare.org immediately if you believe your information has been compromised.
14. Children's Privacy
How Atlas Rare handles accounts for minors.
Atlas Rare is not directed at children under 13. If a caregiver is using Atlas Rare on behalf of a minor patient age 13 or older, the caregiver's account is used and no information identifying the minor is collected.
15. DMCA / Copyright Infringement
How to report copyright issues.
Ocean Liauw — Designated Copyright Agent, SlopLens LLC. Contact: support@atlasrare.org
16. Changes to This Policy
What happens when this policy changes.
We will notify you of material changes by email at least 14 days before they take effect, with plain-language explanations of any changes that affect how your information is used.
17. Contact
How to reach us with questions.
Atlas Rare — operated by SlopLens LLC
support@atlasrare.org
atlasrare.org
This policy is pending attorney review. We will update it after legal review is complete.