Privacy Policy

How we collect, use, and protect your personal information.

Last updated: January 31, 2026

Thesis Atlas ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our research title recommendation platform.

By using Thesis Atlas, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our services.

Information We Collect

We collect several types of information to provide and improve our services:

Personal Information:

  • Email address (for account registration and communication)
  • Full name (for personalization)
  • Education level, faculty, and study program (for tailored recommendations)
  • Password (stored securely using bcrypt hashing)

Research Data:

  • Research descriptions and keywords you provide
  • Research type preferences and constraints
  • Generated title recommendations and scoring results
  • Saved titles and user preferences

Technical Data:

  • IP address and browser information
  • Device type and operating system
  • Session cookies for authentication
  • Usage logs and timestamps

How We Use Your Information

We use the collected information for:

  • Service Delivery: Providing personalized research title recommendations and scoring
  • Account Management: Creating and managing your user account
  • Communication: Sending verification codes, password resets, and payment receipts
  • Payment Processing: Processing credit purchases through Midtrans
  • Service Improvement: Analyzing usage patterns to enhance our platform
  • Security: Detecting and preventing fraud, unauthorized access, and abuse
  • Legal Compliance: Meeting applicable legal requirements

Data Sharing and Third Parties

We share your information only with the following third parties for service provision:

  • OpenAI: Research descriptions and titles are processed by OpenAI's GPT models for recommendation generation. Data is subject to OpenAI's privacy policy and data usage policies.
  • Midtrans: Payment information is processed by Midtrans for credit purchases. We do not store your complete payment card information.
  • Resend: Email addresses are used with Resend for sending transactional emails (verification, receipts).
  • Scopus/Elsevier: Research titles may be queried against Scopus database for novelty and impact assessment.

We do not sell your personal data to third parties for marketing or advertising purposes.

Data Security

We implement appropriate security measures to protect your data:

  • Encryption: All data is transmitted over HTTPS using TLS/SSL encryption
  • Password Security: Passwords are hashed using bcrypt algorithm and never stored in plain text
  • Access Control: Database access is restricted to authorized personnel only
  • Regular Backups: Data is regularly backed up to prevent loss
  • Secure Infrastructure: Our servers are hosted on secure, monitored infrastructure

While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

Data Retention

We retain your data as follows:

  • Account Data: Retained while your account is active
  • Research History: Recommendation runs and scores are kept for your reference
  • Payment Records: Transaction history is retained for accounting and legal purposes
  • Logs: System logs are retained for 90 days for security monitoring

Upon account deletion request, we will remove your personal data within 30 days, except where retention is required by law.

Cookies

We use only essential cookies for:

  • Session Management: Maintaining your logged-in state
  • Security: Protecting against CSRF attacks

We do not use third-party tracking cookies, advertising cookies, or analytics cookies that track you across websites.

Your Rights

You have the following rights regarding your data:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate data via your profile settings
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a machine-readable format
  • Withdrawal: Withdraw consent by deleting your account

To exercise these rights, contact us at privacy@thesisatlas.com.

Children's Privacy

Thesis Atlas is intended for users aged 17 and above (university students and researchers). We do not knowingly collect personal information from children under 17. If you believe a child has provided us with personal data, please contact us immediately.

International Data Transfers

Your data may be processed by third-party services located outside Indonesia (e.g., OpenAI in the United States). By using our services, you consent to this transfer. We ensure these providers maintain adequate data protection standards.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • The "Last updated" date will be revised
  • Material changes will be communicated via email to registered users
  • Continued use of the service after changes constitutes acceptance

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Email: privacy@thesisatlas.com

We aim to respond to privacy inquiries within 7 business days.

Your Privacy Matters to Us

We are committed to being transparent about our data practices and protecting your personal information.