loopling.ai

Cookie Policy · loopling

Effective date: August 23, 2026

Loopling and its private investor deck — both operated by Extensium Inc. — use a small number of cookies. None of them are for advertising or cross-site tracking. The full list is below.

A note on names. This product was called Atelier until August 23, 2026, and is now called Loopling, at https://loopling.ai. Only the name changed: the operating company, your account, your content, your plan, and every right and obligation in this document are the same. Extensium Inc. still trades as Atelier, so that is the merchant name you will see on a card statement or in the Alipay app. Links to the retired address atelier.space redirect here.

1. What loopling sets

Functional (always on)

These cookies are required for the app to work. You can't turn them off without making Loopling non-functional. Browsers consent to "strictly necessary" cookies implicitly under most regulations (GDPR, CCPA), so we don't ask you to opt in to these — but the table is here so you know what they are.

CookiePurposeDuration
atelier_sessionAuthenticated session JWT. Without it, you're signed out.30 days, sliding
atelier_oauth_stateOne-time CSRF token for the Google sign-in round trip.10 minutes
atelier_oauth_verifierOne-time PKCE verifier for the same round trip.10 minutes
atelier_oauth_nonceOne-time OIDC nonce for the same round trip.10 minutes
atelier_oauth_invitecodeThe invite code you entered, carried across the Google redirect so it can be redeemed when you come back.10 minutes
atelier_oauth_returntoWhere to send you after sign-in, so a link you opened before signing in still resolves.10 minutes
atelier_oauth_srcWhich entry point started sign-in, so the right welcome applies.10 minutes
atelier_oauth_entry_intentWhether you were signing in or signing up, so the correct door logic runs on return.10 minutes
atelier_oauth_agent_resumeWhich agent authorization to resume after sign-in, if you started one.10 minutes
atelier_gift_admissionSet only if you open an Ink Gift link without an account: a short-lived ticket holding your Google-verified email and which Gift you were looking at, so you can confirm the destination account and claim it. Cleared the moment you confirm.10 minutes
__Secure-loopling-deckPrivate-deck session token, set only after a visitor enters a valid invitation code. It authorizes deck access without putting the code in the URL.Up to 30 days, or until the invitation expires
__Secure-loopling-deck-deviceDurable private-deck device token. It enforces the invitation's device limit without fingerprinting the browser.Until the invitation expires

Every cookie above is HttpOnly and Secure in production, so none of them is readable by JavaScript. Loopling's account and sign-in cookies are SameSite=Lax; the two Loopling deck cookies are SameSite=Strict. The Loopling session cookie is scoped to the whole Loopling site; each sign-in cookie is scoped to /api/auth/google, the Gift ticket to /api/auth/gift, and the deck cookies to /deck. None of them contains your content, email address, reading activity, or raw invitation code.

Analytics

Loopling does not run any third-party analytics service. We do not use Google Analytics, Mixpanel, Segment, Plausible, or any equivalent.

Advertising

Loopling does not serve advertising and does not set advertising cookies.

2. Stripe-set cookies

When you proceed to Stripe Checkout or the Stripe Customer Portal — both hosted on Stripe's own domain — Stripe may set cookies on its domain (*.stripe.com) for fraud detection, session management, and 3-D Secure handling. These cookies are governed by Stripe's cookie policy. Loopling does not control them and cannot read them.

If you never start a checkout or open the billing portal, no Stripe cookies are set.

3. Local storage and IndexedDB

Loopling uses your browser's local storage and IndexedDB to keep your spaces working offline and to sync changes when you reconnect. These aren't technically cookies but the privacy considerations are similar. The data stored is per-origin (only Loopling can read it) and is described in detail in the privacy policy.

You can clear this data from your browser's site-settings menu. Doing so signs you out of Loopling and removes the local copy of your spaces (the server copy stays intact; signing back in re-syncs it).

Loopling's private deck uses loopling-deck-appearance in local storage to remember light or dark appearance until you clear site data, and loopling-deck-rotate-hint-seen in session storage to avoid repeating a rotation hint during the current browser session. Neither value contains an email address, invitation code, reading activity, or other identity data.

We don't ask for cookie consent through a banner because:

  • All cookies Loopling and the opt-in Loopling deck set are strictly necessary for the selected service or feature to work (authentication, the OAuth flow, or private-deck access). Strictly-necessary cookies are exempt from consent requirements under GDPR and most jurisdictional privacy laws.
  • We don't run any analytics or advertising cookies that would trigger a consent obligation.
  • Cookie banners in the wild often double as dark patterns to push users toward "Accept All." Loopling wouldn't gain anything from showing one — there's nothing to opt into.

If a regulator or your jurisdiction requires a banner anyway, please let us know at hello@loopling.ai and we'll add a region-specific one.

5. Changes to this policy

Every new version is dated at the top, and the version it replaced stays permanently readable at https://loopling.ai/legal/cookies?version=YYYY-MM-DD.

If we start setting a cookie that tracks you, or one that isn't strictly necessary, we email everyone with an active account at least 14 days before it takes effect. A cookie that only appears because you chose to use a new feature, and stays strictly necessary to it, is published with the feature.

Revision history

  • August 23, 2026 — renamed the product from Atelier to Loopling. No cookie name changed: the session and sign-in cookies are still set under their existing atelier_* names, because those names are written by the server and renaming them would sign everyone out for nothing. No cookie was added, removed, or repurposed, and none became non-essential, so this version took effect on publication. The prior version is at /legal/cookies?version=2026-08-11.
  • August 11, 2026 — added the two strictly necessary cookies used by Loopling's optional private investor deck. They hold opaque session and device tokens after successful code entry; they contain no email address, reading activity, or raw invitation code. Also documented the deck's local appearance preference and session-only rotation-hint flag. The prior version is at /legal/cookies?version=2026-08-05.
  • August 5, 2026 — added atelier_gift_admission for Ink Gifts, and corrected the table, which had drifted: it named the PKCE cookie atelier_oauth_pkce (it has always been atelier_oauth_verifier), and it listed four cookies when Loopling was in fact setting nine — the session cookie plus eight sign-in cookies, five of which had never been disclosed. Those corrections describe cookies that already existed and were already strictly necessary — nothing new was set and nothing was taken away. The prior version is at /legal/cookies?version=2026-06-05.

6. Contact

For questions about this policy, email hello@loopling.ai.

Extensium Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, U.S.A.

loopling.ai · grows with you, grows itself

hello@loopling.ai · community · pricing · privacy · terms