Zenith Protocol & Atlas
Last updated: 29 August 2026
Your data is here for your sake. Zenith is built to help you take back control of your attention — and every piece of data we keep serves that: protecting your account, remembering your progress, and making the service better for you. We collect as little as possible, never sell anything, and you can see, export or delete all of it at any time. Below is the whole truth about what we keep and why — no fine print.
Zenith Protocol and Atlas, available at impactzenith.com, are operated by the same operator, who is the controller of the personal data processed when you use the services. Both services run on a server located in Sweden.
Company registration number: 080207-0755
Contact: [email protected]
Here’s how we think about every item below: do we need it to help you or to run the service? If the answer is no, we don’t collect it. That’s why this list is deliberately short. None of it is sold, none of it is used to profile you or influence you quietly, and your sensitive content — your reflections and impulses — stays with you. We show exactly what, where and why, so you never have to guess.
Account details
Email address and password (hashed with Argon2id, never readable in plain text). Stored in a database on our server.
Protocol data (Zenith)
Your confirmed days, daily reflections and free-text journal entries, your optional time-capsule letter, mood logs, impulse records (time, trigger, method, outcome) and baseline values. This is sensitive data: it is stored primarily locally in your browser (localStorage, key: zenith_protocol_v1) and synced over HTTPS to our server when you are logged in — for backup and cross-device sync. The content is never used for marketing or commercial profiling and is never shared with third parties. It is also never shared with other users, with one exception: if you choose to write a short message in the accountability-partner feature, it is shown anonymously to others on the same protocol day. An authorised administrator (the service operator) can access individual data when needed to operate, debug, protect and support the service.
Growth data (Atlas)
Your active life aspects, exercise sessions (time, aspect, exercise name and log data) and declarations. Stored primarily locally in your browser (localStorage, key: lp_state) and synced over HTTPS to our server while you are signed in.
Payment information
When you buy a subscription we share your email address and chosen plan with Stripe (stripe.com) to process the payment. Card details (card number, CVV, expiry) are never stored by us — they are handled exclusively by Stripe, which is PCI DSS certified. We store your Stripe customer ID and subscription status (active, paused, canceled) to manage your access to Atlas. If you make a voluntary contribution we share your email address with Stripe in the same way, and keep the amount and date as accounting records.
Technical data
To keep your account safe and the service running, we store a few technical traces. Your IP address appears on login attempts and in the web server’s ordinary logs — that protects you against automated attacks. From the IP address, Cloudflare reads an approximate country (just the country code), which we use for simple statistics on where our users are. We also note when you last opened the app, where you found us (if available) and whether you run the app installed or in a browser — small signals that help us improve the experience. If you turn on reminders yourself, we store what’s needed to send them: your browser’s push subscription and the times you chose. We never store the IP address itself in our database and never sell it. It reaches a third party only for ad measurement, and only if you consent: your IP is then included in the measurement sent to Meta (Meta Pixel), to TikTok (TikTok Pixel) and to OpenAI (the OpenAI Ads pixel) — see section 5. Without your consent, never. Retention periods are in section 4.
Usage and support data
To see what actually helps and make Zenith and Atlas better, we look at how the service is used: which tabs you open, when you use the dictionary, when the Atlas paywall appears and when you play a group exercise. It’s tied to your account — so not anonymous — but stays internal to us and is used only to improve the product. Never for marketing, never sold or shared with third parties. And if you write to us in the support chat, we of course keep your messages so we can help you properly. Before you create an account we also measure landing-page visits anonymously — a temporary session id with no cookie, plus a coarse traffic source (for example TikTok, Google or direct) derived from where you arrived from. No web address is stored, and none of it can be linked to you.
Providing the service
ContractSo that you can sign in, save your protocol progress and sync data across devices.
Security
Legitimate interestTo protect your access, and that of others, against unauthorised login and automated attacks.
Improving the service
Legitimate interestWe log how the service is used — including some usage tied to your account (see section 2) — to see what works and improve the product. It is used only internally, never for marketing. On the public landing page we also measure anonymous, aggregated traffic without cookies and without login. With your consent we also measure the public pages with PostHog, which records how the page is used — mouse movement, clicks and scrolling — so we can see where visitors get stuck. That recording never runs inside Zenith Protocol or Atlas.
Ad measurement
ConsentWith your explicit consent we measure how our ads perform via the Meta Pixel, the TikTok Pixel and the OpenAI Ads pixel. You can withdraw your consent at any time.
Your account details and all data from Zenith Protocol and Atlas are kept for as long as your account is active. You can delete your account — and all associated data — at any time from the Account page (impactzenith.com/account). Deletion is immediate, permanent and cannot be undone. Contributions you have made are anonymised rather than deleted — the amount and date must remain as accounting records, but the link to you is removed.
Our login limiter holds your IP address temporarily in memory (at most about 60 minutes) to protect against automated attacks. Our web server also keeps ordinary access logs containing IP addresses on disk for operations and security; these are kept for a limited time and then purged. We never store the IP address in our database and never use it ourselves for profiling or marketing. The only third parties that may receive your IP are Meta, TikTok and OpenAI, and only if you have consented to ad measurement (see sections 5 and 6) — otherwise it is never shared.
We never sell or rent your personal data. To measure how our ads perform we use the Meta Pixel with Meta’s Conversions API, which share certain data with Meta Platforms, the TikTok Pixel with TikTok’s Events API, which share certain data with TikTok, and the OpenAI Ads pixel, which shares certain data with OpenAI — but only if you actively consent. If you don’t consent, no ad measurement loads. You can change or withdraw your choice at any time (see section 6). Beyond the services named in this policy, we use no other external analytics or ad-measurement services.
Stripe (stripe.com) is our payment provider for Atlas subscriptions. We share your email address and chosen subscription plan with Stripe to enable payment and subscription management. Stripe is PCI DSS certified — card details are handled directly by Stripe and never pass through our server. Stripe’s own privacy policy is available at stripe.com/privacy.
Besides Stripe we use a small number of trusted sub-processors to run the service, sharing only the data each purpose requires: Cloudflare (network, operations and bot protection — handles all traffic including IP address), Backblaze (storage of database backups), Resend (transactional email such as receipts and password resets), Sentry (error monitoring, within the EU), PostHog (visitor measurement and session recording on the public pages, within the EU — only with your consent), DeepL and, as a fallback when DeepL’s quota is exhausted, Google (machine translation of content you choose to translate) and — only if you consent — Meta Platforms (measuring ad performance via the Meta Pixel and Conversions API) TikTok (measuring ad performance via the TikTok Pixel and Events API) and OpenAI (measuring the performance of ads in ChatGPT via the OpenAI Ads pixel). We have a data processing agreement with each sub-processor, and any transfers outside the EU/EEA use appropriate safeguards such as the EU Standard Contractual Clauses. The transfers to Meta, to TikTok and to OpenAI happen only with your consent, may mean they use the data for their own advertising purposes, and can be withdrawn at any time. TikTok is part of the ByteDance group and the data may be processed outside the EU/EEA, safeguarded by the EU Standard Contractual Clauses. OpenAI is a US company and the data is processed outside the EU/EEA, safeguarded by the EU Standard Contractual Clauses.
We use a session cookie (zenith_session) to keep you logged in. The cookie is HttpOnly and Secure and lasts up to 30 days, or until you log out — at which point it is deleted.
Your progress in Zenith Protocol and your growth data in Atlas are stored in the browser’s localStorage to preserve your data between sessions without constant server calls. The apps require a connection to load — localStorage is not a substitute for an offline mode. It is not used for tracking.
With your consent we use the Meta Pixel, the TikTok Pixel and the OpenAI Ads pixel — advertising and tracking pixels from Meta, TikTok and OpenAI respectively — to measure ad performance. Meta and TikTok set third-party cookies; the OpenAI pixel instead sets first-party cookies (__obref and __oppref) identifying the browser and the ad click respectively. They never load without your approval. You can withdraw your consent at any time using the button below. We use no fingerprinting methods.
With your consent we also use PostHog (EU) to understand how our public pages work. PostHog sets a first-party cookie, measures clicks and page views, and records how the page is used. Anything you type into a field — email, password, free text — is masked and never reaches the recording. Recording runs only on the public pages: the landing page, the blog, registration and checkout. It never runs inside Zenith Protocol or Atlas, where your urge logs, reflections and mood check-ins live. You can refuse or withdraw at any time using the button below. You choose analytics and marketing separately — in the cookie banner, via Cookie settings at the bottom of the page, or with the button below.
You have the following rights under the GDPR:
To exercise your rights: contact us by email or use the features directly in the app.
Passwords are hashed with Argon2id and never stored in plain text. All traffic is encrypted over HTTPS. The database is not publicly accessible over the network. We apply rate limiting to logins to prevent automated attacks.
If you are a California (USA) resident, under the California Consumer Privacy Act (CCPA) you have the right to:
To exercise your CCPA rights, contact us at [email protected]
If we make material changes to how we process your data, we will communicate it clearly in the app. The date of the last update is always shown at the top of this page.