loopling.ai

Cookie Policy · loopling

Effective date: August 29, 2026

Loopling — operated by Extensium Inc. — uses a small number of cookies. The private investor deck is retired, so no new deck cookies are set. None of the current cookies are for advertising or cross-site tracking. The full list is below. Email Magic Link cookies are set only where that entry is available and someone chooses to use it.

A note on names. This product was called Atelier until August 23, 2026, and is now called Loopling, at https://loopling.ai. Only the name changed: the operating company, your account, your content, your plan, and every right and obligation in this document are the same. Extensium Inc. still trades as Atelier, so that is the merchant name you will see on a card statement or in the Alipay app. Links to the retired address atelier.space redirect here.

1. What loopling sets

Functional (always on)

These cookies are required for the app to work. You can't turn them off without making Loopling non-functional. Browsers consent to "strictly necessary" cookies implicitly under most regulations (GDPR, CCPA), so we don't ask you to opt in to these — but the table is here so you know what they are.

CookiePurposeDuration
atelier_sessionAuthenticated session JWT. Without it, you're signed out.30 days, sliding
atelier_oauth_stateOne-time CSRF token for the Google sign-in round trip.10 minutes
atelier_oauth_verifierOne-time PKCE verifier for the same round trip.10 minutes
atelier_oauth_nonceOne-time OIDC nonce for the same round trip.10 minutes
atelier_oauth_invitecodeA legacy invitation code carried from an older link, held only across the Google redirect so an already-issued benefit can still be redeemed.10 minutes
atelier_oauth_invitecode_stagedMarks that the legacy code above was staged for this exact Google sign-in attempt, so an abandoned value cannot leak into a later attempt.10 minutes
atelier_oauth_returntoWhere to send you after sign-in, so a link you opened before signing in still resolves.10 minutes
atelier_oauth_srcWhich entry point started sign-in, so the right welcome applies.10 minutes
atelier_oauth_entry_intentWhether you asked Muse to open from the entry door (the closed wish value), so that exact intent resumes on return.10 minutes
atelier_oauth_agent_resumeWhich agent authorization to resume after sign-in, if you started one.10 minutes
atelier_email_challengeHolds the one-time proof opened from a requested Magic Link after the fragment has been removed from the browser address, so you can confirm the action.15 minutes
atelier_gift_admissionSet only if you open an Ink Gift link without an account: a short-lived ticket holding your verified destination email, proof method, and which Gift you were looking at, so you can confirm the account and claim it. Cleared the moment you confirm.10 minutes
atelier_share_clone_intentPreserves one explicit Clone press through sign-in and binds it to the resulting account session; it cannot authorize another source or another press.15 minutes
_atelier_agent_sessionSigned protocol-session state used only while connecting an external Agent through Loopling's OAuth provider.Up to 14 days
_atelier_agent_interactionSigned state for one external Agent authorization prompt.Up to 1 hour
_atelier_agent_resumeSigned state used to resume that same external Agent authorization prompt after a decision.Up to 1 hour

Every cookie above is HttpOnly and Secure in production, so none of them is readable by JavaScript. Loopling's account and sign-in cookies are SameSite=Lax. The retired deck cookies, if still present in an existing browser, were SameSite=Strict and scoped to /deck; they are no longer issued or accepted. The Loopling session cookie is scoped to the whole Loopling site; Google sign-in cookies are scoped to /api/auth/google, the email challenge to /api/auth/email, the Gift ticket to /api/auth/gift, the Clone intent to /api, and Agent OAuth cookies to /oauth. Authentication cookies can carry an account email or opaque user identifier inside a signed token; the Gift ticket carries the verified destination email needed for its confirmation screen. The legacy compatibility cookie named above temporarily contains the previously issued invitation code itself. No cookie contains your space content or reading activity.

Analytics

Loopling does not run any third-party analytics service. We do not use Google Analytics, Mixpanel, Segment, Plausible, or any equivalent.

Advertising

Loopling does not serve advertising and does not set advertising cookies.

2. Stripe-set cookies

When you proceed to Stripe Checkout or the Stripe Customer Portal — both hosted on Stripe's own domain — Stripe may set cookies on its domain (*.stripe.com) for fraud detection, session management, and 3-D Secure handling. These cookies are governed by Stripe's cookie policy. Loopling does not control them and cannot read them.

If you never start a checkout or open the billing portal, no Stripe cookies are set.

3. Local storage and IndexedDB

Loopling uses your browser's local storage and IndexedDB to keep your spaces working offline and to sync changes when you reconnect. These aren't technically cookies but the privacy considerations are similar. The data stored is per-origin (only Loopling can read it) and is described in detail in the privacy policy.

You can clear this data from your browser's site-settings menu. Doing so signs you out of Loopling and removes the local copy of your spaces (the server copy stays intact; signing back in re-syncs it).

The retired private investor deck no longer sets local-storage or session-storage state on new visits.

We don't ask for cookie consent through a banner because:

  • All current Loopling cookies are strictly necessary for the service to work (authentication, the OAuth flow, an Ink Gift handoff, a Clone resume, or an external Agent connection). The retired deck cookies were strictly necessary for private-deck access but are no longer issued. Strictly-necessary cookies are exempt from consent requirements under GDPR and most jurisdictional privacy laws.
  • We don't run any analytics or advertising cookies that would trigger a consent obligation.
  • Cookie banners in the wild often double as dark patterns to push users toward "Accept All." Loopling wouldn't gain anything from showing one — there's nothing to opt into.

If a regulator or your jurisdiction requires a banner anyway, please let us know at hello@loopling.ai and we'll add a region-specific one.

5. Changes to this policy

Every new version is dated at the top, and the version it replaced stays permanently readable at https://loopling.ai/legal/cookies?version=YYYY-MM-DD.

If we start setting a cookie that tracks you, or one that isn't strictly necessary, we email everyone with an active account at least 14 days before it takes effect. A cookie that only appears because you chose to use a new feature, and stays strictly necessary to it, is published with the feature.

Revision history

  • August 29, 2026 — published a complete Chinese translation alongside the English text and clarified that the email Magic Link cookies are set only where that entry is available and used. No cookie was added, removed, or repurposed. The prior version is at /legal/cookies?version=2026-08-28.
  • August 28, 2026 — added the strictly necessary email Magic Link and Clone-resume cookies, made the Ink Gift ticket provider-neutral, and listed the three existing cookies used by the external Agent OAuth provider. No analytics, advertising, or cross-site tracking cookie was added. The prior version is at /legal/cookies?version=2026-08-26.
  • August 23, 2026 — renamed the product from Atelier to Loopling. No cookie name changed: the session and sign-in cookies are still set under their existing atelier_* names, because those names are written by the server and renaming them would sign everyone out for nothing. No cookie was added, removed, or repurposed, and none became non-essential, so this version took effect on publication. The prior version is at /legal/cookies?version=2026-08-11.
  • August 26, 2026 — retired the private investor deck. The two deck cookies and deck-local-storage hints were removed from the live policy because no new deck sessions are issued now. If an old cookie remains in a browser it is inert; historical deck records keep their existing retention in the Privacy Policy. The prior version is at /legal/cookies?version=2026-08-23.
  • August 11, 2026 — added the two strictly necessary cookies used by Loopling's optional private investor deck. They hold opaque session and device tokens after successful code entry; they contain no email address, reading activity, or raw invitation code. Also documented the deck's local appearance preference and session-only rotation-hint flag. The prior version is at /legal/cookies?version=2026-08-05.
  • August 5, 2026 — added atelier_gift_admission for Ink Gifts, and corrected the table, which had drifted: it named the PKCE cookie atelier_oauth_pkce (it has always been atelier_oauth_verifier), and it listed four cookies when Loopling was in fact setting nine — the session cookie plus eight sign-in cookies, five of which had never been disclosed. Those corrections describe cookies that already existed and were already strictly necessary — nothing new was set and nothing was taken away. The prior version is at /legal/cookies?version=2026-06-05.

6. Contact

For questions about this policy, email hello@loopling.ai.

Extensium Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, U.S.A.

loopling.ai · grows with you, grows itself

hello@loopling.ai · for agents · community · pricing · API · privacy · terms