Effective date: August 5, 2026
Atelier — operated by Extensium Inc. — uses a small number of cookies. None of them are for advertising or cross-site tracking. The full list is below.
These cookies are required for the app to work. You can't turn them off without making Atelier non-functional. Browsers consent to "strictly necessary" cookies implicitly under most regulations (GDPR, CCPA), so we don't ask you to opt in to these — but the table is here so you know what they are.
| Cookie | Purpose | Duration |
|---|---|---|
atelier_session | Authenticated session JWT. Without it, you're signed out. | 30 days, sliding |
atelier_oauth_state | One-time CSRF token for the Google sign-in round trip. | 10 minutes |
atelier_oauth_verifier | One-time PKCE verifier for the same round trip. | 10 minutes |
atelier_oauth_nonce | One-time OIDC nonce for the same round trip. | 10 minutes |
atelier_oauth_invitecode | The invite code you entered, carried across the Google redirect so it can be redeemed when you come back. | 10 minutes |
atelier_oauth_returnto | Where to send you after sign-in, so a link you opened before signing in still resolves. | 10 minutes |
atelier_oauth_src | Which entry point started sign-in, so the right welcome applies. | 10 minutes |
atelier_oauth_entry_intent | Whether you were signing in or signing up, so the correct door logic runs on return. | 10 minutes |
atelier_oauth_agent_resume | Which agent authorization to resume after sign-in, if you started one. | 10 minutes |
atelier_gift_admission | Set only if you open an Ink Gift link without an account: a short-lived ticket holding your Google-verified email and which Gift you were looking at, so you can confirm the destination account and claim it. Cleared the moment you confirm. | 10 minutes |
Every cookie above is HttpOnly, Secure (in production), and SameSite=Lax, so none of them is readable by JavaScript or sent on a cross-site request. The session cookie is scoped to the whole site; each sign-in cookie is scoped to /api/auth/google and the Gift ticket to /api/auth/gift, so they aren't sent with ordinary page or API requests at all. None of them contains anything about your content or your activity.
Atelier does not run any third-party analytics service. We do not use Google Analytics, Mixpanel, Segment, Plausible, or any equivalent.
Atelier does not serve advertising and does not set advertising cookies.
When you proceed to Stripe Checkout or the Stripe Customer Portal — both hosted on Stripe's own domain — Stripe may set cookies on its domain (*.stripe.com) for fraud detection, session management, and 3-D Secure handling. These cookies are governed by Stripe's cookie policy. Atelier does not control them and cannot read them.
If you never start a checkout or open the billing portal, no Stripe cookies are set.
Atelier uses your browser's local storage and IndexedDB to keep your spaces working offline and to sync changes when you reconnect. These aren't technically cookies but the privacy considerations are similar. The data stored is per-origin (only Atelier can read it) and is described in detail in the privacy policy.
You can clear this data from your browser's site-settings menu. Doing so signs you out of Atelier and removes the local copy of your spaces (the server copy stays intact; signing back in re-syncs it).
We don't ask for cookie consent through a banner because:
If a regulator or your jurisdiction requires a banner anyway, please let us know at hello@atelier.space and we'll add a region-specific one.
Every new version is dated at the top, and the version it replaced stays permanently readable at https://atelier.space/legal/cookies?version=YYYY-MM-DD.
Following the same split as Terms §12: if we start setting a cookie that tracks you, or one that isn't strictly necessary, we email everyone with an active account at least 14 days before it takes effect. A cookie that only appears because you chose to use a new feature, and stays strictly necessary to it, is published with the feature and announced in the app.
atelier_gift_admission for Ink Gifts, and corrected the table, which had drifted: it named the PKCE cookie atelier_oauth_pkce (it has always been atelier_oauth_verifier), and it listed four cookies when Atelier was in fact setting nine — the session cookie plus eight sign-in cookies, five of which had never been disclosed. Those corrections describe cookies that already existed and were already strictly necessary — nothing new was set and nothing was taken away. The prior version is at /legal/cookies?version=2026-06-05.For questions about this policy, email hello@atelier.space.
Extensium Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, U.S.A.
loopling.ai · grows with you, grows itself
hello@loopling.ai · community · pricing · privacy · terms