Overview
aturi.to (“Aturi,” “we,” “us,” or “our”) is a free, open-source ecosystem of tools for navigating the Atmosphere — the federated network of services built on the AT Protocol (atproto). These Terms of Service and Privacy Policy (together, this “Agreement”) govern your use of all Aturi products, including:
- The aturi.to web app, including the universal link router, profile and record landing pages, OpenGraph image generation, the public Resolve API, and oEmbed metadata.
- The Atmosphere Explorer (the “Explore” feature), which lets visitors browse public repository data, identity history (via the PLC directory), collections, a live Jetstream commit feed, backlinks (via the Constellation third-party index), and cached reputation scores (via the cred.blue third-party API) for any account on the Atmosphere.
- The Record Editor and other authenticated features that allow you, after signing in, to create, read, update, or delete records and upload blobs in your own atproto repository.
- Sign in with atproto (OAuth) and preference sync via your Personal Data Server (“PDS”). When you sign in, you can personalize the Service by reordering, hiding, grouping, renaming, pinning, and starring waypoints, adding your own custom waypoints, and storing other non-sensitive UI choices. These preferences are written to a record in your own atproto repository (NSID
to.aturi.actor.preferences, rkeyself) so they follow you across devices and clients. Any other authenticated functionality offered through aturi.to is also covered. - The Aturi browser extension for Chrome, Firefox, Safari, and other supported browsers, including its detection, Inspect, auto-redirect, and waypoint-jump features. The extension is also governed by its dedicated Extension Privacy Policy, which controls in case of any conflict with this Agreement.
- Any other websites, APIs, integrations, share-sheet endpoints, Apple Shortcuts, or related features we make available under the aturi.to brand (collectively with the items above, the “Service”).
By accessing or using any part of the Service, you agree to be bound by this Agreement. If you do not agree, do not use the Service. If you are using the Service on behalf of an entity, you represent that you have authority to bind that entity, and “you” refers to that entity.
The Service is provided free of charge. We may add, change, or remove features at any time and without notice.
Terms of Service
1. Eligibility
You must be at least 13 years of age (or the minimum age of digital consent in your jurisdiction, if higher) to use the Service. By using the Service, you represent and warrant that (a) you meet this age requirement, (b) you have the legal capacity to enter into this Agreement, and (c) your use of the Service does not violate any applicable law or regulation, any order of any court or government authority, or any agreement you have with a third party.
2. The Service
Aturi is, in substance, a routing and inspection layer over public data and identities that already exist on the Atmosphere. You should understand the following before using it:
- Universal link routing. aturi.to URLs resolve to a landing page that lets the recipient pick which third-party Atmosphere client they want to use to view a profile, post, list, or other public record. We do not host, store, modify, or curate the underlying content.
- Explore. The Atmosphere Explorer renders public repository data fetched on demand from public Personal Data Servers, the Bluesky AppView (
public.api.bsky.app), the PLC directory (plc.directory) for identity-history lookups, the Constellation third-party backlink index (constellation.microcosm.blue) for incoming-link aggregates, the cred.blue third-party API for cached reputation scores when available, and a public Jetstream relay (a WebSocket firehose of public atproto commits) for live feed views. Aturi does not warehouse this data; we display what those upstream services return, when you request it. Some of these services are operated by third parties and may be unavailable, rate-limited, or removed at any time. - Record Editor and authenticated actions. When you sign in with atproto OAuth and grant write scopes, authenticated actions (create, update, delete records; upload blobs) are performed by your browser directly against your PDS using your DPoP-bound access tokens. Aturi acts as a client interface; the resulting data lives in your repository on your PDS, not on our servers. You are solely responsible for any record you create, modify, or delete through the Service, including the consequences of deletion (such as broken references, lost engagement metadata, or removal of content others have linked to).
- Preference sync and personalization. If you sign in, the Service may store non-sensitive preferences — including waypoint groups (name and order), per-group waypoint ordering, hidden/visible/pinned waypoints, custom waypoints you have defined (display name, domain, URL templates, supported record types), and other UI choices — as a record in your own PDS (NSID
to.aturi.actor.preferences, rkeyself). The authoritative copy lives in your repository, under your control. A local copy is kept in your browser’s storage for fast access and to support anonymous use. You can delete the preferences record at any time using the Service or any other atproto client. We do not maintain a separate copy. - Resolve API and oEmbed. Aturi exposes a public Resolve API and oEmbed endpoint that accept an HTTP(S) URL or AT URI and return structured metadata, including a list of waypoint URLs that can render the same content. To detect AT URIs in HTML pages, the Resolve API may fetch a limited portion of the page over standard HTTP(S) using a clearly identified user agent.
- Browser extension. The browser extension is distributed via official browser web stores (Chrome Web Store, Firefox Add-ons, and the Mac App Store for Safari). In addition to one-click waypoint jumping and auto-redirect, the extension offers AT URI detection (a content script that passively looks for
<link href="at://…">in the document head on pages you visit, so the popup can offer relevant waypoints) and an Inspect view (which, when you open it, scans the active page for AT URIs in head, meta, anchor, JSON-LD, and body text, and then fetches identity, record, and backlink data from public atproto services to display details inline). Its full data handling, network requests, and permissions are described in the Extension Privacy Policy. The extension does not transmit data to Aturi-operated servers in normal use.
Atmosphere data is, by its nature, public. Records you publish to the AT Protocol are visible to anyone with access to your PDS or the relevant AppView, regardless of whether you use Aturi.
3. Your account and authentication
Aturi authentication is performed entirely through standard atproto OAuth. We do not operate an identity provider, do not issue or store passwords, and do not maintain a centralized user account database. Your atproto identity is administered by your PDS host and any associated identity authority. Your continued ability to sign in depends on those upstream providers.
When you sign in:
- You authorize Aturi to act as an OAuth client against your PDS within the scopes you grant at the consent screen (e.g., create, update, delete records; upload blobs). Reads of records in your own repository are public and are not gated by a scope.
- Access and refresh tokens are bound to a DPoP key generated in your browser, stored in your browser’s local storage (e.g., IndexedDB), and never transmitted to Aturi servers. Signing out from the Service removes the local session from your browser; it does not revoke tokens upstream. You can revoke tokens at any time through your PDS.
- You are responsible for safeguarding your atproto credentials and the device(s) where you sign in. Any action taken through a signed-in session is your action, including creating, modifying, or deleting records in your repository.
- We may decline to authenticate any request, end any session, or refuse to service any OAuth client interaction at our sole discretion, including to protect the Service or comply with applicable law.
4. Your content and your repository
The Service does not host user content. When you create, update, or delete records or upload blobs while signed in, you are doing so against your own atproto repository on your own PDS. You retain all right, title, and interest in and to your content, subject to the protocols, terms, and policies of the PDS, AppView, and downstream services that store and propagate it.
You represent and warrant that:
- You have all rights necessary to create, modify, and publish any content you operate on through the Service.
- Your content and your use of the Service do not infringe, misappropriate, or violate any third party’s intellectual property, privacy, publicity, contract, or other rights, and do not violate any applicable law.
- You understand that records published via the AT Protocol are public, may be replicated by third parties (including AppViews, relays, mirrors, and archives), and that deleting a record from your PDS does not guarantee deletion from those third parties.
To the extent any content you create or modify through the Service is processed by or briefly transits Aturi infrastructure in the course of operating the Service (for example, parsing or rendering inside your browser), you grant Aturi a worldwide, non-exclusive, royalty-free license to perform such processing solely for the purpose of providing the Service to you. No other license is granted.
5. Acceptable use
You agree that you will not, and will not attempt to:
- Violate any applicable law, regulation, or court order;
- Use the Service to harass, threaten, defame, dox, stalk, or otherwise harm any person, or to incite or facilitate violence;
- Create, modify, distribute, or share content that is illegal, including content that sexually exploits or endangers minors, infringes intellectual property, or violates export control or sanctions law;
- Use the Service to send unsolicited bulk communications, spam, phishing, malware, ransomware, scams, or fraudulent content;
- Probe, scan, overload, disrupt, degrade, or test the vulnerability of the Service or its infrastructure, or attempt to bypass any rate limits, throttling, abuse protections, authentication, or security mechanism;
- Access the Service, or any account or repository, using automated means in a manner that imposes a disproportionate load, or that is not consistent with this Agreement;
- Reverse engineer, decompile, or disassemble any portion of the Service except to the extent that activity is expressly permitted by applicable law or by the open-source license governing our code;
- Impersonate any person or entity, misrepresent your affiliation, or misrepresent the origin of any record or link;
- Use the Service to redirect to, or otherwise route traffic to, malicious, deceptive, or unlawful destinations;
- Use the Service in any way that could damage, disable, or impair the Service, the rights of other users, or the broader atproto ecosystem.
We may investigate suspected violations, cooperate with law enforcement, and take any action we deem appropriate, including blocking IP addresses, refusing service to specific identities, removing or rejecting links, suspending OAuth sessions, or terminating access entirely, in each case without notice and at our sole discretion.
6. Third-party services and destinations
The Service interoperates with and routes to third-party services that we do not control, including without limitation:
- The Bluesky AppView (
public.api.bsky.app) — profile lookups, handle resolution, post/list fetches. - The PLC directory (
plc.directory) — DID document and identity-audit-log lookups for Explore. - Constellation (
constellation.microcosm.blue) — a third-party backlink index queried for incoming-reference counts on records. - cred.blue (
api.cred.blue) — a third-party reputation/score API queried to display a cached score badge on certain profile pages. - A public Jetstream relay WebSocket (e.g.,
jetstream2.us-east.bsky.network) — live stream of public atproto commits used to render the Explore live feed. Standard connection metadata (IP address, user agent) is visible to the relay operator while the connection is open. - Your PDS and identity authority — authentication, repository reads and writes, blob uploads.
- Third-party Atmosphere clients and waypoints (e.g., Bluesky, Anisota, Blacksky, Red Dwarf, Leaflet, Tangled, Margin, Grain, Pinkleap, Semble, Streamplace, Popfeed, Sifa, Blento, PDSls, atp.tools) and custom waypoints you define.
- Vercel — hosting, edge runtime, and anonymous analytics.
- Browser web stores and operating-system vendors (Google, Mozilla, Apple) that distribute the extension and may, depending on your settings, sync extension storage across your devices.
Your use of any third-party service is governed by that service’s own terms and privacy policy. Aturi makes no representations or warranties about any third-party service and is not responsible for any third-party content, conduct, or practices, including how a third party handles data we hand off to it when you click a waypoint, follow a redirect, or sign in.
7. Open source and intellectual property
The Aturi source code is licensed under the GNU General Public License version 3 or later. You may inspect, fork, modify, and redistribute the source code subject to that license. The license to the source code is separate from this Agreement; this Agreement governs only your use of the hosted Service we operate at aturi.to.
All rights, title, and interest in and to the Service, including all related intellectual property rights, are and will remain the exclusive property of Aturi and its contributors. Nothing in this Agreement transfers any such rights to you, except the limited, revocable, non-exclusive, non-transferable license to access and use the Service in accordance with this Agreement.
The names “aturi” and “aturi.to” and any associated logos or marks are the property of their owner and may not be used to imply endorsement of, or affiliation with, any third-party fork, product, or service without prior written permission. Forks must comply with the attribution and licensing terms set out in the source repository.
8. Copyright and DMCA-style notices
Because Aturi does not host atproto content and acts only as a client and router, takedown requests for underlying records must be directed to the operator of the PDS, AppView, or other service that hosts or surfaces the record in question. If you believe a routing link or rendered page on aturi.to itself infringes your rights, you may send a notice to contact@aturi.to that includes (i) identification of the work, (ii) identification of the aturi.to URL at issue, (iii) your contact information, (iv) a statement that you have a good-faith belief that the use is not authorized, (v) a statement, under penalty of perjury, that the information in your notice is accurate and that you are the rights holder or authorized to act on the rights holder’s behalf, and (vi) your signature (physical or electronic). We may forward notices to relevant parties and take any action we deem appropriate.
9. Fees
The Service is currently provided free of charge. We reserve the right to introduce paid features in the future, but no charge will be incurred without your express consent.
10. Service availability and changes
The Service is provided on an as-available basis. We may modify, suspend, throttle, rate-limit, discontinue, or terminate the Service, any feature, any API, any waypoint, or any aspect of the Service at any time, with or without notice, and without liability. We do not guarantee any uptime, latency, response time, redirect success rate, or that the Service will be free of bugs, errors, or interruptions. We are not responsible for failures of third-party services on which the Service depends.
11. Termination and suspension
You may stop using the Service at any time. We may suspend or terminate your access, in whole or in part, at any time and for any reason, including suspected violations of this Agreement, suspected abuse, threats to the Service or other users, or to comply with applicable law. Sections of this Agreement that by their nature should survive termination (including, without limitation, sections on intellectual property, disclaimers, limitation of liability, indemnification, dispute resolution, and miscellaneous provisions) will survive.
12. Disclaimers
The Service, including all features, content, software, and data made available through it, is provided “AS IS” and “AS AVAILABLE,” with all faults and without warranty of any kind. To the maximum extent permitted by applicable law, Aturi and its contributors, affiliates, and service providers disclaim all warranties, whether express, implied, statutory, or otherwise, including any warranties of merchantability, fitness for a particular purpose, title, quiet enjoyment, accuracy, non-infringement, and any warranties arising from course of dealing, course of performance, or usage of trade.
Without limiting the foregoing, Aturi does not warrant that the Service will be uninterrupted, secure, timely, accurate, or error-free; that defects will be corrected; that any content (including atproto records, links, and waypoints) is accurate, complete, lawful, or reliable; that any third-party service or destination is safe, available, or trustworthy; that data stored in your repository will be preserved or recoverable; or that any redirect, link rewrite, or auto-fill will produce the intended result.
You assume sole responsibility and all risk arising from your use of the Service. Some jurisdictions do not allow the exclusion of certain warranties, so some of the above exclusions may not apply to you. In that case, any implied warranties are limited to the shortest period permitted by law.
13. Limitation of liability
To the maximum extent permitted by applicable law, in no event will Aturi or its contributors, affiliates, officers, directors, employees, agents, suppliers, or licensors be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, goodwill, use, data (including loss or corruption of records in your repository), substitute goods or services, or other intangible losses, arising out of or related to this Agreement or the Service, whether based in contract, tort (including negligence), strict liability, statute, or any other legal theory, and whether or not Aturi has been advised of the possibility of such damages.
To the maximum extent permitted by applicable law, the aggregate liability of Aturi and its contributors, affiliates, officers, directors, employees, agents, suppliers, and licensors arising out of or related to this Agreement or the Service will not exceed the greater of (a) the amount you have paid to Aturi in the twelve (12) months preceding the event giving rise to the claim, and (b) fifty US dollars (US$50.00).
The exclusions and limitations in this section apply regardless of the cause of action or the form of damages sought, and survive any failure of essential purpose of any limited remedy. Some jurisdictions do not allow the exclusion or limitation of certain damages, so these limitations may not fully apply to you; in such jurisdictions, the liability of Aturi is limited to the smallest extent permitted by law.
14. Indemnification
You agree to defend, indemnify, and hold harmless Aturi and its contributors, affiliates, officers, directors, employees, and agents from and against any and all claims, demands, actions, liabilities, losses, damages, judgments, settlements, costs, and expenses (including reasonable attorneys’ fees and disbursements) arising out of or related to: (a) your access to or use of the Service; (b) your content or any actions you take through the Service, including any records you create, update, or delete in your repository; (c) your violation of this Agreement; (d) your violation of any law or any third party’s rights; or (e) any third-party claim that your use of the Service caused harm to that third party. We reserve the right to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which case you agree to cooperate with our defense.
15. Beta and experimental features
From time to time we may make available features that are identified as beta, preview, experimental, or otherwise not ready for general use. Such features are provided for evaluation purposes only, may be modified or removed at any time, are not subject to the same level of testing or support, and may behave unexpectedly. You use such features at your own risk.
16. Force majeure
Aturi will not be liable for any failure or delay in performance to the extent caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, governmental action, labor disputes, internet or telecommunications failures, denial-of- service attacks, outages of upstream services (including PDSes, AppViews, and infrastructure providers), or other similar events.
17. Changes to this Agreement
We may update this Agreement from time to time. The “Last updated” date at the top of this page indicates when this Agreement was last revised. Material changes will be made apparent through reasonable means (for example, a notice on the Service or in release notes). Your continued use of the Service after the revised Agreement takes effect constitutes your acceptance of the revised Agreement. If you do not agree to the revised Agreement, you must stop using the Service.
18. Dispute resolution and governing law
Before filing any formal action, you agree to first attempt to resolve any dispute informally by contacting us at contact@aturi.to and providing a written description of the dispute, your contact information, and the relief sought. We will attempt in good faith to resolve the dispute within sixty (60) days of receipt.
The parties have not selected an exclusive forum or governing law for disputes arising out of or related to this Agreement or the Service. Each party reserves all rights, remedies, and defenses available under any applicable law. Each party irrevocably waives, to the maximum extent permitted by applicable law, any right to participate in a class, collective, or representative action against the other party arising out of or related to this Agreement or the Service.
19. Miscellaneous
Entire agreement. This Agreement, together with any other terms expressly referenced in it (including the Extension Privacy Policy), constitutes the entire agreement between you and Aturi regarding the Service and supersedes all prior or contemporaneous understandings on that subject.
Severability. If any provision of this Agreement is held to be invalid or unenforceable, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.
No waiver. Our failure to enforce any right or provision will not be deemed a waiver of that right or provision. Any waiver must be in writing and signed by us to be effective.
Assignment. You may not assign or transfer this Agreement or any rights or obligations under it without our prior written consent. We may freely assign this Agreement, including to a successor in interest. Any prohibited assignment is null and void.
No third-party beneficiaries. This Agreement does not create any third-party beneficiary rights.
Relationship. Nothing in this Agreement creates any partnership, joint venture, employment, agency, or franchise relationship between you and Aturi.
Notices. We may provide notices to you by posting on the Service or by sending to any email address you provide. You may send notices to us at contact@aturi.to.
Headings. Section headings are for convenience only and have no legal effect.
Privacy Policy
Aturi is designed to collect as little personal data as possible. This Privacy Policy explains what information we and our infrastructure providers process when you use the Service, why, and what your choices are. The Aturi browser extension is covered by its own dedicated Extension Privacy Policy; this section covers the web app and associated server-side features.
1. Information we collect
Anonymous analytics. We use Vercel Analytics to collect aggregate, anonymous usage statistics, which may include page views and visitor counts, referrer source, country-level location, and general device information (browser type, operating system, device type). Vercel Analytics does not use cookies and cannot track individual visitors across days or websites. Visitor data is anonymized using temporary daily identifiers that reset.
Server logs. Our hosting and edge-compute provider (Vercel) may temporarily log standard request metadata to operate, secure, and debug the Service. This may include IP addresses, timestamps, request method and path, user agent, response status, and the originating geography of the request.
OAuth and session data. When you sign in with atproto, the OAuth handshake occurs between your browser and your PDS (and any identity authority associated with it). Aturi acts as a public OAuth client. We do not run an identity provider and we do not store your password. Access tokens, refresh tokens, the DPoP key, and the session metadata required to keep you signed in are stored client-side in your browser’s local storage (e.g., IndexedDB) and never transmitted to Aturi’s servers. Signing out clears that local session in the browser you used.
Preferences and personalization. Non-sensitive preferences — including waypoint groups, per-group ordering, pinned/visible/hidden waypoints, custom waypoints you create (display name, domain, URL templates, supported record types), and other UI choices — are stored locally in your browser. If you are signed in, we also mirror those preferences as a record in your own PDS (NSID to.aturi.actor.preferences, rkey self) so they sync across your devices. The authoritative copy lives in your repository, under your control; we do not maintain a separate copy. The PDS record is technically public — like all atproto records — and may be visible to anyone with access to your PDS or relays that ingest your repository.
Atmosphere data. When you use Explore, view a landing page, request an OG image, or call the Resolve or oEmbed APIs, the Service may fetch records, identity documents (including PLC audit logs), blobs, profile data, backlink aggregates, reputation scores, and live commit streams from public atproto services (PDSes, the Bluesky AppView, the PLC directory, Constellation, cred.blue, Jetstream relays, and similar). That data is rendered or returned to you and is not stored by Aturi for any purpose other than fulfilling the request (subject to short-lived edge caching for performance). The identifiers (handles, DIDs, AT URIs) you supply are necessarily transmitted to the relevant third party so it can answer the query.
Resolve API and oEmbed. When a third-party tool (such as a share sheet, an Apple Shortcut, or another app) calls the Resolve API or oEmbed endpoint with a URL or AT URI, that URL or URI and standard request metadata are processed in order to return a response. If a URL is provided and AT-URI detection in HTML is enabled, Aturi may fetch a limited portion of the page over HTTP(S) using a clearly identified user agent.
Information you choose to send us. If you email us, file an issue in our public repository, or contact us through any other channel, we will process the information you provide so that we can respond.
We do not use tracking pixels, advertising SDKs, third-party advertising cookies, fingerprinting, session replay, or behavioral profiling on the Service.
2. How we use information
Information processed in connection with the Service is used to:
- Operate, maintain, secure, and improve the Service;
- Resolve, route, and render Atmosphere content you (or your recipients) request;
- Sync your preferences to and from your own PDS when you are signed in;
- Detect, prevent, and respond to abuse, fraud, security incidents, and violations of this Agreement;
- Understand aggregate usage trends to inform product decisions;
- Comply with applicable law and respond to lawful requests.
We do not sell, rent, or trade your personal information. We do not share your information with third parties for their own marketing purposes. We do not use your information to train machine-learning models.
3. Legal bases (EEA/UK users)
If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with similar law, our legal bases for processing your personal data are: (a) our legitimate interests in operating, securing, and improving the Service and preventing abuse; (b) performance of a contract with you (this Agreement); and (c) compliance with our legal obligations.
4. Cookies and local storage
Aturi does not use cookies for tracking or advertising. Vercel Analytics is cookieless. The Service does use your browser’s local storage technologies (such as localStorage and IndexedDB) to remember your preferences, hold the OAuth session if you sign in, and store the DPoP key bound to your session. You can clear this data at any time via your browser’s site-data controls; doing so will sign you out and reset your local preferences.
5. Where information is processed
The Service is hosted on Vercel’s global edge infrastructure, and requests are typically served from the region closest to you. As a result, information may be processed in countries other than your own, including the United States. If you access the Service from outside the country where our infrastructure providers operate, you consent to the transfer and processing of information in those countries, which may have different data protection laws than your own.
6. Sub-processors and third parties
We rely on a set of third parties to operate the Service:
- Vercel — hosting, edge functions, and anonymous analytics.
- Bluesky AppView (
public.api.bsky.app) — resolving handles and DIDs, fetching public profile and post data. - PLC directory (
plc.directory) — DID document and identity-audit-log lookups. - Constellation (
constellation.microcosm.blue) — third-party backlink index. - cred.blue (
api.cred.blue) — third-party reputation/score API. - Jetstream relays (e.g.,
jetstream2.us-east.bsky.network) — live public-commit firehose used to render Explore live feeds. - Your PDS and identity authority — authentication, repository reads and writes, blob uploads.
- Other public atproto services — relays, AppViews, and other public endpoints that may be queried to render Explore, OG images, oEmbed, and Resolve responses.
- Third-party Atmosphere clients and waypoints — the destinations you (or your recipients) choose to open links in. We do not control these services.
- Browser web stores and OS vendors (Google, Mozilla, Apple) — distribute the extension and, depending on your settings, may sync extension storage across your devices.
Each of these parties is subject to its own privacy policy and terms. We have no control over their practices.
7. Data retention
Server logs. Operational logs are retained for a maximum of 30 days, except where a longer period is required for security, abuse investigation, or legal compliance.
Anonymous analytics. Aggregate analytics may be retained indefinitely; this data does not identify individual visitors.
Preferences and OAuth sessions. Preferences mirrored to your PDS persist until you delete the record; local session data persists in your browser until you sign out or clear your browser data.
Atmosphere data. The Service does not persist atproto records, blobs, or identity documents fetched from upstream services beyond what is required to serve the request and apply short-lived edge cache.
8. Security
We use commercially reasonable technical and organizational measures to protect the Service, including transport encryption (HTTPS), DPoP-bound OAuth tokens, and the principle of minimum data collection. No system is perfectly secure, however, and we cannot guarantee that the Service will be free of unauthorized access. You are responsible for keeping your atproto credentials and the device(s) on which you use the Service secure.
9. Your rights
Because we collect very little personal data on our own infrastructure, the practical scope of access, correction, or deletion requests is limited. Subject to applicable law, you may have the right to (a) confirm whether we process personal data about you, (b) access a copy of that data, (c) request correction or deletion of that data, (d) object to or restrict certain processing, (e) request portability, and (f) lodge a complaint with a supervisory authority. To exercise these rights, contact contact@aturi.to. Many requests — especially those relating to records in your atproto repository — are best made directly to your PDS, since that is where the authoritative copy of your data lives.
California residents may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of certain processing. We do not sell or share personal information as defined by those laws. To submit a request, use the contact address above. We will not discriminate against you for exercising your rights.
10. Children’s privacy
The Service is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction, if higher), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact contact@aturi.to and we will take appropriate steps to delete it.
11. Do Not Track
Aturi does not perform cross-site behavioral tracking and therefore does not respond differently to Do Not Track signals.
12. Browser extension
The Aturi browser extension is covered by its own dedicated privacy policy. Please see the Extension Privacy Policy for the full description of what the extension stores, what network requests it makes, and what permissions it uses.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated “Last updated” date. Material changes will be made apparent through reasonable means.
Contact
Questions, legal notices, privacy requests, abuse reports, or other concerns about Aturi can be sent to contact@aturi.to. You can also file a public issue in our source repository or reach the maintainer on Bluesky at @atpota.to. The source code is available under GPL v3 at tangled.org/atpota.to/aturi.