Effective date: August 29, 2026
Loopling — operated by Extensium Inc. — uses a small number of cookies. The private investor deck is retired, so no new deck cookies are set. None of the current cookies are for advertising or cross-site tracking. The full list is below. Email Magic Link cookies are set only where that entry is available and someone chooses to use it.
A note on names. This product was called Atelier until August 23, 2026, and is now called Loopling, at https://loopling.ai. Only the name changed: the operating company, your account, your content, your plan, and every right and obligation in this document are the same. Extensium Inc. still trades as Atelier, so that is the merchant name you will see on a card statement or in the Alipay app. Links to the retired address atelier.space redirect here.
These cookies are required for the app to work. You can't turn them off without making Loopling non-functional. Browsers consent to "strictly necessary" cookies implicitly under most regulations (GDPR, CCPA), so we don't ask you to opt in to these — but the table is here so you know what they are.
| Cookie | Purpose | Duration |
|---|---|---|
atelier_session | Authenticated session JWT. Without it, you're signed out. | 30 days, sliding |
atelier_oauth_state | One-time CSRF token for the Google sign-in round trip. | 10 minutes |
atelier_oauth_verifier | One-time PKCE verifier for the same round trip. | 10 minutes |
atelier_oauth_nonce | One-time OIDC nonce for the same round trip. | 10 minutes |
atelier_oauth_invitecode | A legacy invitation code carried from an older link, held only across the Google redirect so an already-issued benefit can still be redeemed. | 10 minutes |
atelier_oauth_invitecode_staged | Marks that the legacy code above was staged for this exact Google sign-in attempt, so an abandoned value cannot leak into a later attempt. | 10 minutes |
atelier_oauth_returnto | Where to send you after sign-in, so a link you opened before signing in still resolves. | 10 minutes |
atelier_oauth_src | Which entry point started sign-in, so the right welcome applies. | 10 minutes |
atelier_oauth_entry_intent | Whether you asked Muse to open from the entry door (the closed wish value), so that exact intent resumes on return. | 10 minutes |
atelier_oauth_agent_resume | Which agent authorization to resume after sign-in, if you started one. | 10 minutes |
atelier_email_challenge | Holds the one-time proof opened from a requested Magic Link after the fragment has been removed from the browser address, so you can confirm the action. | 15 minutes |
atelier_gift_admission | Set only if you open an Ink Gift link without an account: a short-lived ticket holding your verified destination email, proof method, and which Gift you were looking at, so you can confirm the account and claim it. Cleared the moment you confirm. | 10 minutes |
atelier_share_clone_intent | Preserves one explicit Clone press through sign-in and binds it to the resulting account session; it cannot authorize another source or another press. | 15 minutes |
_atelier_agent_session | Signed protocol-session state used only while connecting an external Agent through Loopling's OAuth provider. | Up to 14 days |
_atelier_agent_interaction | Signed state for one external Agent authorization prompt. | Up to 1 hour |
_atelier_agent_resume | Signed state used to resume that same external Agent authorization prompt after a decision. | Up to 1 hour |
Every cookie above is HttpOnly and Secure in production, so none of them is readable by JavaScript. Loopling's account and sign-in cookies are SameSite=Lax. The retired deck cookies, if still present in an existing browser, were SameSite=Strict and scoped to /deck; they are no longer issued or accepted. The Loopling session cookie is scoped to the whole Loopling site; Google sign-in cookies are scoped to /api/auth/google, the email challenge to /api/auth/email, the Gift ticket to /api/auth/gift, the Clone intent to /api, and Agent OAuth cookies to /oauth. Authentication cookies can carry an account email or opaque user identifier inside a signed token; the Gift ticket carries the verified destination email needed for its confirmation screen. The legacy compatibility cookie named above temporarily contains the previously issued invitation code itself. No cookie contains your space content or reading activity.
Loopling does not run any third-party analytics service. We do not use Google Analytics, Mixpanel, Segment, Plausible, or any equivalent.
Loopling does not serve advertising and does not set advertising cookies.
When you proceed to Stripe Checkout or the Stripe Customer Portal — both hosted on Stripe's own domain — Stripe may set cookies on its domain (*.stripe.com) for fraud detection, session management, and 3-D Secure handling. These cookies are governed by Stripe's cookie policy. Loopling does not control them and cannot read them.
If you never start a checkout or open the billing portal, no Stripe cookies are set.
Loopling uses your browser's local storage and IndexedDB to keep your spaces working offline and to sync changes when you reconnect. These aren't technically cookies but the privacy considerations are similar. The data stored is per-origin (only Loopling can read it) and is described in detail in the privacy policy.
You can clear this data from your browser's site-settings menu. Doing so signs you out of Loopling and removes the local copy of your spaces (the server copy stays intact; signing back in re-syncs it).
The retired private investor deck no longer sets local-storage or session-storage state on new visits.
We don't ask for cookie consent through a banner because:
If a regulator or your jurisdiction requires a banner anyway, please let us know at hello@loopling.ai and we'll add a region-specific one.
Every new version is dated at the top, and the version it replaced stays permanently readable at https://loopling.ai/legal/cookies?version=YYYY-MM-DD.
If we start setting a cookie that tracks you, or one that isn't strictly necessary, we email everyone with an active account at least 14 days before it takes effect. A cookie that only appears because you chose to use a new feature, and stays strictly necessary to it, is published with the feature.
atelier_* names, because those names are written by the server and renaming them would sign everyone out for nothing. No cookie was added, removed, or repurposed, and none became non-essential, so this version took effect on publication. The prior version is at /legal/cookies?version=2026-08-11.atelier_gift_admission for Ink Gifts, and corrected the table, which had drifted: it named the PKCE cookie atelier_oauth_pkce (it has always been atelier_oauth_verifier), and it listed four cookies when Loopling was in fact setting nine — the session cookie plus eight sign-in cookies, five of which had never been disclosed. Those corrections describe cookies that already existed and were already strictly necessary — nothing new was set and nothing was taken away. The prior version is at /legal/cookies?version=2026-06-05.For questions about this policy, email hello@loopling.ai.
Extensium Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, U.S.A.
loopling.ai · grows with you, grows itself
hello@loopling.ai · for agents · community · pricing · API · privacy · terms