Privacy Policy

Atelier Order Book — last updated 8 August 2026

Atelier Order Book is order, invoicing and inventory software for small leather-goods studios, operated by Arnaud Rouillot Consulting, a sole proprietorship registered in British Columbia, Canada ("we", "us"). This policy explains what the application stores, why, and what happens to data from a Google account you choose to connect to it.

1. Who this policy covers

The application is used by a studio (the "customer") and the people that studio gives accounts to (the "user", "you"). Records the studio enters about its own clients are the studio's data; we process them only to run the service on the studio's behalf. If you are a client of a studio using this application and want to know what it holds about you, contact that studio — they control those records, not us.

2. What the application stores

  • Account data — your email address, your name, a salted password hash (never the password itself), and your email signature.
  • Business records you enter — clients and their contact details, orders and line items, invoices and payments, materials and stock levels, company settings and letterhead.
  • Files you upload — documents and images attached to an order, stored as files on the server that runs the application.
  • An audit log — a record of security-relevant events such as connecting or disconnecting a mailbox.

The application sets a session cookie so you stay signed in. It sets no advertising or analytics cookies, and it runs no third-party trackers.

3. Google user data

Connecting a Google account is optional; the application is fully usable without one. If you connect one, you are asked to grant these permissions, and nothing more:

PermissionWhat we do with it
gmail.modify Read messages and conversations in the connected mailbox so they can be shown next to the matching client, and set read state or move a conversation to the Gmail trash when you triage it. This permission cannot permanently delete mail, and the application deliberately exposes no permanent-delete action anywhere.
gmail.send Send the messages and replies you compose in the application. It sends nothing you have not explicitly submitted.
calendar Read, create and update calendar events so they appear on the application's month view and can be edited there.
userinfo.email / openid Record which Google account was connected, so the application can show it and you do not have to type it.

We deliberately do not request the full https://mail.google.com/ scope, which would grant unrestricted mailbox access including permanent deletion.

From a connected mailbox we store, in the application's own database: message headers (sender, recipients, subject, date), message bodies, attachment files, conversation and message identifiers, and read/trash state. From a connected calendar we store event titles, descriptions, times, locations and attendees. Only mail and events within the sync window the studio configures are retrieved.

Limited Use

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • Google user data is used only to provide and improve the features described above, which are visible to you in the application.
  • We do not sell Google user data, and we do not use it for advertising, ad targeting, credit assessment, lending, or any similar purpose.
  • We do not transfer Google user data to third parties except as needed to provide the features above, to comply with applicable law, or as part of a merger or acquisition after notice to affected customers.
  • No human at Arnaud Rouillot Consulting reads your mail or calendar data, except with your explicit permission to resolve a support issue you raised, where required by law, or where necessary for security or abuse investigations — and in aggregated, anonymised form.

4. Artificial intelligence features

The application offers two optional AI features: drafting a suggested reply to an email conversation, and rendering a product image from an order's description. They are off unless the studio enters its own API key for a model vendor.

  • Reply drafting sends the text of the conversation you are replying to, plus your signature, to the configured text-model vendor (OpenAI by default). Image rendering sends the order description and any reference images you select to the configured image-model vendor (Google Gemini by default).
  • Nothing is sent to a vendor unless you press the button that requests it, on the conversation or order you are looking at.
  • Vendor API keys are stored encrypted and are never displayed back in full.
  • A generated draft is placed in the compose box for you to edit. The application never sends a message on its own.

Data sent to a model vendor is subject to that vendor's terms. A studio that does not want its mail leaving the application should simply not configure an AI key.

5. How data is stored and protected

  • Google OAuth tokens are encrypted at rest with Fernet (AES) using a key held in the deployment's environment, never in the database and never in source control. AI vendor API keys are encrypted the same way.
  • All application traffic is served over HTTPS in production.
  • Sign-in is required for every view. Passwords are stored only as salted hashes.
  • Each studio is a separate tenant; every database query is filtered by the signed-in user's company, so one studio cannot read another's records or mail.
  • Session cookies are marked SameSite=Lax, and every form that changes data carries a CSRF token.

No system is perfectly secure. We do not warrant that a breach is impossible, and we will notify affected customers without undue delay if one occurs.

6. Who else sees the data

We do not sell data. It is shared only with:

  • Google — for the mail and calendar features you connect, and, if enabled, image generation.
  • The configured AI vendor — only for the AI features described in section 4, only when triggered.
  • The hosting provider that runs the deployment.
  • Authorities, where we are legally required to disclose.

7. Retention, and how to delete your data

  • Disconnect a mailbox or calendar in Settings → Email/Calendar. This deletes the stored OAuth tokens immediately and stops all further syncing.
  • Revoke access from Google's side at any time at myaccount.google.com/permissions. Access ends whether or not you tell us.
  • Delete everything. Email the address in section 10 and ask for deletion of your account and its data. We will delete the studio's records, stored mail and calendar copies, uploaded files and audit log within 30 days, except where law requires us to retain something (invoicing records, for example, carry statutory retention periods in Canada).
  • Data that is still in use is kept as long as the studio's account is active, because it is the studio's working records.

8. Your rights

We are established in British Columbia, so British Columbia's Personal Information Protection Act (PIPA) governs how we handle personal information, and Canada's federal PIPEDA applies to personal information we handle across provincial or national borders. Under both, you may request access to the personal information we hold about you, ask for it to be corrected, withdraw consent, or ask that it be deleted. Write to the address in section 10; we respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner for British Columbia, or to the Office of the Privacy Commissioner of Canada.

9. Children

The application is business software and is not directed at children. We do not knowingly collect personal information from anyone under 16.

10. Contact

Arnaud Rouillot Consulting
British Columbia, Canada
arnaud.rouillot@gmail.com

11. Changes to this policy

We may update this policy as the application changes. The "last updated" date at the top reflects the current version, and material changes will be announced in the application before they take effect.

See also the Terms of Service.

v0.8.0 · Privacy Policy · Terms of Service