Effective September 30, 2026
Privacy Policy
Atelier (“Atelier”, “we”, “us”) is a personal AI assistant available at atelier.ciprari.ai. This policy explains what data Atelier accesses, how it is used, where it is stored, who it is shared with, and how you can delete it.
1. Who can use Atelier
Atelier is a private application. Access is protected by an owner-set passcode; there is no public sign-up. It is not directed at children under 13, and we do not knowingly collect data from them.
2. Data we access and collect
Information you provide
- Prompts and conversations — the questions, instructions, text and images you enter.
- Profile and memory — optional information you add in the “You” panel (name, a description of yourself, writing samples, a style guide, and remembered facts), plus facts Atelier notes from your conversations, which you can view and delete.
- Imported history — if you choose to import a ChatGPT/Claude data export or Claude Code session files, Atelier reads the messages you wrote in them to build your profile. The files are read in your browser and are not uploaded or stored.
Connected accounts (only if you connect them)
- Gmail (via Google OAuth) — see Google user data below.
- Slack, GitHub, Stripe, Cloudflare, Railway — when connected, Atelier reads the data needed to answer a request (for example, messages matching a search, open pull requests, recent payments, DNS records or deployments).
- Browser extension — if you install the optional Atelier Browser extension, Atelier can list your open tabs and read the page you ask about. Clicks and typing happen only after you approve each one, and the extension never enters passwords or payment details.
Technical data
- Our host, Cloudflare, processes standard request data (such as IP address and request logs) to operate and secure the service. We use IP addresses to block repeated wrong-passcode attempts. We do not use analytics, advertising or tracking cookies.
3. Google user data (Gmail)
If you connect Gmail, Atelier requests these permissions:
| Scope | What Atelier does with it |
|---|---|
gmail.readonly | Searches and reads your email when you ask (for example, “what’s unread from today?” or “summarize the thread with Alex”). |
gmail.compose | Saves draft emails you ask Atelier to write. |
gmail.send | Sends an email only after you review and approve it on an approval card in the app. Atelier never sends email on its own. |
How Google user data is used
- Only to provide the user-facing features you request: searching, reading, summarizing, drafting and — with your approval — sending email.
- Email content needed for a request is sent to the AI model provider selected for that request (see Sharing) solely to generate the response you asked for.
- It is not used for advertising, not sold, not used to develop, improve or train generalized AI or machine-learning models, and not read by humans unless you explicitly ask for help with a specific message, it is necessary for security or legal compliance, or the data is aggregated and anonymized for internal operations.
How Google user data is stored
- Atelier stores only the OAuth refresh token (and a short-lived access token) in encrypted Cloudflare storage so it can call Gmail on your behalf. Email content is not stored on our servers.
- Answers that quote or summarize your email are saved in your conversation history in your own browser, where you can delete them.
4. How we use data
- To answer your requests and perform the actions you ask for (chat, code, images, video, ideas, apps, and account tasks).
- To personalize answers using your profile, memory and writing style.
- To keep the service secure and working (for example, rate-limiting passcode attempts and diagnosing errors).
We do not use your data for advertising, profiling for third parties, or selling.
5. Sharing and third-party processors
Atelier does not sell or rent personal data. To provide the service, data needed for a specific request is shared with these processors:
| Processor | Purpose |
|---|---|
| Cloudflare | Hosting, network security, and storage of your profile, memory and connection tokens. |
| Anthropic (Claude), OpenAI, Google (Gemini, Veo) and NVIDIA | AI models that generate responses, images and video. Only the content needed for the request is sent, via their business APIs, which do not use API data to train their models by default. |
| Gmail, Slack, GitHub, Stripe, Cloudflare, Railway | Only when you connect them, to read or act on your own account at your request. |
We may disclose information if required by law or to protect the rights, safety or security of users or the service.
6. Where data is stored and for how long
- In your browser: conversations, generated media and settings — kept until you delete them (Settings → Erase everything, or delete individual threads).
- Cloudflare (server): your profile/memory (so it syncs between your devices) and connection tokens — kept until you delete or disconnect them.
- AI providers: may retain request data briefly under their own API policies for abuse monitoring; they do not use it for advertising.
- Operational logs: short-lived request logs kept by Cloudflare for reliability and security.
7. Security
Traffic is encrypted with HTTPS. API keys and account tokens are stored as encrypted server-side secrets and never sent to your browser. Access requires the owner’s passcode, with automatic lockout after repeated wrong attempts. Actions that send, post, pay or change something require your explicit approval.
8. Your choices and deletion
- Delete conversations and media: delete threads in the app, or use Settings → Erase everything.
- Delete profile and memory: edit or remove entries in the “You” panel.
- Disconnect Gmail: Settings → Connections → Disconnect (this deletes the stored token), and/or revoke access at myaccount.google.com/permissions.
- Disconnect other services: revoke the token in that service’s settings; Atelier then loses access immediately.
- Request deletion of everything: email cole@ciprari.ai and we will delete server-side data within 30 days.
9. Changes
We may update this policy. The effective date at the top shows the latest version. Material changes to how Google user data is used will be reflected here before they take effect.
10. Contact
Questions or requests: cole@ciprari.ai