Legal
Privacy Policy
Last updated October 2, 2026
Phoenix Horizon, Inc. operates Silicon Valley Atlas (svatlas.io), its hosted MCP server at svatlas.io/mcp, and the Silicon Valley Atlas plugins and connectors for AI assistants. This policy covers all of them.
What we collect
- Account. When you sign in with Google we receive your name, email address, and profile picture.
- What you save. Lists, the companies on them, notes, and list sharing settings.
- Preferences. The verticals, focus, and hidden items you set in Settings, and any token you save there for pipeline features.
- What you ask. Search queries and product URLs you submit for matching, and which company, founder, and firm pages you open (so the site can show what you have already seen).
- Usage counts. How many searches and matches you ran this month, to enforce plan limits.
- LinkedIn connections, only if you upload them. The names, companies, titles, and connection dates in the export you choose to import.
- Agent connections. When you connect an AI assistant (ChatGPT, Claude, Codex, Muse, or another MCP client) we store the client's name and redirect address and a hashed access token. We never store the token itself.
- Billing. If you subscribe, Stripe collects your payment details. We receive the subscription status, never your card number.
What we do not collect
The MCP server and plugins receive only the arguments of the tool an assistant calls, such as a search query or a list name. They never request or receive your chat history. We do not sell personal data, show ads, or build advertising profiles.
How we use it
- To run the features you use: search, matching, lists, and the Network page.
- To keep your account signed in and your agent connections working.
- To enforce plan limits and manage billing.
- To debug failures and protect the service from abuse.
Who processes it
We share data only with the providers that run the service:
- Cloudflare, which hosts the site and MCP server.
- Supabase, which stores the database and handles sign-in.
- Google, for sign-in.
- Stripe, for payments.
- OpenRouter, which receives search queries, product pages you submit, and the vertical descriptions you save, to embed and summarize them. No account details are sent.
We disclose data to others only when the law requires it.
How long we keep it
Account data, lists, visits, and imported connections stay until you delete them or your account. Monthly usage counts are kept for billing history. Access tokens for agents expire after one hour and refresh tokens after 90 days, and you can revoke any agent connection in Settings at any time.
Your choices
You can delete lists, clear your visit history, and disconnect agents yourself. To remove imported LinkedIn connections, get a copy of your data, or delete your account and everything attached to it, email privacy@getrush.ai. We delete it and confirm by email.
People and companies in the directory
The directory lists startups, founders, and investors using information from public pages such as accelerator directories, company websites, and press. Each fact links to its source. If you are listed and want something corrected or removed, email privacy@getrush.ai.
Children
The service is for professional use and is not directed at anyone under 16.
Changes and contact
We will post changes on this page and update the date above. Questions go to privacy@getrush.ai.