Skip to content
Atelier. est. MMXXVI
  • About
  • Studio
  • Manifesto
  • Journal
  • Pricing
Open Studio
Atelier. est. MMXXVI
  • About
  • Studio
  • Manifesto
  • Journal
  • Pricing
Open Studio
  • The letter
  • Help & support

Privacy Policy

Last updated: 17 September 2026

In short

This is the short version. The full policy follows it, and the full policy is the one that counts.

  • Who we are. Atelier is run by Talastron Ltd, which is responsible for your personal data. Write to [email protected] about anything on this page.
  • What we collect. Your email address and name, the wardrobe you build (pieces, photos, looks, notes, and your measurements if you add them), your membership details from our payment provider or Google Play, and what you ask the styling features.
  • Why. To give you your wardrobe, your membership and the features you use. We don’t sell your data, show advertising, or use analytics or tracking.
  • The AI features. They send what they need, through our own server in London, to Google’s Gemini models, and only once you have agreed. You can withdraw at any time in Profile → Your data.
  • Who else handles it. A small number of providers who run the Service for us, chiefly Google. Some are in the United States, under safeguards UK law recognises.
  • How long. While you’re a member. When a membership ends, your wardrobe stays readable for 30 days and is then deleted. You can delete your account at any time, and it is erased straight away.
  • Your choices. Export your wardrobe, correct it, delete it, withdraw your agreement, and object to what we do, including any marketing. You can complain to us, or to the Information Commissioner’s Office.
  • Cookies. There’s no cookie banner, because nothing is stored for advertising, analytics or tracking. What sits on your device is there to make Atelier work and to remember your choices — with one exception we’d rather you heard from us: the app is protected by Google’s reCAPTCHA, which sets a cookie of Google’s own and reads what your browser and device look like. It runs before you sign in, so it reaches a visitor with no account too, on the demo and on a shared link. We explain it under “Cookies and similar technologies”.

Who we are

Atelier is a product of Talastron Ltd, a private limited company registered in England & Wales.

  • Company name: Talastron Ltd
  • Company number: 15464691
  • VAT number: GB 463 5874 58
  • Registered office: The Long Barn, Cobham Park Road, Cobham, Surrey, KT11 3NE, United Kingdom
  • Previously known as: Orion Data Analytics Ltd

Talastron Ltd is the data controller responsible for your personal data when you use our website at myatelier.style, the application at edit.myatelier.style, the Atelier app for Android on Google Play, and our emails (together, the “Service”; “we”, “us”, “our”). For anything about your data, write to [email protected].

The Android app opens the application at edit.myatelier.style inside your phone’s browser (usually Chrome), so everything this policy says about the application applies to it too. Where the Android app is different, this policy says so.

We are a small company and are not required to appoint a data protection officer, so we haven’t. Questions and requests about your data are dealt with directly by the people who run Atelier, at the same address.

We are registered with the UK Information Commissioner’s Office (ICO) as a data controller under registration reference ZB804967.

What we collect, why, and on what basis

Each row below is one thing we use your data for: what we use, and the lawful basis UK data protection law lets us rely on. The bases are:

  • Contract: we need the data to give you what you signed up for.
  • Consent: you have agreed, and you can withdraw at any time. Withdrawing stops what happens from then on; it doesn’t undo what was done before.
  • Legitimate interests: we have a genuine reason, named in the row, which doesn’t override your interests. You can object (see “Your right to object”).
  • Legal obligation: the law requires it.
Purpose What we use Lawful basis
Your account and signing in Your email address and name; the account identifier, sign-in method and sign-in times kept by Firebase Authentication; if you sign in with Google, what your Google account shares with apps: name, email address and profile picture Contract
Your wardrobe The pieces, photos, wear log, looks, lookbooks, inspirations, wishlist, plans and notes you add; your style profile; your measurements, if you add them Contract
The styling features (AI) What each feature needs, as listed under “How the styling features use your data” Consent. Withdraw in Profile → Your data → The Concierge and your data
Find this online The photo you choose, and the brand, name and category you’ve noted Consent, the same agreement as the styling features
Fair use of the AI features How many AI requests you make, from which feature, and their estimated cost; the times of your recent requests Legitimate interests: keeping the AI features affordable, and stopping misuse
Your membership and payments From Lemon Squeezy: your email address, name, its customer, order and subscription references, your plan, and the state and dates of your membership. From Google Play, if you join in the Android app: a one-way fingerprint of your purchase, its order reference, your plan, and the state and dates of your membership (see “Membership through Google Play”) Contract; legal obligation for our accounting records
Emails about your account Your email address, for sign-in links, the notice before a lapsed membership’s data is deleted, and important service notices Contract
Invitations The email address, and any name, of someone we invite Legitimate interests: letting people we know try Atelier at our invitation
The Atelier letter Your email address and the page you signed up from Consent. Unsubscribe with the link in any letter, or email us
Remembering that you unsubscribed Your email address, marked as unsubscribed, with Resend; and, on our own records, a one-way fingerprint of it with the date you left Legal obligation: to respect your objection to marketing
Shared links The look, lookbook or piece you share, copies of its photos, the name shown on it and the date Contract: you ask us to publish it
Reports about the AI’s words What the AI wrote, your reason and note, where it appeared, the app version, the time and your account identifier Legitimate interests: looking into what the AI said, and making the AI features safer and better
Answering you What you write to us, and your email address Legitimate interests: answering you; legal obligation when you exercise a data protection right
Security and preventing abuse Information from your browser and device for App Check and reCAPTCHA; your account identifier and error details in our server logs; a daily, keyed hash of your IP address for the demo’s daily allowances Legitimate interests: keeping Atelier and your data secure, and stopping bots and misuse
Weather Your approximate location, or a place name you type Contract: to show the forecast you asked for. Your device asks your permission first
Your calendar The title, time and location of your upcoming events, and the key that lets us read them Consent. Disconnect in Profile → Account → Calendar
The demo The sample wardrobe and what you type or add; the demo’s daily allowance Consent for the AI features; legitimate interests for the allowance: stopping misuse
Records the law requires Records of payments and tax; responses to lawful requests from authorities Legal obligation
Fixing faults Error messages and basic performance data Legitimate interests: keeping Atelier working
Our Instagram and Pinterest accounts What the platform shows us when you follow, save, comment on, tag, mention or message us there: your profile name and picture, and what you wrote; statistics about our accounts that don’t identify anyone Legitimate interests: telling people about Atelier, and answering them

What you have to give us

To have an account you need to give us an email address; without one we can’t sign you in. Everything else you add is up to you. If you don’t agree to the styling features, they don’t run, and the rest of Atelier works as before. To pay, you give your details to Lemon Squeezy or, in the Android app, to Google Play, not to us.

Where we get data from, other than you

  • Lemon Squeezy, our payment provider, tells us about your membership. If you pay before you have an account, it gives us your email address and name, and we create your account from them.
  • Google Play, if you join in the Android app, tells us about your subscription: its plan, its state and its dates.
  • Google, if you sign in with Google: your name, email address and profile picture. If you connect your Google Calendar, your upcoming events.
  • Us, if we invite you: your email address, and a name if we noted one.
  • Instagram and Pinterest, if you follow, message, comment on or mention our accounts there: your profile name and picture, and what you wrote (see “Atelier on Instagram and Pinterest”).

The detail

Your account

  • Email address — required to create your account, sign you in, and contact you about your membership.
  • Name — the name that comes with your sign-in, for example from your Google account, or the name you gave when you paid. It personalises the app, and is shown on any outfit, lookbook or piece you share by public link (see “Shared links”). The name on your shared links can be changed or removed in Profile. To change the name on your account itself, email us.
  • Authentication metadata — sign-in timestamps, sign-in method (Google, magic link, or an email and password), and an account identifier issued by Firebase Authentication. Sign-in with an email and password is only for the test accounts we create for the app-store reviewers who check the app before it is published. The Android app shows a link to it, but members can’t create a password account, and a reviewer gets in only because we have invited them.

Your wardrobe

The personal data you choose to add as you use the Service:

  • Garment data — items you add to your wardrobe (brand, category, colour, materials, size, cost, notes, photos).
  • Wear logs — when you record having worn an item.
  • Outfits, lookbooks, plans and saved inspirations — collections you create.
  • Style profile — the preferences you choose in Profile → Style & fit, such as your undertone, body shape, how formally you like to dress, your style principles and goals, and what you typically spend on a piece.
  • Measurements — measurements you optionally enter in Profile → Style & fit: height, weight, chest, waist, hips and shoe size. From these the app may show you a body-shape fit profile, worked out on your device. They are used only by “Will it fit?” and “Is it worth it?” on a wishlist piece — never by the Concierge chat (see “How the styling features use your data”). Your measurements are a sizing reference, and we treat them as nothing more: we use them to answer “Will it fit?” and “Is it worth it?”, we do not use them to identify you or to infer anything about your health, and we do not process them as biometric data or as data concerning health under Article 9 of the UK GDPR.

Some photos you upload — inspiration images, or a photo of an outfit as worn — may include images of you or other people. Please only upload photos you have the right to use. We do not run facial recognition on your photos.

You own this content. We don’t sell it, share it with anyone for their own use, or use it to train AI models.

How the styling features use your data

Atelier’s styling features are powered by Google’s Gemini models. When you use a feature such as item identification, the Daily Brief, the Styling Studio, the Concierge, the Style Manifesto, gap analysis, “Will it fit?”, “Is it worth it?” or the travel planner, the app sends the content that feature needs to Atelier’s own server, which passes it to Gemini on Google Cloud (Vertex AI), on Google’s paid service. Our server and the Gemini service it calls are both in Google’s London region (europe-west2). “Find this online” goes a little further; see below.

The app asks you before anything is sent, and asks again if what is sent changes. Nothing is sent until you agree. You can withdraw at any time in Profile → Your data → The Concierge and your data, and nothing more is sent from then.

Depending on the feature, what is sent can include:

  • photos you ask it to read (for example, a garment, a clothing label, a receipt, or an inspiration image);
  • details of your wardrobe: the names, brands, categories, colours, materials and seasons of your pieces, and, where a feature needs them, their sizes and prices. Most features see the colours, including the Daily Brief, the Styling Studio, the travel planner, inspiration analysis and “Is it worth it?”;
  • your saved outfits and your wear history (how often you have worn each piece, and any occasions you have noted);
  • your saved inspirations: the caption on each one, whether you typed it or it came from the page you saved it from, and the summary the stylist wrote of it;
  • your Style Manifesto, once you have one, for notes on how a look or a piece suits your style;
  • your wishlist — the name, brand, category, colours and, where you’ve saved one, price of pieces on your wishlist, sent to the Concierge clearly as pieces you’re considering, not pieces you own; and, for gap analysis, their names and brands and the reasons you’ve noted for wanting them;
  • the details of a wishlist piece you ask about — its name, brand, category, colours, materials, size and price, as each feature needs them — when you use “Will it fit?”, “Is it worth it?” or style it with your wardrobe;
  • your style profile, including the body shape and spending you have set. Gap analysis also sends the total you have spent on the pieces you own and, if you have not set a spending range, one worked out from their prices (what you typically pay, and what counts as a big buy for you);
  • what you type into a feature, such as your Concierge messages, a request in the Styling Studio, or the plans for a trip;
  • if you have connected Google Calendar, the title, time and location of your upcoming events;
  • today’s forecast, used by the Daily Brief, the Styling Studio, the Concierge and the short note written when you log a wear, or add a photo of one, that day; and, for the travel planner, the forecast for your trip and the destination you type in;
  • for “Will it fit?” on a wishlist piece, your height, weight, chest, waist, hips and shoe size, and up to 12 pieces you own with a size recorded, each by its category, name and size. For a piece with a brand, these are your pieces from that brand. For a piece without one, they are pieces from the same category, and no brand is sent;
  • for “Is it worth it?” on a wishlist piece, your height, chest, waist and hips — not your weight or shoe size.

Your measurements are sent only for those two features, never to the Concierge or any other feature. Your first name is never sent to the AI models — it is used only on your own screen. We never send your email address, name or payment details to the AI models, or anything beyond what is listed above.

Under Google Cloud’s terms for generative AI on Vertex AI, Google does not use what is sent, or its replies, to train its models. To answer faster, it may hold what is sent in memory for up to 24 hours, in the London data centre that answered; and it may log requests for a limited time, only to detect misuse of its service. Because the request comes from our server, Google does not receive your device’s IP address with it.

Your Concierge conversation is kept in your account so the chat keeps its context. You can clear it at any time in the chat, with Clear conversation.

Find this online

When you use Find this online on a photo of a piece, the app sends the photo, and the brand, name and category you’ve noted, to our own server in London. It needs the same agreement as the styling features. Then:

  • Google’s Gemini, on Google Cloud in London, describes the piece and suggests words to search for.
  • The search words, such as a brand, a product name and a colour, are sent to Brave Search. Your photo is not sent to Brave, and neither is anything that identifies you.
  • If the photo looks like a shop’s own picture, or the first search finds nothing, the photo is also sent to Google Cloud Vision, to look for the same picture on the web. Cloud Vision runs on Google’s global service, not only in London.
  • Our server then visits the shop pages those searches find, to check that they match. The shops see a visit from Atelier’s server, not from you. When we show you a listing, its pictures load from the shop’s own site, so the shop sees your device’s IP address, as with any web page.

Nothing from the searches is stored: not your photo, the search words or the results. We keep a count of how many searches you’ve made this month, a record of each request for fair use (see “Usage, fair use and fixing faults”), and the times of your recent searches.

The demo

You can try Atelier without an account at edit.myatelier.style/?demo=1. It opens a sample wardrobe. Anything you add or change stays in your browser and is gone when you reload. Nothing you do in the demo is saved to our servers, apart from the count below.

The demo’s AI features are live. If you agree to use them, the sample wardrobe and what you type or add are sent through our server to Google’s Gemini models, as described in “How the styling features use your data”. The demo has a daily AI allowance, and “Find this online” in the demo has its own. To hold them, our server keeps a keyed, salted hash of your IP address, not the address itself, with a count of the day’s requests that is deleted about two days later. The key changes every day and is deleted after about three days; from then on the hash can’t be linked back to your address.

The demo also keeps a few small records in your browser, such as your answer about the AI features and the day’s allowance (see “Cookies and similar technologies”). It shows London’s weather and never asks for your location.

Your membership and payments

When you join, you pay Lemon Squeezy, our Merchant of Record. Lemon Squeezy sells you the membership, takes payment, and handles invoices, sales tax and VAT. You give your card details to Lemon Squeezy, not to us; we never see or store them. Lemon Squeezy tells us:

  • your email address and name;
  • its customer, order and subscription references, and the plan and product you chose;
  • the state of your membership (on trial, active, cancelled, expired, refunded or unpaid) and its dates;
  • a short-lived link to your billing portal.

Its messages also include the amounts charged or refunded; we read them and don’t keep them. When the app opens the checkout for you, it passes your account identifier to Lemon Squeezy, so the membership lands on your account. If you pay before you have an account, we create one from your email address and name, and send you a sign-in link.

For taking payment, preventing fraud and meeting its own tax duties, Lemon Squeezy decides how your data is used and is responsible for it under its own privacy policy. Where it handles data for us, it does so under its data processing agreement with us.

Membership through Google Play

In the Atelier app for Android, you join through Google Play instead. Google Play takes the payment, with the payment method on your Google account; we never see or store your card details. For taking payment, preventing fraud and meeting its own duties, Google decides how your data is used and is responsible for it under its own privacy policy.

The app tells Google Play only which membership you chose. When you subscribe, and each time you sign in to the Android app, the app sends our server the purchase’s token: a code Google gives each subscription. Our server sends the token to Google to check the subscription and confirm it, and asks Google again each time Google tells us the subscription has changed. We keep:

  • a one-way fingerprint of the token, never the token itself, linked to your account identifier and your email address;
  • the plan you chose, monthly or annual, and any offer, such as the trial;
  • the state of your membership (on trial, active, in a grace period, on hold, paused, cancelled, expired or refunded) and its dates;
  • Google’s order reference, whether your membership renews, and whether the purchase was a test.

You manage or cancel it in Google Play; Manage subscription in Profile opens it there.

The Atelier letter

If you subscribe to our newsletter (the Atelier letter), we first send you a confirmation email. To confirm, you open its link and press Confirm my subscription on our site (double opt-in). The link works for seven days, and until you press the button you are not on the list. We keep your email address and the page you signed up from, with Resend (see “Who receives your data”). We process them on the basis of your consent, which you can withdraw at any time using the unsubscribe link in every letter or by emailing us.

We do not add you to the letter as part of signing up for the Service — it is always a separate, optional choice. For the same reason, deleting your Atelier account doesn’t unsubscribe you: use the link in any letter. And once you have unsubscribed, that is final while we hold the record of it — the sign-up form won’t write to you again, even if you use it yourself. If you want to come back, email us and we will take you off the list of people not to write to.

Shared links

If you create a public share of an outfit, a lookbook or a piece, the shared card (including a copy of the relevant item images) is stored so that anyone with the link can view it without signing in. The share also stores your display name and the date you shared it, and shows them on the page, as “Shared by” your name and the date. The name on your shared links can be changed or removed in Profile → Your data → Shared links; with no name, the page says “Shared from Atelier”. Treat a share link as public — anyone you send it to, or who obtains it, can open it, and see your name on it, until you delete the share.

If you choose to send a link to Pinterest or WhatsApp from the app, that service receives the link and the picture and words you share, under its own terms.

Reports about the AI’s words

If you use Report this reply, we keep what the AI wrote (up to 4,000 characters), the reason you chose, any note you add, where in the app it appeared, the app version and when you sent it, with your account identifier. We use them to look into the reply and to improve the AI features. Our own mailbox may also be told that a report has arrived: a notice with a link to the report, not its words.

Usage, fair use and fixing faults

To operate the Service, keep it reliable, and manage the cost of AI features, we record:

  • AI usage and cost records — for each account we log the number of AI requests you make, which feature they came from, and approximate token and cost totals. These are held against your account (not anonymised) and used to enforce fair-use limits and manage our costs.
  • Rate limits — the app keeps the times of your AI requests over the last day in your browser, to hold the per-minute and per-day limits. Our server also keeps the times of your recent AI requests and “Find this online” searches, for the same limits, and deletes them about two days after your last one.
  • Diagnostic information — error messages and basic performance data, kept by our providers so we can fix faults. Our server’s logs can include your account identifier and, when we invite someone, the address we invited. Our own code never writes what you type to the AI features, your photos or your IP address into them; Google’s standard request logs may record the IP address a request came from. When the app itself hits an error, it records what went wrong: the error’s message, where in the app it happened, the app version, and whether you were using the Android app, the installed app or a browser. That record holds nothing that identifies you (no account identifier, name, email or photos), and each one is deleted after 30 days.

We do not use Google Analytics, advertising trackers, behavioural-profiling tools, or third-party analytics scripts, and we do not track you across other websites.

Weather and your location

If you use the weather-aware features (such as the daily forecast or the travel packing planner), your device may ask your permission to share your approximate location. If you allow it, your coordinates, which your device first makes approximate (to one decimal place, about 11 km), or a place name you type, are sent to our weather provider (Open-Meteo) to retrieve a local forecast. For the travel planner, the destination you type is sent to Open-Meteo to find the place and its forecast. We do not store your location on our servers; forecasts are cached only in your browser. You can decline the browser permission, or turn it off later in your browser or phone settings, and still use the rest of the Service. In the Android app, Android asks for the permission in Atelier’s name, and for your approximate location only; you can change it in your phone’s settings for Atelier.

Your calendar

If — and only if — you connect your Google Calendar, Atelier reads your upcoming events to give the AI stylist context about your week, so it can suggest outfits suited to what’s actually on (a meeting, a dinner, a quiet day in). Specifically:

  • We request read-only access to your Google Calendar.
  • We use each event’s title, time and, where it has one, location solely to generate styling suggestions inside the app.
  • We never create, edit, delete, or share your calendar events, and we do not retain a copy of your calendar — events are read on demand and not stored.
  • The key that lets us read your calendar is kept on our server, where the app itself can’t read it.
  • You can disconnect at any time in Profile → Account → Calendar, which revokes our access and deletes the stored key.

Atelier’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you write to us

If you email us, we receive your email address and what you write, in our mailbox with Microsoft 365. We use it to answer you and, for a data protection request, to deal with it and keep a record of how we did.

Atelier on Instagram and Pinterest

We have accounts on Instagram (@myatelier.style) and Pinterest (MyAtelierStyle), and we may keep a Facebook Page, which Meta needs for us to schedule posts on Instagram. The icons at the foot of our website are plain links to them (see “Cookies and similar technologies”).

If you follow us there, save or comment on our posts, tag or mention us, or send us a message, we see what the platform shows us: your profile name and picture, and what you wrote. We use it to answer you and to look after the comments under our posts, on the basis of our legitimate interests. If your message is about your Atelier account, we’ll ask you to email us instead, so your account’s details stay off the platform. We don’t copy what we see into your Atelier account, match followers to members, or use any of it for advertising.

The platforms also give us statistics about our accounts: how many people saw, saved or clicked on a post, and broad figures such as the countries and age ranges of our followers. They don’t tell us who anyone is.

Instagram and Facebook are run by Meta, and Pinterest by Pinterest. Each decides how your data is used on its own service, under its own privacy policy: Meta’s and Pinterest’s. If we keep a Facebook Page, then for the statistics Meta gives us about it, Meta and we are joint controllers, under Meta’s Page Insights Controller Addendum: Meta takes primary responsibility for them, and you can exercise your rights over them with Meta or with us.

Comments and messages stay on the platform, where you or we can delete them. We keep a copy only when we need one to deal with what you asked, as we do with emails you send us.

Who receives your data

We don’t sell your data, and we don’t share it with anyone for their own marketing. These providers handle it to run the Service. Unless the table says otherwise, each acts as our processor: it may use your data only on our instructions, under a contract that requires it to protect it.

Who What they do Where, and on what terms
Google (Google LLC and Google Ireland Limited) Firebase and Google Cloud: sign-in and sign-in emails, the database, photo storage, our server functions, hosting the app, and bot protection (App Check with reCAPTCHA). Gemini on Vertex AI, for the styling features and “Find this online”. Cloud Vision, for “Find this online”. Google Play, for a membership bought in the Android app The database: the EU (Belgium and the Netherlands). Photos, our server functions, and Gemini: London. Cloud Vision: wherever Google has facilities, including the United States. Under Google’s data processing terms for Firebase and Google Cloud. For taking payment in Google Play, a separate controller, under its own privacy policy
Lemon Squeezy (Sold through Link, LLC, formerly Lemon Squeezy LLC, a Stripe company) Our Merchant of Record: sells you the membership, takes payment, and handles invoices, sales tax and VAT The United States. For payment, fraud and tax it is a separate controller, under its own privacy policy; for what it tells us and does for us, under its data processing agreement
Resend (Plus Five Five, Inc.) Sends our emails: the letter and its confirmation, invitations, the notice before a lapsed membership’s data is deleted, and a notice to our own mailbox when you report something the AI wrote (a link to the report, not its words). Keeps the letter’s list The United States. Under its data processing agreement
Cloudflare (Cloudflare, Inc.) Delivers our website, myatelier.style, and runs its small server functions: the letter’s sign-up and confirmation, and the messages Lemon Squeezy sends us about your membership Cloudflare’s global network; a US company. Under its data processing terms
Microsoft (Microsoft Corporation) Our mailbox, [email protected] (Microsoft 365) Under Microsoft’s data processing terms
Open-Meteo (OpenMeteo GmbH) Weather forecasts. Your browser sends it your approximate location or the place you type, with your IP address Switzerland. Under its own terms, which say its server logs are deleted after 90 days
Brave (Brave Software, Inc.) Web search for “Find this online”. Our server sends it the search words only The United States. Brave says it keeps them for up to 90 days, for billing and troubleshooting, and does not link them to a person
Microlink (microlink.io) When you paste a product link, your browser sends the link, without its tracking tags, to Microlink, which reads the product’s name, description and picture Under its own privacy policy. It receives your IP address
img.ly (IMG.LY GmbH) The background-removal tool. Your browser downloads it from img.ly’s servers, which see your IP address. Your photos are processed on your own device and are not sent to img.ly Germany. Under its own privacy policy
Google Fonts (Google) Our typefaces, on the website and in the app. Your browser requests them from Google, which receives your IP address and basic browser information Under Google’s own privacy policy
images.weserv.nl A public image service. If a shop’s picture won’t load directly when the app draws a share card, your browser fetches it through this service, which receives the picture’s address and your IP address Under its own terms

reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.

Others who may receive your data:

  • Shops. When the app shows a shop’s picture (when you import a link, or in “Find this online”), your browser loads it from the shop’s site, which sees your IP address. Our own server also fetches shop pages and pictures, as “AtelierBot”, so the shop sees our server rather than you.
  • Anyone with one of your share links, as described under “Shared links”.
  • Authorities, if the law requires us to share something with them.

Transfers outside the UK

Some of your data leaves the UK. Where UK law treats that as a restricted transfer, it is covered by one of these:

  • Adequacy. UK regulations recognise the countries of the European Economic Area, and Switzerland, as protecting personal data adequately. This covers our database in Belgium and the Netherlands, img.ly in Germany and Open-Meteo in Switzerland.
  • The UK–US data bridge. The UK Extension to the EU–US Data Privacy Framework covers US companies certified under it. Google, Cloudflare, Resend and Microsoft are certified.
  • The UK’s transfer contracts. For anything the data bridge doesn’t cover, we rely on the contracts UK law recognises for a restricted transfer: the International Data Transfer Agreement (IDTA), or the UK Addendum to the European Commission’s standard contractual clauses. Our providers’ data processing terms — Google’s, Cloudflare’s, Resend’s and Microsoft’s — carry one of these, in practice the UK Addendum, which is what a company that already offers the EU clauses adds for the UK.
  • Lemon Squeezy’s transfer contract. For what we exchange with Lemon Squeezy about your membership, we rely on its data processing addendum, which carries the European Commission’s standard contractual clauses together with the UK International Data Transfer Addendum to them. Lemon Squeezy is Link, LLC, a Stripe company; Stripe, Inc. is certified under the Data Privacy Framework, but it is that addendum, not the certification, that covers Lemon Squeezy and us.

When you pay, you give your details to Lemon Squeezy in the United States directly, under its own privacy policy. In the Android app, you pay Google Play directly, under Google’s privacy policy. Brave receives only search words, which don’t identify you.

You can ask us for a copy of the safeguards for any of these providers.

Where your data is stored

  • Wardrobe data is stored in Firestore (Google Cloud), in Google’s EU multi-region (Belgium and the Netherlands).
  • Photos of your pieces are stored as files in Firebase Storage (Google Cloud), in a folder under your account, in Google’s London region (europe-west2). Only you can open that folder from the app. Each photo is shown through a long, unguessable link; the app never publishes these links, but anyone who had one could open that photo. Photos added before 11 September 2026, or whose upload could not finish (for example, offline), stay inside your wardrobe records in Firestore, as do inspiration images and photos of a look as worn. Background-removed and cropped copies of your photos are also kept in Firebase Storage.
  • Authentication data is held by Firebase Authentication (Google Cloud).
  • Payment data is held by Lemon Squeezy in their own systems or, if you join in the Android app, by Google.
  • On your device, the app keeps copies of some of this so it works quickly and offline (see “Cookies and similar technologies”).

We do not maintain our own database servers.

How long we keep your data

  • While your membership is active: we keep your data so you can go on using the Service. If you use Atelier at our invitation rather than with a membership, we keep it until you delete your account or ask us to.
  • After your membership ends: your account stays fully open for the rest of the period you have paid for. After that, your studio stays open to you read-only for 30 days: you can sign in, see everything and export it, but not add or change anything. We email you at least a week before we delete anything. At the end of the 30 days, or on the later date given in that email, we permanently delete your wardrobe, photos, shares and the other records listed below as “deleted with your data”, unless you have rejoined in the meantime.
  • If a payment fails: nothing closes at once. Lemon Squeezy writes to you — five emails over about three weeks — asking you to update your card, and updating it settles the payment and opens everything again. You keep full access at first; if the payment is still outstanding after that, your studio becomes read-only for the rest of the three weeks. Nothing is deleted in that time. If the three weeks pass with the payment still unmade, Lemon Squeezy cancels your subscription, your membership ends at that moment, and the 30 read-only days above begin.
  • If a Google Play payment fails: you keep full access during Google’s grace period. If Google still cannot take the payment, it puts your subscription on hold, and your studio becomes read-only; nothing is deleted while it is on hold, and paying opens everything again. If the subscription then ends, the 30 read-only days above begin.
  • If you are refunded in full: a full refund ends your membership, and full access, at once rather than at the end of the period; the 30 read-only days above then begin.
  • If you delete your account: you can do this from Profile → Your data → Delete account at any time. Your data, photos and shares are erased straight away, and a Lemon Squeezy subscription is cancelled. A Google Play subscription is not: you cancel it in Google Play (see “Deleting your account” below).
What How long
Your wardrobe, photos, looks, profile and everything else you add Until you delete it, or until your data is deleted as above
Items in the Trash 30 days, then removed for good the next time you open Atelier. The photo files of a deleted piece stay in your private folder until your data is deleted
Your Concierge conversation Until you clear it, or your data is deleted
AI usage and cost records, and your “Find this online” count Deleted with your data
The times of your recent AI requests and “Find this online” searches About two days after your last one
Reports about the AI’s words Deleted with your data
Your calendar connection Until you disconnect it, or your data is deleted. The events themselves are never stored
Public shares Until you delete them, or your data is deleted. Shares made before 10 September 2026 are not linked to your account, so they stay until you delete them or ask us to
The demo Nothing on our servers, except for “Find this online”: the day’s count, about two days, and the day’s key, about three days
Your sign-in account and membership records, once your data has been deleted after a membership ends Your email address, name and account identifier; Lemon Squeezy’s references or, for Google Play, the fingerprint of your purchase; your plan, and your membership’s state and dates; your invitation, if you had one; and our note of when your data was deleted. We keep these so you can sign in and rejoin, and as a record of your membership, until you delete your account or ask us to
The Atelier letter While you’re subscribed. After you unsubscribe, the suppression record described below
Our accounting records Six years from the end of the financial year they relate to, as HMRC requires. Lemon Squeezy keeps its own billing records under its privacy policy
Emails you send us For as long as we need them to deal with what you asked, and to show how we handled a data protection request
Comments and messages on our Instagram and Pinterest accounts On the platform, until you or we delete them. A copy only if we need one to deal with what you asked, kept as emails you send us are
Our server logs Google keeps our server functions’ logs for 30 days

The Atelier letter: while you’re subscribed, we keep your email address and the page you signed up from. If you unsubscribe, we keep your email address, marked as unsubscribed, so we never write to you again by mistake; Resend keeps the page you signed up from with it. We also keep a record of our own: a one-way fingerprint of your address and the date you left, and nothing else — not your address in the clear, not your name, not where you signed up. We check that record before the sign-up form sends anything, so if your address is entered again, by you or by anyone else, no email goes out. That is a suppression record, and we keep it because we need it to honour your objection: it is kept for as long as we send the letter at all, and it does not go when you close your Atelier account, because the letter and the account are separate things. You can ask us to erase even that; we will, but we then can’t guarantee we won’t write to you if your address is entered again.

Your rights

You have these rights over your personal data. Most you can use in the app; for any of them you can email [email protected].

  • Access — ask for a copy of the personal data we hold about you. The backup described under “Portability” gives you your wardrobe at once, in a file. It is not everything we hold: your membership records, your sign-in history, the reports you’ve sent us about the AI’s words, your AI usage records, and what our server logs hold against your account all sit outside it. Email us and we’ll send you those too. (Our record of an app error deliberately holds nothing that identifies you, so there is nothing in it to find under your name.)
  • Rectification — correct anything inaccurate or incomplete. You can edit your wardrobe, style profile and measurements in the app. To change the email address or name on your account, email us.
  • Erasure — ask us to delete your data. You can delete your account yourself (see “Deleting your account” below).
  • Restriction — ask us to pause using your data, for example while we check something you’ve said is wrong.
  • Portability — take your data with you. Profile → Your data → Backup & export → Download backup gives you one file (JSON) with your pieces, looks, inspirations, shops, profile, measurements and Concierge conversation, with your photos included where they can be fetched. In the 30 read-only days after a membership ends, Export your wardrobe does the same.
  • Withdrawing consent — at any time, as easily as you gave it: the AI features in Profile → Your data → The Concierge and your data → Withdraw agreement; your calendar in Profile → Account → Calendar → Disconnect; the letter with the unsubscribe link in any letter; location and notifications in your browser or phone settings.
  • Automated decisions — not to be subject to a significant decision made solely by automated means without safeguards. We make none (see “Automated decisions and profiling”).

We will answer within one month of receiving your request, or of confirming who you are if we need to. If a request is complex, or you’ve sent several, we may take up to two further months, and we’ll tell you within the first month. There’s normally no charge. We may ask you to confirm your identity, usually by writing from the email address on your account.

Your right to object

You can object at any time to our using your data on the basis of our legitimate interests (the rows marked so in the table above). Tell us why, and we’ll stop unless we have compelling grounds that override your interests, or need the data for a legal claim.

You have an absolute right to object to direct marketing. The Atelier letter is the only marketing we send. Use the unsubscribe link in any letter, or email us, and we will stop.

Deleting your account

You can permanently delete your account and its data from within the app (Profile → Your data → Delete account → Delete my account), or by emailing us. Deletion removes your wardrobe, photos, outfits, Concierge history, public shares, reports about the AI’s words, calendar key, your sign-in account and your membership records from our systems straight away. Please note:

  • A Lemon Squeezy subscription is cancelled too. Deleting your account cancels your Lemon Squeezy subscription, so you are not billed again. It does not by itself refund a period you have already paid for; see “Refunds” in our Terms.
  • A Google Play subscription is not. Deleting your account doesn’t cancel a membership you took out in the Android app: only you can, in Google Play, under Payments & subscriptions. If it could still bill you, the app tells you so before you delete your account, with a link to Google Play. Cancel it there first, so you aren’t billed again.
  • Public shares made before 10 September 2026 are not linked to your account, so they are not removed. Delete any of those you no longer want before closing your account, or ask us to remove them.
  • The Atelier letter is separate: deleting your account doesn’t unsubscribe you.
  • We keep the records the law requires (for example, accounting records). We also keep a one-way fingerprint of your email address with the date you deleted your account, so that a late renewal from Lemon Squeezy can never quietly recreate your account, and the reference numbers of the payment messages we’ve already handled. Our server logs expire as above.

Automated decisions and profiling

Atelier builds a picture of your style from your wardrobe. In data protection terms that is profiling. The Style Manifesto, the Concierge, the Daily Brief, gap analysis and “Will it fit?” do it with Google’s Gemini, from what you’ve added. Today’s Pick, Style DNA and your fit profile do it in the app on your device, from your pieces, the weather, what you’ve worn lately and your measurements.

All of them make suggestions, for you to take or leave. None of them makes a decision about you with a legal or similarly significant effect: nothing about your price, your access or your membership depends on them, and nobody else sees them. You can turn the AI features off at any time by withdrawing your agreement in Profile → Your data → The Concierge and your data; the suggestions worked out on your device carry on.

Cookies and similar technologies

Under the Privacy and Electronic Communications Regulations, a service may store or read information on your device without asking when it is strictly necessary to provide what you asked for, including keeping it secure, or when it only remembers how you’ve chosen the service should look or work, as long as you’re told and can object (ICO guidance).

Nothing we store is used for advertising, for analytics, or to follow you across other sites, which is why there’s no cookie banner. Here is everything the app keeps on your device.

One line in the table below is not ours, and deserves saying plainly: reCAPTCHA. The app is protected by Firebase App Check, which uses Google’s reCAPTCHA v3 to tell a real visitor from a bot. It starts with the app itself, before you sign in and before the app knows who you are — so it runs for someone with no account at all: anyone who opens the demo, and anyone who opens a shared link you send them. reCAPTCHA sets a cookie of Google’s own, and reads what your browser and device look like — the user agent, the screen, the plugins, how the page is used — and sends that to Google, which scores how likely the request is to be a bot. Google receives your IP address with it.

We use it for one thing: keeping bots out of the app, and off the AI features we pay for by the request. Google’s score is used to let a request through or refuse it, and nothing else. We don’t get a profile of you from it, we don’t use it for advertising or analytics, and no part of it follows you to other sites for us.

Why we haven’t asked you first. We treat this as strictly necessary for the security of the service, which is the exception the regulations allow. That is a judgement, and we’d rather show it than assert it: it is a stronger one for a member using her own wardrobe than for a stranger who opened a share link and never asked us for bot protection. We have put it in front of you here rather than burying it, and whether reCAPTCHA remains the right tool for the pages a visitor with no account can reach is a question we keep open. If it changes, this page changes with it.

What Why How long
Your sign-in (Firebase Authentication, in your browser’s storage) Keeps you signed in Until you sign out
Your email address, while a sign-in link is on its way Lets the link finish signing you in on this device Until you finish signing in
App Check and reCAPTCHA v3 (Google) Checks that requests come from the real app and not a bot. reCAPTCHA sets its own cookie and reads information about your browser and device, and Google receives your IP address with it. It starts before you sign in, so it runs for every visitor, including the demo and share pages Set by Google
A copy of your wardrobe (Firestore’s offline copy) So the app opens quickly, works offline and never loses a save Until you sign out
The app’s files, and copies of your photos So Atelier opens quickly and works offline Photos of your pieces up to a year; cut-outs and share cards 30 days. Signing out clears the cut-outs and cards, not the photo copies
Your answer about the AI features So you aren’t asked again on this device Until you change it
The times of your AI requests over the last day; in the demo, the day’s allowance The fair-use limits A day
Today’s look, and the last few So the Daily Brief isn’t composed twice, and doesn’t repeat itself Replaced as the days go by
The last forecast Saves asking for it again. No location is stored An hour
A note that the app has just reloaded after an update So it reloads only once Until you close the tab
Your sort order, grid or flat-lay view, and whether you’ve seen the tour, the install prompt and the reminders question Remember what you chose Until you change it
A note for each day a reminder appears, if you allow notifications So each reminder appears only once Kept on your device
Shops whose pages or pictures wouldn’t load So the app stops retrying them for a while Until the pause ends
Notes of any save that was slow Shown to you in Profile → Your data, where you can clear them. Never sent anywhere Up to 25, until you clear them
Firebase’s usage record The Firebase software notes the days it was used, and tells Google with its requests which versions of its software are in use Kept by the Firebase software

On our website, myatelier.style, we set no cookie of our own, and none of our own pages runs reCAPTCHA — the website carries no Firebase and no App Check at all. The only thing stored is a note, for as long as the tab is open, so the logo’s animation plays once per visit. The Instagram and Pinterest icons at the foot of every page are plain links: nothing loads from either service, and neither learns of your visit, until you follow one. The page about the Studio shows the live demo inside it; when you scroll to it, the demo loads as it would at edit.myatelier.style, with its reCAPTCHA and its storage. Lemon Squeezy’s checkout runs on Lemon Squeezy’s own site, with its own cookies.

Some features ask your device’s permission before they run, and you can decline any of them:

  • Location — for weather and travel features (see “Weather and your location”).
  • Notifications — optional reminders, such as a look you have planned for tomorrow. The app asks once you have added a few pieces, and shows nothing unless you allow it. Reminders appear when the app is open; we don’t send them from a server. In the Android app, Android asks for this permission in Atelier’s name.
  • Camera / photos — to add items by photo.

To object to any of it, change the choice in the app, or clear this site’s data in your browser settings (you’ll be signed out).

Children’s data

Atelier is for adults. Our Terms require you to be 18 or over to have an account, and the service is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe someone under 18 has given us personal data, please contact us and we will delete it.

Security

We take appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (HTTPS / TLS) for all data
  • Encryption at rest, by Google, for everything stored in Firebase and Google Cloud
  • Security rules on our database and photo storage, so that each account can reach only its own data, and records that only our server may use can’t be read from the app at all
  • App Check with reCAPTCHA, which keeps bots away from the app, and which our search and shared-link functions check before they answer
  • Cryptographic signature checks on every message from Lemon Squeezy
  • A check with Google of every message from Google Play, before anything changes

No system can guarantee absolute security, but we work to minimise risk and respond promptly to any incident. If a breach is likely to put your rights at high risk, we will tell you without undue delay.

Complaints

If you’re unhappy with how we’ve handled your data, please tell us first, at [email protected]. We will acknowledge your complaint within five working days, look into it, keep you told of our progress, and give you our answer within one month of receiving it. If it turns out to be complex, we may need up to two further months; we’ll tell you so within that first month, and say why.

You also have the right to complain to the UK Information Commissioner’s Office, the regulator for data protection: at ico.org.uk/make-a-complaint, or on its helpline, 0303 123 1113. If you live in the European Union, you can also complain to the data protection authority where you live or work.

Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated via email to active subscribers and posted prominently on this page. If a change would mean sending something new to the AI features, the app asks for your agreement again before anything more is sent. The “last updated” date at the top reflects when changes were last made.

How to contact us

For any privacy questions, data requests, or concerns, please contact:

Email: [email protected]

We aim to respond to all data-protection enquiries within five working days.

Atelier.

A private stylist for the wardrobe you own.

Coming to Google Play

The House

  • About
  • Studio
  • Manifesto
  • Journal
  • Pricing
  • The letter

Membership

  • Open Studio
  • Manage subscription

Help

  • Help & support
  • Privacy
  • Terms
  • Security
  • Accessibility

The Atelier letter

Occasional essays on dressing well from what you already own.

Unsubscribe anytime.

© MMXXVI Atelier · A product of Talastron Ltd, registered in England & Wales Company no. 15464691 · VAT no. GB 463 5874 58 · ICO registration ZB804967 · Registered office: The Long Barn, Cobham Park Road, Cobham, Surrey KT11 3NE

Back to top