Effective date: August 5, 2026
This document explains what data Atelier collects, where we store it, and who sees it. We don't sell data. We don't run third-party analytics. We don't run user-tracking pixels. The processing here is the minimum needed to run a synced creative tool.
Who we are. Atelier is operated by Extensium Inc., a Delaware corporation. Extensium is the controller of the personal data described below. You can reach us at hello@atelier.space, or by post at Extensium Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, U.S.A.
sub claim — if you sign in with Google, the stable opaque user id Google provides. We use it to confirm "same Google account = same user" across sessions.createdAt, lastActiveAt — admin diagnostics: who's been using Atelier and when.note field) — an admin may write a private note about who you are (e.g. "met through Vimeo", "studio in Tokyo") to remember context across long gaps. Visible only to admins.gift_cards) — if you buy or receive an Ink Gift, one row per Gift holding: which account bought it, which account claimed it (empty until someone does), the face value, the lifecycle status, the timestamps for funding / cancellation / claiming, the Stripe price, checkout-session, payment-intent, refund and event ids, the refund accounting, and a pointer to the Ink ledger entry the claim created. We need this to fund exactly one Gift per payment, to enforce "claimed once", and to reconcile refunds and disputes against Stripe.Two things this deliberately does not do. It stores no message, no recipient email address you typed, and no delivery record — Atelier never sends the Gift for you, so we never learn who you meant it for; you carry the link yourself. And the two accounts stay hidden from each other: the buyer sees only whether their Gift has been claimed, never the identity or email of the person who claimed it, and the recipient is not shown who bought it unless the buyer told them.
We do not see or store your full payment-card number — card details go directly to Stripe, our payment processor.
If you are in the European Economic Area or the United Kingdom, we process your personal data on these legal bases:
When you're signed in, Atelier mirrors a working copy of your spaces, conversations, and files into your browser's IndexedDB so they load fast and work offline. This data is yours alone — it lives in the browser's per-origin sandbox; we can't see it remotely.
The authoritative copy of your data lives on:
All three are hosted in the United States.
We use the following third-party services. Each has a defined role and can only see the data needed for that role.
| Sub-processor | What they see | Purpose |
|---|---|---|
| Anthropic | Your message text + canvas context for chat turns | Muse model inference |
| OpenAI / LiteLLM | Image generation prompts + reference images | Image generation |
| ByteDance (Volcano Engine, Seedance, Seed3D, Ark) | Video / 3D generation prompts + frames | Video / 3D generation |
| Kling / HappyHorse | Video generation prompts | Video generation |
| Mureka, MiniMax, ElevenLabs | Audio generation prompts | Music / TTS / SFX |
| Tavily, Serper / Scrapingdog, Jina | Search queries and URLs Muse generates from your requests | Web search & page retrieval |
| Cloudflare R2 | Encrypted file blobs | Object storage |
| Cloudflare (CDN edge, Workers) | Request metadata; deployed-app code you publish | Network delivery, app hosting |
| Supabase | Postgres rows | Database hosting |
| Upstash | Redis keys (no message content) | Rate limiting |
| Stripe | Email address + billing details | Payments |
| Resend | Email address + transactional message body | Email delivery |
| Sentry | Error stack traces (no message bodies) | Error monitoring |
| Google (OAuth) | Email + sub claim | Sign-in |
If we add or change a sub-processor in a way that materially affects data flow, we'll update this table and notify users 14 days before the change takes effect.
The AI providers above each have their own policy on whether they train on API inputs. We direct your prompts to API endpoints whose terms prohibit training on input, and we track these policies and switch providers if any of them change the default to "trains on inputs without explicit opt-out." If you want a complete current list with citations, email hello@atelier.space.
| Data | Retention |
|---|---|
| Account record | Until you close your account |
| Spaces, conversations, files | Until you delete them or close your account |
Ink ledger (ink_transactions) | Until you close your account |
Activity log (activity_log) | 30 days, then trimmed by cron |
| Quota usage aggregates | 18 months |
| Stripe billing records | 7 years (regulatory requirement) |
Ink Gift records (gift_cards) | 7 years, as a payment record; de-identified when either account closes |
Email log (email_log) | 60 days |
| Server access logs | 30 days |
When you close your account: spaces / conversations / file blobs / ink_transactions are deleted within 30 days. Stripe billing records remain for the regulatory retention period. We may retain a hashed record of your email address for a brief period to honour suspensions (stops re-creating an account that was suspended for abuse).
An Ink Gift record is a payment record, so it survives on the same 7-year clock as the Stripe charge behind it — but de-identified: closing your account drops the link between the row and you, on both sides, leaving the amount, dates, status and Stripe ids with no account attached. If you close your account while a Gift you bought is still unclaimed, tell us first so we can refund it instead of leaving it stranded.
Depending on where you live, you have some or all of these rights. We honour the core rights (access, correction, deletion, portability) for all users, not just those in a specific jurisdiction.
California residents (CCPA/CPRA). In the past 12 months we have not sold or "shared" (as those terms are defined under California law) your personal information, and we do not do so. We do not process sensitive personal information to infer characteristics. You have the rights to know, delete, correct, and opt out; we don't discriminate against you for exercising them. Categories collected and their purposes are described in Sections 1–3.
To exercise any of these rights, email hello@atelier.space. We respond within 30 days; complex requests may take longer, in which case we tell you the timeline up front. We may need to verify your identity (usually by confirming control of the account email) before acting.
Your data is stored in the United States. If you're in the EU, EEA, or UK, your data is transferred to the U.S. and to our sub-processors under an appropriate transfer mechanism — typically the European Commission's Standard Contractual Clauses (and the UK Addendum), or a provider's Data Privacy Framework certification where available. The sub-processors listed above each commit to compatible safeguards. Email hello@atelier.space for a copy of the relevant transfer terms.
We are not perfect. If you find a security issue, please email hello@atelier.space — we'll respond quickly and keep you informed.
Atelier is not directed to children. You must be at least 16 to use it (see the Terms). We don't knowingly collect personal data from anyone under 16; if we learn we have, we delete it and close the account.
Every new version is dated at the top, and the version it replaced stays permanently readable at https://atelier.space/legal/privacy?version=YYYY-MM-DD.
How much warning you get depends on what changed, on the same split as Terms §12:
gift_cards row exists only if you choose to buy or claim a Gift, so this version took effect on publication. The prior version is at /legal/privacy?version=2026-06-05.loopling.ai · grows with you, grows itself
hello@loopling.ai · community · pricing · privacy · terms